information System security

profileDinesh_sharma01
file_2013-09-12_08_53_40_Fajrian_Nur_Adnan_M.CS__0071786198_toc.pdf

Principles of Computer Security: CompTIA

Security+™ and Beyond (Exam SY0-301)

Third Edition

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:40:47 PM

Color profile: Disabled Composite Default screen

■ About the Authors Dr. Wm. Arthur Conklin is an assistant professor in the College of Technol- ogy at the University of Houston. Dr. Conklin has terminal degrees from the Naval Postgraduate School in electrical engineering and The University of Texas at San Antonio in business administration. Dr. Conklin’s research in- terests lie in the areas of software assurance and the application of systems theory to security issues associated with critical infrastructures. His disser- tation was on the motivating factors for home users in adopting security on their own PCs. He has coauthored six books on information security and has written and presented numerous conference and academic journal papers. He has over ten years of teaching experience at the college level and has as- sisted in building two information security programs that have been recog- nized by the NSA and DHS as Centers of Academic Excellence in Information Assurance Education. A former U.S. Navy officer, he was also previously the Technical Director at the Center for Infrastructure Assurance and Security at The University of Texas at San Antonio.

Dr. Gregory White has been involved in computer and network security since 1986. He spent 19 years on active duty with the U.S. Air Force and is currently in the Air Force Reserves assigned to the Pentagon. He obtained his Ph.D. in computer science from Texas A&M University in 1995. His dis- sertation topic was in the area of computer network intrusion detection, and he continues to conduct research in this area today. He is currently the Director for the Center for Infrastructure Assurance and Security and is an associate professor of computer science at The University of Texas at San Antonio. Dr. White has written and presented numerous articles and con- ference papers on security. He is also the coauthor for five textbooks on computer and network security and has written chapters for two other secu- rity books. Dr. White continues to be active in security research. His current research initiatives include efforts in high-speed intrusion detection, com- munity infrastructure protection, and visualization of community and orga- nization security postures.

Dwayne Williams is Associate Director, Special Projects for the Center for Infrastructure Assurance and Security (CIAS) at the University of Texas at San Antonio and has over 18 years of experience in information systems and network security. Mr. Williams’s experience includes six years of commis- sioned military service as a Communications-Computer Information Sys- tems Officer in the U.S. Air Force, specializing in network security, corporate information protection, intrusion detection systems, incident re- sponse, and VPN technology. Prior to joining the CIAS, he served as Direc- tor of Consulting for SecureLogix Corporation, where he directed and provided security assessment and integration services to Fortune 100, government, public utility, oil and gas, financial, and technology clients. Mr. Williams graduated in 1993 from Baylor University with a Bachelor of Arts in Computer Science. Mr. Williams is a Certified Information Systems Security Professional (CISSP) and coauthor of McGraw-Hill’s Voice and Data Security and CompTIA Security+ All-in-One Exam Guide.

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter ii

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:40:48 PM

Color profile: Disabled Composite Default screen

Roger L. Davis, CISSP, CISM, CISA, is Program Manager of ERP systems at the Church of Jesus Christ of Latter-day Saints, managing the Church’s global financial system in over 140 countries. He has served as president of the Utah chapter of the Information Systems Security Association (ISSA) and various board positions for the Utah chapter of the Information Systems Audit and Control Association (ISACA). He is a retired Air Force lieutenant colonel with 30 years of military and information systems/security experi- ence. Mr. Davis served on the faculty of Brigham Young University and the Air Force Institute of Technology. He coauthored McGraw-Hill’s CompTIA Security+ All-in-One Exam Guide and Voice and Data Security. He holds a mas- ter’s degree in computer science from George Washington University, a bachelor’s degree in computer science from Brigham Young University, and performed post-graduate studies in electrical engineering and computer science at the University of Colorado.

Chuck Cothren, CISSP, is the president of Globex Security, Inc., and applies a wide array of network security experience to consulting and training. This includes performing controlled penetration testing, network security poli- cies, network intrusion detection systems, firewall configuration and man- agement, and wireless security assessments. He has analyzed security methodologies for voice over IP (VoIP) systems and supervisory control and data acquisition (SCADA) systems. Mr. Cothren was previously em- ployed at the University of Texas Center for Infrastructure Assurance and Security. He is coauthor of Voice and Data Security and CompTIA Security+ All-in-One Exam Guide. Mr. Cothren holds a B.S. in Industrial Distribution from Texas A&M University.

About the Technical Editor Bobby E. Rogers is a principal information security analyst with Dynetics, Inc., a national technology firm specializing in the certification and accredi- tation process for the U.S. government. He also serves as a penetration test- ing team lead for various government and commercial engagements. Bobby recently retired from the U.S. Air Force after almost 21 years, where he served as a computer networking and security specialist and designed and managed networks all over the world. His IT security experience includes several years working as an information assurance manager and a regular consultant to U.S. Air Force military units on various cybersecurity/com- puter abuse cases. He has held several positions of responsibility for net- work security in both the Department of Defense and private company networks. His duties have included perimeter security, client-side security, security policy development, security training, and computer crime investi- gations. As a trainer, he has taught a wide variety of IT-related subjects in both makeshift classrooms in desert tents and formal training centers. Bobby is also an accomplished author, having written numerous IT articles in various publications and training materials for the U.S. Air Force. He has also authored numerous security training videos.

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter iii

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:40:48 PM

Color profile: Disabled Composite Default screen

He has a Bachelor of Science degree in computer information systems from Excelsior College and two Associates in Applied Science degrees from the Community College of the Air Force. Bobby’s professional IT certifica- tions include A+, Security+, ACP, CCNA, CCAI, CIW, CIWSA, MCP+I, MCSA (Windows 2000 & 2003), MCSE (Windows NT4, 2000 & 2003), MCSE: Security (Windows 2000 & 2003), CISSP, CIFI, CEH, CHFI, and CPTS, and he is also a certified trainer.

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter iv

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:40:48 PM

Color profile: Disabled Composite Default screen

Principles of Computer Security: CompTIA

Security+™ and Beyond (Exam SY0-301)

Third Edition

Wm. Arthur Conklin Gregory White

Dwayne Williams Roger Davis

Chuck Cothren

New York Chicago San Francisco Lisbon London Madrid Mexico City Milan

New Delhi San Juan Seoul Singapore Sydney Toronto

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:40:51 PM

Color profile: Disabled Composite Default screen

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

Cataloging-in-Publication Data is on file with the Library of Congress

McGraw-Hill books are available at special quantity discounts to use as premiums and sales promotions, or for use in corporate training programs. To contact a representative, please e-mail us at [email protected].

Principles of Computer Security: CompTIA Security+™ and Beyond, Third Edition (Exam SY0-301)

Copyright © 2012 by The McGraw-Hill Companies. All rights reserved. Printed in the United States of America. Except as permitted under the Copyright Act of 1976, no part of this publication may be reproduced or distributed in any form or by any means, or stored in a database or retrieval system, without the prior written permission of publisher, with the exception that the program listings may be entered, stored, and executed in a computer system, but they may not be reproduced for publication.

All trademarks or copyrights mentioned herein are the possession of their respective owners and McGraw-Hill makes no claim of ownership by the mention of products that contain these marks.

1 2 3 4 5 6 7 8 9 0 QDB QDB 1 0 9 8 7 6 5 4 3 2

ISBN: Book p/n 978-0-07-178616-4 and CD p/n 978-0-07-178617-1 of set 978-0-07-178619-5

MHID: Book p/n 0-07-178616-3 and CD p/n 0-07-178617-1 of set 0-07-178619-8

Information has been obtained by McGraw-Hill from sources believed to be reliable. However, because of the possibility of human or mechanical error by our sources, McGraw-Hill, or others, McGraw-Hill does not guarantee the accuracy, adequacy, or completeness of any information and is not responsible for any errors or omissions or the results obtained from the use of such information.

McGraw-Hill is an independent entity from CompTIA®. This publication and CD may be used in assisting students to prepare for the CompTIA Security+ exam. Neither CompTIA nor McGraw- Hill warrants that use of this publication and CD will ensure passing any exam. CompTIA and CompTIA Security+ are trademarks or registered trademarks of CompTIA in the United States and/or other countries. All other trademarks are trademarks of their respective owners.

SANS Institute IT Code of Ethics reproduced with permission, © SANS Institute.

Sponsoring Editor Timothy Green

Editorial Supervisor Janet Walden

Project Editor LeeAnn Pickrell

Acquisitions Coordinator Stephanie Evans

Technical Editor Bobby E. Rogers

Copy Editor LeeAnn Pickrell

Proofreader Paul Tyler

Indexer Rebecca Plunkett

Production Supervisor Jean Bodeaux

Composition Cenveo Publisher Services

Illustration Cenveo Publisher Services

Art Director, Cover Jeff Weeks

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:40:51 PM

Color profile: Disabled Composite Default screen

■ This book is dedicated to the many security professionals who daily work to ensure the safety of our nation’s critical infrastructures. We want to recognize the thousands of dedicated individuals who strive to protect our national assets but who seldom receive praise and often are only noticed when an incident occurs. To you, we say thank you for a job well done!

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter vii

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:40:51 PM

Color profile: Disabled Composite Default screen

■ Acknowledgments We, the authors of Principles of Computer Security: CompTIA Security+™ and Beyond, Third Edition, have many individuals who we need to acknowl- edge—individuals without whom this effort would not have been success- ful. This third edition would not have been possible without Tim Green, who navigated a myriad of problems and made life easier for the author team. He brought together an all-star production team that made this book more than just a new edition, but a complete learning system.

The list needs to start with those folks at McGraw-Hill who worked tire- lessly with the project’s multiple authors and contributors and lead us suc- cessfully through the minefield that is a book schedule and who took our rough chapters and drawings and turned them into a final, professional prod- uct we can be proud of. We thank all the good people from the Acquisitions team, Tim Green and Stephanie Evans; from the Editorial Services team, Janet Walden and LeeAnn Pickrell; from the Illustration and Production teams, Jean Bodeaux and Amarjeet Kumar and the composition team at Cenveo Publisher Services. We also thank the technical editor, Bobby Rogers; the copy editors, Bill McManus and LeeAnn Pickrell; the proofreader, Paul Tyler; and the indexer, Rebecca Plunkett; for all their attention to detail that made this a finer work after they finished with it.

We also need to acknowledge our current employers who, to our great delight, have seen fit to pay us to work in a career field that we all find excit- ing and rewarding. There is never a dull moment in security, because it is constantly changing.

We would like to thank Art Conklin for herding the cats on this one. Finally, we would each like to individually thank those people who—on a

personal basis—have provided the core support for us individually. Without these special people in our lives, none of us could have put this work together.

Successful cat herders have many behind them helping them succeed. I owe thanks to many friends, their friendship and support makes efforts such as this possible. And to Susan, my lovely wife and friend, thank you for your sacrifices that enable me to do the things I do.

—Art Conklin, Ph.D.

I would like to thank my wife, Charlan, for the tremendous support she has always given me. It doesn’t matter how many times I have sworn that I’ll never get involved with another book project only to return within months to yet another one; through it all, she has remained supportive.

I would also like to publicly thank the United States Air Force, which provided me numerous opportunities since 1986 to learn more about secu- rity than I ever knew existed.

To whoever it was who decided to send me as a young captain—fresh from completing my master’s degree in artificial intelligence—to my first assignment in computer security: thank you, it has been a great adventure!

—Gregory B. White, Ph.D.

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter viii

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:40:51 PM

Color profile: Disabled Composite Default screen

For Macon. —Chuck Cothren

Geena, thanks for being my best friend and my greatest support. Any- thing I am is because of you. Love to my kids and grandkids!

—Roger L. Davis

To my wife and best friend Leah for your love, energy, and support— thank you for always being there. Here’s to many more years together.

—Dwayne Williams

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter ix

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:40:51 PM

Color profile: Disabled Composite Default screen

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

ABOUT THIS BOOK

■ Important Technology Skills

Information technology (IT) offers many career paths and information security is one of the fastest- growing tracks for IT professionals. This book provides coverage of the materials you need to begin your exploration of information security.

In addition to covering all of the CompTIA Security+ exam objectives, additional material is included to help you build a solid introductory knowledge of information security.

Makes Leaning Fun!— Rich, colorful text and illustrations bring technical concepts to life.

Engaging and Motivational — Using a conversational style and proven instructional approach, the authors explain technical subjects in a clear, interesting way using real-world examples.

Tech Tip sidebars provide inside information from experienced information security professionals.

Key Terms, identified in red, point out important vocabulary and definitions that you need to know.

Proven Learning Method Keeps You on Track Designed for classroom use and written by instructors for use in their own classes, Principles of Computer Security: CompTIA Security+ and Beyond is structured to give you comprehensive knowledge of information security. The textbook’s active learning methodology guides you beyond mere recall and—through thought-provoking activities, labs, and sidebars—helps you develop critical- thinking, diagnostic, and communication skills.

Cross Check questions develop reasoning skills: ask, compare, contrast, and explain.

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:41:37 PM

Color profile: Disabled Composite Default screen

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

Offers Practical Experience— Tutorials and lab assignments develop essential hands-on skills and put concepts in real-world contexts.

Robust Learning Tools— Summaries, key term lists, quizzes, essay questions, and lab projects help you practice skills

Notes, Tips, Warnings, and Exam Tips create a road map for success.

Chapter Review sections provide concept summaries, key terms lists, and lots of questions and projects.

Each chapter includes: ■ Learning Objectives that set measurable goals for

chapter-by-chapter progress

■ Illustrations that give you a clear picture of the concepts and technologies

■ Try This!, Cross Check, and Tech Tip sidebars that encourage you to practice and apply concepts in real- world settings

■ Notes, Tips, and Warnings that guide you, and Exam Tips that give you advice or provide information specifically related to preparing for the exam

■ Chapter Summaries and Key Terms Lists that provide you with an easy way to review important concepts and vocabulary

■ Challenging End-of-Chapter Tests that include vocabulary-building exercises, multiple-choice questions, essay questions, and on-the-job lab projects

■ Effective Learning Tools

This feature-rich textbook is designed to make learning easy and enjoyable and to help you develop the skills and critical thinking abilities that will enable you to adapt to different job situations and to troubleshoot problems. Written by

instructors with decades of combined information security experience, this book conveys even the most complex issues in an accessible, easy-to- understand format.

Try This! exercises apply core skills in a new setting.

Key Terms List presents the important terms identified in the chapter.

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:03 PM

Color profile: Disabled Composite Default screen

CONTENTS AT A GLANCE

Chapter 1 ■ Introduction and Security Trends 1

Chapter 2 ■ General Security Concepts 20

Chapter 3 ■ Operational and Organizational Security 50

Chapter 4 ■ The Role of People in Security 66

Chapter 5 ■ Cryptography 82

Chapter 6 ■ Public Key Infrastructure 116

Chapter 7 ■ Standards and Protocols 154

Chapter 8 ■ Physical Security 180

Chapter 9 ■ Network Fundamentals 208

Chapter 10 ■ Infrastructure Security 232

Chapter 11 ■ Authentication and Remote Access 264

Chapter 12 ■ Wireless Security 298

Chapter 13 ■ Intrusion Detection Systems and Network Security 322

Chapter 14 ■ Baselines 364

xii Contents at a Glance

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:03 PM

Color profile: Disabled Composite Default screen

Chapter 15 ■ Types of Attacks and Malicious Software 396

Chapter 16 ■ E-Mail and Instant Messaging 430

Chapter 17 ■ Web Components 454

Chapter 18 ■ Secure Software Development 484

Chapter 19 ■ Disaster Recovery, Business Continuity, and Organizational Policies 502

Chapter 20 ■ Risk Management 536

Chapter 21 ■ Change Management 556

Chapter 22 ■ Privilege Management 572

Chapter 23 ■ Computer Forensics 594

Chapter 24 ■ Legal Issues and Ethics 610

Chapter 25 ■ Privacy 632

Appendix A ■ Objective Map 654

Appendix B ■ About the CD 666

■ Glossary 668

■ Index 684

Contents at a Glance xiii

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:03 PM

Color profile: Disabled Composite Default screen

CONTENTS

Preface. . . . . . . . . . . . . . . . . . . . . . . . . xxi Introduction . . . . . . . . . . . . . . . . . . . . . xxiii CompTIA Approved Quality Curriculum . . . . xxvi Instructor and Student Web Site . . . . . . . . . . xxxi

Chapter 1 ■ Introduction and Security Trends 1 The Security Problem . . . . . . . . . . . . . . . 1

Security Incidents . . . . . . . . . . . . . . . 1 Threats to Security . . . . . . . . . . . . . . . 7 Security Trends . . . . . . . . . . . . . . . . 10

Avenues of Attack . . . . . . . . . . . . . . . . . 11 The Steps in an Attack . . . . . . . . . . . . . 12 Minimizing Possible Avenues of Attack . . . . 13 Types of Attacks . . . . . . . . . . . . . . . . 14

Chapter 1 Review . . . . . . . . . . . . . . . . . . 15

Chapter 2 ■ General Security Concepts 20 Basic Security Terminology . . . . . . . . . . . . 21

Security Basics . . . . . . . . . . . . . . . . . 21 Access Control . . . . . . . . . . . . . . . . . 31 Authentication . . . . . . . . . . . . . . . . . 31 Authentication and Access Control Policies . . . 32

Social Engineering . . . . . . . . . . . . . . . . . 33 Security Policies . . . . . . . . . . . . . . . . . . . 34

Change Management Policy . . . . . . . . . . 35 Classification of Information . . . . . . . . . . 36 Acceptable Use Policy . . . . . . . . . . . . . 36 Due Care and Due Diligence . . . . . . . . . 38 Due Process . . . . . . . . . . . . . . . . . . 38 Need to Know . . . . . . . . . . . . . . . . . 39 Disposal and Destruction Policy . . . . . . . 39 Service Level Agreements . . . . . . . . . . . 40 Human Resources Policies . . . . . . . . . . . 40

Security Models . . . . . . . . . . . . . . . . . . . 42 Confidentiality Models . . . . . . . . . . . . . 43 Integrity Models . . . . . . . . . . . . . . . . 44

Chapter 2 Review . . . . . . . . . . . . . . . . . . 46

Chapter 3 ■ Operational and Organizational

Security 50 Security Operations

in Your Organization . . . . . . . . . . . . . . 51 Policies, Procedures, Standards,

and Guidelines . . . . . . . . . . . . . . . 51 The Security Perimeter . . . . . . . . . . . . 52

Physical Security . . . . . . . . . . . . . . . . . . 53 Access Controls . . . . . . . . . . . . . . . . 54 Physical Barriers . . . . . . . . . . . . . . . . 56

Environmental Issues . . . . . . . . . . . . . . . 56 Fire Suppression . . . . . . . . . . . . . . . . 57

Wireless . . . . . . . . . . . . . . . . . . . . . . . 58 Electromagnetic Eavesdropping . . . . . . . . . 59 Location . . . . . . . . . . . . . . . . . . . . . . . 60 Chapter 3 Review . . . . . . . . . . . . . . . . . . 62

Chapter 4 ■ The Role of People in Security 66 People—A Security Problem . . . . . . . . . . . 67

Social Engineering . . . . . . . . . . . . . . . 67 Poor Security Practices . . . . . . . . . . . . 72

People as a Security Tool . . . . . . . . . . . . . 76 Security Awareness . . . . . . . . . . . . . . 76 Individual User Responsibilities . . . . . . . . 77

Chapter 4 Review . . . . . . . . . . . . . . . . . . 79

Chapter 5 ■ Cryptography 82 Algorithms . . . . . . . . . . . . . . . . . . . . . 84 Hashing Functions . . . . . . . . . . . . . . . . . 87

SHA . . . . . . . . . . . . . . . . . . . . . . 89 RIPEMD . . . . . . . . . . . . . . . . . . . . 90 Message Digest . . . . . . . . . . . . . . . . 90 Hashing Summary . . . . . . . . . . . . . . . 92

Symmetric Encryption . . . . . . . . . . . . . . . 92 DES . . . . . . . . . . . . . . . . . . . . . . 93 3DES . . . . . . . . . . . . . . . . . . . . . . 94

xiv Contents

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:03 PM

Color profile: Disabled Composite Default screen

AES . . . . . . . . . . . . . . . . . . . . . . 94 CAST . . . . . . . . . . . . . . . . . . . . . . 95 RC . . . . . . . . . . . . . . . . . . . . . . . 96 Blowfish . . . . . . . . . . . . . . . . . . . . 97 Twofish . . . . . . . . . . . . . . . . . . . . . 98 IDEA . . . . . . . . . . . . . . . . . . . . . . 98 Symmetric Encryption Summary . . . . . . . 98

Asymmetric Encryption . . . . . . . . . . . . . . 99 RSA . . . . . . . . . . . . . . . . . . . . . . 99 Diffie-Hellman . . . . . . . . . . . . . . . . . 100 ElGamal . . . . . . . . . . . . . . . . . . . . 101 ECC . . . . . . . . . . . . . . . . . . . . . . 101 Asymmetric Encryption Summary . . . . . . 102

Quantum Cryptography . . . . . . . . . . . . . . 102 Steganography . . . . . . . . . . . . . . . . . . . 103 Cryptography Algorithm Use . . . . . . . . . . . 105

Confidentiality . . . . . . . . . . . . . . . . . 105 Integrity . . . . . . . . . . . . . . . . . . . . 105 Nonrepudiation . . . . . . . . . . . . . . . . 106 Authentication . . . . . . . . . . . . . . . . . 106 Key Escrow . . . . . . . . . . . . . . . . . . . 107 Digital Signatures . . . . . . . . . . . . . . . 108 Digital Rights Management . . . . . . . . . . 108 Transport Encryption . . . . . . . . . . . . . 109 Cryptographic Applications . . . . . . . . . . 110

Chapter 5 Review . . . . . . . . . . . . . . . . . . 112

Chapter 6 ■ Public Key Infrastructure 116 The Basics of Public Key Infrastructures . . . . . 117 Certificate Authorities . . . . . . . . . . . . . . . 119 Registration Authorities . . . . . . . . . . . . . . 120

Local Registration Authorities . . . . . . . . . 122 Certificate Repositories . . . . . . . . . . . . . . 122 Trust and Certificate Verification . . . . . . . . . 123 Digital Certificates . . . . . . . . . . . . . . . . . 126

Certificate Attributes . . . . . . . . . . . . . 127 Certificate Extensions . . . . . . . . . . . . . 128 Certificate Lifecycles . . . . . . . . . . . . . . 129

Centralized and Decentralized Infrastructures . 134 Hardware Storage Devices . . . . . . . . . . . 135 Private Key Protection . . . . . . . . . . . . . 136 Key Recovery . . . . . . . . . . . . . . . . . . 137 Key Escrow . . . . . . . . . . . . . . . . . . . 138

Public Certificate Authorities . . . . . . . . . . . 139 In-House Certificate Authorities . . . . . . . . . 140

Choosing Between a Public CA and an In-House CA . . . . . . . . . . . . 140

Outsourced Certificate Authorities . . . . . . 141

Tying Different PKIs Together . . . . . . . . 142 Trust Models . . . . . . . . . . . . . . . . . . 142

Certificate-Based Threats . . . . . . . . . . . . . 147 Chapter 6 Review . . . . . . . . . . . . . . . . . . 149

Chapter 7 ■ Standards and Protocols 154 PKIX and PKCS . . . . . . . . . . . . . . . . . . . 156

PKIX Standards . . . . . . . . . . . . . . . . 157 PKCS . . . . . . . . . . . . . . . . . . . . . . 158 Why You Need to Know the PKIX

and PKCS Standards . . . . . . . . . . . . 160 X.509 . . . . . . . . . . . . . . . . . . . . . . . . . 162 SSL/TLS . . . . . . . . . . . . . . . . . . . . . . . 163 ISAKMP . . . . . . . . . . . . . . . . . . . . . . . 164 CMP . . . . . . . . . . . . . . . . . . . . . . . . . 165 XKMS . . . . . . . . . . . . . . . . . . . . . . . . 166 S/MIME . . . . . . . . . . . . . . . . . . . . . . . 168

IETF S/MIME History . . . . . . . . . . . . 168 IETF S/MIME v3 Specifications . . . . . . . . 169

PGP . . . . . . . . . . . . . . . . . . . . . . . . . . 170 How PGP Works . . . . . . . . . . . . . . . . 170

HTTPS . . . . . . . . . . . . . . . . . . . . . . . . 171 IPsec . . . . . . . . . . . . . . . . . . . . . . . . . 172 CEP . . . . . . . . . . . . . . . . . . . . . . . . . . 172 FIPS . . . . . . . . . . . . . . . . . . . . . . . . . 172 Common Criteria for Information Technology

Security (Common Criteria or CC) . . . . . . 173 WTLS . . . . . . . . . . . . . . . . . . . . . . . . 173 PPTP . . . . . . . . . . . . . . . . . . . . . . . . . 174 WEP . . . . . . . . . . . . . . . . . . . . . . . . . 174

WEP Security Issues . . . . . . . . . . . . . . 174 ISO/IEC 27002 (Formerly

ISO 17799) . . . . . . . . . . . . . . . . . . . . 175 Chapter 7 Review . . . . . . . . . . . . . . . . . . 176

Chapter 8 ■ Physical Security 180 The Security Problem . . . . . . . . . . . . . . . 181 Physical Security Safeguards . . . . . . . . . . . 185

Walls and Guards . . . . . . . . . . . . . . . 185 Policies and Procedures . . . . . . . . . . . . 187 Access Controls and Monitoring . . . . . . . 191 Environmental Controls . . . . . . . . . . . . 194 Fire Suppression . . . . . . . . . . . . . . . . 195 Electromagnetic Interference . . . . . . . . . . 198 Authentication . . . . . . . . . . . . . . . . . 199

Chapter 8 Review . . . . . . . . . . . . . . . . . . 204

Contents xv

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:04 PM

Color profile: Disabled Composite Default screen

Chapter 9 ■ Network Fundamentals 208 Network Architectures . . . . . . . . . . . . . . . 209 Network Topology . . . . . . . . . . . . . . . . . 210 Network Protocols . . . . . . . . . . . . . . . . . 211

Packets . . . . . . . . . . . . . . . . . . . . . 213 TCP vs. UDP . . . . . . . . . . . . . . . . . 214 ICMP . . . . . . . . . . . . . . . . . . . . . . 215

Packet Delivery . . . . . . . . . . . . . . . . . . . 217 Local Packet Delivery . . . . . . . . . . . . . 217 Remote Packet Delivery . . . . . . . . . . . . 218 IP Addresses and Subnetting . . . . . . . . . 219 Network Address Translation . . . . . . . . . 221 Security Zones . . . . . . . . . . . . . . . . . 222 VLANs . . . . . . . . . . . . . . . . . . . . . 226

Tunneling . . . . . . . . . . . . . . . . . . . . . . 227 Chapter 9 Review . . . . . . . . . . . . . . . . . . 228

Chapter 10 ■ Infrastructure Security 232 Devices . . . . . . . . . . . . . . . . . . . . . . . . 233

Workstations . . . . . . . . . . . . . . . . . . 233 Servers . . . . . . . . . . . . . . . . . . . . . 235 Virtualization . . . . . . . . . . . . . . . . . 236 Network Interface Cards . . . . . . . . . . . . 236 Hubs . . . . . . . . . . . . . . . . . . . . . . 237 Bridges . . . . . . . . . . . . . . . . . . . . . 237 Switches . . . . . . . . . . . . . . . . . . . . 238 Loop Protection . . . . . . . . . . . . . . . . 239 Routers . . . . . . . . . . . . . . . . . . . . . 239 Firewalls . . . . . . . . . . . . . . . . . . . . 240 Wireless . . . . . . . . . . . . . . . . . . . . 242 Modems . . . . . . . . . . . . . . . . . . . . 243 Telecom/PBX . . . . . . . . . . . . . . . . . . 245 VPN . . . . . . . . . . . . . . . . . . . . . . 245 Intrusion Detection Systems . . . . . . . . . . 246 Network Access Control . . . . . . . . . . . . 246 Network Monitoring/Diagnostic . . . . . . . 247 Mobile Devices . . . . . . . . . . . . . . . . . 248 Device Security, Common Concerns . . . . . 249

Media . . . . . . . . . . . . . . . . . . . . . . . . 249 Coaxial Cable . . . . . . . . . . . . . . . . . . 249 UTP/STP . . . . . . . . . . . . . . . . . . . . 250 Fiber . . . . . . . . . . . . . . . . . . . . . . 251 Unguided Media . . . . . . . . . . . . . . . . 252

Security Concerns for Transmission Media . . . 254 Physical Security Concerns . . . . . . . . . . . . 254

Removable Media . . . . . . . . . . . . . . . . . 255 Magnetic Media . . . . . . . . . . . . . . . . 255 Optical Media . . . . . . . . . . . . . . . . . 258 Electronic Media . . . . . . . . . . . . . . . . 259

Cloud Computing . . . . . . . . . . . . . . . . . 259 Software as a Service . . . . . . . . . . . . . . 260 Platform as a Service . . . . . . . . . . . . . . 260 Infrastructure as a Service . . . . . . . . . . . 260 Network Attached Storage . . . . . . . . . . . 260

Chapter 10 Review . . . . . . . . . . . . . . . . . 261

Chapter 11 ■ Authentication and Remote Access 264 The Remote Access Process . . . . . . . . . . . . 265

Identification . . . . . . . . . . . . . . . . . . 266 Authentication . . . . . . . . . . . . . . . . . 266 Authorization . . . . . . . . . . . . . . . . . 271 Access Control . . . . . . . . . . . . . . . . . 272

IEEE 802.1X . . . . . . . . . . . . . . . . . . . . . 274 Wireless Protocols . . . . . . . . . . . . . . . 275

RADIUS . . . . . . . . . . . . . . . . . . . . . . . 275 RADIUS Authentication . . . . . . . . . . . 276 RADIUS Authorization . . . . . . . . . . . . 277 RADIUS Accounting . . . . . . . . . . . . . 277 Diameter . . . . . . . . . . . . . . . . . . . . 278

TACACS+ . . . . . . . . . . . . . . . . . . . . . . 278 TACACS+ Authentication . . . . . . . . . . 279 TACACS+ Authorization . . . . . . . . . . . 280 TACACS+ Accounting . . . . . . . . . . . . 280

Authentication Protocols . . . . . . . . . . . . . 281 L2TP and PPTP . . . . . . . . . . . . . . . . 281 PPP . . . . . . . . . . . . . . . . . . . . . . . 281 PPTP . . . . . . . . . . . . . . . . . . . . . . 282 EAP . . . . . . . . . . . . . . . . . . . . . . 283 CHAP . . . . . . . . . . . . . . . . . . . . . 283 NTLM . . . . . . . . . . . . . . . . . . . . . 284 PAP . . . . . . . . . . . . . . . . . . . . . . 284 L2TP . . . . . . . . . . . . . . . . . . . . . . 284 Telnet . . . . . . . . . . . . . . . . . . . . . . 285 SSH . . . . . . . . . . . . . . . . . . . . . . 285

FTP/FTPS/SFTP . . . . . . . . . . . . . . . . . . 287 VPNs . . . . . . . . . . . . . . . . . . . . . . . . . 287 IPsec . . . . . . . . . . . . . . . . . . . . . . . . . 288

Security Associations . . . . . . . . . . . . . 289 IPsec Configurations . . . . . . . . . . . . . . 289 IPsec Security . . . . . . . . . . . . . . . . . 290

Vulnerabilities of Remote Access Methods . . . . . . . . . . . . . . . . . 293

Connection Summary . . . . . . . . . . . . . . . 294 Chapter 11 Review . . . . . . . . . . . . . . . . . 295

xvi Contents

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:04 PM

Color profile: Disabled Composite Default screen

Chapter 12 ■ Wireless Security 298 Introduction to Wireless Networking . . . . . . 299 Mobile Phones . . . . . . . . . . . . . . . . . . . 300

WAP . . . . . . . . . . . . . . . . . . . . . . 302 3G Mobile Networks . . . . . . . . . . . . . . 304

Bluetooth . . . . . . . . . . . . . . . . . . . . . . 304 802.11 . . . . . . . . . . . . . . . . . . . . . . . . 307

802.11: Individual Standards . . . . . . . . . 308 Attacking 802.11 . . . . . . . . . . . . . . . . 311 New Security Protocols . . . . . . . . . . . . 315 Implementing 802.1X . . . . . . . . . . . . . 316

Chapter 12 Review . . . . . . . . . . . . . . . . . 318

Chapter 13 ■ Intrusion Detection Systems and

Network Security 322 History of Intrusion

Detection Systems . . . . . . . . . . . . . . . . 323 IDS Overview . . . . . . . . . . . . . . . . . . . . 324 Network-Based IDSs . . . . . . . . . . . . . . . . 326

Advantages of a NIDS . . . . . . . . . . . . . 330 Disadvantages of a NIDS . . . . . . . . . . . 330 Active vs. Passive NIDSs . . . . . . . . . . . 330

Signatures . . . . . . . . . . . . . . . . . . . . . . 331 False Positives and False Negatives . . . . . . . 332 IDS Models . . . . . . . . . . . . . . . . . . . . . 333 Firewalls . . . . . . . . . . . . . . . . . . . . . . . 334

How Do Firewalls Work? . . . . . . . . . . . 335 Intrusion Prevention Systems . . . . . . . . . . . 337

Detection Controls vs. Prevention Controls . . 338 Web Application Firewalls vs. Network

Firewalls . . . . . . . . . . . . . . . . . . . . . 339 Proxy Servers . . . . . . . . . . . . . . . . . . . . 339 Internet Content Filters . . . . . . . . . . . . . . 341 Protocol Analyzers . . . . . . . . . . . . . . . . . 341 Honeypots and Honeynets . . . . . . . . . . . . 343 Host-Based IDSs . . . . . . . . . . . . . . . . . . 345

Advantages of HIDSs . . . . . . . . . . . . . 348 Disadvantages of HIDSs . . . . . . . . . . . . 349 Active vs. Passive HIDSs . . . . . . . . . . . 350 Resurgence and Advancement of HIDSs . . . 350

PC-Based Malware Protection . . . . . . . . . . 351 Antivirus Products . . . . . . . . . . . . . . 351 Personal Software Firewalls . . . . . . . . . . 353 Pop-up Blockers . . . . . . . . . . . . . . . . 355 Windows Defender . . . . . . . . . . . . . . . 356 Antispam . . . . . . . . . . . . . . . . . . . . 357

All-in-One Security Appliances . . . . . . . . . . 358 Chapter 13 Review . . . . . . . . . . . . . . . . . 359

Chapter 14 ■ Baselines 364 Overview of Baselines . . . . . . . . . . . . . . . 365 Password Selection . . . . . . . . . . . . . . . . . 365 Operating System and Network Operating

System Hardening . . . . . . . . . . . . . . . . 366 Hardening Microsoft Operating Systems . . . 367 Hardening UNIX- or Linux-Based

Operating Systems . . . . . . . . . . . . . 370 Updates (a.k.a. Hotfixes,

Service Packs, and Patches) . . . . . . . . . 379 Network Hardening . . . . . . . . . . . . . . . . 381

Software Updates . . . . . . . . . . . . . . . 382 Device Configuration . . . . . . . . . . . . . 382 Securing Management Interfaces . . . . . . . 383 VLAN Management . . . . . . . . . . . . . . 383 IPv4 vs. IPv6 . . . . . . . . . . . . . . . . . . 384

Application Hardening . . . . . . . . . . . . . . 384 Application Configuration Baseline . . . . . . 384 Application Patches . . . . . . . . . . . . . . 384 Patch Management . . . . . . . . . . . . . . 385 Host Software Baselining . . . . . . . . . . . 387

Group Policies . . . . . . . . . . . . . . . . . . . 388 Security Templates . . . . . . . . . . . . . . . . . 390 Chapter 14 Review . . . . . . . . . . . . . . . . . 392

Chapter 15 ■ Types of Attacks and Malicious

Software 396 Avenues of Attack . . . . . . . . . . . . . . . . . 397

The Steps in an Attack . . . . . . . . . . . . . 397 Minimizing Possible Avenues of Attack . . . . 399

Attacking Computer Systems and Networks . . . . . . . . . . . . . . . . . . 400

Denial-of-Service Attacks . . . . . . . . . . . 400 Backdoors and Trapdoors . . . . . . . . . . . 403 Null Sessions . . . . . . . . . . . . . . . . . . 403 Sniffing . . . . . . . . . . . . . . . . . . . . . 404 Spoofing . . . . . . . . . . . . . . . . . . . . 405 Man-in-the-Middle Attacks . . . . . . . . . . 408 Replay Attacks . . . . . . . . . . . . . . . . . 409 TCP/IP Hijacking . . . . . . . . . . . . . . . 409 Drive-by Download Attacks . . . . . . . . . . 409 Phishing and Pharming Attacks . . . . . . . . 410 Attacks on Encryption . . . . . . . . . . . . . 410 Address System Attacks . . . . . . . . . . . . 411 Password Guessing . . . . . . . . . . . . . . 412 Software Exploitation . . . . . . . . . . . . . 414 Client-side Attacks . . . . . . . . . . . . . . . 414 Malicious Code . . . . . . . . . . . . . . . . . 415

Contents xvii

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:04 PM

Color profile: Disabled Composite Default screen

Malware Defenses . . . . . . . . . . . . . . . 421 War-Dialing and War-Driving . . . . . . . . 422 Social Engineering . . . . . . . . . . . . . . . 423

Auditing . . . . . . . . . . . . . . . . . . . . . . . 423 Chapter 15 Review . . . . . . . . . . . . . . . . . 425

Chapter 16 ■ E-Mail and Instant Messaging 430 Security of E-Mail . . . . . . . . . . . . . . . . . . 431 Malicious Code . . . . . . . . . . . . . . . . . . . 433 Hoax E-Mails . . . . . . . . . . . . . . . . . . . . 437 Unsolicited Commercial

E-Mail (Spam) . . . . . . . . . . . . . . . . . . 438 Mail Encryption . . . . . . . . . . . . . . . . . . . 441

S/MIME . . . . . . . . . . . . . . . . . . . . 442 PGP . . . . . . . . . . . . . . . . . . . . . . 443

Instant Messaging . . . . . . . . . . . . . . . . . 445 Chapter 16 Review . . . . . . . . . . . . . . . . . 450

Chapter 17 ■ Web Components 454 Current Web Components

and Concerns . . . . . . . . . . . . . . . . . . 455 Web Protocols . . . . . . . . . . . . . . . . . . . . 455

Encryption (SSL and TLS) . . . . . . . . . . 456 The Web (HTTP and HTTPS) . . . . . . . . . 462 Directory Services (DAP and LDAP) . . . . . 463 File Transfer (FTP and SFTP) . . . . . . . . . 464 Vulnerabilities . . . . . . . . . . . . . . . . . 465

Code-Based Vulnerabilities . . . . . . . . . . . . 465 Buffer Overflows . . . . . . . . . . . . . . . . 466 Java and JavaScript . . . . . . . . . . . . . . 467 ActiveX . . . . . . . . . . . . . . . . . . . . 469 Securing the Browser . . . . . . . . . . . . . 470 CGI . . . . . . . . . . . . . . . . . . . . . . . 471 Server-Side Scripts . . . . . . . . . . . . . . . 471 Cookies . . . . . . . . . . . . . . . . . . . . . 472 Signed Applets . . . . . . . . . . . . . . . . . 474 Browser Plug-ins . . . . . . . . . . . . . . . . 475

Application-Based Weaknesses . . . . . . . . . . 477 Open Vulnerability and Assessment Language

(OVAL) . . . . . . . . . . . . . . . . . . . 478 Web 2.0 and Security . . . . . . . . . . . . . 478

Chapter 17 Review . . . . . . . . . . . . . . . . . 480

Chapter 18 ■ Secure Software Development 484 The Software Engineering Process . . . . . . . . 485

Process Models . . . . . . . . . . . . . . . . . 485 Secure Development Lifecycle . . . . . . . . . 486 Threat Modeling Steps . . . . . . . . . . . . . 488

Chapter 18 Review . . . . . . . . . . . . . . . . . 498

Chapter 19 ■ Disaster Recovery, Business Continuity,

and Organizational Policies 502 Disaster Recovery . . . . . . . . . . . . . . . . . . 503

Disaster Recovery Plans/Process . . . . . . . 503 Backups . . . . . . . . . . . . . . . . . . . . 505 Utilities . . . . . . . . . . . . . . . . . . . . . 512 Secure Recovery . . . . . . . . . . . . . . . . 512 Cloud Computing . . . . . . . . . . . . . . . 513 High Availability and Fault Tolerance . . . . 513 Failure and Recovery Timing . . . . . . . . . 515 Computer Incident Response Teams . . . . . . 516 Test, Exercise, and Rehearse . . . . . . . . . . 517

Policies and Procedures . . . . . . . . . . . . . . 518 Security Policies . . . . . . . . . . . . . . . . 518 Privacy . . . . . . . . . . . . . . . . . . . . . 524 Service Level Agreements . . . . . . . . . . . 525 Human Resources Policies . . . . . . . . . . . 525 Code of Ethics . . . . . . . . . . . . . . . . . 527 Incident Response Policies and Procedures . . 527

Chapter 19 Review . . . . . . . . . . . . . . . . . 532

Chapter 20 ■ Risk Management 536 An Overview of Risk Management . . . . . . . . 537

Example of Risk Management at the International Banking Level . . . . . . 537

Risk Management Vocabulary . . . . . . . . . 538 What Is Risk Management? . . . . . . . . . . . . 539 Business Risks . . . . . . . . . . . . . . . . . . . . 540

Examples of Business Risks . . . . . . . . . . 540 Examples of Technology Risks . . . . . . . . . 541

Risk Management Models . . . . . . . . . . . . . 541 General Risk Management Model . . . . . . . 541 Software Engineering Institute Model . . . . 544 Model Application . . . . . . . . . . . . . . . 545

Qualitatively Assessing Risk . . . . . . . . . . . 545

xviii Contents

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:04 PM

Color profile: Disabled Composite Default screen

Quantitatively Assessing Risk . . . . . . . . . . . 547 Adding Objectivity to

a Qualitative Assessment . . . . . . . . . . 547 A Common Objective Approach . . . . . . . . 548

Qualitative vs. Quantitative Risk Assessment . . . . . . . . . . . . . . . . . 549

Tools . . . . . . . . . . . . . . . . . . . . . . . . . 550 Chapter 20 Review . . . . . . . . . . . . . . . . . 551

Chapter 21 ■ Change Management 556 Why Change Management? . . . . . . . . . . . . 557 The Key Concept:

Separation of Duties . . . . . . . . . . . . . . . 559 Elements of Change Management . . . . . . . . 560 Implementing Change Management . . . . . . . 562

The Purpose of a Change Control Board . . . . 563 Code Integrity . . . . . . . . . . . . . . . . . 565

The Capability Maturity Model Integration . . . 565 Chapter 21 Review . . . . . . . . . . . . . . . . . 567

Chapter 22 ■ Privilege Management 572 User, Group, and Role Management . . . . . . . 573

User . . . . . . . . . . . . . . . . . . . . . . 573 Group . . . . . . . . . . . . . . . . . . . . . 575 Role . . . . . . . . . . . . . . . . . . . . . . . 576

Password Policies . . . . . . . . . . . . . . . . . . 576 Domain Password Policy . . . . . . . . . . . 577

Single Sign-On . . . . . . . . . . . . . . . . . . . 579 Time of Day Restrictions . . . . . . . . . . . 580 Tokens . . . . . . . . . . . . . . . . . . . . . 580 Account and Password Expiration . . . . . . 581

Security Controls and Permissions . . . . . . . . 582 Access Control Lists . . . . . . . . . . . . . . 584

Handling Access Control (MAC, DAC, and RBAC) . . . . . . . . . . . . 585

Mandatory Access Control (MAC) . . . . . . 585 Discretionary Access Control (DAC) . . . . . 586 Role-Based Access Control (RBAC) . . . . . . 587 Rule-Based Access Control (RBAC) . . . . . . 587 Account Expiration . . . . . . . . . . . . . . 588

Preventing Data Loss or Theft . . . . . . . . . . . 588 Chapter 22 Review . . . . . . . . . . . . . . . . . 589

Chapter 23 ■ Computer Forensics 594 Evidence . . . . . . . . . . . . . . . . . . . . . . . 596

Standards for Evidence . . . . . . . . . . . . 596 Types of Evidence . . . . . . . . . . . . . . . 596 Three Rules Regarding Evidence . . . . . . . 597

Collecting Evidence . . . . . . . . . . . . . . . . 597 Acquiring Evidence . . . . . . . . . . . . . . 597 Identifying Evidence . . . . . . . . . . . . . . 599 Protecting Evidence . . . . . . . . . . . . . . 599 Transporting Evidence . . . . . . . . . . . . . 600 Storing Evidence . . . . . . . . . . . . . . . . 600 Conducting the Investigation . . . . . . . . . 600

Chain of Custody . . . . . . . . . . . . . . . . . . 601 Free Space vs. Slack Space . . . . . . . . . . . . . 602

Free Space . . . . . . . . . . . . . . . . . . . 602 Slack Space . . . . . . . . . . . . . . . . . . . 602

Message Digest and Hash . . . . . . . . . . . . . 602 Analysis . . . . . . . . . . . . . . . . . . . . . . . 603 Chapter 23 Review . . . . . . . . . . . . . . . . . 605

Chapter 24 ■ Legal Issues and Ethics 610 Cybercrime . . . . . . . . . . . . . . . . . . . . . 611

Common Internet Crime Schemes . . . . . . . 613 Sources of Laws . . . . . . . . . . . . . . . . 614 Computer Trespass . . . . . . . . . . . . . . . 614 Significant U.S. Laws . . . . . . . . . . . . . 615 Payment Card Industry Data

Security Standard (PCI DSS) . . . . . . . 618 Import/Export Encryption Restrictions . . . . 619 Non-U.S. Laws . . . . . . . . . . . . . . . . . 621 Digital Signature Laws . . . . . . . . . . . . 621 Digital Rights Management . . . . . . . . . . 623

Ethics . . . . . . . . . . . . . . . . . . . . . . . . . 625 Chapter 24 Review . . . . . . . . . . . . . . . . . 628

Chapter 25 ■ Privacy 632 Personally Identifiable

Information (PII) . . . . . . . . . . . . . . . . . 633 Sensitive PII . . . . . . . . . . . . . . . . . . 634 Notice, Choice, and Consent . . . . . . . . . . 634

U.S. Privacy Laws . . . . . . . . . . . . . . . . . 634 Privacy Act of 1974 . . . . . . . . . . . . . . 635 Freedom of Information Act (FOIA) . . . . . . 635

Contents xix

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:04 PM

Color profile: Disabled Composite Default screen

Family Education Records and Privacy Act (FERPA) . . . . . . . . . 636

U.S. Computer Fraud and Abuse Act (CFAA) . . . . . . . . . . . . . . . . . . . 636

U.S. Children’s Online Privacy Protection Act (COPPA) . . . . . . . . . . 637

Video Privacy Protection Act (VPPA) . . . . 637 Health Insurance Portability

& Accountability Act (HIPAA) . . . . . . 638 Gramm-Leach-Bliley Act (GLBA) . . . . . . . 639 California Senate Bill 1386 (SB 1386) . . . . . 639 U.S. Banking Rules and Regulations . . . . . 639 Payment Card Industry Data

Security Standard (PCI DSS) . . . . . . . 640 Fair Credit Reporting Act (FCRA) . . . . . . 641 Fair and Accurate Credit

Transactions Act (FACTA) . . . . . . . . . 641 Non-Federal Privacy Concerns

in the United States . . . . . . . . . . . . . . . 642 International Privacy Laws . . . . . . . . . . . . 643

OECD Fair Information Practices . . . . . . . 643 European Laws . . . . . . . . . . . . . . . . . 643 Canadian Laws . . . . . . . . . . . . . . . . . 645 Asian Laws . . . . . . . . . . . . . . . . . . . 645

Privacy-Enhancing Technologies . . . . . . . . . 646 Privacy Policies . . . . . . . . . . . . . . . . . . . 646

Privacy Impact Assessment . . . . . . . . . . 647

Web Privacy Issues . . . . . . . . . . . . . . . . . 648 Platform for Privacy Preferences

Project (P3P) . . . . . . . . . . . . . . . . 648 Cookies . . . . . . . . . . . . . . . . . . . . . 648

Chapter 25 Review . . . . . . . . . . . . . . . . . 650

Appendix A ■ Objective Map 654

Appendix B ■ About the CD 666 System Requirements . . . . . . . . . . . . . . . 666 LearnKey Online Training . . . . . . . . . . . . . 666 Installing and Running MasterExam . . . . . . . 666

MasterExam . . . . . . . . . . . . . . . . . . 666 Electronic Book . . . . . . . . . . . . . . . . . . . 667 CompTIA Exam Objectives . . . . . . . . . . . . 667 Help . . . . . . . . . . . . . . . . . . . . . . . . . 667 Removing Installation(s) . . . . . . . . . . . . . . 667 Technical Support . . . . . . . . . . . . . . . . . 667

LearnKey Technical Support . . . . . . . . . . 667

■ Glossary 668

■ Index 684

xx Contents

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:04 PM

Color profile: Disabled Composite Default screen

PREFACE

Information and computer security has moved from the confines of acade- mia to mainstream America in the last decade. The Code Red, Nimda, and Slammer attacks were heavily covered in the media and broadcast into the average American’s home. Today, the Internet has turned 40, and with its maturing, the threats are increasing. Botnets and cyber-criminals are mak- ing news regularly. It has become increasingly obvious to everybody that something needs to be done to secure not only our nation’s critical infra- structure but also the businesses we deal with on a daily basis. The question is, “Where do we begin?” What can the average information technology professional do to secure the systems that he or she is hired to maintain? One immediate answer is education and training. If we want to secure our computer systems and networks, we need to know how to do this and what security entails.

Complacency is not an option in today’s hostile network environment. While we once considered the insider to be the major threat to corporate net- works, and the “script kiddie” to be the standard external threat (often thought of as only a nuisance), the highly interconnected network world of today is a much different place. The U.S. government identified eight critical infrastruc- tures a few years ago that were thought to be so critical to the nation’s daily op- eration that if one were to be lost, it would have a catastrophic impact on the nation. To this original set of eight sectors, more have recently been added. A common thread throughout all of these, however, is technology—especially technology related to computers and communication. Thus, an individual, or- ganization, or nation who wanted to cause damage to this nation could attack it not just with traditional weapons but with computers through the Internet. It is not surprising to hear that among the other information seized in raids on ter- rorist organizations, computers and Internet information are usually seized as well. While the insider can certainly still do tremendous damage to an organi- zation, the external threat is again becoming the chief concern among many.

So, where do you, the IT professional seeking more knowledge on secu- rity, start your studies? The IT world is overflowing with certifications that can be obtained by those attempting to learn more about their chosen pro- fession. The security sector is no different, and the CompTIA Security+ exam offers a basic level of certification for security. In the pages of this book you will find not only material that can help you prepare for taking the CompTIA Security+ exam but also the basic information that you will need in order to understand the issues involved in securing your computer sys- tems and networks today. In no way is this book the final source for learning all about protecting your organization’s systems, but it serves as a point from which to launch your security studies and career.

Preface xxi

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:05 PM

Color profile: Disabled Composite Default screen

One thing is certainly true about this field of study—it never gets boring. It constantly changes as technology itself advances. Something else you will find as you progress in your security studies is that no matter how much technology advances and no matter how many new security devices are de- veloped, at its most basic level, the human is still the weak link in the secu- rity chain. If you are looking for an exciting area to delve into, then you have certainly chosen wisely. Security offers a challenging blend of technology and people issues. We, the authors of this book, wish you luck as you em- bark on an exciting and challenging career path.

Wm. Arthur Conklin, Ph.D. Gregory B. White, Ph.D.

xxii Preface

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:05 PM

Color profile: Disabled Composite Default screen

INTRODUCTION

Computer security is becoming increasingly important today as the number of security incidents steadily climbs. Many corporations are now spending significant portions of their budget on security hardware, software, ser- vices, and personnel. They are spending this money not because it increases sales or enhances the product they provide, but because of the possible con- sequences should they not take protective actions.

Why Focus on Security? Security is not something that we want to have to pay for; it would be nice if we didn’t have to worry about protecting our data from disclosure, modifi- cation, or destruction from unauthorized individuals, but that is not the en- vironment we find ourselves in today. Instead, we have seen the cost of recovering from security incidents steadily rise along with the rise in the number of incidents themselves. Since September 11, 2001, this has taken on an even greater sense of urgency as we now face securing our systems not just from attack by disgruntled employees, juvenile hackers, organized crime, or competitors; we now also have to consider the possibility of at- tacks on our systems from terrorist organizations. If nothing else, the events of September 11, 2001, showed that anybody is a potential target. You do not have to be part of the government or a government contractor; being an American is sufficient reason to make you a target to some, and with the global nature of the Internet, collateral damage from cyber attacks on one organization could have a worldwide impact.

A Growing Need for Security Specialists To protect our computer systems and networks, we will need a significant number of new security professionals trained in the many aspects of com- puter and network security. This is not an easy task as the systems connected to the Internet become increasingly complex, with software whose lines of code number in the millions. Understanding why this is such a difficult prob- lem to solve is not hard if you consider how many errors might be present in a piece of software that is several million lines long. When you add the addi- tional factor of how fast software is being developed—from necessity as the market is constantly moving—understanding how errors occur is easy.

Not every “bug” in the software will result in a security hole, but it doesn’t take many to affect the Internet community drastically. We can’t just blame the

Introduction xxiii

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:05 PM

Color profile: Disabled Composite Default screen

vendors for this situation, because they are reacting to the demands of govern- ment and industry. Most vendors are fairly adept at developing patches for flaws found in their software, and patches are constantly issued to protect sys- tems from bugs that may introduce security problems. This introduces a whole new problem for managers and administrators—patch management. How im- portant this has become is easily illustrated by how many of the most recent se- curity events have occurred as a result of a security bug for which a patch was available months prior to the security incident; members of the community had not correctly installed the patch, however, thus making the incident possible. One of the reasons this happens is that many of the individuals responsible for installing the patches are not trained to understand the security implications surrounding the hole or the ramifications of not installing the patch. Many of these individuals simply lack the necessary training.

Because of the need for an increasing number of security professionals who are trained to some minimum level of understanding, certifications such as the Security+ have been developed. Prospective employers want to know that the individual they are considering hiring knows what to do in terms of security. The prospective employee, in turn, wants to have a way to demonstrate his or her level of understanding, which can enhance the can- didate’s chances of being hired. The community as a whole simply wants more trained security professionals.

Preparing Yourself for the Security+ Exam Principles of Computer Security: CompTIA Security+ and Beyond, Third Edition is designed to help prepare you to take the Security+ certification exam. When you pass it, you will demonstrate you have that basic understanding of security that employers are looking for. Passing this certification exam will not be an easy task, for you will need to learn many things to acquire that basic understanding of computer and network security.

How This Book Is Organized The book is divided into chapters to correspond with the objectives of the exam itself. Some of the chapters are more technical than others—reflecting the nature of the security environment where you will be forced to deal with not only technical details but also other issues such as security policies and procedures as well as training and education. Although many individuals involved in computer and network security have advanced degrees in math, computer science, information systems, or computer or electrical en- gineering, you do not need this technical background to address security ef- fectively in your organization. You do not need to develop your own cryptographic algorithm, for example; you simply need to be able to under- stand how cryptography is used, along with its strengths and weaknesses.

xxiv Introduction

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:05 PM

Color profile: Disabled Composite Default screen

As you progress in your studies, you will learn that many security problems are caused by the human element. The best technology in the world still ends up being placed in an environment where humans have the opportu- nity to foul things up—and all too often do.

Onward and Upward At this point, we hope that you are now excited about the topic of security, even if you weren’t in the first place. We wish you luck in your endeavors and welcome you to the exciting field of computer and network security.

Introduction xxv

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:05 PM

Color profile: Disabled Composite Default screen

CompTIA APPROVED QUALITY CURRICULUM

■ CompTIA Security+ ■ Designed for IT professionals focused on

system security.

■ Covers network infrastructure, cryptography, assessments, and audits.

■ Security+ is mandated by the U.S. Department of Defense and is recommended by top companies such as Microsoft, HP, and Cisco.

■ It Pays to Get Certified In a digital world, digital literacy is an essential survival skill. Certification proves you have the knowledge and skill to solve business problems in vir- tually any business environment. Certifications are highly valued creden- tials that qualify you for jobs, increased compensation, and promotion.

Security is one of the highest-demand job categories—growing in im- portance as the frequency and severity of security threats continue to be a major concern for organizations around the world.

■ Jobs for security administrators are expected to increase by 18 percent; the skill set required for these types of jobs map to CompTIA Security+ certification.

■ Network security administrators can earn as much as $106,000 per year.

■ CompTIA Security+ is the first step in starting your career as a network security administrator or systems security administrator.

■ CompTIA Security+ is regularly used in organizations such as Hitachi Information Systems, Trendmicro, the McAfee Elite Partner program, the U.S. State Department, and U.S. government contractors such as EDS, General Dynamics, and Northrop Grumman.

xxvi CompTIA APPROVED QUALITY CURRICULUM

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:06 PM

Color profile: Disabled Composite Default screen

How Certification Helps Your Career

CompTIA Career Pathway CompTIA offers a number of credentials that form a foundation for your ca- reer in technology and that allow you to pursue specific areas of concentra- tion. Depending on the path you choose, CompTIA certifications help you build upon your skills and knowledge, supporting learning throughout your career.

CompTIA APPROVED QUALITY CURRICULUM xxvii

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:06 PM

Color profile: Disabled Composite Default screen

■

■ Steps to Getting Certified and Staying Certified

1. Review exam objectives. Review the certification objectives to make sure you know what is covered in the exam: www.comptia.org/certifications/testprep/examobjectives.aspx

2. Practice for the exam. After you have studied for the certification, take a free assessment and sample test to get an idea what type of questions might be on the exam: www.comptia.org/certifications/testprep/practicetests.aspx

3. Purchase an exam voucher. Purchase exam vouchers on the CompTIA Marketplace, which is located at: www.comptiastore.com

4. Take the test! Select a certification exam provider, and schedule a time to take your exam. You can find exam providers at the following link: www.comptia.org/certifications/testprep/testingcenters.aspx

5. Stay Certified! Meet the Continuing Education Requirement. Effective January 1, 2011, new CompTIA Security+ certifications are valid for three years from the date of your certification. There are a number of ways the certification can be renewed. For more information go to: http://certification.comptia.org/getCertified/steps_to_ certification/stayCertified.aspx

■ Join the Professional Community The free online IT Pro Community provides valuable content to students and professionals.

Career IT job resources include

■ Where to start in IT

■ Career assessments

■ Salary trends

■ U.S. job board

Join the IT Pro Community and get access to:

■ Forums on networking, security, computing, and cutting-edge technologies

■ Access to blogs written by industry experts

xxviii CompTIA APPROVED QUALITY CURRICULUM

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:06 PM

Color profile: Disabled Composite Default screen

■ Current information on cutting-edge technologies

■ Access to various industry resource links and articles related to IT and IT careers

■ Content Seal of Quality This courseware bears the seal of CompTIA Approved Quality Content. This seal signifies this content covers 100 percent of the exam objectives and implements important instructional design principles. CompTIA recom- mends multiple learning tools to help increase coverage of the learning objectives.

■ Why CompTIA? ■ Global recognition CompTIA is recognized globally as the leading

IT nonprofit trade association and has enormous credibility. Plus, CompTIA’s certifications are vendor-neutral and offer proof of foundational knowledge that translates across technologies.

■ Valued by hiring managers Hiring managers value CompTIA certification because it is vendor- and technology-independent validation of your technical skills.

■ Recommended or required by government and businesses Many government organizations and corporations (for example, Dell, Sharp, Ricoh, the U.S. Department of Defense, and many more) either recommend or require technical staff to be CompTIA certified.

■ Three CompTIA certifications ranked in the top 10 In a study by DICE of 17,000 technology professionals, certifications helped command higher salaries at all experience levels.

CompTIA APPROVED QUALITY CURRICULUM xxix

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:07 PM

Color profile: Disabled Composite Default screen

■ How to Obtain More Information ■ Visit CompTIA online Go to www.comptia.org to learn more

about getting CompTIA certified.

■ Contact CompTIA Please call 866-835-8020, ext. 5 or e-mail [email protected].

■ Join the IT Pro Community Go to http://itpro.comptia.org to join the IT community to get relevant career information.

■ Connect with CompTIA Find us on Facebook, LinkedIn, Twitter, and YouTube.

■ CAQC Disclaimer The logo of the CompTIA Approved Quality Curriculum (CAQC) program and the status of this or other training material as “Approved” under the CompTIA Approved Quality Curriculum program signifies that, in CompTIA’s opinion, such training material covers the content of CompTIA’s related certification exam.

The contents of this training material were created for the CompTIA Se- curity+ exam covering CompTIA certification objectives that were current as of the date of publication.

CompTIA has not reviewed or approved the accuracy of the contents of this training material and specifically disclaims any warranties of merchant- ability or fitness for a particular purpose. CompTIA makes no guarantee concerning the success of persons using any such “Approved” or other training material in order to prepare for any CompTIA certification exam.

xxx CompTIA APPROVED QUALITY CURRICULUM

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:07 PM

Color profile: Disabled Composite Default screen

INSTRUCTOR AND STUDENT WEB SITE

For instructor and student resources, check out www.PrinciplesSecurity3e .com. Students will find chapter quizzes that will help them learn more about computer security, and teachers can access support materials (ask your sales representative for details).

■ Additional Resources for Teachers The Principles of Computer Security: CompTIA Security+ and Beyond Online Learning Center (www.PrinciplesSecurity3e.com) provides many resources for instructors:

■ Answer keys to the end-of-chapter activities in the textbook

■ Answer keys to the lab manual activities

■ Access to testbank files and software that allows you to generate a wide array of paper- or network-based tests, and that features automatic grading

■ Hundreds of practice questions and a wide variety of question types and difficulty levels, enabling you to customize each test to maximize student progress

■ Blackboard cartridges and other formats may also be available upon request; contact your sales representative

■ Engaging PowerPoint slides on the lecture topics (including full-color artwork from the book)

Instructor and Student Web Site xxxi

BaseTech / Principles of Computer Security: CompTIA Security+™ and Beyond / Wm. Arthur Conklin / 619-8 / Front Matter

P:\010Comp\BaseTech\619-8\FM.vp Wednesday, November 09, 2011 5:43:07 PM

Color profile: Disabled Composite Default screen