This blog contains notes from different learning sites. This notes falls in Information Security, Cyber Security, Network Security and other Security Domain class. Any suggestion to make this site helpful is truly welcome :)
Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts
Saturday, January 12, 2019
Tuesday, August 30, 2016
Cyber Security: Data Protection Act
The Data Protection Act 1998 (DPA)
The original Data Protection Act (DPA) became law in 1984. Organisations were legally obliged to act responsibly with respect to personal information, which relates to data on any living individual, held in computer databases.
It was replaced by the Data Protection Act 1998 which was implemented in two stages in 2000 and 2003. This change was needed to reflect the changes in technology that had passed since the original DPA. The 1998 Act is currently in force and will be for the foreseeable future.

The Information Commissioner’s Office is an independent supervisory authority appointed by the government to oversee and enforce compliance with the Act in all dealings with personal information and to ensure access is freely available to recorded information held by public authorities. The Office reports directly to the UK Parliament. Note that the Scottish Information Commissioner’s Office promotes and enforces freedom of information in Scotland.
The DPA enforces strict rules on the storage and processing of electronic data that can uniquely identify a living person. It is designed to stop data being obtained or stored unnecessarily, to prevent it from being exchanged without good reason, to ensure it is held under secure conditions and to give individuals redress if they feel their personal data has been misused.
So, all organisations that store information on living individuals must comply with the Data Protection Act. The Information Commissioner maintains a public register of these organisations called the Data Protection Register.
Before you look at the Act in more depth, let’s define what is meant by ‘information’ and ‘data’ and how are they different?
data is a representation of information so that it can be conveyed, manipulated or stored
information is the meaning that we give to data in particular contexts.
So data cannot really be considered as information until it is given meaning and is interpreted by us. Opinion polls, where members of the public are asked their opinion on particular subjects, are good examples of where data is collected, stored and manipulated to show the resulting information as statistics They may demonstrate how we might vote in the next parliamentary election, or whether one brand of food is preferred to another.
In terms of the DPA, data controllers are people who are employed by any organisation that stores, manipulates and retrieves personal information held on computers.

The DPA is based around eight fundamental principles of good information handling. Data controllers are legally required to act in accordance with these rules, the details of which are explained in the Principles of the DPA (PDF). The case study below describes an example of the data protection act being used.
Case study: The British Pregnancy Advisory Service
The British Pregnancy Advisory Service is a charity offering confidential advice to pregnant women, including information about abortion and sterilisation.
In early 2012, a hacker defaced the charity’s site, claiming to have obtained records of nearly 10,000 people who had contacted BPAS and threatening to post their details online. Police were able to determine the IP number of the attacker’s computer and James Jeffery was arrested the next day in the West Midlands. No confidential data was released, although copies of the BPAS data were found on Jeffery’s computer.
BPAS had initially acquired the names through a ‘call back’ form where people could leave details so they could be contacted later, but had chosen to not continue with the ‘call back’ because of security concerns. However, unbeknownst to BPAS, the data was retained on the site and inadequately secured from attacks.

BPAS was fined £200,000 for the breach, although at the time of writing it was contesting the fine. In April 2012, James Jeffery, was sentenced to 32 months in prison under the Computer Misuse Act.
Inadvertent breaches of the Data Protection Act may be prosecuted although no harm was intended.
Case study: Hertfordshire County Council
In June 2010, Hertfordshire County Council breached the DPA on two occasions when its childcare department accidentally sent faxes to incorrect numbers.
On the first occasion, documents intended for lawyers were sent to members of the public, and on the second occasion, information including personal information about two children in council care, criminal convictions of two people and domestic violence records were sent to a legal practice unconnected to their case.
The council correctly alerted the Information Commissioner to the two breaches, but was fined £100,000 because of the seriousness of their mistake which could have had serious consequences for the safety of children in the council’s care.
The Computer Misuse Act 1990 (CMA)
The Computer Misuse Act 1990 (CMA) is one of the most influential pieces of legislation relating to computers. It has been the inspiration for similar laws being introduced in other countries.

It came about, in part, because of a 1988 case where two hackers broke in to the British Telecom Prestel network and obtained access to user accounts including that of Prince Philip.
Prestel was a text-based interactive information system developed by the UK Post Office in the late 1970s. Users could browse numbered pages of text (similar to the contemporaneous Ceefax and Teletext information services) on their television as well as send electronic messages to other Prestel users. Prestel services were expensive and the system did not become widely used, although Prestel technology was sold to many other telecom companies. Prestel was gradually sold off in the early 1990s as the internet became available to domestic users.
The two hackers were originally tried and convicted under a law concerned with forgery and counterfeiting, but the conviction was overturned by higher courts who concluded that the Forgery and Counterfeiting Act 1981 had never been intended to be used for this purpose. This led the majority of legal experts to conclude that hacking was not actually illegal in Britain at the time.
The CMA was drawn up hurriedly and was criticised at the time for not being adequately scrutinised, but its central aims have stood the test of time. The original Act introduced three new criminal offences:
The CMA has been amended a number of times, including through the Police and Justice Act 2006, to cover new offences including denial of access or denial of service to legitimate users (making denial of service attacks a criminal offence in the UK), and criminalising the creation and supply of software and hardware that might aid an attack on a computer. This not only criminalises the development of programs designed to break passwords or the development of certain types of malware, but it could potentially criminalise tools used by forensics experts to investigate computer systems which can be abused by attackers.
The CMA has been successfully used in a wide range of criminal cases including denial of service attacks against Kent Police, Oxford University, the United States Air Force, the CIA, Sony and Nintendo; fraudulent activities in online games; illegal access and disclosure of confidential emails and personal information; theft from online banks; stalking; hoax calls to emergency telephone numbers and piracy.
The Fraud Act 2006
The Fraud Act 2006 was introduced to simplify a notoriously complex Act of Parliament called the Theft Act.
The previous law defined a large number of types of fraud, often tied to specific circumstances, that made for complex cases that were difficult to prosecute and for juries to understand. In fact, it wasn’t until 1996 that obtaining money from a fraudulent bank transfer was specifically illegal in the UK!
The Fraud Act defines fraud in three ways:

The Fraud Act can be used against anyone attempting to perform fraud whether or not it takes place over the internet. However, Section 11 of the Act makes specific reference to electronic fraud and can be used to prosecute in response to:
The original Data Protection Act (DPA) became law in 1984. Organisations were legally obliged to act responsibly with respect to personal information, which relates to data on any living individual, held in computer databases.
It was replaced by the Data Protection Act 1998 which was implemented in two stages in 2000 and 2003. This change was needed to reflect the changes in technology that had passed since the original DPA. The 1998 Act is currently in force and will be for the foreseeable future.
The Information Commissioner’s Office is an independent supervisory authority appointed by the government to oversee and enforce compliance with the Act in all dealings with personal information and to ensure access is freely available to recorded information held by public authorities. The Office reports directly to the UK Parliament. Note that the Scottish Information Commissioner’s Office promotes and enforces freedom of information in Scotland.
The DPA enforces strict rules on the storage and processing of electronic data that can uniquely identify a living person. It is designed to stop data being obtained or stored unnecessarily, to prevent it from being exchanged without good reason, to ensure it is held under secure conditions and to give individuals redress if they feel their personal data has been misused.
So, all organisations that store information on living individuals must comply with the Data Protection Act. The Information Commissioner maintains a public register of these organisations called the Data Protection Register.
Before you look at the Act in more depth, let’s define what is meant by ‘information’ and ‘data’ and how are they different?
data is a representation of information so that it can be conveyed, manipulated or stored
information is the meaning that we give to data in particular contexts.
So data cannot really be considered as information until it is given meaning and is interpreted by us. Opinion polls, where members of the public are asked their opinion on particular subjects, are good examples of where data is collected, stored and manipulated to show the resulting information as statistics They may demonstrate how we might vote in the next parliamentary election, or whether one brand of food is preferred to another.
In terms of the DPA, data controllers are people who are employed by any organisation that stores, manipulates and retrieves personal information held on computers.
The DPA is based around eight fundamental principles of good information handling. Data controllers are legally required to act in accordance with these rules, the details of which are explained in the Principles of the DPA (PDF). The case study below describes an example of the data protection act being used.
Case study: The British Pregnancy Advisory Service
The British Pregnancy Advisory Service is a charity offering confidential advice to pregnant women, including information about abortion and sterilisation.
In early 2012, a hacker defaced the charity’s site, claiming to have obtained records of nearly 10,000 people who had contacted BPAS and threatening to post their details online. Police were able to determine the IP number of the attacker’s computer and James Jeffery was arrested the next day in the West Midlands. No confidential data was released, although copies of the BPAS data were found on Jeffery’s computer.
BPAS had initially acquired the names through a ‘call back’ form where people could leave details so they could be contacted later, but had chosen to not continue with the ‘call back’ because of security concerns. However, unbeknownst to BPAS, the data was retained on the site and inadequately secured from attacks.
BPAS was fined £200,000 for the breach, although at the time of writing it was contesting the fine. In April 2012, James Jeffery, was sentenced to 32 months in prison under the Computer Misuse Act.
Inadvertent breaches of the Data Protection Act may be prosecuted although no harm was intended.
Case study: Hertfordshire County Council
In June 2010, Hertfordshire County Council breached the DPA on two occasions when its childcare department accidentally sent faxes to incorrect numbers.
On the first occasion, documents intended for lawyers were sent to members of the public, and on the second occasion, information including personal information about two children in council care, criminal convictions of two people and domestic violence records were sent to a legal practice unconnected to their case.
The council correctly alerted the Information Commissioner to the two breaches, but was fined £100,000 because of the seriousness of their mistake which could have had serious consequences for the safety of children in the council’s care.
The Computer Misuse Act 1990 (CMA)
The Computer Misuse Act 1990 (CMA) is one of the most influential pieces of legislation relating to computers. It has been the inspiration for similar laws being introduced in other countries.
It came about, in part, because of a 1988 case where two hackers broke in to the British Telecom Prestel network and obtained access to user accounts including that of Prince Philip.
Prestel was a text-based interactive information system developed by the UK Post Office in the late 1970s. Users could browse numbered pages of text (similar to the contemporaneous Ceefax and Teletext information services) on their television as well as send electronic messages to other Prestel users. Prestel services were expensive and the system did not become widely used, although Prestel technology was sold to many other telecom companies. Prestel was gradually sold off in the early 1990s as the internet became available to domestic users.
The two hackers were originally tried and convicted under a law concerned with forgery and counterfeiting, but the conviction was overturned by higher courts who concluded that the Forgery and Counterfeiting Act 1981 had never been intended to be used for this purpose. This led the majority of legal experts to conclude that hacking was not actually illegal in Britain at the time.
The CMA was drawn up hurriedly and was criticised at the time for not being adequately scrutinised, but its central aims have stood the test of time. The original Act introduced three new criminal offences:
- unauthorised access to computer materials
- unauthorised access with intent of committing or aiding further offences
- unauthorised modification of computer material.
The CMA has been amended a number of times, including through the Police and Justice Act 2006, to cover new offences including denial of access or denial of service to legitimate users (making denial of service attacks a criminal offence in the UK), and criminalising the creation and supply of software and hardware that might aid an attack on a computer. This not only criminalises the development of programs designed to break passwords or the development of certain types of malware, but it could potentially criminalise tools used by forensics experts to investigate computer systems which can be abused by attackers.
The CMA has been successfully used in a wide range of criminal cases including denial of service attacks against Kent Police, Oxford University, the United States Air Force, the CIA, Sony and Nintendo; fraudulent activities in online games; illegal access and disclosure of confidential emails and personal information; theft from online banks; stalking; hoax calls to emergency telephone numbers and piracy.
The Fraud Act 2006
The Fraud Act 2006 was introduced to simplify a notoriously complex Act of Parliament called the Theft Act.
The Fraud Act defines fraud in three ways:
- false representation
- failing to disclose information
- abusing power.
The Fraud Act can be used against anyone attempting to perform fraud whether or not it takes place over the internet. However, Section 11 of the Act makes specific reference to electronic fraud and can be used to prosecute in response to:
- dishonestly obtaining electronic communications services such as a telephone, ISP or satellite television subscription
- cloning mobile phones so that calls made on one handset are billed to another
- reprogramming mobile phones to interfere with their operation or change their unique identifier information
- breaking encryption on encrypted communications services such as subscription television services or telephone conversations.
Cyber Security: Risk of Data Loss
Risks of data loss
As the case studies showed, there are serious consequences of losing data.
These consequences can be expressed as a series of costs, such as:
the cost of recreating the lost data – either by buying new hardware and software or re-entering the lost data (which may not always be possible)
the cost of continuing without that data (availability)
the cost of informing others about the loss.
The costs cannot just be expressed in terms of money. For instance, the last cost, of informing others, is not just limited to, for example, postage and email charges. A company that suffers a data loss can also suffer a loss in its reputation as a professional organisation. This problem is greatly magnified if personal data belonging to other people has been lost.
Case study: JournalSpace
At the end of 2008, the blog provider JournalSpace went into liquidation after the crucial database containing its customers’ blogs was corrupted by a disgruntled former employee. This criminal action should not have proved fatal, but it became clear that the six-year old company had not been keeping complete backups of their data.
JournalSpace customers were able to recover some of their data using copies of their postings held in Google’s giant cache, but JournalSpace’s reputation was ruined. JournalSpace was later reborn under new management, but by then it had lost most of its users.
The risk of data loss cannot be completely eliminated, but it can be minimised. The 2013 Forrester report suggested that malicious actions by disgruntled employees was the leading cause of internal breaches, but a significant number of security threats are caused inadvertently by employees who are unaware of the risks of their actions, such as copying data to external devices or websites, opening infected emails, clicking malicious links, installing software and so on. Better staff training could reduce the risk of accidental data loss.
The Infosecurity Europe survey revealed that while a slight majority of companies had implemented an internal information security policy to secure computers, networks and data, only a minority had provided staff training to raise awareness of potential security risks. Another important way of minimising the effect of any loss is by backing up data – making secure copies of data either on to a separate device, to a separate disk, or even to a different location.

© The Open University
https://www.futurelearn.com/courses/introduction-to-cyber-security/8/steps/83138
As the case studies showed, there are serious consequences of losing data.
These consequences can be expressed as a series of costs, such as:
the cost of continuing without that data (availability)
the cost of informing others about the loss.
The costs cannot just be expressed in terms of money. For instance, the last cost, of informing others, is not just limited to, for example, postage and email charges. A company that suffers a data loss can also suffer a loss in its reputation as a professional organisation. This problem is greatly magnified if personal data belonging to other people has been lost.
Case study: JournalSpace
At the end of 2008, the blog provider JournalSpace went into liquidation after the crucial database containing its customers’ blogs was corrupted by a disgruntled former employee. This criminal action should not have proved fatal, but it became clear that the six-year old company had not been keeping complete backups of their data.
JournalSpace customers were able to recover some of their data using copies of their postings held in Google’s giant cache, but JournalSpace’s reputation was ruined. JournalSpace was later reborn under new management, but by then it had lost most of its users.
The risk of data loss cannot be completely eliminated, but it can be minimised. The 2013 Forrester report suggested that malicious actions by disgruntled employees was the leading cause of internal breaches, but a significant number of security threats are caused inadvertently by employees who are unaware of the risks of their actions, such as copying data to external devices or websites, opening infected emails, clicking malicious links, installing software and so on. Better staff training could reduce the risk of accidental data loss.
The Infosecurity Europe survey revealed that while a slight majority of companies had implemented an internal information security policy to secure computers, networks and data, only a minority had provided staff training to raise awareness of potential security risks. Another important way of minimising the effect of any loss is by backing up data – making secure copies of data either on to a separate device, to a separate disk, or even to a different location.
© The Open University
https://www.futurelearn.com/courses/introduction-to-cyber-security/8/steps/83138
Monday, August 29, 2016
Cyber Security: Identity Theft
Identity theft
Identity theft is a type of fraud in which an attacker uses stolen personal information to impersonate another person.
Traditionally, this type of fraud was achieved by an attacker intercepting postal deliveries which contain personal information such as names, addresses, bank account details and so on. Attackers could then open credit card accounts and apply for loans in the victim’s name. Victims have had their financial security and lives ruined by identity theft.
The online world has opened up a new, lucrative source of information for fraudsters. Many users have been quite relaxed about sharing their information with online services and other users, but even security conscious individuals are threatened by malware designed to sniff out personal information on a computer, or phishing attacks that persuade users to divulge personal information. Additionally, as we have seen, hacking attacks on big retailers can make millions of personal records available for potential abuse.
Online identity theft still only makes up a tiny proportion of all cases of identity theft and it is actually quite a rare occurrence, but it is a growing threat.
Preventing identity theft
You can greatly limit your risk of online identity theft by following simple security procedures such as running an antivirus program, keeping it up to date and by not responding to phishing emails.

Detecting identity theft
Online identity theft may pass unnoticed for some time, during which great damage can be done to your financial security. Some signs that a victim might notice are:
Data loss can mean several things ranging from the destruction and deletion of data, to making unauthorised copies that are no longer under your control.
Data can be stolen by people who have direct access to a computer, such as by copying data to a flash memory drive, and also by attackers gaining access over a network connection.
Insider attacks
The hardest attack to defend against is when an attacker has direct access to a computer, especially in an organisation where many people might have access to a single computer, and one, or more, of them might not have the organisation’s best interests at heart. Security risks posed by employees (or ex-employees) of an organisation to their employers are known as insider threats.

A 2013 Forrester survey of businesses employing two or more people in the UK, US, Canada, France and Germany found that 36% of information security breaches were caused by insiders and represented the leading threat to organisational security. These findings were supported in a survey of attendees to the Infosecurity Europe conference where 37% of respondents said the biggest threat to their information security came in the form of ‘rogue employees’. This placed insider threats ahead of cyber attacks (19%) and device security (15%).
Case study: Stealing data
In 2012, a programmer for the Federal Reserve Bank of New York was sentenced for stealing source code used to develop the bank’s computer systems.
Bo Zhang was a third party contractor for the bank with privileged access to software that was under development. He pleaded guilty to copying the code to personal computers in violation of his contract of employment although there is no evidence that he intended to share the programs with anyone.
Similarly, in 2013, the social networking game developer Zynga settled a lawsuit with a former employee, Alan Patmore, who had copied hundreds of files, including unreleased game designs to a Dropbox cloud storage folder before taking up employment with a rival company. Patmore expressed deep regret for his actions and agreed to ensure all copies of the data were destroyed in exchange for Zynga dropping charges against him.
The case of Chelsea Manning is one of the more significant insider attacks involving the loss of data. It is another example where the attacker simply copied the data and shared it with others, depriving the data owners of control over the confidentiality of the information.
Case study: Chelsea Manning
Chelsea Manning (born Bradley Manning) was a United States Army soldier who leaked confidential information, including 250,000 United States diplomatic messages and 500,000 United States Army reports as well as videos of military action in Iraq, to the WikiLeaks website.
Manning obtained copies of classified materials during service in Iraq in 2009, copying them directly to a data CD disguised as a music disc, from which the materials were transferred to a laptop and then to the WikiLeaks servers for dissemination.
The reports were widely published around the world and caused enormous diplomatic embarrassment for the United States government. Manning was eventually identified after confessing in an online chat to Adrian Lamo, who informed the Army. Manning was charged with 22 offences, including that of aiding the enemy, and pleaded guilty to 10 charges. She was found guilty in 2013 and sentenced to 35 years in military prison.
Identity theft is a type of fraud in which an attacker uses stolen personal information to impersonate another person.
Traditionally, this type of fraud was achieved by an attacker intercepting postal deliveries which contain personal information such as names, addresses, bank account details and so on. Attackers could then open credit card accounts and apply for loans in the victim’s name. Victims have had their financial security and lives ruined by identity theft.
The online world has opened up a new, lucrative source of information for fraudsters. Many users have been quite relaxed about sharing their information with online services and other users, but even security conscious individuals are threatened by malware designed to sniff out personal information on a computer, or phishing attacks that persuade users to divulge personal information. Additionally, as we have seen, hacking attacks on big retailers can make millions of personal records available for potential abuse.
Online identity theft still only makes up a tiny proportion of all cases of identity theft and it is actually quite a rare occurrence, but it is a growing threat.
Preventing identity theft
You can greatly limit your risk of online identity theft by following simple security procedures such as running an antivirus program, keeping it up to date and by not responding to phishing emails.
Detecting identity theft
Online identity theft may pass unnoticed for some time, during which great damage can be done to your financial security. Some signs that a victim might notice are:
- unexplained bank withdrawals or credit card charges
- bills and other expected official letters don’t arrive
- cards or cheques are declined
- debt collectors make contact about debts they know nothing about
- they receive notice that their information was compromised by a data breach at a company where they do business or have an account
- their bank or credit card provider makes contact about suspicious behaviour on their account.
Data loss can mean several things ranging from the destruction and deletion of data, to making unauthorised copies that are no longer under your control.
Data can be stolen by people who have direct access to a computer, such as by copying data to a flash memory drive, and also by attackers gaining access over a network connection.
Insider attacks
The hardest attack to defend against is when an attacker has direct access to a computer, especially in an organisation where many people might have access to a single computer, and one, or more, of them might not have the organisation’s best interests at heart. Security risks posed by employees (or ex-employees) of an organisation to their employers are known as insider threats.
A 2013 Forrester survey of businesses employing two or more people in the UK, US, Canada, France and Germany found that 36% of information security breaches were caused by insiders and represented the leading threat to organisational security. These findings were supported in a survey of attendees to the Infosecurity Europe conference where 37% of respondents said the biggest threat to their information security came in the form of ‘rogue employees’. This placed insider threats ahead of cyber attacks (19%) and device security (15%).
Case study: Stealing data
In 2012, a programmer for the Federal Reserve Bank of New York was sentenced for stealing source code used to develop the bank’s computer systems.
Bo Zhang was a third party contractor for the bank with privileged access to software that was under development. He pleaded guilty to copying the code to personal computers in violation of his contract of employment although there is no evidence that he intended to share the programs with anyone.
Similarly, in 2013, the social networking game developer Zynga settled a lawsuit with a former employee, Alan Patmore, who had copied hundreds of files, including unreleased game designs to a Dropbox cloud storage folder before taking up employment with a rival company. Patmore expressed deep regret for his actions and agreed to ensure all copies of the data were destroyed in exchange for Zynga dropping charges against him.
The case of Chelsea Manning is one of the more significant insider attacks involving the loss of data. It is another example where the attacker simply copied the data and shared it with others, depriving the data owners of control over the confidentiality of the information.
Chelsea Manning (born Bradley Manning) was a United States Army soldier who leaked confidential information, including 250,000 United States diplomatic messages and 500,000 United States Army reports as well as videos of military action in Iraq, to the WikiLeaks website.
Manning obtained copies of classified materials during service in Iraq in 2009, copying them directly to a data CD disguised as a music disc, from which the materials were transferred to a laptop and then to the WikiLeaks servers for dissemination.
The reports were widely published around the world and caused enormous diplomatic embarrassment for the United States government. Manning was eventually identified after confessing in an online chat to Adrian Lamo, who informed the Army. Manning was charged with 22 offences, including that of aiding the enemy, and pleaded guilty to 10 charges. She was found guilty in 2013 and sentenced to 35 years in military prison.
Wednesday, August 24, 2016
Cyber Security: Honeypots
Honeypots
Sometimes network administrators want to study attacks, either so the attackers’ methods can be understood more fully and countermeasures prepared, or as part of an investigation that might lead to civil or criminal prosecutions.

One method of safely studying an attack is to deflect attackers towards an isolated computer or network which appears to be completely legitimate, but is in fact a closely-monitored trap known as a honeypot. There, every action performed by the attacker can be recorded and analysed without risking important data.

Honeypots are also used by researchers to identify new attacks that are circulating in the hacking community, as well as by anti-spam organisations which use them to identify the location and identities of spam email senders.
Sometimes network administrators want to study attacks, either so the attackers’ methods can be understood more fully and countermeasures prepared, or as part of an investigation that might lead to civil or criminal prosecutions.
One method of safely studying an attack is to deflect attackers towards an isolated computer or network which appears to be completely legitimate, but is in fact a closely-monitored trap known as a honeypot. There, every action performed by the attacker can be recorded and analysed without risking important data.
Honeypots are also used by researchers to identify new attacks that are circulating in the hacking community, as well as by anti-spam organisations which use them to identify the location and identities of spam email senders.
Cyber Security: VPN - Security Risks of VPN
VPNs might sound like a panacea to a number of problems as they can extend, in our example, a corporate network across a wide geographic area via the internet. However, in doing so, they raise a number of new problems.
Security of remote machines
When a remote machine is part of a VPN it effectively creates a new frontier between the ‘secure’ corporate network and the internet. This remote machine now offers a direct route into a corporate network. Previously, it had been relatively simple to secure machines within a corporate network; now the remote user might be using their own computer, network connection, operating system and software – none of which are controlled by the organisation. Worse still, they might be sharing the machine with a number of other users, some of which might not be employed by the organisation. Perhaps the same PC is used to manage corporate documents, as well as downloading pirated music from the internet and playing video games!
The remote machines must themselves be secured from abuse. That may mean enforcing certain minimum standards with regards to operating system, antivirus software, firewalls and so on. Employers may have to stipulate that antivirus software is kept up to date, and that all patches and service packs are installed.
Security of the VPN implementation
As you learned earlier, the security of various VPN implementations has come under scrutiny. Protocols themselves might be well-designed and apparently secure, but the method of implementation, where programmers have taken shortcuts or offered ‘additional convenience’ to the user, may compromise the protection offered.
For instance, there are no major problems with the PPTP protocol, but Microsoft’s implementation of PPTP was found to have a number of serious defects. Microsoft’s implementation of PPTP was introduced in 1996, and hacker software exploiting weaknesses began circulating the following year. Papers describing the weaknesses appeared in 1998, it was only after publication that Microsoft addressed the most serious weaknesses in PPTP by releasing a patch (DUN 1.3), even then some issues remained unresolved.
In addition to errors in protocol implementations, security vulnerabilities can be introduced if the design or configuration of the overall VPN solution is done incorrectly.
Security of interoperation
VPN is still a relatively immature technology with a number of competing standards, often supported by different vendors. Mixing and matching hardware and software might cause problems. Until technology matures (which is happening at a rapid rate), it might be necessary to use a single technology provider.
Security of network availability
Since VPNs typically rely on the internet for delivering information there are no guarantees about the reliability. The internet cannot guarantee delivery of information from one location to another.
Tuesday, August 23, 2016
Cyber Security: Firewall - VPN
VPN basics
In some ways, our local networks resemble forts sitting in the Wild West of a Hollywood movie. Inside strong walls, life goes on as normal, with data being exchanged freely between trusted machines. Meanwhile, beyond the firewall there is the lawless frontier of the internet; traffic crossing the internet must make a risky journey largely unprotected.
The problem of secure data transmission is especially acute for organisations based in several physical locations, such as those who need to exchange information with sub-contractors or those with a dispersed workforce such as sales teams or home workers.
Traditionally, companies invested in private communications links (usually called leased lines) whose cost might run to thousands of pounds per month. Most organisations cannot justify such an investment and in any case, leased lines cannot serve a mobile or highly dispersed workforce. So the lawless frontier of the internet is our only choice – this is where VPNs come to the rescue!
A VPN, as the name implies, is a means of creating a private network across an untrusted network such as the internet. VPNs can be used for a number of different purposes such as:
- to securely connect isolated Local Area Networks (LANs) across the internet
- to allow mobile users remote access to a corporate network using the internet
- to control access within an intranet environment.
VPNs are typically implemented using dedicated network devices (sometimes this might be a firewall), and software. There are two parts to the software; the first, called a VPN client, is installed on the computer of anyone who wants to be part of the VPN. The client is responsible for connecting users to the VPN so that it can send and receive information in a secure manner with, in this example, a corporate network. The second part is the VPN server which is part of a dedicated network device, usually located on the perimeter of an organisation’s network. The server software typically performs the authentication of users and route traffic to the corporate network.
The VPN software creates a path known as a ‘tunnel’ between the VPN client and the VPN server. It can establish this ‘tunnel’ by using any third party or untrusted network such as the internet. Unlike other paths through the internet, information which passes through this ‘tunnel’ can be encrypted to protect it from inspection or modification. So we can use these tunnels to protect our data while it crosses the lawless frontier of the internet back to the safety of our forts!
Securing the tunnels
The VPN path or tunnel between the VPN client and the VPN server relies on encryption to protect the data from interception or modification as it travels across the internet.
Encryption
In a VPN, encryption and decryption is typically performed by the client and server software. Early VPN solutions used proprietary encryption techniques, but shortcomings in many of these methods has forced a switch to public encryption standards.
Authenticity and integrity
It is vital to ensure that information can be trusted – that it is coming from an authenticated user and that it has not been altered in transit. VPNs use a number of methods to ensure authenticity:
- hashes (see Week 5)
- digital signatures (see Week 5)
- message authentication codes (MACs).
VPN protocols
There are three main forms of VPN protocol currently in use, these are:
- PPTP (Point to Point Tunnelling Protocol)
PPTP proved unsuited to large companies (being limited to 255 connections per server), but more seriously, the PPTP standard did not settle on a single form of user authentication or encryption; therefore two companies could offer software supporting PPTP, yet each product would be incompatible with the other! From Windows 2000 onwards, Microsoft replaced PPTP with L2TP (see below).
- L2TP (Layer 2 Tunnelling Protocol)
- IPSec (Internet Protocol Security)
IPSec has gained a reputation for security thanks to its use of well-known and trusted technologies. Rather than invent new techniques for encryption, the designers of the protocol built their system on top of existing encryption technologies, which had, in themselves been subjected to intense scrutiny.
Cyber Security: Firewall - Firewall basics
In a building, a firewall is a reinforced masonry wall that is designed to prevent a fire spreading through the structure, allowing people time to escape. Similarly, in a computer network, a firewall is a barrier that blocks dangerous communications from spreading across a network, either from the outside world into a local network, or from one part of a local network to another.
Firewalls can be supplied as dedicated network devices or they may form part of a network router. A firewall might also be included as part of a computer’s operating system.
The internet existed for a long time before firewalls were invented. The first discussion of the necessary technologies took place late 1988, and came about after several attacks from organised groups of hackers and the very first malicious software.
At their simplest, firewalls block network communications by looking at the addressing and protocol information in the data packet’s header. As a data packet (or datagram) arrives at the firewall’s interface, the addressing (usually IP) and protocol information (usually TCP or UDP) is compared to rules programmed into the firewall’s software. These rules can be supplied by the firewall’s manufacturer, or more often they are created by an administrator or sometimes the user.
So if a packet originating from a hacker conducting a scan of your network or computer arrives at a firewall, it will inspect its addressing and protocol information and then compare this against its set of rules. If the set of rules say that packets from an unknown address (the hacker) are to be blocked, then the firewall may either discard the packet ‘silently’ or ‘close’ the connection with the hacker.
Most firewalls store the state of connections to determine if they represent new or existing connections. It will only allow packets belonging to a known, active connection to pass (provided the rule set allows this). More advanced firewalls can identify the applications responsible for sending and receiving packets, allowing network managers to block applications that use excessive bandwidth – such as media players, or those widely used for distributing copyright infringing content – such as BitTorrent applications, as well as protecting from application attacks.
Personal firewalls
Most operating systems come with a firewall that is installed as part of an operating system.
This firewall is only able to protect the computer it is installed on (and any devices attached to it) from an attack, so it is called a personal firewall. It is not intended to replace a network firewall which prevents attacks from outside of the network (such as from the internet).
Personal firewalls are especially useful for people with portable computers which will inevitably be connected to a wide range of computer networks. While we all hope and, to some extent, trust the people responsible for maintaining these networks to maintain a safe system, we cannot be sure that these networks are not compromised. The personal firewall on our own computers therefore adds a layer of protection between our personal data and a potentially untrustworthy (but useful) network.
Personal firewalls are the responsibility of individual computer users. If you have complete access to your computer’s settings then it is entirely possible to turn off the personal firewall and leave your computer vulnerable.
Other firewalls
Other firewalls are available either to download or as software packages that can be bought from retailers.
You may prefer to use one of these programs, but if you do, please remember:
- you should only keep one firewall running at a time since multiple firewalls will not offer significantly better protection and can interfere with one another
- you must keep one firewall running at all times.
Subscribe to:
Posts (Atom)
