Cybersecurity
1
6
Project: Malware Threats & Vulnerabilities
My name
CIS212: Principles of Cybersecurity
September 8, 2021
Network Vulnerabilities
The network in scope for this project seem to have multiple vulnerabilities which could be exploited intentional or unintentional. A network vulnerability is a weakness of flaw in software hardware, or simply an organization processes, which when compromised by a threat actor, can results in a security breach (Firch, 2021). Considering the scenario, I believe this network could be vulnerable to nonphysical weakness which involves the operating system (OS), Malwares such as Trojans, Viruses, and Worms that are installed on the user’s machine or even on the host server itself. It may also be vulnerable to some physical vulnerabilities such theft.
Threats
Security continues to be an important part of any company. A network security threat to this network, is any attempt to breach the network and obtain access to the data on the network. For this scenario, I will analyze this network to identify an internal threat and external threat this network could be vulnerable to.
Internal Threats
An insider threat is a security risk that originates from within the targeted company. It typically involves a current or former employee or business associates who has access to sensitive inform or privilege accounts within the network. There is malicious insider, who is someone who maliciously or intentionally abuse legitimate credentials. In this current network, we have users or developers who may need elevated privileges to perform their work functions. As an example, if this user is to leave this company and no proper diligence is performed to remove their access on time, they may have back door access into the network to cause harm.
At the same time, there maybe an innocent user who unknowingly exposes the system to the outside threats. Example new developers that would be hired, may not get the adequate training needed may click on a malicious link or insecure link, infecting the systems with malware.
An external threat refers to the risk of someone or something from the outside the company that attempts to exploit system /network vulnerabilities using various attack vectors. This network could be exploited externally using malicious software, hacking sabotage, DNS flooding due to a vulnerability that may exist in the DSL router, hidden backdoor programs. Phishing attacks, unknown security bugs among others. From my observation, this network could benefit from network protection measures such as:
· Installing stateful firewall to inspect packets
· Noticeably, IDS/IPS could be implemented to track potential packet floods.
· This network use segmentation to boost performance and increase security
· Use a virtual private network (VPN) for authorized users needs to access the network remotely.
· Just performing proper maintenance of the network. Updating older technology with a newer technology could be very impactful. For instance, replacing DSL technology.
Sometimes external threats are successful because of an insider threat. Ensuring that the new hires and all active employees undergoes security training throughout the year is very important.
Potential Attacks
To sum it up, here are potential attach that could be done against this network:
· DDOS
· DOS
· DNS flooding
· Man in the Middle attack
· Code and SQL injection attacks.
· Privilege escalation
· Ransomware attack
· Malware
Conclusion
Network vulnerabilities covers a lot of technologies, devices, technology, and processes. It refers to a set of rules and configurations designed to protect the integrity, confidentiality, and accessibility of computer networks and data. Sound network security controls are recommended for organizations to reduce the risk of an attack or data breach. These measures also enable the safe operation of IT systems. The network in the scenario is vulnerable to many attacks, however with the right assessment and some preventative controls in place, we can reduce the threat surface and attack surface.
References
Firch, J. (2021). 2021 Trends Report. Retrieved from Purplesec: https://purplesec.us/common-network-vulnerabilities/