05823 - 2 - Pages Within 12Hrs

profileltdprinwival
wk3-James_Moring-prioritizing_threats.docx

1

Prioritizing Threats

Prioritizing Threats 13

CMGT/433 Cyber Security

Prioritizing Threats – Dayton Soft Products

Name

University

April 3, 2019

Cyber Security Executive Summary

Introduction

The following Executive Summary illustrates items the team is requesting additional information on, including types of challenges and cybersecurity threats, how they impact the organization, and how these threats should be addressed. Prioritization of the top five risks is shown in table format along with the impact these cyber threats could have on Dayton Soft Products network and devices. Finally, the explanation of the importance of detection and intrusion testing is reviewed, along with challenges that mobile and cloud computing brings to our organization.

Cyber Security Threat Categories

1. Mobile Device Security Threats

2. Web Application Security Threats

3. Internet of Things Security Risks

4. Cloud Security Risks

5. Network Security Threats

6. Email Security Threats

7. Social Media Security Risks

8. Endpoint Security Risks

Common cybersecurity threats come from several categories, including mobile threats, Internet of Things (IoT) risks, web application threats, cloud threats, network threats, email security threats, social media risks, and endpoint security risks (Fortinet.com, 2019). Within these cyber threat categories, some subcategories are identified below each main class. Below is a table that lists the main cybersecurity threat categories and common cyber threats for each main type, underneath them.

CATEGORIES

Mobile

Web Apps

Internet of Things (IoT)

Cloud

Network

Email

Social Media

Endpoint

Cyber Threat #1

Unsecured

Wi-Fi

Injection

Application Vulnerabilities

Data Loss

Virus/Trojan Horse

Malicious Links

Phishing Scams

Mobile threats (BYOD)

Cyber Threat #2

Data Leaks

Cross-Site Scripting

Unsecured wireless devices

Insider Threats

Rogue Software

Distributed Denial of Service (DDoS)

Malware

Compromised Routers

Cyber Threat #3

Broken Cryptography

Misconfigurations

BYOD unsecured devices

Denial of Service

Spyware and Adware

Ransom-ware

Malicious Links

Fax Machines & Printers

Table 1. Cyber Threat Categories and Sub-categories

The above challenges and their detailed impact statements are prioritized below, beginning with Mobile Security threats.

Challenges

Impact on Dayton Soft Products

Mobile Security Threats

Unsecured Wi-Fi

Threats to the organization can occur when employees use unsecured wi-fi in places such as airports, coffee shops, etc. With 743 off-site employees place around the globe, training and other security protocols must be rolled out to all employees. Off-site employees are not the only ones at risk, onsite employees travel and frequent coffee shops too.

Data Leaks

Applications downloaded to mobile phones can be the cause of unintentional data leakage (Kaspersky.com, 2019). Some applications contain risky-ware that sends data to servers remotely that is used by cybercriminals for illegal actions.

Broken Cryptography

Broken cryptograph occurs when developers use poor encryption algorithms containing vulnerabilities. This can lead to hackers modifying the send/receive capabilities of the application and send copies of text messages to other locations without the users’ knowledge.

Web Application Threats

Injection

Hackers use this threat on a target interpreter to exploit its syntax by attacking them through text (Owasp.org, 2019, Top 10 Injection). By understanding the syntax, the attackers can send untrusted data to the target interpreter. This type of threat is very common in legacy applications, such as SQL and XPath queries.

Cross-Site Scripting

This type of threat involves hackers using scripts to hijack a user’s session via the browser. It can redirect users, use malware to hijack their browser, or even deface websites (OWasp.org, 2019).

Misconfigurations

Misconfigurations can occur at all levels of the application stack, from the web server to the application server. The hacker exploits this threat by accessing unused pages, unpatched flaws, default accounts, and unprotected files to obtain access to a business system. This frequently occurs to machines that do not have the latest security patches and the updates installed and can result in the entire system being compromised.

Internet of Things (IoT) Security Threats

Application Vulnerabilities

The Internet of Things brings along with its massive vulnerabilities and threats to Dayton Soft Product. Application software is distributed for an exponential number of devices and balancing security with flexibility can be a real challenge.

Unsecured Wireless Devices

The Internet of Things (IoT) apps can be installed on a wide number of different device types, such as refrigerators, automobiles, hospital equipment, and other business machines and many of these device types do not have the capability of a secure environment in which to monitor or scan for security threats.

BYOD Unsecured Devices

BYOD is in this category because employees bringing personal devices containing a multitude of unsecured applications is normal in today's business environment. Often, companies do not provide company-issued iPads, Smartphones, Tablets, Laptops, etc., so the employee is expected to purchase and use personal devices for business needs. Companies are making a huge mistake by not providing secured devices for their employees since the cost of infiltration can range in the millions if the right hacker gets into the right app and steals company or customer information.

Cloud Security Threats

Data Loss

This type of threat does not always come from an attack. Data loss can occur when events such as an environmental or weather-related issue occur, human error, or employees accidentally deleting files. This threat can happen unintentionally, and the best way for Dayton Soft Products to mitigate damage is to keep up-to-date backups of all files in the cloud environment.

Insider Threats

This type of attack comes from disgruntled employees or even those who are just plain malicious. Insider threats can also include employees of the hosted cloud server environment who already has inside access to all data and information files.

Denial of Service (DoS) Attacks

DoS uses botnets usually purchased from the Dark Web using cryptocurrency. When a DoS occurs in a cloud environment, it gives the criminal(s) plenty of time to do major damage and cover their tracks to avoid being caught.

Network Security Threats

Virus/Trojan Horse

According to Mello, (2014), the chances of a third of the computers in the world being affected by a malicious ware are very high. The impact to Dayton is that employees may not be properly trained on how to identify email links that are malicious code ready to take down the company's network. In the case of the Trojan Horse, users willingly install software from links by being tricked since the sender is most often someone they know (the email is not really from that sender – in fact, the sender more than likely has the virus and is unaware that an email was sent out under their name).

Rogue Software

This type of threat comes in the form of a pop-up on an employee's computer that alerts them in red letters that their computer is infected, and they are offering software to save their files, if they just click and install it. Unfortunately, this still occurs today and the reason behind it is lack of company training.

Spyware and Adware

Third-party software programs, usually free that contain some spyware, adware, or bloatware that is meant to advertise products and bog down an employee's computer, and productivity for Dayton Soft Product. Adware track browsing history and habits and give popups for things you may have searched for previously. Users usually give authorization by not unchecking a box during installation. This poses a serious threat to employee productivity and employees should be prevented from downloading any software by removing Admin privileges from all company computers.

Email Security Threats

Malicious Links

Clicking on random links inside an email can be disastrous and can cause the company’s entire network to crash. Some links can install viruses on the computer and leak into the network where it will replicate as a worm, continually destroying data, files, or anything in its path.

Distributed Denial of Service (DDoS)

This type of attack occurs from many devices that are compromised and many Internet connections to flood a target, usually distributed via a botnet. The goal is to prevent a user from utilizing critical services.

Ransomware

Ransomware can be distributed through software applications, infected external storage devices, websites and are compromised, remote desktop sessions, or even email attachments. When this type of threat occurs, the ransomware changed the user's login information and holds the computer and the data therein, hostage, until the user pays a ransom using cryptocurrency. The only way to get out of paying the ransom is if the user has a good backup to restore the computer.

Social Media Threats

Phishing Scams

This type of threat involves trickery through fake websites, text messages, email, phone calls, etc. The goal of the criminal is to get the target to send them money, confidential information, passwords/login information, or any other valuable commodity by tricking them into thinking they are helping or being ordered to do this by a superior.

Malware

Malware runs rampant on social media websites and works in the background to take over social media profiles while the user remains unaware that this is occurring. Dayton Soft Products would do well to block employee access to social media websites during working hours.

Malicious Links

Malicious links still work because people continue to click on unknown links. This is risky because clicking on a malicious link could download malware that hackers may use to take control of the computer. This attack is vicious because the user has no idea that they have opened the door to allow a hacker to potentially control their machine and the company data on the computer.

Endpoint Security Threats

Mobile threats (BYOD)

Endpoint security is usually controlled by installing software on the endpoint, such as a gateway or server on a network. With the rapid growth of employees at Dayton Soft Products, the concern here is that the BYOD policies for employees do not require personal devices to be submitted to IT to install endpoint security software on them. Since employees will be using these devices to connect to the company network, there is a huge risk here.

Compromised Routers

Routers are also endpoints and are prone to attack by hackers who attempt to compromise them to change settings. Once the settings are changed, employees could easily be routed to malicious websites that will steal company and personal data. The hacker's goal is based on the financial gain if the attack is a success. One of the main problems that create this vulnerability is that Security personnel fail to change default passwords on routers which give hackers an easier way in using web-based scripts (TrendMicro.com, 2019).

Fax Machines & Printers

Fax machines and printers can easily be overlooked but are endpoints. Since fax machines are rarely used in today's office, they may be sitting in a corner gathering dust, but still connected to the company network or unsecured Internet connection, making them an ideal target for hackers.

Table 2. Cyberthreat categories and impact to Dayton soft products

Top Five Threats

1. Mobile Device Security Threats

2. Web Application Security Threats

3. Cloud Security Risks

4. Network Security Threats

5. Endpoint Security Risks

Recommended Cybersecurity Category to Address for Dayton Soft Products

The recommended category is network security threats. This is because of the importance of securing all devices and avenues that can lead to access to the company network.

Identify Challenges that Mobile and Cloud Computing Needs bring to Dayton Soft Products

Challenges regarding mobile and cloud computing needs for our organization are many. However, the benefits far outweigh the risks. Some of these risks include geographic risks, infrastructure risks, and platform risks. Geographically, the company currently operates out of one data center, leaving all types of challenges and risks for our organization. These risks include Internet outages, fires, natural disasters, etc. Additionally, having only one data center increases latency and lag time resulting in poor performance of the network. By moving to the cloud, we can experience a cost-effective way to diversify geographically and have our data redundantly stored at several data centers. Platform diversity includes cyber threats that target our security protocols, applications, and operating systems. Since cloud providers have their own sets of security protocols, this decreased the likelihood that both our data center and the cloud provider’s data center will succumb to the same cyber-attack.

Security tools utilized by cloud providers can assist Dayton Soft Products with email filtering, network monitoring, and DDoS protection against cyber threats. Cloud providers can greatly reduce our risk by getting malicious email links that our employees cannot resist clicking on by filtering and removing malicious attachments and spam. They can store these attachments in a quarantined folder before deleting to give our Cybersecurity Team a chance to review the attachments.

As discussed above, mobile challenges continue to be a threat as new employees are hired and therefore use their unsecured personal devices to access the company network. All devices must be turned into the IT Department so that the Cybersecurity Team can install the proper security tools.

Importance of Testing for Detection and Intrusion of Risks

Testing the vulnerability of a company's systems and network is critical to securing our data, information, and overall systems. Several specialized tests can be used including penetration tests, intrusion tests, and vulnerability analysis. The penetration test reveals a detailed analysis of system vulnerabilities that are open to the hacker for exploitation. Ignoring results of any of these tests can open our company up to severe harm and financial liability. It is essential to detect and understand threats before they occur to initiate maximum mitigation efforts to lessen the impact to Dayton Soft Products. Finally, conducting these tests is an IT Security best practice and concludes that our systems are thoroughly resistance to infiltration of cyber threats.

References

Eurotux.com (2019). Intrusion Tests and Vulnerability Analysis Reduce IT Security Risks. Retrieved from https://eurotux.com/intrusion-tests-and-vulnerability-analysis-reduce-it-security-risks

Fortinet.com (2019). Web Application Security. Retrieved from https://www.fortinet.com/solutions/enterprise-midsize-business/webapplication-security.html

Mello, J.P. (2014). Report: Malware Poisons One-Third of World's Computers. TechNewsWorld.com. Retrieved from https://www.technewsworld.com/story/80707.html

OWasp.org (2019). Top 10 Cross-Site Scripting. Retrieved from https://www.owasp.org/index.php/Top_10_2010-A2-Cross-Site_Scripting_(XSS)

OWasp.org (2019). Top 10 Injection. Retrieved from https://www.owasp.org/index.php/Top_10_2010-A1-Injection

TrendMicro.com (2019). 3 Overlooked Endpoints for Cyber Attacks and How to Protect them. Retrieved from https://blog.trendmicro.com/3-overlooked-endpoints-for-cyber-attacks-and-how-to-protect-them/