CrypographyTateAPr5v2ReportDrK18-Sep-2019.docx

Running head: Cryptography 1

Cryptography 16

Cryptography

Aisha Tate

UMUC

August 29, 2019

Hi Aisha

I am puzzled – didn’t we talk about a focused report for a particular organization? Did you review the table below. Please continue to work to improve your research skills and find peer-reviewed/scholarly resources to support your work.

Best wishes,

Dr K

Student Name: Aisha Tate

 

Date: 18-Sep-2019

 

This form provides the same classroom instructions in a checklist form to help students and professors quickly evaluate a submission

 

Project 5: Requires the Following TWO Pieces

Areas to Improve

1. Paper

 

2. Lab Experience Report with Screenshots

 

1. Paper

 

IT Systems Architecture

 

You will provide this information in tabular format and call it the Network Security and Vulnerability Threat Table

 

security architecture of the organization

 

the cryptographic means of protecting the assets of the organization

 

the types of known attacks against those types of protections

 

means to ward off the attacks

 

Include and define the following components of security in the architecture of your organization, and explain if threats to these components are likely, or unlikely:

 

LAN security

 

identity management

 

physical security

 

personal security

 

availability

 

privacy

 

Then list the security defenses you employ in your organization to mitigate these types of attacks.

 Needs better research and writing skills

Plan of Protection

 

Learn more about the transmission of files that do not seem suspicious but that actually have embedded malicious payload, undetectable to human hearing or vision. This type of threat can enter your organization’s networks and databases undetected through the use of steganography or data hiding. You should include this type of threat vector to an organization in your report to leadership.

 No details on organization or strategy?

Provide the leadership of your organization with your plan for protecting identity, access, authorization and nonrepudiation of information transmission, storage, and usage

 

Data Hiding Technologies

 

describe to your organization the various cryptographic means of protecting its assets. descriptions will be included in the network security vulnerability and threat table for leadership

 Basic elements explained

Encryption Technologies

 

1. Shift / Caesar cipher

 

2. Polyalphabetic cipher

 

3. One time pad cipher/Vernam cipher/perfect cipher

 

4. Block ciphers

 

5. triple DES

 

6. RSA

 

7. Advanced Encryption Standard (AES)

 

8. Symmetric encryption

 

9. Text block coding

 

Data Hiding Technologies

 

1. Information hiding and steganography

 

2. Digital watermarking

 

3. Masks and filtering

 

Network Security Vulnerability and Threat Table

 

Describe the various cryptographic means of protecting its assets. descriptions will be included in the network security vulnerability and threat table for leadership

 Basic information provided

Encryption Technologies

 

1. Shift / Caesar cipher

 

2. Polyalphabetic cipher

 

3. One time pad cipher/Vernam cipher/perfect cipher

 

Access Control Based on Smart Card Strategies

 

Describe how identity management would be a part of your overall security program and your CAC deployment plan:

 

2. Lab Experience Report

 

Summarizes the Lab Experience and Findings

 See note below*

Responds to the Questions

 

Provides Screenshots of Key Results

 Yes

Lab Experience Report Feedback

 

Cryptography

Introduction

This is a security assessment report on cyber security threats against varying cryptographic mechanisms, and sets out control access programs to try to stop/inhibit such security threats for a property management firm. Within the report, there will be an overview of the property management firm’s network. Moreover, I will try to establish the different potential threats that the company faces. This report will also feature suggestions for improvement such as the property management company needs to consider the installation of stored information protection features, as well as controlling the access of its employees. Perhaps, the report will also explain the enrollment of CAC (Control Access Cards) for authentication purposes????. Then lastly, the report will cover email security and encryption types that can be used to aid in email security.

IT System Architecture

A distributed system is the network system used within our company’s offices. The constituents of this system includes WLAN, LAN and a WAN. The office’s LAN is made up of a computer network across a small office area. LAN is mainly used for one purpose within the office: sharing of resources, which includes printers and data storage infrastructures. These connections are wired due to physical connections being fast, they are also characterized for security enhancement. The purpose of the WAN network is to function as an interconnection of the office’s LAN for the entire firm. The primary advantage of this system is that the firm’s agents and employees can work from different workstations yet have the access to shared company’s resources (Pirandola, 2015). The LAN also is also connected to the internet through a firewall to further, protect the integrity of the firm’s network. All of the firm’s offices are connected to WLAN, this allows the firm’s agents to connect there devices (i.e. phones and laptops) to access to important company resources via the LAN.

LAN security

This is a wireless transmission network that covers a small network area via private VLANs

Identity management

This is a discipline in it system management that ensure only the allowed people have access to specific resources and their intentions are not malicious.

Physical security

It is the installation of policies to physical threats that could lead to destruction of the organization’s hardware and software like theft.

Personal security

This involves the personal responsibility of the employees of the organization to safeguard the systems data and information.

Availability

It’s the state of the organization being readily accessed when needed.

Privacy

Is the quality of being reclusive in regard to keeping your or the company’s information confidential

Table 1: components of security system architecture

Types of attacks

A cyber-attack is a deliberate use of codes to manipulate computer systems and networks in an attempt to manipulate and compromise the confidentially of certain information (Bennett, 201). Perhaps there are different motivations behind every cyber-attack, such as political or social motivations. The targets can also vary, places such as a corporate organization, the government or an individual might be targeted by malevolent entities. The important factor is the internet is the main channel through which this happens. Cybersecurity attacks are carried out by use of malicious programs like fake websites, viruses, and unauthorized web access among many other means. The intention can be either for financial gain or for boosting the ego of the perpetrator through causing harm to a victim.

From the article, “Types of attacks”, we learn of the examples and definition of the different types of cyberattacks.

1. Back door attack – this is a type attack where an attacker takes advantage of the vulnerabilities and flaws of a system though use of viruses, worms and Trojan horses to gain access into system after which he sets up a backdoor (Bennett, 2014). This allows him access to important information without the administrator realizing.

2. Denial of service. This can be abbreviated as DDoS. Denial of service attack is carried out by numerous systems relaying ICMP packets to a server. The objective of this attack is preventing access to a certain site to due to an overload of traffic. This type of attack is one most problematic for us, as agents of a property management firm. The main source of leads and traffic is the website, where clients get to know our services and can thereafter reach out. Therefore, sometimes competitors might want to employ this ill-natured strategy to deter clients from having the ability to reach out to us.

3. Phishing – This is an attack where something malicious is sent through the email. At most times, they will send out a link and request you to click on it (Peikert, 2016). Most times, a link will be sent in an email requesting that a user click on it these emails will try to eliminate all sources of suspicion by making it look as genuine as possible. There are circumstances in which you might be directed to download something; this could be as innocuous as antivirus software or downloading a movie. Just as the other types of security attacks, phishing is another attack a property management firm can be exposed to if not careful. Our workstations would be the primary targets of this attack, in the hopes of deteriorating our network safeguards. Since most of our server, information contains details on our clients; such events might lead to the tarnishing of the name of the firm leading to reduced client flow.

4. Use of SQL – This is a programming language, which facilitates communication with the database. When an attacker uses SQL, he or she will send out malicious codes, which will lead to your database giving out more information than what it is usually meant to share (Van Tilborg, 2014). The attacker will do this by taking advantage of the commonly identifies SQL vulnerabilities.

5. Cross-site scripting. This is abbreviated as XXS. This kind of attack is targeted at vulnerable websites with weak security systems for attaining user credentials or other classified information. Just as the SQL, XXS is also carried out by use of malicious codes. In XXS, the site is not the primary target but rather its visitors (Van Tilborg, 2014). As a property management firm, our clients who have accounts/portals on our website are the ones who could fall prey of such as attack. This is because on registration with the firm, a client is required to submit confidential information about one’s property and oneself, which is meant to be confidential between the firm and the client.

Security mechanisms

A security mechanism consists of policies and that are meant to detect, inhibit or recover from a security threat posed by an attacker. Example of security mechanism include:

1. Physical security – This is a mechanism that requires installation of physical barriers to restrict access to crucial network resources. This can include the installation of RFID doors and the policy of who is granted access and who is not. The advantage of this is to prevent mishandling of equipment by new unskilled agents and to prevent criminal access.

2. Authentication – Authentication means that the information given by a person on his or her identity is true (Katz, 2014). These guidelines can be as deep as a three-tiered identification process requiring a valid password, an active key, and approved fingerprints before being authenticated. It is widely accepted that a strong authentication process is one that involves the incorporation of two or more of the prior mentioned three authentication procedures. The last means of authentication is assessment of a certain physical character trait (Katz, 2014)

3. Authorization mechanism – This involves giving the user access to the network and whichever resource they might want to retrieve. The administrator of the network is the person sanctioned with the power to grant access to the network to approved employees and contractors for the property management firm. The managing broker of the firm will be given access to all information on the network. On the other hand, the agents of the firm will only have access to shared data and data/information that they themselves have uploaded on their personal portals in the network.

4. Data encryption – This is the formatting of information in a way that only the intended person can decode it. This is done to protect information from being intercepted and read by third parties who might use the same information for hostile reasons. This mechanism may come in handy in future efforts to strive towards an absolute safeguard of customer data.

5. Firewalls – Firewalls enhances security policies by acting as a boundary of two communicating networks. Use of various sets of instructions is what is used by firewalls in deciding which of the incoming traffic will be granted access and which are not.

6. Intrusion detection system and intrusion prevention system – These security mechanisms are used to inhibit security risks and prevent occurrence of new ones. An IDS makes use of intrusion alerts to sense and analyse outbound and inbound network traffic for suspicious undertakings (Rouse, 2017). In case of an event of suspicious activity, the IDS kicks the users out of the network accompanied by a notification to the security personnel of the potential threat. The IDS works by examining incoming traffic to reject harmful requests, doing this in tandem with the IPS as a complimentary. The IPS averts threats by uncovering malicious packets and blocking these packet carrying IPs and notifying the security personnel of the incidence. The property management firm needs to continue utilising both IPS and IDS in its 24/7 operations to ensure enhanced security of the network, below is a table showing access points and how they can be secured.

Protection Plan

Security and protection of client’s information and assets is one of our top priorities. So far, we have looked at the system architecture of the property management firm, and the potential types of cybersecurity needed by the firm, along with the various types of mechanisms that can be deployed. The next important step is the formulation of a protection plan, a multi-tier system that will aid in the firm’s identification process. The firm’s agents will be provided with personnel security cards, as well as the installation of retina identification systems at major access points to the company’s network. Along with the distribution of the personnel security cards, agents will be required to devise a PIN, which will be used complimentary to the cards. These PINS created by the agents will be classified as sensitive information, as such it will be expected that no one is to share them with third parties. Moreover, the passwords/PINs will comprise of numbers, letters, and special characters in alphanumeric to ensure the stability of the network. A system administrator will assign a network password to the WLAN and only a select few of agents with valid credentials will be able to access it. He will be responsible for making any future changes when updates to the parameters for protecting the WLAN have changed. A strong protection plan will ensure that our clients and agents information and files is protected.

Issuance of CAC will be used to control access to the firm’s buildings. Besides a strong six-character digit pin, the company’s agents will have a badge with their picture, fingerprint, name and the name of the firm on it. Outside the building, there will be a door system which will require a person to provide his/her fingerprint or/and the scanning of a badge. A green light will be accompanied by an “access granted” feedback while a red light will display “access denied” based on assessment of a persons’ credentials. All agents will submit their schedules to the security specialists to be programmed in the system to ensure security. For example, any person who randomly shows up on days in which they are not supposed to be on duty will not be allowed entry into the firm’s premises. So all the agents will be required to submit their schedules so that necessary adjustment can be done to the system to grant you access into the premises. This will be done within 48hrs. The policy will help deny access to people who are not supposed to be there. Perhaps, this will not only help ensure the general security of the firm but also the company’s personal information. Each team or group of agents will only have access to files, which they themselves uploaded or has been granted access to be shared as a part of company resources. The only person supposed to have access to all files is the managing broker only. This plan of protection will be set in place to make sure confidential information of our clients and agents does not land in the hands of a third party.

Nonrepudiation protections will be ensured by a digital signature present on the CAC issued to all agents. CAC readers will be installed on all desks besides the workstations. This will make sure the information sent and deleted from the network can be traced to the originator (Lord, 2017). This will help increase accountability, as no one will be able deny their culpability if found have done something which has compromised the security of the network and its information. Each employee and contractor will be responsible for anything that happens while logged in through his or her card, PIN or retina recognition system.???

Cryptography Protection

One of the several ways of encrypting data is called triple DES; this method involves the application of a block cipher algorithm to every data block thrice ensuring each block is always characterized by 64 bits worth of data. As the word ‘triple’ suggests, in triple DES, data is encrypted three time, they major downside of this process is its lagging speed. However, this method is considered harder to break than most, making it the most secure of the methods.

RSA is a public key encryption algorithm. It uses both the public key and private key in its encryption process. One thing to note is that both keys are paired, so while the public key is distributed, the private key is not. The process starts with two prime numbers, then the multiplication products of those numbers and finally their exponents. Besides RSA being secure, it is hard to crack though the encryption process lacks in pace when encrypting large amounts of data.

Blowfish is another symmetric block cipher, this one makes use of an adjustable key whose length can range from 32 - 448 bits, and it can be used for foreign or domestic uses. No patent was ever made for this cipher and so the licence for the use of this cipher is free. Of all the bock ciphers, the blowfish is relatively fast, however, its’ use does requires a key and the management of said key is not easy.

Twofish, just as the Blowfish, is another type of block cipher algorithm encryption, the difference being the length of the key for this method only goes to 256 bits. Additionally, just as Blowfish, it is not patented hence the availability to all users for no profit. The advantage of using this type of encryption is its’ considered swift as block ciphers go and can be used by bigger CPUs as well as smartcards but because of its huge size, slowdowns on the system are frequent.

Advanced Encryption Standard (AES) is another symmetrical encryption algorithm. It constitutes AES 256, AES 192 and AES 128. Because of its symmetrical nature, the key used in its encryption is supposed to be shared in order to decrypt. Advanced encryption standard is usually recommended because it is secure and the fact that it uses varying key lengths in its encryption (Lord, 2017). One drawback is that the algebraic structure used for decryption is generally simple and the form used is uniform across all the blocks.

Use of AES for data encryption in our offices is highly recommended, considering it is overall a more secure method compared to other models of date encryption. This is promising in terms of ensuring security for our clients as well as the firm, more importantly, clients can securely entrust us with their most confidential information.

Data Hiding Technologies

1. Text block coding- This technology involves the coding of data into bits by use of collective data correcting codes

2. Digital watermarking- This is the concealment of information within a carrier signal

3. Masks and filtering – This process is used in identification of which section of the message has been exposed.

Network Security Vulnerability and Threat Table

DESCRIPTION

The organization’s security architecture

The system comprises of wireless switches, client devices and Aps, which adds to the network security advantage by acting as the basis for providing recommendations and improving the client’s devices.

The organization’s architecture needs to be standardised in order to it’s through this one can identify the possible vulnerabilities and the damages the attacks can cause. WLAN consists of independence, microcells, roaming and infrastructure

Cryptographic means of protection

Cryptographic is the use of secret codes in writing. The following requirements are necessary: non-repudiation, privacy, authentication and integrity.

They include ECC cypher suites, CNG provider model, default cipher suites and EAS cipher suites. Encryption and decryption are the primary ways that ensures that there is free data flow within the organization.

Potential attacks against the protection mechanisms

1. Malware –this is are codes intended to disorient the security system of the organization with the aim of stealing or destruction of data

2. Dos attacks- its main intend is disruption of the network but with the right security measures, it can be prevented.

3. Password attacks- this is are attempts made to crack set password with the aim of gaining access to a certain information resource.

Measures to ward of the threats

· Malware attacks can be prevented by installation of strong and reliable anti-malware software.

· DoS attacks can be prevented by regular update of security software

· Setting up of hard to crack passwords is the reliable way of curbing this type of challenge.

Data hiding and encryption technologies

· Shift cipher- it’s a technique where a letter is substituted by another which is one more according to the alphabets.

· Polyalphabetic cipher- unlike the shift cipher, Polyalphabetic cipher requires substitution by use of the multiple substitution alphabets.

· Block cipher- involve an installation of algorithmic functions which operates within a given intervals.

· Triple des- applies the DES functions of the algorithm 3 times to the bits of the data within the infrastructure

· RSA is an encryption process meant to ensure secure transmission of data

· Use of data hiding technologies such as digital watermarking, masks and filtering and text blocks.

· Use of advanced encryption standard

· Use of symmetric encryption

CAC Deployment Strategy

CAC is a user identification method, which is a card implanted with a chip containing information relative to the cards owner???. It has a digital signature that allows the user/owner to decrypt and encrypt using the card keys. The CAC deployment plan is meant to give the agents of the firm a common network access. During the beginning of the day, agents will use their PINs and cards for access into the firm’s premises. In the midst of the workday the CAC will only be necessary when agents want to delete or upload to the network or if they want to maintain access to the office after normal working hours. The CAC will not be necessary whenever they want to use the WLAN, the only necessity in this instance will be a password. The aim of these measures is to ensure the security of our clients, as well as the security of our employees from cyberattacks.

Email Security Strategy

Emails and internal messaging services are the main communication channels of the property management firm. The agents update the clients’ information and keep track of the clients through emails as well. Considering the number of emails flowing through the network in a day, daytime cyberattacks makes it easier for an attacker to find a vulnerability within the network and gain access to important data. In an attempt to prevent this risk, the firm has put in place policies to ensure email security. Varying encryption technologies can be made of use in this process, but the most efficient method would be to use digital certificates. The advantage of having digital certificates is that they are hard to bypass, though access to data cannot be granted in the event a key is lost. As a measure to ensure higher standards of security, the digital certificates can be incorporated into all emails originating for our firm, which will bring about an automatic encryption of all the emails flowing through the network. (Any references?)

Conclusion

We have explored the explanation and organization of the property management firm and looked at the potential cyberattack threats facing the firm. Moreover, I have also looked at the various security mechanisms and policies that can be implemented to prevent and neutralize the attacks. Given the fact that our firm is a service delivery company, we need to have all the security systems intact, it would behove the firm to invest more on security in order to secure the firm’s future clientele and their investments. As this would lead to an increased trust between the clients, and us. This will increase traffic to our website and our firm, and more traffic paves to way to more profits. To ensure the security of future emails, the company should use CAC’s steeped with digital certificates. More attention to our email security is deserved, as this is the firm’s main channel of communication internally and externally. In short, strong security features will help our clients have confidence in our company that we are handling their property and their security with the respect they deserve.

References

Bennett, C. H., & Brassard, G. (2014). Quantum cryptography: public key distribution and coin tossing. Theor. Comput. Sci.560(12), 7-11.

Cisco Press. (2016, February 09). Retrieved September 9, 2018, from http://www.ciscopress.com/articles/article.asp?p=1626588&seqNum=2

Ledford, Jerri (2018) What is a cyber attack and how to prevent one? Retrieved from https://www.lifewire.com/cyber-attacks-4147067

Peikert, C. (2014, October). Lattice cryptography for the internet. In international workshop on post-quantum cryptography (pp. 197-219). Springer, Cham.

Peikert, C. (2016). A decade of lattice cryptography. Foundations and Trends® in Theoretical Computer Science10(4), 283-424.

Lord, Nate (2017) What is a phishing attack? Defining and identifying different types of phishing attacks. Retrieved from https://digitalguardian.com/blog/what-phishing-attack-defining-and-identifying-different-types-phishing-attacks

Pirandola, S., Ottaviani, C., Spedalieri, G., Weedbrook, C., Braunstein, S. L., Lloyd, S., ... & Andersen, U. L. (2015). High-rate measurement-device-independent quantum cryptography. Nature Photonics9(6), 397.

Van Tilborg, H. C., & Jajodia, S. (Eds.). (2014). Encyclopedia of cryptography and security. Springer Science & Business Media.

Menegaz, Gery (2012) SQL Injection Attack: What is it, and how to prevent it. Retrieved from https://www.zdnet.com/article/sql-injection-attack-what-is-it-and-how-to-prevent-it/

Merriam-Webster Dictionary. (n.d.). Retrieved September 19, 2018, from https://www.merriam-webster.com/dictionary/cyberattack

Oppenheimer, Priscilla (2010) Developing Network Security Strategies. Retrieved from http://www.ciscopress.com/articles/article.asp?p=1626588&seqNum=2

Rouse, Margaret (2017) Ransomware, defend your data with best practices. Retrieved from https://searchsecurity.techtarget.com/definition/ransomware