05823 - 2 - Pages Within 12Hrs
1
Prioritizing Threats
Prioritizing Threats 13
CMGT/433 Cyber Security
Prioritizing Threats – Dayton Soft Products
Name
April 3, 2019
Cyber Security Executive Summary
Introduction
The following Executive Summary illustrates items the team is requesting additional information on, including types of challenges and cybersecurity threats, how they impact the organization, and how these threats should be addressed. Prioritization of the top five risks is shown in table format along with the impact these cyber threats could have on Dayton Soft Products network and devices. Finally, the explanation of the importance of detection and intrusion testing is reviewed, along with challenges that mobile and cloud computing brings to our organization.
Cyber Security Threat Categories
1. Mobile Device Security Threats
2. Web Application Security Threats
3. Internet of Things Security Risks
4. Cloud Security Risks
5. Network Security Threats
6. Email Security Threats
7. Social Media Security Risks
8. Endpoint Security Risks
Common cybersecurity threats come from several categories, including mobile threats, Internet of Things (IoT) risks, web application threats, cloud threats, network threats, email security threats, social media risks, and endpoint security risks (Fortinet.com, 2019). Within these cyber threat categories, some subcategories are identified below each main class. Below is a table that lists the main cybersecurity threat categories and common cyber threats for each main type, underneath them.
|
CATEGORIES |
Mobile |
Web Apps |
Internet of Things (IoT) |
Cloud |
Network |
|
Social Media |
Endpoint |
|
Cyber Threat #1 |
Unsecured Wi-Fi |
Injection |
Application Vulnerabilities |
Data Loss |
Virus/Trojan Horse |
Malicious Links |
Phishing Scams |
Mobile threats (BYOD) |
|
Cyber Threat #2 |
Data Leaks |
Cross-Site Scripting |
Unsecured wireless devices |
Insider Threats |
Rogue Software |
Distributed Denial of Service (DDoS) |
Malware |
Compromised Routers |
|
Cyber Threat #3 |
Broken Cryptography |
Misconfigurations |
BYOD unsecured devices |
Denial of Service |
Spyware and Adware |
Ransom-ware |
Malicious Links |
Fax Machines & Printers |
Table 1. Cyber Threat Categories and Sub-categories
The above challenges and their detailed impact statements are prioritized below, beginning with Mobile Security threats.
|
Challenges |
Impact on Dayton Soft Products |
|
Mobile Security Threats |
|
|
Unsecured Wi-Fi |
Threats to the organization can occur when employees use unsecured wi-fi in places such as airports, coffee shops, etc. With 743 off-site employees place around the globe, training and other security protocols must be rolled out to all employees. Off-site employees are not the only ones at risk, onsite employees travel and frequent coffee shops too. |
|
Data Leaks |
Applications downloaded to mobile phones can be the cause of unintentional data leakage (Kaspersky.com, 2019). Some applications contain risky-ware that sends data to servers remotely that is used by cybercriminals for illegal actions. |
|
Broken Cryptography |
Broken cryptograph occurs when developers use poor encryption algorithms containing vulnerabilities. This can lead to hackers modifying the send/receive capabilities of the application and send copies of text messages to other locations without the users’ knowledge. |
|
Web Application Threats |
|
|
Injection |
Hackers use this threat on a target interpreter to exploit its syntax by attacking them through text (Owasp.org, 2019, Top 10 Injection). By understanding the syntax, the attackers can send untrusted data to the target interpreter. This type of threat is very common in legacy applications, such as SQL and XPath queries. |
|
Cross-Site Scripting |
This type of threat involves hackers using scripts to hijack a user’s session via the browser. It can redirect users, use malware to hijack their browser, or even deface websites (OWasp.org, 2019). |
|
Misconfigurations |
Misconfigurations can occur at all levels of the application stack, from the web server to the application server. The hacker exploits this threat by accessing unused pages, unpatched flaws, default accounts, and unprotected files to obtain access to a business system. This frequently occurs to machines that do not have the latest security patches and the updates installed and can result in the entire system being compromised. |
|
Internet of Things (IoT) Security Threats |
|
|
Application Vulnerabilities |
The Internet of Things brings along with its massive vulnerabilities and threats to Dayton Soft Product. Application software is distributed for an exponential number of devices and balancing security with flexibility can be a real challenge. |
|
Unsecured Wireless Devices |
The Internet of Things (IoT) apps can be installed on a wide number of different device types, such as refrigerators, automobiles, hospital equipment, and other business machines and many of these device types do not have the capability of a secure environment in which to monitor or scan for security threats. |
|
BYOD Unsecured Devices |
BYOD is in this category because employees bringing personal devices containing a multitude of unsecured applications is normal in today's business environment. Often, companies do not provide company-issued iPads, Smartphones, Tablets, Laptops, etc., so the employee is expected to purchase and use personal devices for business needs. Companies are making a huge mistake by not providing secured devices for their employees since the cost of infiltration can range in the millions if the right hacker gets into the right app and steals company or customer information. |
|
Cloud Security Threats |
|
|
Data Loss |
This type of threat does not always come from an attack. Data loss can occur when events such as an environmental or weather-related issue occur, human error, or employees accidentally deleting files. This threat can happen unintentionally, and the best way for Dayton Soft Products to mitigate damage is to keep up-to-date backups of all files in the cloud environment. |
|
Insider Threats |
This type of attack comes from disgruntled employees or even those who are just plain malicious. Insider threats can also include employees of the hosted cloud server environment who already has inside access to all data and information files. |
|
Denial of Service (DoS) Attacks |
DoS uses botnets usually purchased from the Dark Web using cryptocurrency. When a DoS occurs in a cloud environment, it gives the criminal(s) plenty of time to do major damage and cover their tracks to avoid being caught. |
|
Network Security Threats |
|
|
Virus/Trojan Horse |
According to Mello, (2014), the chances of a third of the computers in the world being affected by a malicious ware are very high. The impact to Dayton is that employees may not be properly trained on how to identify email links that are malicious code ready to take down the company's network. In the case of the Trojan Horse, users willingly install software from links by being tricked since the sender is most often someone they know (the email is not really from that sender – in fact, the sender more than likely has the virus and is unaware that an email was sent out under their name). |
|
Rogue Software |
This type of threat comes in the form of a pop-up on an employee's computer that alerts them in red letters that their computer is infected, and they are offering software to save their files, if they just click and install it. Unfortunately, this still occurs today and the reason behind it is lack of company training. |
|
Spyware and Adware |
Third-party software programs, usually free that contain some spyware, adware, or bloatware that is meant to advertise products and bog down an employee's computer, and productivity for Dayton Soft Product. Adware track browsing history and habits and give popups for things you may have searched for previously. Users usually give authorization by not unchecking a box during installation. This poses a serious threat to employee productivity and employees should be prevented from downloading any software by removing Admin privileges from all company computers. |
|
Email Security Threats |
|
|
Malicious Links |
Clicking on random links inside an email can be disastrous and can cause the company’s entire network to crash. Some links can install viruses on the computer and leak into the network where it will replicate as a worm, continually destroying data, files, or anything in its path. |
|
Distributed Denial of Service (DDoS) |
This type of attack occurs from many devices that are compromised and many Internet connections to flood a target, usually distributed via a botnet. The goal is to prevent a user from utilizing critical services. |
|
Ransomware |
Ransomware can be distributed through software applications, infected external storage devices, websites and are compromised, remote desktop sessions, or even email attachments. When this type of threat occurs, the ransomware changed the user's login information and holds the computer and the data therein, hostage, until the user pays a ransom using cryptocurrency. The only way to get out of paying the ransom is if the user has a good backup to restore the computer. |
|
Social Media Threats |
|
|
Phishing Scams |
This type of threat involves trickery through fake websites, text messages, email, phone calls, etc. The goal of the criminal is to get the target to send them money, confidential information, passwords/login information, or any other valuable commodity by tricking them into thinking they are helping or being ordered to do this by a superior. |
|
Malware |
Malware runs rampant on social media websites and works in the background to take over social media profiles while the user remains unaware that this is occurring. Dayton Soft Products would do well to block employee access to social media websites during working hours. |
|
Malicious Links |
Malicious links still work because people continue to click on unknown links. This is risky because clicking on a malicious link could download malware that hackers may use to take control of the computer. This attack is vicious because the user has no idea that they have opened the door to allow a hacker to potentially control their machine and the company data on the computer. |
|
Endpoint Security Threats |
|
|
Mobile threats (BYOD) |
Endpoint security is usually controlled by installing software on the endpoint, such as a gateway or server on a network. With the rapid growth of employees at Dayton Soft Products, the concern here is that the BYOD policies for employees do not require personal devices to be submitted to IT to install endpoint security software on them. Since employees will be using these devices to connect to the company network, there is a huge risk here. |
|
Compromised Routers |
Routers are also endpoints and are prone to attack by hackers who attempt to compromise them to change settings. Once the settings are changed, employees could easily be routed to malicious websites that will steal company and personal data. The hacker's goal is based on the financial gain if the attack is a success. One of the main problems that create this vulnerability is that Security personnel fail to change default passwords on routers which give hackers an easier way in using web-based scripts (TrendMicro.com, 2019). |
|
Fax Machines & Printers |
Fax machines and printers can easily be overlooked but are endpoints. Since fax machines are rarely used in today's office, they may be sitting in a corner gathering dust, but still connected to the company network or unsecured Internet connection, making them an ideal target for hackers. |
|
|
Table 2. Cyberthreat categories and impact to Dayton soft products
Top Five Threats
1. Mobile Device Security Threats
2. Web Application Security Threats
3. Cloud Security Risks
4. Network Security Threats
5. Endpoint Security Risks
Recommended Cybersecurity Category to Address for Dayton Soft Products
The recommended category is network security threats. This is because of the importance of securing all devices and avenues that can lead to access to the company network.
Identify Challenges that Mobile and Cloud Computing Needs bring to Dayton Soft Products
Challenges regarding mobile and cloud computing needs for our organization are many. However, the benefits far outweigh the risks. Some of these risks include geographic risks, infrastructure risks, and platform risks. Geographically, the company currently operates out of one data center, leaving all types of challenges and risks for our organization. These risks include Internet outages, fires, natural disasters, etc. Additionally, having only one data center increases latency and lag time resulting in poor performance of the network. By moving to the cloud, we can experience a cost-effective way to diversify geographically and have our data redundantly stored at several data centers. Platform diversity includes cyber threats that target our security protocols, applications, and operating systems. Since cloud providers have their own sets of security protocols, this decreased the likelihood that both our data center and the cloud provider’s data center will succumb to the same cyber-attack.
Security tools utilized by cloud providers can assist Dayton Soft Products with email filtering, network monitoring, and DDoS protection against cyber threats. Cloud providers can greatly reduce our risk by getting malicious email links that our employees cannot resist clicking on by filtering and removing malicious attachments and spam. They can store these attachments in a quarantined folder before deleting to give our Cybersecurity Team a chance to review the attachments.
As discussed above, mobile challenges continue to be a threat as new employees are hired and therefore use their unsecured personal devices to access the company network. All devices must be turned into the IT Department so that the Cybersecurity Team can install the proper security tools.
Importance of Testing for Detection and Intrusion of Risks
Testing the vulnerability of a company's systems and network is critical to securing our data, information, and overall systems. Several specialized tests can be used including penetration tests, intrusion tests, and vulnerability analysis. The penetration test reveals a detailed analysis of system vulnerabilities that are open to the hacker for exploitation. Ignoring results of any of these tests can open our company up to severe harm and financial liability. It is essential to detect and understand threats before they occur to initiate maximum mitigation efforts to lessen the impact to Dayton Soft Products. Finally, conducting these tests is an IT Security best practice and concludes that our systems are thoroughly resistance to infiltration of cyber threats.
References
Eurotux.com (2019). Intrusion Tests and Vulnerability Analysis Reduce IT Security Risks. Retrieved from https://eurotux.com/intrusion-tests-and-vulnerability-analysis-reduce-it-security-risks
Fortinet.com (2019). Web Application Security. Retrieved from https://www.fortinet.com/solutions/enterprise-midsize-business/webapplication-security.html
Mello, J.P. (2014). Report: Malware Poisons One-Third of World's Computers. TechNewsWorld.com. Retrieved from https://www.technewsworld.com/story/80707.html
OWasp.org (2019). Top 10 Cross-Site Scripting. Retrieved from https://www.owasp.org/index.php/Top_10_2010-A2-Cross-Site_Scripting_(XSS)
OWasp.org (2019). Top 10 Injection. Retrieved from https://www.owasp.org/index.php/Top_10_2010-A1-Injection
TrendMicro.com (2019). 3 Overlooked Endpoints for Cyber Attacks and How to Protect them. Retrieved from https://blog.trendmicro.com/3-overlooked-endpoints-for-cyber-attacks-and-how-to-protect-them/