CYBR515 - Harry And Mae’s - Milestone 5

profilekartiukt18
Milesonte_4_summary.docx

RUNNING HEAD: HARRY AND MAE’S RECOMMENDATION 2

HARRY AND MAE’S RECOMMENDATION 2

HARRY AND MAE’S RECOMMENDATION

The Intrusion prevention system alone provides the necessary protection against malicious content whose pattern has been previously identified to match a specific signature (Prabha & Sree, 2016). Since new attacks may go unattended if they do not match any signature of the Intrusion prevention system, it is placed after the firewall. This ensures added security, so that traffic first traverses the firewall before being analyzed by the Intrusion prevention system. The Intrusion prevention system performs both detection and prevention therefore there is no need to implement both an Intrusion prevention system and an intrusion detection system in one network architecture. The virtual private network prevents interception of traffic as it is being relayed, thereby maintaining the privacy of communication. The virtual private network works by providing an encrypted communication connection between the Wi-Fi users and the network in the form of a VPN tunnel. No one can intercept such communication or even monitor it because the relay channel is encrypted.

The preferred mode of communication is through email when compared to phone calls and letters. The best way of securing email messages is through end-to-end encryption. An email message is encrypted as soon as a user sends an email message from a computing terminal and it remains in this form until it reaches the recipient. The other encryption conventions provide for encryption at the sender’s terminal, the email messages are still stored in a decrypted format (Dechand et al., 2019). This poses a threat at the storage point since anyone who can successfully access the email storage facility can read or misuse the email messages. End to end encryption ensures that the email messages remain unmodified and encrypted until they reach the recipient. It eliminates the threat posed when there is access to the email servers. To access any resource, such as email messages, an individual will have to pass through an authentication server to ensure that he or she is liable to the email service, which further protects the email architecture from unauthorized access.

The changes made to the topology include the inclusion of an authentication server to identify who can access what resource, the deletion of the IDS as the IPS alone is enough, and the inversion of the switch and gateway along the dedicated network since switches work on local network level and gateways at edge of a network.

References

Dechand, S., Naiakshina, A., Danilova, A., & Smith, M. (2019, June). In Encryption We Don’t Trust: The Effect of End-to-End Encryption to the Masses on User Perception. In 2019 IEEE European Symposium on Security and Privacy (EuroS&P) (pp. 401-415). IEEE.

Prabha, K., & Sree, S. S. (2016). A Survey on IPS Methods and Techniques. International Journal of Computer Science Issues (IJCSI), 13(2), 38