assignemnet 2 risk recovery

profilegoodworkneeded
20150820230009assignment_1.docx

1

POTENTIAL ATTACKS, THREATS AND VULNERABILITIES 2

POTENTIAL ATTACKS, THREATS AND VULNERABILITIES 8

We have been tasked by the CIO to draft a report identifying potentially malicious attacks, threats, and vulnerabilities specific to our organization. Further, the CIO would like us to briefly explain each item and potential impact it could have on the organization.

Malicious Network Attacks

A network attack is normally defined as a type of intrusion within a network infrastructure that is going to analyze an environment as well as collect different information in order to gain improper access to an existing port that is vulnerable. This could also include an unauthorized access to different resources, (Symantec, 2013). We are going to have to begin analyzing the actual threat or attack in order to protect the system against other potential attacks that are or could be occurring within your network. Most of the attacks we are going to find will be consistent with those who have hacked the system, blended attacks, or either viruses.

1. A virus is known as a program in which is activated by attaching a variety of copies of itself within an object. The viruses can also begin to reach within your computer from another computer that has been effected via other sources such as DVD’s, CD’s, or other devices. It could also occur via a network, (Symantec, 2013). Due to the fact that virus attacks are consistent with sheer frequency, we have to list them as being number one on our list. According to the Department of Trade and Industry survey they have conducted, there is 73% of all organizations that have received infected emails or even files during the past year and the greater organizations have rose to become 83%, (Vernon, 2004).

The actual impact within the network can become greatly infected with the known or even hidden virus and can become quite tragic to the system. There could be files that will be destructed or corrupted, programs can become disabled, and there could be a critical loss of data while overloading the network. This could be just a few to name the least of devastating occurrences with viruses on systems. These viruses can also be introduced to the network within various ways. An employee can download an effected email, or software, or they could open and execute the attachments that are effected in the emails while bringing in the virus from the files to the home mark on the drive.

This can also occur as well as assess the actual network within smart phones and other devices. According to a survey that was produced by IT managers, that was conducted by SupportSoft, there was 75% within companies that stated they were not adequately protected or prepared from such events that viruses can cause and74% said their organizations are hit on a monthly basis within one or more devices in regards to viruses, (SupportSoft, 2005).

2. When it comes to the hacking of a system, despite the actual continuing problems of Denial of Services, and the Dedicated Denial of Service intrusions, the treat that has been greater lately is the SQL injection attack. This particular attack tends to take advantage of any improper coding within a web application that allows outside users which are the hackers, to inject SQL commands that are allowing them to gain full functions of their organizations database. The results within the secure information are being confused with that of the non-secured information.

For instance with passwords, the classified information is going to confuse that of the public information such as product details or even their contacts within the database. This then allows the hackers to gain access to all of the secured information a company otherwise wouldn’t want to let out. A report that was conducted on behalf of the Strategic and International Studies located in Washington came to estimate that it costs the organizations around the world over $300 billion dollars a year as well as cyber insurance is becoming the fastest growing insurance available for businesses which is worth over $1.3 billion dollars within the United States, (Lawson, 2014). It isn’t just the costs that have accrued, it is the confidential and private information that is being obtained from this hackers that cost the business the most because it creates the loss of employee productivity, network downtime, as well as an increase in IT personnel costs.

3. The blended attacks are threats that consist of being that of a multi-pronged attack against a network of computers. Symantec goes to describe these blended attacks as a threat that is combining the versus, Trojan horses, worms, and malicious codes within a server and enhancing internet vulnerabilities in order to initiate or transmit in spreading that attack. These blended threats and attacks are also designed to propagate quicker but instead are actually relying upon a single attack vector which could be something as small as an email being opened that is infected. Blended attacks are usually taking over the actual administrative privileges within the computers it is attacking and thus is able to in theory perform their operations that are available enabling keystrokes, copying the businesses files, or even removing and modifying them, (Piscitello, n.d.).

4. What has led to the act of blended acts is the use of Bring Your Own Device policy within many organizations and also has to do with the lackadaisical approach that mobile phone users don’t take into consideration with their phone security. In regards to the lack of the anti-virus as well as the anti-malware software being installed, each of these devices are posting a real security threat when they are being connected into the organizations network system. Pertaining to the employees while using their own devices such as their mobile phones, they use it for work and personal use which is storing business contacts within the phone that can become compromised.

Security Controls (Personnel)

Each of these three network threats and risks that have been identified above are posing threats to not only of the malicious attacks, but the threats of data theft as well. We could mitigate this types of risks by allowing our network and the intellectual property be highly sensitive data within the said network. However, the first step in implementing this would be to conduct a specific review or audit of the users and their network security policies. As annual user training session should be implemented each year to include the below basic policies:

· There should be no installation of unauthorized software downloaded on any of the organizations machines

· Never give out any personal information such as your password or your username

· Log off each computer or device when you are not using them

· Never provide intellectual or sensitive data to a user that is unknown, specifically via the communication of email

· When you check email, never download or open attachments that are from unknown or untrusted sources

· Implement a strong password policy that has mandatory changing of them with a set timeframe that the organization deems more appropriate

· Each of the policies being implemented can help reduce the threats or viruses from attacking the internal and external systems of the organizations infrastructure can could occur by accident or even intentional.

· Users should also be trained within the identification of such malware as well as trained in the proper ways of reporting them once they have been identified.

Each of the IT personnel members should also gain knowledge of the newest threats and how they can respond to those threats and viruses. If it is also identified that a specific IT personnel require additional training, this could be done by the organization if it is deemed to be financially feasible.

Security Controls (Hardware/Software)

The first and critical step in conducting an audit of the network security hardware and software is crucial for gaining adherence to known or unknown threats. A reconnaissance as well as probing test could also be performed with Zenmap GUI in order to identify the actual security deficiencies within all open ports. The very best defense against these types of attacks are implementing a multi-layered approach to ensure all is caught and identified. A Host Intrusion Detection System or otherwise known as (HIDS) should complement the program known as Intrusion Detection System better known as (NIDS) should both be installed within the computer or device system, (Gale, 2013).

Any additional NIDS should be implemented within the actual firewall in which would also detect the threats and attacks that could possibly get through this way. Host computers connected via the internet should also be isolated from any of the computers on the network itself, (Gale, 2013). We should also harden the software and hardware in order to configure what is necessary via the services that are turned off and protected on the ones that are running continuously. A review of the anti-virus as well as the anti-malware software should be done on a regular basis to ensure its security functions are properly working. All of the software should always be up to date with any latest virus and malware updates to ensure proper identification and stopping all attacks or viruses.

Performing scans on all virus and malware software that has been implement within the networks as well as devices and computers should be on a regular basis as well. Wireless Access Points (WAP) should also include the latest encryption that is installed within the system in order to ensure that only the authorized users will have access to it. A BOYD security policy could also be implemented within these said policies. Whereas each of the mobile devices being used under this program are susceptible to the exact security policies within the organization and its framework, (Gale, 2013). The policy consistent with Cisco could also be considered to be implemented within your organization. Their particular policy requires that all of the users have or create a pin, and that the device have an auto lock implemented that will be triggered after 10 seconds of not being in use. Cisco also reserves their own right to wipe any of the devices located within their network by remotely processes if the device is lost or stolen. The organization controls the corporate data within its own network while utilizing a combination of such security access PINS, the encryption tools, as well as the read only features that highly prevent malicious attacks and threats, (Gale, 2013).

Conclusion

With an ever evolving, infinite amount of threats to a network, there are many available solutions to attempt to mitigate those types of risks within organizations. Training personnel on best security practices, creating a secure network with firewalls including intrusion detection and anti-virus/malware software, to performing security audits will help ensure the best possible defense against a malicious attack against the network. The worst nightmare an organization could accrue is having their system hacked or a virus attacking their confidential and critical information that is not supposed to be known to other than those who have permission.

References

Gale, S. F. (2013, April 2). BYOD Brings Security Risks for Companies. Retrieved 07/21/2015, from workforce: http://www.workforce.com/articles/byod-brings-security-risks-for-companies

Lawson, A. (2014, May 23). Businesses need to wake up and smell the hackers. Retrieved 07/21/2015, from The Independent: http://www.independent.co.uk/news/business/analysis-andfeatures/businesses-need-to-wake-up-and-smell-the-hackers-9422300.html

Piscitello, D. (n.d.). What is a blended threat? Retrieved 07/21/2015, from The Security Skeptic: http://securityskeptic.typepad.com/the-security-skeptic/what-is-a-blended-threat.html

SupportSoft. (2005, March). By the Stats: The Impact of Computer Virus Attacks on Business. Retrieved 07/22/2015, from Retail Online Integration: http://www.retailonlineintegration.com/article/by-statsthe-impact-computer-virus-attacks-business-51445/1

Symantec. (2013, December 27). Security 1:1 - Part 3 - Various types of network attacks. Retrieved 07/22/2015, from Symantec: http://www.symantec.com/connect/articles/security-11-part-3-various-typesnetwork-attacks

Vernon, M. (2004, April). Top five threats. Retrieved 07/21/2015, from Computer Weekly:

http://www.computerweekly.com/feature/Top-five-threats