Group PowerPoint Residency - Day 2 Residency Assignment
002835518 - Chalamalasetty, Srinivas
002826551 - Ganji, Umakumar
002849521 - Karra, Ravi Sastry
002838332 - Kukkala, Indrakaran Reddy
002826761 - Malineni, Srinivas
002837463 - Namburu, Krishna Chaitanya Chowdary
University of the Cumberlands
THREAT MODELING FOR LIBRARY RESOURCE BY GROUP 3
LIBRARIAN CREDENTIALS:
- Librarian credentials should have the strong passwords polices
- least minimum length 8 characters and password should contain numerical and special characters, Uppercase and Lowercase letters.
- Password retention polices
- Use the password retention for every few months
- Librarian Username should be more complex logical private identity
- Last four digits of SSN or DOB or employee Id number
- Librarian must have more privileges than library user
- Add or remove inventory and access to write complex quires to filter or search the books
- Librarian permission create new library user
- Librarian must have Ability to audit system events
- who logged in website and what all activities user performed on the library site
USER PERSONAL INFORMATION:
- User personal information include
- Name, address, email address, phone number, race, nationality, ethnicity, origin, color, age, sex, identifying number, passcode, fingerprints, and educational details.
- User data can help to build better products
- Product design, implementing iterative solutions and resource allocation
- User personal information Privacy
- The United States' privacy law
- User personal data protection
- Implement strong password policies
- Password retention
- Encrypted the data transportation policies
- Multiple layer application infrastructure to protect from DDoS attacks
- Implement the web application firewall (WAF)
LIBRARY WEBSITE SYSTEM
- Scenario
- Graphical User interface that allows user to login
- Graphical User interface that allows user to create account
- Graphical User interface that allows user to access the books and other material from the library database system
- Threat Model
- Website outsourced tools and security firewalls are not completely reliable for website development.
- Encrypt and decrypt the data sent ad received from and to the user.
- Mitigations
- Identification
- Authentication
LIBRARY WEBSITE SYSTEM
LIBRARY DATABASE SYSTEM
- Scenario
- Database tool and architecture that allows user to CRUD information
- Database tool and architecture that allows user to that links between the Graphical User Interface of the website and the database of the library resources
- Database tool and architecture that allows user to post and administer on a reliable network system
- Threat Model
- Modify data over public network like WiFi.
- Load on the database system for multiple threads of requests.
- Mitigation
- Identification and authentication of user.
- Use approved database tools and reviewed architecture for uninterrupted data flow.
WEB SERVER ATTACKS & COUNTERMEASURES
- DOS attack
- Website Defacement
- Misconfiguration attacks
- Phishing Attack
- Vulnerability Scanning
DB SERVER ATTACKS & COUNTERMEASURES
- Excessive privileges
- Database injection attacks
- Storage media exposure
- Exploitation ofdatabases vulnerable
DFD DIAGRAM FOR WEB/DB SERVER
USER DB READ ACCESS
LIBRARIAN/ADMIN DB READ/WRITE ACCESS
THANK YOU