Identifying Potential Risk, Response, and Recovery

profileycakmakk41
identifying_potential_malicious.doc

Running head: IDENTIFYING POTENTIAL MALICIOUS ATTACKS 1

IDENTIFYING POTENTIAL MALICIOUS ATTACKS 6

Identifying Potential Malicious Attacks

Identifying Potential Malicious Attacks

Analyze three (3) specific potential malicious attacks and/or threats that could be carried out against the network and organization.

Malicious attack is to damage or access of a computer without the owner’s knowledge. This is normally done with the intention of stealing personal information or to minimize the usage of the target computer. The three potential malicious attacks that could be carried out against the network and organization are Malware, Social engineering and Network hacking (Jung, Park, Ko, Lin, & Tong, n.d).

Malware is the main commonly ways of damaging a computer. It is defined as software that affects the computer. Examples are adware, Trojan horse, spyware, worms, and computer viruses. Social engineering is the act of manipulating people psychologically, to undertake actions that lead to leakage of company’s confidential information causing a lot of damage. Examples social engineering includes phishing, baiting, and spam. Network hacking is any technical effort to influence the usual behavior of connected systems and network connections.

Explain in detail the potential impact of the three (3) selected malicious attacks.

Malware may be planned to spy on a computer or steal information for a given period without the knowledge of the user, or it may be designed to cause trouble, or to extort payment. Other impacts on a computer may include; it may lead to slow connection, it may cause computer to display error messages repeatedly, it may redirect the user to sites for its purpose, it may also send spam through and to user’s inbox.

Social engineering is to trick a computer user into thinking that the user is networking with the actual computer system and the user to give confidential information. It declines the information security of an organization which can cause the fall of organization from attacks like terrorism attacks. The financial cost could be disciplinary to the company and the individual. It could also cause reputation and goodwill loss.

Impacts of network hacking are mysterious decrease of space in the hard drive, unexpectedly disappearance and modification of file, rapid network or computer performance changes, regular clashes, and computer or internet router light blinking even when the internet is not in use.

Propose the security controls that you would consider implementing in order to protect against the selected potential malicious attacks.

As malware attacks increase, there are ways that would be considered to protect against it. One way to control the malware attack is by use of anti-virus and anti-malware software normally known as an on-access or real time scanner. It hooks inside the core of operating system and works similarly to how malware would try to work. When the operating system retrieves a file, the on-access scanner verifies the legitimacy of the file. If the file is found malware, the operation is stopped. The other possible is by imposing an air gap, which is totally disconnecting computer from other networks.

Proposed measures of minimizing the impact of social engineering are planning a well documented and retrievable security policy, offering training on security policy, teaching awareness of it to the employees, and identifying management policy. Examples of ways preventing computer hacking are installing firewall to prevent access of computer from outside, change of passwords, keeping patches updated, and installing antivirus software (SebastianZ, December 27, 2013).

Analyze three (3) potential concerns for data loss and data theft that may exist in the documented network

Data loss prevention is the act of noticing and avoiding confidential data from being disclosed out of the boundaries of an organization for unofficial purpose. Data may be removed from the organization logically or physically either planned or unplanned. The three potential concerns of data loss and theft that may exist in the documented network are data breaches, data loss and account or service traffic hijacking.

Data breach can be defined as a security event, where protected, sensitive or secretive data is duplicated, conveyed, stolen, viewed, or used by unauthorized person. It may entail financial information like bank details, credit cards, or personal health information. Data loss is a situation where information is obliterated by neglect or failures in storage, communication, or processing. Data loss may be permanent. Cloud account or service hijacking happens when an attacker hijacks or steals individual or organization cloud account.

Explain the potential impact of the three (3) selected concerns for data loss and theft

Data breach poses a risk of theft of identity or other stern consequences. However, in many cases there is no long-term damage because the breach security is remedied sooner than the unscrupulous people access the information, or other cases the thief is only after the hardware and not the information. Under data loss, there are different ways that data can be lost. It can be through planned action, accidental action, failure such as power or hardware, disaster, or crime. The price of a data loss occurrence is directly connected to the data value and the time length that is not available yet required. Impacts of data to an individual or organization are the cost of ongoing with no data, the price of creating new data, and the cost of informing users in the affair of a comprise.

The occurrence of cloud account or service hijacking at the level of enterprise can be overwhelming, depending on the action that the attackers will do with the information. The reputations and integrity of a company can be tarnished, and confidential information can be viewed or falsified resulting to noteworthy price to businesses or their clientele. Legal impacts are also likely for firms and organizations in highly regulated businesses.

Propose the security controls that you would consider implementing in order to protect against the selected concerns for data loss and data theft.

Ways to prevent data breach in a company are; a company to look past IT security when assessing data breaches risks in the company, set up a comprehensive plan for data loss that will enhance decisive act and avoid operational paralysis in case of a data breach occurrence, the company could also educate employees about suitable handling and protection of sensitive data, and may be get a third-party corporate breach to examine the level of risk and exposure.

The regularity of data loss and its effects can be highly reduced by taking right precautions, which can differ depending on the kind of data loss. Some of the prevention measure that can be taken is the insertion of battery back-ups and a generator to guard upon power failures. Cloud account hijacking can be prevented by the company taking proactive steps when selecting providers for cloud service. The company should also take a data-driven technique when assessing providers; this is inclusive of the number of data loss or interference happenings they have undergone (Insights on governance, risk and compliance, October, 2011).

References

Insights on governance, risk and compliance. October, 2011. Data Loss Prevention. Keeping your sensitive data out of the public domain. Retrieved from http://www.ey.com/Publication/vwLUAssets/EY_Data_Loss_Prevention/$FILE/EY_Data_Loss_Prevention.pdf

Jung. C., Park. M., Ko. S., Lin.Y., & Tong. M. n.d. Malicious Attacks. What are Malicious attack?

SebastianZ. December 27, 2013. Security 1:1- Part 3 - Various types of network attacks. Welcome to the Security 1:1 – Part 3. Retrieved from http://www.symantec.com/connect/articles/security-11-part-3-various-types-network-attacks