Showing posts with label Futurelearn. Show all posts
Showing posts with label Futurelearn. Show all posts

Tuesday, August 30, 2016

Cyber Security: Risk of Data Loss

Risks of data loss
As the case studies showed, there are serious consequences of losing data.

These consequences can be expressed as a series of costs, such as:

April2516-25off-sitewide728X90 the cost of recreating the lost data – either by buying new hardware and software or re-entering the lost data (which may not always be possible)
the cost of continuing without that data (availability)
the cost of informing others about the loss.
The costs cannot just be expressed in terms of money. For instance, the last cost, of informing others, is not just limited to, for example, postage and email charges. A company that suffers a data loss can also suffer a loss in its reputation as a professional organisation. This problem is greatly magnified if personal data belonging to other people has been lost.

Case study: JournalSpace
At the end of 2008, the blog provider JournalSpace went into liquidation after the crucial database containing its customers’ blogs was corrupted by a disgruntled former employee. This criminal action should not have proved fatal, but it became clear that the six-year old company had not been keeping complete backups of their data.

JournalSpace customers were able to recover some of their data using copies of their postings held in Google’s giant cache, but JournalSpace’s reputation was ruined. JournalSpace was later reborn under new management, but by then it had lost most of its users.
April1816-30off-programwide728X90 
The risk of data loss cannot be completely eliminated, but it can be minimised. The 2013 Forrester report suggested that malicious actions by disgruntled employees was the leading cause of internal breaches, but a significant number of security threats are caused inadvertently by employees who are unaware of the risks of their actions, such as copying data to external devices or websites, opening infected emails, clicking malicious links, installing software and so on. Better staff training could reduce the risk of accidental data loss.

The Infosecurity Europe survey revealed that while a slight majority of companies had implemented an internal information security policy to secure computers, networks and data, only a minority had provided staff training to raise awareness of potential security risks. Another important way of minimising the effect of any loss is by backing up data – making secure copies of data either on to a separate device, to a separate disk, or even to a different location.

April0416-20off-sitewide728X90

© The Open University
https://www.futurelearn.com/courses/introduction-to-cyber-security/8/steps/83138

Monday, August 29, 2016

Cyber Security: Identity Theft

Identity theft
Identity theft is a type of fraud in which an attacker uses stolen personal information to impersonate another person.

Traditionally, this type of fraud was achieved by an attacker intercepting postal deliveries which contain personal information such as names, addresses, bank account details and so on. Attackers could then open credit card accounts and apply for loans in the victim’s name. Victims have had their financial security and lives ruined by identity theft.

Coursera - Hundreds of Specializations and courses in business, computer science, data science, and more Discover Data Science with Coursera Master Computer Science on Coursera

The online world has opened up a new, lucrative source of information for fraudsters. Many users have been quite relaxed about sharing their information with online services and other users, but even security conscious individuals are threatened by malware designed to sniff out personal information on a computer, or phishing attacks that persuade users to divulge personal information. Additionally, as we have seen, hacking attacks on big retailers can make millions of personal records available for potential abuse.

Online identity theft still only makes up a tiny proportion of all cases of identity theft and it is actually quite a rare occurrence, but it is a growing threat.

Preventing identity theft
You can greatly limit your risk of online identity theft by following simple security procedures such as running an antivirus program, keeping it up to date and by not responding to phishing emails.






Build Project Management Skills with Coursera Learn Data Science, Digital Marketing, Business Foundations & More. Start Learning. Master Big Data with UCSD and Coursera

Detecting identity theft
Online identity theft may pass unnoticed for some time, during which great damage can be done to your financial security. Some signs that a victim might notice are:
  • unexplained bank withdrawals or credit card charges
  • bills and other expected official letters don’t arrive
  • cards or cheques are declined
  • debt collectors make contact about debts they know nothing about
  • they receive notice that their information was compromised by a data breach at a company where they do business or have an account
  • their bank or credit card provider makes contact about suspicious behaviour on their account.
Loss of data
Data loss can mean several things ranging from the destruction and deletion of data, to making unauthorised copies that are no longer under your control.
Data can be stolen by people who have direct access to a computer, such as by copying data to a flash memory drive, and also by attackers gaining access over a network connection.

Insider attacks
The hardest attack to defend against is when an attacker has direct access to a computer, especially in an organisation where many people might have access to a single computer, and one, or more, of them might not have the organisation’s best interests at heart. Security risks posed by employees (or ex-employees) of an organisation to their employers are known as insider threats.

Learn Social Media Marketing with Northwestern and Coursera Learn Business Analytics with UPenn and Coursera Become a Web Developer in 2016 with Coursera

A 2013 Forrester survey of businesses employing two or more people in the UK, US, Canada, France and Germany found that 36% of information security breaches were caused by insiders and represented the leading threat to organisational security. These findings were supported in a survey of attendees to the Infosecurity Europe conference where 37% of respondents said the biggest threat to their information security came in the form of ‘rogue employees’. This placed insider threats ahead of cyber attacks (19%) and device security (15%).

Case study: Stealing data
In 2012, a programmer for the Federal Reserve Bank of New York was sentenced for stealing source code used to develop the bank’s computer systems.

Bo Zhang was a third party contractor for the bank with privileged access to software that was under development. He pleaded guilty to copying the code to personal computers in violation of his contract of employment although there is no evidence that he intended to share the programs with anyone.

Similarly, in 2013, the social networking game developer Zynga settled a lawsuit with a former employee, Alan Patmore, who had copied hundreds of files, including unreleased game designs to a Dropbox cloud storage folder before taking up employment with a rival company. Patmore expressed deep regret for his actions and agreed to ensure all copies of the data were destroyed in exchange for Zynga dropping charges against him.

The case of Chelsea Manning is one of the more significant insider attacks involving the loss of data. It is another example where the attacker simply copied the data and shared it with others, depriving the data owners of control over the confidentiality of the information.


Coursera CS  Case study: Chelsea Manning
Chelsea Manning (born Bradley Manning) was a United States Army soldier who leaked confidential information, including 250,000 United States diplomatic messages and 500,000 United States Army reports as well as videos of military action in Iraq, to the WikiLeaks website.

Manning obtained copies of classified materials during service in Iraq in 2009, copying them directly to a data CD disguised as a music disc, from which the materials were transferred to a laptop and then to the WikiLeaks servers for dissemination.

The reports were widely published around the world and caused enormous diplomatic embarrassment for the United States government. Manning was eventually identified after confessing in an online chat to Adrian Lamo, who informed the Army. Manning was charged with 22 offences, including that of aiding the enemy, and pleaded guilty to 10 charges. She was found guilty in 2013 and sentenced to 35 years in military prison.
 

Wednesday, August 24, 2016

Cyber Security: Network Security - Quiz

Question 1
What is the role of a personal firewall?

  • To protect the network to which your computer is attached from attacks that come from outside the network
  • To protect your computer and the devices attached to it as an extra layer of security
  • To protect your computer so that you don’t need to use any other firewalls
  • To encrypt the data coming to and from your computer

Default Creative-30percent April2516-25off-sitewide300X250  Question 2
You are recommending a networking solution for an organisation that is based in several locations and wants to exchange data securely between those locations and with its mobile sales force. Which of the following would be the most practical option?

  • Leased lines
  • LANs
  • Encryption
  • VPNs


 Cisco CCIE Lab Builder Cisco Expert Level Training for CCIE Routing and Switching v5.0Question 3
For what purpose are hashes, MACs and digital signatures used in a VPN?

  • To provide authentication and ensure integrity
  • To ensure confidentiality and availability
  • To ensure integrity and availability
  • To ensure confidentiality and provide authentication

Cisco Security and Virtual Private Network (VPN) courses

Question 4
Which method of intrusion detection looks for unusual patterns of network use to warn system administrators that there might be a problem?
  • Digital signatures
  • VPN tunnelling
  • Anomaly detection
  • Misuse detection
  • Intrusion prevention
Learn Business Analytics with UPenn and Coursera Become a Web Developer in 2016 with Coursera Top Computer Science Specializations on Coursera

Question 5
What is the term used for an isolated computer that can be used by researchers to study new types of attack?

  • Botnet
  • Zombie
  • Tunnel
  • Honeypot
  • Misuse detection
Course-specific creative-The Complete Ethical Hacking Course: Beginner to Advanced! Course-specific creative-JavaScript: Understanding the Weird Parts Course-specific creative-The Complete Web Developer Course - Build 14 Websites

Tuesday, August 23, 2016

Cyber Security: Cryptography - Digital signatures and certificates

https://view.vzaar.com/6632179/video

Default Creative-30percent April2516-25off-sitewide300X250  April1816-30off-programwide300X250

Hashing can show that data has not changed in transmission, but on its own cannot demonstrate that the data originated with its supposed author. To do that, a digital signature should be used.
Digital signatures use the sender’s private key to encrypt the hash. Previously, you learned how documents can be encrypted with a public key which can be used by anyone, but can only be decrypted using the corresponding private key known only to the owner.

Encrypting data using the private key isn’t suitable for securing secrets (as anyone with access to the public key could decrypt it). However, it is perfectly possible to encrypt a hash using the private key so that the hash can be decrypted and compared by anyone possessing the matching public key. This can be used to provide authenticity since the encrypted hash must have been produced by the holder of the private key – hence the name digital signature.

Case study: Alice and Bob
Imagine that Alice wants to send the company’s quarterly profit statement to Bob, who works in the financial markets, for public announcement. Both Alice and Bob want confidence that the quarterly profit statement has not been intercepted by Eve en route and altered.


Alice will therefore produce a hash of the quarterly profit statement and then encrypt this with her private key to produce a digital signature. Alice will then include the digital signature with the quarterly profit statement and send this to Bob, (depending on any time-bound sensitivities she may or may not encrypt this with Bob’s public key).

Upon receipt Bob will decrypt the digital signature using Alice’s corresponding public key to reveal the hash, (again depending on any time-bound sensitivities he may initially decrypt the entire message using his private key). Bob will then calculate a hash of the quarterly profit statement and then compare this with the encrypted hash that he received from Alice. If the hashes are the same then both Bob and Alice can be confident that the quarterly profit statement was not altered en route by Eve.

Digital signatures do not provide us with complete confidence of the author or originator. Just because a digitally signed document claims to come from a person or a company it doesn’t mean that it actually did, a malicious individual could masquerade as the sender by producing their own public/private key pair and using these to produce digital signatures.

Case study: Alice and Bob
Imagine that a digitally signed business invoice arrives in Alice’s mailbox from Bob. She uses Bob’s public key from a public key server to decrypt the digital signature and validate the business invoice by comparing the hashes. Alice, assuring herself that it is Bob (as the hashes are the same), follows the instructions and transfers money to the account details in the business invoice.

April2516-25off-sitewide640x480

A few weeks later, Alice receives an angry email from Bob because he has not been paid. After a bank investigation she finds out that she had transferred the money to Eve by mistake – so what went wrong?

It’s clear that the business invoice and the associated signature did not come from Bob, instead the signed business invoice actually came from Eve. Eve used Bob’s personal information to create a new key pair in Bob’s name and placed a copy of the public key on a public key server. Eve then used her corresponding private key to sign the business invoice and send it to Alice.

Alice, convinced that the document was a genuine business invoice from Bob (as it included what she believed to be his digital signature), followed the instructions and paid money into an account belonging to Eve – oh dear!

April0416-20off-sitewide300X250    Course-specific creative-The Complete iOS 9 Developer Course - Build 18 Apps

Digital certificates help us overcome this problem. A digital certificate is a means of binding public keys to their owner. These are issued by Certificate Authorities (CAs) who validate the owners of public keys. The CA does this by validating (through various processes), the identity of the owner of the public key. Once it has done this it will bind the public key to a digital certificate and sign it using its private key to attest authenticity. The CA’s public key is available to all parties who need to validate the CA’s assertion of public key ownership.

Case study: Alice and Bob
So, this prevents Eve from creating a key pair of her own, and claiming that the corresponding public key is Bob’s. If Eve were to now send a business invoice appearing to be signed by Bob, when Alice uses Bob’s validated public key to try and decrypt the hash and compare them, this will not work; she would know that something was wrong, and (hopefully), not transfer money to Eve.

https://www.futurelearn.com/courses/introduction-to-cyber-security/8/steps/83113
© The Open University

Cyber Security: Cryptography - Using cryptography to prove identity

Course-specific creative-Learn and Understand AngularJS Course-specific creative-The Complete Android Developer Course - Build 14 Apps Course-specific creative-iOS 9 and Swift 2: From Beginner to Paid Professional

Using cryptography to prove identity
Cryptography isn’t just used to hide secrets, it can also be used to authenticate data sent on an insecure network – such as the internet. The process begins by checking that your copy of a piece of data is an exact match for the one you requested.

  • Hashing
Hashing is the mathematical process of converting data of any size into data of fixed length known as the ‘hash’ (alternative names include message digest, hash codes, hash sums or hash values).

Hashing operates in one direction only, making it impossible to deduce the original data from the resultant hash. The intention of hashing is not to preserve the contents of the data but to create a unique identifier for every single piece of data. When a file is published on the internet, the author may choose to publish the hash value for that file. For instance, here is some information published by the GnuPG encryption software authors on their website:

Example of hash value.

                 

Each long line of numbers and letters on the left is a hash (in this case from a hashing program called SHA-1), the text on the right is the name of the file. If you download one of these programs, you can then run your own copy of SHA-1 on your download and obtain a hash – if your file exactly matches the original the two hashes will be identical.

A variation of a single bit of data between two otherwise identical files will result in vastly different hash values, so any edits to a file between two hashing operations will result in different hash values revealing that the data has been tampered with and should not be trusted.

Top Courses in IT & Software 300x250 Top Courses in Network & Security 300x250   Udemy 

A large number of hashing algorithms have been developed; the most widespread are algorithms called MD5, SHA-1 and SHA-2. Although MD5 and SHA-1 are in common use, both have been found to be flawed. Under certain circumstances ‘collisions’ can occur where two pieces of different data can generate the same hash value (albeit under specifically controlled conditions).

This weakness in the MD5 hashing algorithm has been used in malware targeting Microsoft Windows computers. Since neither algorithm can be guaranteed to generate unique hashes they can be considered ‘broken’ and should not be used. The United States government requires all hashes to be generated using the newer SHA-2 algorithm which has not shown any such weaknesses.

 Implementing Cisco Network Security (IINS) v3.0 e-learning course

Cyber Security: Cryptography - Encryption Key

Encryption keys
Keys are pieces of information that determine the output from an encryption (or decryption) process. A single cipher can produce an almost limitless number of different outputs with different key values; allowing secure communication even if the cipher itself is known to hostile third parties.


Implementing Cisco Network Security (IINS) v3.0 e-learning course

It might surprise you to know that almost all ciphers are published in the scientific press or in standards documents, having them available for widespread scrutiny allows many people to check that they are secure and do not contain weaknesses which could be exploited to compromise the security of the data encrypted using that cipher.

A computer encryption key is nothing more than a string of bits where each bit can have a value of either 0 or 1. The number of possible values for a key is simply the total number of values that the key can have. So our one-bit long key can only have two possible values – 0 and 1. If we chose to have a two-bit key it could have one of four possible values – 00, 01, 10 and 11. In fact every time we increase the length of the key by one bit we double the number of possible keys – so a three-bit key has eight possible values – 000, 001, 010, 011, 100, 101, 110 and 111.

Cisco Security and Virtual Private Network (VPN) courses

The total number of keys can be written in scientific form as 2key length; so a key with a length of eight has 28 – that is 256 – values.

But how long should a key be? How short is too short?

The problem with short keys
Short keys are vulnerable to what is known as a brute force attack about passwords. A brute force attack is where a computer, or a number of computers, try every possible value for a key until they produce recognisable plaintext.

Cisco E-Learning for ICND1 v2.0 180-day subscription

Since computers can work through key values extremely rapidly, keys must be sufficiently long that they offer a very large number of possible values.

Keys may be known to the user in the form of passwords, or they may be stored in a computer’s hardware (such as the decryption keys stored on a DVD player that allow it to play the encrypted data stored on the movie disk), or they can be generated by a computer as and when they are needed (such as conducting a secure transaction on a shopping site).

The key distribution problem
Traditionally, symmetric encryption suffered one enormous shortcoming – it was necessary for either the sender or the recipient to create a key and then send it to the other party. While the key was in transit, it could be stolen or copied by a third party who would then be able to decrypt any ciphertexts encrypted with that key.
Another problem is that a large number of key pairs are needed between communicating parties. This quickly becomes difficult to manage the more there are. This can be calculated as n(n-1)/2 where n is the number of communicating parties.

For example, if ten parties want to communicate with each other securely they would need 45 different key pairs: 10(10-1)/2 = 45. This would increase to 4,950 if there were 100 communicating parties!

This problem, called the key distribution problem, affected anyone wishing to use encryption until the 1970s when a method of distributing keys without actually sending the keys themselves was developed independently by GCHQ in the United Kingdom and Whitfield Diffie and Martin Hellman in the United States. The British discovery was kept secret for many years, so today the solution is known as the Diffie–Hellman key exchange method.

Symmetric encryption methods have the advantage that encryption and decryption is extremely fast, making them ideal for transmitting large amounts of secure data.

Cisco CCIE Lab Builder Cisco Expert Level Training for CCIE Routing and Switching v5.0 Cisco CCNA Collaboration Courses





Asymmetric or public key cryptography
Asymmetric cryptography, better known as public key cryptography, sidesteps the key distribution problem as each user creates their own keys:

  • the private key which they keep safe and never distribute
  • the public key which can be sent to anyone with whom they want exchange encrypted information.
Together the two keys are known as a key pair, which is what was used by Alice and Bob.

Whereas symmetric encryption only provides confidentiality of the messages exchanged, the use of two different keys allows asymmetric encryption to provide both confidentiality and authenticity. To get confidentiality Alice encrypts the message with Bob’s public key. This message can only be decrypted with the Bob’s private key so Alice and Bob can be sure that nobody else will be able to read it. However, if Alice also wants to prove to Bob that the message is authentically from her, she can first encrypt it using her private key, and encrypt the resulting message again using Bob’s public key. Once Bob decrypts the message using his private key, he can try to decrypt the result again using Alice’s public key. If this is successful, he can be confident that message must have come from Alice (since nobody else should know her private key).

Implementing Cisco Threat Control Solutions (SITCS) v1.0 e-learning course Cisco Security and Virtual Private Network (VPN) courses  Cisco E-Learning for CCNP SWITCH v2.0 180-day Subscription 

So an important property of asymmetric cryptography is that the private key is the only key that can decrypt ciphertext encrypted using the corresponding public key and the public key is the only key capable of decrypting files encrypted with the corresponding private key. Crucially, the value of one key cannot easily be determined from the other, so even if the public key falls into hostile hands, the value of the private key cannot be determined.

Public keys can be distributed using email attachments or through public key chain servers which act as distributors for large numbers of public keys. The creator of a public key uploads their key to the key chain server and it is freely available to anyone who wants to use it.

Although the mathematics behind public key cryptography is incredibly complex, the process of using it is relatively simple. To send a message using public key cryptography is simple. The sender obtains a copy of the recipient’s public key, either by email or from a key chain server, and uses it to encrypt the message. The resulting ciphertext is then sent to the recipient who uses their corresponding private key to restore the original plaintext.

Public key cryptography is popular because there does not have to be any initial secure exchange of secret keys for an encrypted message to be sent (remember, users only ever exchange their public keys). However, it is generally far slower than symmetric encryption; and because of a quirk in the underlying mathematics, traditional public key cryptographic techniques require far longer keys to offer the same level of protection as symmetric encryption.

A newer type of public key cryptography, known as ‘elliptic curve cryptography’, can be just as secure as symmetric encryption using similar key lengths.

  Testive Testive Testive