Business Information Technology- Assignment

profileAJ-773
gallaugher_informationsystems_3.0_ch15.pptx

Published by Flat World Knowledge, Inc.

© 2014 by Flat World Knowledge, Inc. All rights reserved. Your use of this work is subject to the License Agreement available

here http://www.flatworldknowledge.com/legal. No part of this work may be used, modified, or reproduced in any form or by

any means except as expressly permitted under the License Agreement.

Information Systems: A Manager’s Guide to Harnessing Technology V 3.0

By John Gallaugher

Chapter 15

Information Security: Barbarians at the Gateway (and just about Everywhere Else)

Learning objectives

Recognize that information security breaches are on the rise.

Understand the potentially damaging impact of security breaches.

Recognize that information security must be made a top organizational priority.

Security Breach

Factors that can amplify a firm’s vulnerability of a breach:

Personnel issues

Technology problems

Procedural factors

Operational issues

Constant vigilance regarding security needs to be:

Part of one’s individual skill set.

A key component in an organization’s culture.

Learning Objectives

Understand the source and motivation of those initiating information security attacks.

Relate examples of various infiltrations in a way that helps raise organizational awareness of threats.

Motivation for Information Security Attacks

Account theft and illegal funds transfer.

Some hackers steal data for personal use.

Data harvesters sell to cash-out fraudsters.

Data harvesters: Cybercriminals who infiltrate systems and collect data for illegal resale.

Cash-out fraudsters: Purchase assets from data harvesters to buy goods using stolen credit cards or create false accounts.

Stealing personal or financial data.

Compromising computing assets for use in other crimes.

Botnets send spam, launch click fraud efforts or stage distributed denial of service (DDoS) attacks.

Botnets: Surreptitiously infiltrated computers, controlled remotely.

Distributed denial of service (DDoS) attacks: Shutting down Web sites with a crushing load of seemingly legitimate requests.

Motivation for Information Security Attacks

EXTORTION

ESPIONAGE

CYBERWARFARE

TERRORISM

PRANKSTERS

PROTEST HACKING

REVENGE

INTELLECTUAL PROPERTY THEFT

HACKER

White hat hackers: Uncover computer weaknesses without exploiting them.

Contribute to improving system security.

Black hat hackers: Computer criminals who exploit a system’s weakness for personal gain.

Someone who breaks into computer systems

Learning Objectives

Recognize the potential entry points for security compromise.

Understand infiltration techniques such as social engineering, phishing, malware, Web site compromises (such as SQL injection), and more.

Identify various methods and techniques to thwart infiltration.

User and Administrator Threats

BAD APPLES

Rogue employees who steal secrets, install malware, or hold a firm hostage.

SOCIAL ENGINEERING

Con games that trick employees into revealing information or performing other tasks that compromise a firm.

PHISHING

Con executed using technology, in order to:

Acquire sensitive information.

Trick someone into installing malicious software.

User and Administrator Threats

SPOOFED

Email transmissions and packets that have been altered to forge or disguise their origin or identity.

ZERO-DAY EXPLOITS

New attacks that haven’t been clearly identified and haven’t been incorporated into security screening systems.

PASSWORDS

Most users employ inefficient and insecure password systems

Biometrics: Measure and analyze human body characteristics for identification or authentication.

Technology Threats: Malware

Methods of infection:

Viruses: Infect other software or files.

Worms: Take advantage of security vulnerability to automatically spread.

Trojans: Attempt to sneak in by masquerading as something they’re not.

Seeks to compromise a computing system without permission

Goals of Malware

Botnets or zombie networks: Used in click fraud, sending spam, to decipher accounts that use CAPTCHAs.

CAPTCHAs: Scrambled character images to thwart automated account setup or ticket buying attempts.

Malicious adware: Installed without full user consent or knowledge, later serve unwanted advertisements.

Spyware: Monitors user actions, network traffic, or scans for files.

Keylogger: Records user keystrokes.

Software-based or hardware-based.

Screen capture: Records pixels that appear on a user’s screen to identify proprietary information.

Card skimmer: Captures data from a card’s magnetic strip.

RAM scraping or storage scanning software: Malicious code that scans for sensitive data.

Blended threats: Attacks combining multiple malware or hacking exploits.

Technology Threats

Compromising poorly designed software.

SQL injection technique: Targeting sloppy programming practices that do not validate user input.

Cross-site scripting attacks and HTTP header injection.

Push-Button hacking: Tools designed to easily automate attacks.

Network threats: Network itself is a source of compromise.

Physical threats

DUMPSTER DIVING

Combing through trash to identify valuable assets.

SHOULDER SURFING

Gaining compromising information through observation.

BRUTE-FORCE ATTACKS

Exhausts all possible password combinations to break into an account.

Encryption

Key: Code that unlocks encryption.

Public key encryption: Two key system used for securing electronic transmissions.

Certificate authority: Trusted third party that provides authentication services in public key encryption schemes.

Scrambling data using a code, thereby hiding it from those who do not have the unlocking key

Learning Objectives

Identify critical steps to improve your individual and organizational information security.

Be a tips, tricks, and techniques advocate, helping make your friends, family, colleagues, and organization more secure.

Recognize the major information security issues that organizations face, as well as the resources, methods, and approaches that can help make firms more secure.

Taking Action as a User

Surf smart.

Stay vigilant.

Stay updated.

Install a full suite of security software.

Secure home networks and encrypt hard drives.

Regularly update passwords.

Be disposal smart.

Regularly back up your system.

Check with your administrator.

Taking Action as an Organization

Follow frameworks, standards, and compliance.

ISO27k or ISO 27000 series: Establishing, operating, maintaining, and improving an Information Security Management System.

Compliance requirements: Legal or professionally binding steps that must be taken.

Education, audit, and enforcement.

Functions of research and development:

Understanding emerging threats and updating security techniques.

Working on broader governance issues.

Employees should:

Know a firm’s policies and be regularly trained.

Understand the penalties for failing to meet their obligations.

Audits: Real-time monitoring of usage: announced and surprise.

How protected?

Firms should avoid:

Spending money targeting unlikely exploits.

Underinvesting in methods to thwart common infiltration techniques.

Risk assessment team: Consider vulnerabilities and countermeasure investments.

Lobbying for legislation that imposes severe penalties on crooks helps:

Raise adversary costs.

Lower one’s likelihood of becoming a victim.

Technology’s Role

Patches: Software updates that plug existing holes

Lock down hardware:

Prevent unapproved software installation.

Force file saving to hardened, backed-up, and monitored servers.

Reimage hard drives of end-user PCs.

Disable boot capability of removable media.

Prevent Wi-Fi use and require VPN encryption for network transmissions.

Lock down networks:

Firewalls: Control network traffic, block unauthorized traffic.

Intrusion detection systems: Monitor network use for hacking attempts and take preventive action.

Honeypots: Tempting, bogus targets meant to lure hackers.

Blacklists: Deny the entry of specific IP addresses and other entities.

Whitelists: Permit communication only with approved entities or in an approved manner.

Technology’s role

Lock down partners:

Insist on partner firms being compliant with security guidelines and audit them regularly.

Use access controls to control data access on a need-to-know basis.

Use recording, monitoring, and auditing to hunt for patterns of abuse.

Maintain multiple administrators to jointly control key systems.

Lock down systems: Audit for SQL injection and other application exploits.

Have failure and recovery plans:

Employ recovery mechanisms to regain control if key administrators are incapacitated or uncooperative.

Broad awareness reduces organizational stigma in coming forward.

Share knowledge on hacking techniques with technology partners.