Practical connection assignment 500 WORD ( due in 4 hours MANDATORY ) NO PLAGIARISIM ).

profileanve5h.5p10
ISOL532Spring2017Week1.pptx

ISOL 532 Telecommunications and Network Security

Week 1: Introduction to Network Security

Introduction

My background

My goals for you

Weekly Lectures

Syllabus

Syllabus

Course Description

Course Objectives

Course Structure

Materials

Grading

Course Expectations

Tentative Course Outline

Assignment Information

This is a Master’s level course and I expect Master’s level work

Deadlines\Due Dates

Most work – with the exceptions being Exams and the Residency Weekend Project – will be assigned with a due date in 2 weeks

With the two week window, there is no reason (other than something catastrophic), that the assignments cannot be completed

Residency Weekend Attendance - Mandatory

Graduate International Students English Help

Office of International Academic Services

These services are specifically designed and run to help international students improve their writing (essays, research, projects, etc.) and can also be used to improve reading, listening and speaking skills. Most importantly, our tutoring services are  very easy to access because they are open to graduate students ONLINE.

Online tutoring help on Blackboard, on the home page under “Organizations”.

In a recent on-campus survey, our international students noted that our services helped them improve their grades, and would recommend our help to others.

Resources:

Sarah Hammond ([email protected])

Julie Deyrup - Director, International Academic Services ([email protected])

Your Work

I do not give grades, students earn grades

SafeAssign

Pulls from a large number of sources, including all submitted writings both past and present classes

Highlights sources with only a few or no words changed

Considers usage on another paper the highest priority when isolating\identifying plagiarism

If SafeAssign flags it pulled almost directly from other sources, the grade will be a “0”

Following slides are taken directly from http://www.plagiarism.org/plagiarism-101/what-is-plagiarism (with some formatting changes)

Plagiarism

What is Plagiarism?

Many people think of plagiarism as copying another's work or borrowing someone else's original ideas. But terms like "copying" and "borrowing" can disguise the seriousness of the offense:

According to the Merriam-Webster Online Dictionary, to "plagiarize" means

to steal and pass off (the ideas or words of another) as one's own

to use (another's production) without crediting the source

to commit literary theft

to present as new and original an idea or product derived from an existing source

In other words, plagiarism is an act of fraud. It involves both stealing someone else's work and lying about it afterward.

But can words and ideas really be stolen?

According to U.S. law, the answer is yes. The expression of original ideas is considered intellectual property and is protected by copyright laws, just like original inventions. Almost all forms of expression fall under copyright protection as long as they are recorded in some way (such as a book or a computer file).

Plagiarism

All of the following are considered plagiarism:

turning in someone else's work as your own

copying words or ideas from someone else without giving credit

failing to put a quotation in quotation marks

giving incorrect information about the source of a quotation

changing words but copying the sentence structure of a source without giving credit

copying so many words or ideas from a source that it makes up the majority of your work, whether you give credit or not

Most cases of plagiarism can be avoided, however, by citing sources. Simply acknowledging that certain material has been borrowed and providing your audience with the information necessary to find that source is usually enough to prevent plagiarism.

From the Course Syllabus

Academic Integrity

At a Christian liberal arts University committed to the pursuit of truth and understanding, any act of academic dishonesty is especially distressing and cannot be tolerated. In general, academic dishonesty involves the abuse and misuse of information or people to gain an undeserved academic advantage or evaluation. The common forms of academic dishonesty include:

cheating - using deception in the taking of tests or the preparation of written work, using unauthorized materials, copying another person’s work with or without consent, or assisting another in such activities

lying—falsifying, fabricating, or forging information in either written, spoken, or video presentations

plagiarism—using the published writings, data, interpretations, or ideas of another without proper documentation

 

Episodes of academic dishonesty are reported to the Vice President for Academic Affairs. The potential penalty for academic dishonesty includes a failing grade on a particular assignment, a failing grade for the entire course, or charges against the student with the appropriate disciplinary body.

Terms

OSI Model: Open Systems Interconnect network Model

TCP Model – Model similar to OSI, but older and less complex

Scanners: Commercial or freeware software tools used to “scan” against a system to determine open ports where data can be transmitted and received through, which could be a vulnerability that allows an attacker to exploit

Network Tap: Devices used to collect data flows through a network for monitoring purposes

Network Entities (AKA: the 7 domains of a typical IT infrastructure) pages 9 - 21

Workgroups

SOHO networks

Client\Server networks

LAN (Local Area Network)

WAN (Wide Area Network)

Thin Clients\Remote Desktop

Remote Control, Remote Access and VPN

Boundary Network (DMZ, Extranet, Honeynet)

Networking: Things to Consider

Redundancy

Single Point of Failure

Chokepoints

Access Controls

Budget

What Is Network Security?

How do you define network security?

What is included in network security?

What are you trying to protect?

Who is responsible for Network Security?

The Information Security Triad

Security Objectives

Confidentiality

Protection against unauthorized access while providing authorized users access to resources

Integrity

Protection against unauthorized changes while allowing authorized changes to be made by authorized users

Availability

Protection against downtime, loss of data and blocked access while providing consistent uptime, protecting data and supported authorized access to resources

Basic Functions of Telecommunications and Network Security

Message protection – Telecommunications security is focused on the protection of data in transport

Non-repudiaton – Is the assurance that a specific author actually did create and send a specific item to a specific recipient, and that it was successfully received

Redundancy – Is very important if systems are to remain highly available

Defense-in-depth – Series of hurdles

Collection of Controls

Any one of these alone has its vulnerabilities and can be circumvented

When taken together as a holistic system, however, breaking in becomes much more difficult and requires significantly greater resources

Network-based Attacks

Attackers may be motivated by profit or gain, recognition (ego), revenge, etc.

“Active attacks” change or damage systems; they exploit vulnerabilities, infiltrate networks, launch malicious code, or deny service

“Passive attacks” wiretap or eavesdrop on data flows using spyware

Attacks such as man-in-the-middle attacks intercept data streams

Network as a channel for attacks

Network as the target of attack

Denial of Service (DoS) attack

Distributed Denial of Service (DDoS) attack

Network Security and Risks

Network attacks

Attack trees

Path of least resistance

Attack Steps

Target Acquisition (discovery)

Target Analysis (enumeration)

Target Appropriation (exploitation)

Target Access (vulnerability mapping)

This Week

Read chapters 1, 2, 4 and NIST SP 800-30: Guide for Conducting Risk Assessments (http :// csrc.nist.gov/publications/PubsSPs.html) – use the latest version

Labs 1, 2 and 3 – due Sunday, January 22nd

Discussion board post