proof reading my paper ultimate writer
QWD Vulnerability and weakness analysis
Laila Panjawani Submitted to: William Crumm
SE571 Principles of Information Security and Privacy
Keller Graduate School of Management
Submitted: March 22, 2015
Table of Content
Two Security Vulnerabilities 4
Introduction
Quality Web Design is company that focuses on creating Web site for numerous businesses. System security is crucial asset in any company and should be protected in order to stay in business for extensive period of time. Quality Web Design requires analyzing their system to understand weakness in their Security system so that their system is not compromised. QWD Software security and hardware are potential Vulnerabilities that needs to be addressed in order to avoid compromising their system Security Vulnerabilities
1
Two Security Vulnerabilities
Software Vulnerability and Hardware Vulnerability:
The first potential hardware threat is inherent with use of VPN Tunnels that can cause damage to their hardware system. According to Bank Security Report, remote access can cause security breach by user not using necessary security precautions that are used in the company, institution’s servers, and data that’s transmitted through wireless internet. VPN fails to protect all of this weakness that can cause security breach due to not having proper protections in place (Bank Security Report, 2012). For example, QWD allows employees to access their server through corporate owned computer and mobile phone to Virtual point Network, email, and Exchange server however, this could leave company vulnerable to intruders having access to their laptops, mobile device, data, compromising user names, and passwords.
Organization system may also have potential risk of new viruses being transmitted via encrypted packet due to wireless network used (Bank Security Report, 2012). In Addition to, having access to VPNs means that the user has full access to the internal server, thus allowing the hacker to have full access to internal network if it is compromised (Roy Hills, 2005). This means that the intruder will have access to confidential information of accounting, payroll and marketing operations that can be used to cause company some damage.
The likelihood that the threat will occur is most likely due to being easily hacked over unsecured network, full access to internal network through mobile, and being invisible to IDS monitoring can be easy target for any intruders (Roy Hills, 2005). Company can loose its competitive advantage against other competitors by hackers damaging system through virus, getting hold of sensitive data and having direct access to internal network. This could damage the trust QWD confidentially and reliability it has with its customers and company.
QWD system can also be subjected to SQL injection attack. SQL injection attack is caused by using Structured Query language code to gain unauthorized access to the backend database (Abdoulaye, Pathan, 2012). In other words, the attacker may use malicious code through SQL query and injects that to input box of Web Application (Abdoulaye, Pathan, 2012).
QWD could be at potential risk of compromising their database in such a way that it can alter or destroy their data, and give unauthorized access to confidential data such as customer’s addresses, phone numbers, credit card information and much more. SQL injection is known to by bass firewall and gain access to the database (Kindey, Patha, 2013). For example, QWD customers can be entering information on their “feedback” screen and click submit, the attacker can easily get the confidential information send back by entering the correct SQL quires into those fields and gaining easy access to their information (Richards, 2006).
In addition to, SQL injections can also be potential threat to company’s confidentiality, integrity and authority if the attacker succeeds to attack the backend data on the system (Abdoulaye, Pathan, 2012). This could greatly hurt their competitive advantage against other competitors in the market. For example, hacker can have access to customer’s information that might be simply browsing through their website, which may cause serious damage to company reputation and reliability.
According to Jonathan Richards, more than 50% of the company computers systems are not securely protected from hacker to gain administrative privileges. This could cause company large amount of money if proper steps are not taken to prevent this. This could most likely happen to QWD due to the vulnerability in their system that can allow hackers to gain unlimited access to their backend database and cause irreversible damage to the company. There is several preventative solutions QWD can take in order prevent hackers from intruding their software and hardware, which will help company protect their asset for long time to come.
Recommended solutions
QWD is required to take necessary steps to protect their hardware from being effected through usage of VPN tunnels that may cause security breach in the company. According to research, VPN can be considered as a weak link in a secure system if proper protections are not set. QWD must consider effective way to avoid split tunneling, define central authentication, ensure safe encryption and SSL connection, and aim for customizability and versatility. In addition to, look for VPN gateways to prevent access abuse, verify IP addresses and ports with a protocol analyzer, make sure applications are supported, and most importantly have effective policy implementation (Dan,2014).
Figure 1. Threat-Protected VPN Services Use Onboard Security to Protect Against VPN
QWD can achieve this level of protection by implementing CISCO ASA 5500 series adaptive security router appliance, that includes top of the line security and VPN services for small and medium-sized business (SMBs) and enterprise applications (cisco.com, n.d). According to BarcodesInc, ASA 5500 series adaptive security appliance cost approximately $779.50 (barcordsinc.com, n.d). The IT staff, at no additional cost to the company can load this appliance and meet QWD remote office needs.
Figure 2. Customizable VPN Services for Any Deployment Scenario (Cisco. Com, nd.)
This software provides Internet transport by ensuring integrity through advanced endpoint and network level security (Figure 2). Cisco ASA 500 series offers top of the line VPN technologies with scalability up to 10,000 simultaneous users per device (cisco.com, n.d).
Impact on Business
According to Cisco, Cisco ASA 500 will reduce the cost associated with equipment needed to scale and protect a VPN. QWD employees will have “SSL (TLS &DTLS), and IPsec-based full network access, Superior clientless network access, Cisco any connect secure mobility solution, network-aware site to site VPNs, threat-protected remote access VPNs, cost effective VPN deployment and operations, scalability and resiliency, openSSL technology ( cisco.com,n.d).”
In addition to, QWD is recommended to take several precautions to prevent SQL injections attacks. According to How to Prevent SQL Injection Attacks, QWD will have to filter all the data entered via websites known as data sanitization. In addition to, use free web application firewall known as Mod Security, which provides protection from threatening request (Aaron, 2012). QWD will also have to limit database privileges by context and avoid constructing SQL queries with user input (Aaron,2012).The company may also buy software Acunetix, web application security. Acunetic software helps scans for SQL injections, and blind SQL injections along with cross-site scripting. This software can be purchased at the cost of $ 4,995 and maintenance cost $1,000 yearly (acunetix.com, n.d). These preventative actions will help protect QWD organization from compromising their network, data, and control of their website.
Impact on business
QWD implementing recommended solutions would gain customer satisfaction. In addition to, will save lot of money by avoiding unauthorized access and control to intruders. Will insure competitive advantage by enforcing reliability and confidentially against SQL injections.
In conclusion, QWD is susceptible to hardware and software vulnerability. It is recommended that QWD invest in recommended solution to sustain their competitive advantage in the market. QWD will save thousands of dollars by taking preventative actions vs. fixing the problem after their system is compromised. Research have shown that approximately 90% of the of the sites using VPN tunnels had substantial vulnerabilities in three years of testing (Roy, 2005). Company must take necessary steps to protect their assets and customers information from being compromised.
· Abdoulaye, D, Pathan,K. (2013). A Detailed Survey on Various Aspects of SQL Injection in Web Applications: Vulnerabilities, Innovative Attacks, and Remedies, International Journal of Communication Networks & Information, Vol. 5 Issue 2, p, 80.
· Identifying VPN Security Weaknesses. (2012). Bank Security Report, 41(4), 5-8.
· Jonathan, R. (n.d). On the hackers' trail - have they got your number? Times, The (United Kingdom).
· Roy, H. (2005). Common VPN Security Flaws. Roy Hills, NTA Monitor LTD. Retrieved on March 22 March.2015 from
http://www.nta-monitor.com/files/whitepapers/VPN-Flaws-Whitepaper.pdf
http://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/product_data_sheet0900aecd80402e3f.html
http://www.acunetix.com/ordering/
http://www.esecurityplanet.com/hackers/how-to-prevent-sql-injection-attacks.html
Aaron Weiss posted August 16,2012
http://www.barcodesinc.com/cisco/asa-5500-series.htm
http://resources.infosecinstitute.com/importance-effective-vpn-remote-access-policy/