<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>CSC408. REVISION CHAPTER 7 &amp; 8 by Pian Fiyyan</title>
      <link>https://padlet.com/pianhafiyyan/bn8t6ddvo46o</link>
      <description>AM2284A
MADAM YUSMAWATI</description>
      <language>en-us</language>
      <pubDate>2018-12-24 04:59:29 UTC</pubDate>
      <lastBuildDate>2018-12-24 05:45:09 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url>https://padlet-assets.s3.amazonaws.com/icons/Apple.png</url>
      </image>
      <item>
         <title>QUESTION 1</title>
         <author>pianhafiyyan</author>
         <link>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590591</link>
         <description><![CDATA[<div><strong>Briefly explain the following computer crimes. <br><br>a) Sniffer </strong></div><div><br></div><div><strong>Sniffer</strong> allows individuals to capture data as it is transmitted over a network. This technique is used by network professionals to diagnose network issues, and by malicious users to capture unencrypted data, like passwords and usernames. If this information is captured in transit, a user can gain access to a system or network.<br><br><strong>b)</strong> <strong>Phishing </strong></div><div><br></div><div><strong>Phishing</strong> is a cyber-attack that uses disguised email as a weapon. The goal is to trick the email recipient into believing that the message is something they want or need a request from their bank, for instance, or a note from someone in their company and to click a link or download an attachment.<br><br><strong>c)</strong> <strong>Pharming </strong></div><div><br></div><div><strong>Pharming</strong> is a scamming practice in which malicious code is installed on a personal computer or server, misdirecting users to fraudulent Web sites without their knowledge or consent. Pharming has been called "phishing without a lure.<br><br><strong>d)Spoofing </strong></div><div><br></div><div><strong>Spoofing</strong> is a type of scam where an intruder attempts to gain unauthorized access to a user's system or information by pretending to be the user. The main purpose is to trick the user into releasing sensitive information in order to gain access to one's bank account, computer system or to steal personal information, such as passwords.</div><div><br></div><div> </div><div> </div><div> </div><div> </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-24 05:09:23 UTC</pubDate>
         <guid>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590591</guid>
      </item>
      <item>
         <title>Question 2</title>
         <author>pianhafiyyan</author>
         <link>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590606</link>
         <description><![CDATA[<div><strong>a) Distinguish the TWO (2) methods for encrypting network traffic on the Web.</strong></div><div><strong>&gt; Secure Sockets Layer (SSL)</strong> and successor<strong> Transport Layer Security (TLS) </strong>enables client &amp; server computers to manage encryption &amp; decryption activities; so they communicate with each other during a secure web session. </div><div><strong>&gt;</strong> <strong>Secure Hypertext Transfer Protocol (SHTTP)</strong> is used for encrypting data flowing over the Internet but it is limited to individual messages, whereas SSL &amp; TLS are designed to establish a secure connection between 2 computers.<br> <strong>b) Briefly explain the following terms:</strong></div><div><strong>i. Cyber warfare:</strong><br> State-sponsored activity designed to cripple &amp; defeat another state or nation by penetrating its computers or networks for the purposes of causing damage &amp; disruption.</div><div><strong>ii. Computer Forensic:</strong><br> Scientific collection, examination, authentication, preservation, and analysis of data from computer storage media for use as evidence in court of law and it includes recovery of ambient and hidden data.</div><div> </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-24 05:10:30 UTC</pubDate>
         <guid>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590606</guid>
      </item>
      <item>
         <title></title>
         <author>pianhafiyyan</author>
         <link>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590713</link>
         <description><![CDATA[<div><strong>QUESTION 3</strong><br><strong>a) Without protection against malware and intruders, connecting to the Internet could be very dangerous. Firewalls, intrusion detection system and antivirus software have become the tools to overcome this problem. Briefly explain these THREE (3) tools.<br></strong><br></div><div>1) Firewall - combination of hardware and software that prevents unauthorized users from accessing private networks Static packet filtering - examines selected fields in the header of data packet flowing back and forth between the trusted network &amp; Internet, examining individual packets in isolation.<br><br></div><div>2) Intrusion detection system - monitors hot spots on corporate networks to detect and deter intruders and examines events as they are happening to discover attacks in progress.<br><br></div><div>3) Antivirus software - checks computers for presence of malware and can often eliminate it as well. It requires continual updating. <br><br></div><div><strong>b) Information systems controls is one of the components of an organizational framework for security and control. Information systems controls consist of two - general and application control. A company must know how and where to deploy security tools and security personnel must know what controls a company must have in place to protect its information system. Contrast between General Controls and Application Controls.<br></strong><strong><em><br></em></strong>1) General Controls – It is a for govern design, security and use of computer programs and security of data files in general through out organization information technology infrastructure. It apply to all computerized applications. Moreover it is a combination of hardware, software and manual to create overall control environment.<br><br></div><div>2) Application controls – It specific controls unique to each computerized application such as payroll or order processing. It includes both automated ad manual procedure, for example input control, output control and processing controls. Moreover, it ensures that only authorized data are completely and accurately can processed by that applications. </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-24 05:15:47 UTC</pubDate>
         <guid>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590713</guid>
      </item>
      <item>
         <title></title>
         <author>pianhafiyyan</author>
         <link>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590756</link>
         <description><![CDATA[<div><strong>QUESTION 4<br>Malicious Software programs are referred to as Malware. Describe FOUR (4) types of malicious software.</strong><strong><em><br><br></em></strong><em>1) </em>Spyware is any technology that aids in gathering information about a person or organization without their knowledge. On the Internet (where it is sometimes called a Spybot or tracking software), Spyware is programming that is put in someone's computer to secretly gather information about the user and relay it to advertisers or other interested parties. <br><br></div><div>2) Virus is a program or programming code that replicates by being copied or initiating its copying to another program, computer boot sector or document. Viruses can be transmitted as attachments to an e-mail note or in a downloaded file, or be present on a diskette or CD.<br><br></div><div>3) Worm is a self-replicating virus that does not alter files but duplicates itself. It is common for worms to be noticed only when their uncontrolled replication consumes system resources, slowing or halting other tasks.<br><br></div><div>4) Trojan (Trojan Horse) is a program in which malicious or harmful code is contained inside apparently harmless programming or data in such a way that it can get control and do its chosen form of damage, such as ruining the certain area on your hard disk. A Trojan horse may be widely redistributed as part of a computer virus.</div><div><strong><br></strong><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-24 05:17:31 UTC</pubDate>
         <guid>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590756</guid>
      </item>
      <item>
         <title></title>
         <author>pianhafiyyan</author>
         <link>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590769</link>
         <description><![CDATA[<div><strong><em>QUESTION 5<br>a) Nowadays securing information systems has become an important issue in organization to protect itself against computer crime. Define computer crime and provide an appropriate example. </em></strong><strong><br></strong><br></div><div>Computer crime means any violations of criminal law that involves knowledge of computer technology for their perpetration, investigation, or prosecution. Some examples are breaching confidentiality of protected computerized data and accessing a computer system without authority. <br><br></div><div><strong><em>b) Briefly explain THREE (3) reasons why information systems are vulnerable to destruction, error and abuse? </em></strong><strong><br></strong><br></div><div>1) There are internet vulnerabilities which mean network is open to anyone and size of Internet means abuses can have wide impact. <br><br></div><div>2) There are wireless security challenges whereby eavesdroppers can drive by buildings and try to intercept network traffic and hacker that gains access to SSID, has access to network’s resources. <br><br></div><div>3) There are malicious software such as worms, viruses, Trojan horses and spyware. <br><br></div><div><strong><em>c) Discuss the THREE (3) most important tools and technology for safeguarding information resources.</em></strong></div><div><strong> </strong></div><div>1) Identity management software which automatically keeps track of all users &amp; privileges authenticates users, protecting identities, and controlling access.</div><div> </div><div>2) Authentication which is a system that checks the identification of an end user who wants to access it. Some types of authentications are token, smart cards, biometric authentication and two-factor authentication.</div><div> </div><div>3) Firewalls which is a combination of hardware and software that prevents unauthorized users from accessing private networks and provides additional security by determining whether packets are part of an on-going dialogue between sender &amp; receiver.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-24 05:18:15 UTC</pubDate>
         <guid>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590769</guid>
      </item>
      <item>
         <title>CHAPTER 7</title>
         <author>pianhafiyyan</author>
         <link>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590799</link>
         <description><![CDATA[<div><br><br><strong>1)Security isn’t simply a technology issue, it’s a business issue. Discuss</strong></div><div>IT Security should be seen as a task to minimize risk for an organization. This risk management is not just limited to the IT department or within the office because many people do work a little when we get home even if its just checking their emails. Employees use of unauthorized personal mobile devices can be a threat because it is an unknown object on the IT network. For example, if a user was to save business data onto an unauthorized device and then it was infected by malware, the data could end up in the wrong hands. However, it is not about the IT department forbidding personal devices. If devices are approved then it is safe to have on the network. It’s all about having policies in place and training employees on how to access business data securely.<br><br><strong>2)Who poses the biggest security threat: insiders or outsiders?<br></strong>Insiders poses the greatest security threat as they have access to sensitive information on a regular basis, and may know how that information is protected. If they want to steal it or leak it they can usually do so with far greater ease than outsiders. Furthermore, insiders may also accidentally leak data or otherwise put it at risk which is something that outsiders typically cannot do. Whether by attaching the wrong file to an email being sent, oversharing on social media, losing a laptop or USB drive, or through some other mistake, insiders can put an organization's data at risk with little effort. Policies and technology can help address this risk, but without it, problems are likely to occur<br><br><strong>3)Suppose your business had an e-commerce Web site where it sold goods and accepted credit card payments. Discuss the major security threats to this Web site and their potential impact. What can be done to minimize these threats<br><br></strong>E-commerce involves transactions that take place over the Internet. Therefore, e-commerce utilizes internal networks that interface with the World Wide Web. The nature of this kind of business, introduces internal and external risks to both the website and the business systems to which it is connected to. An E-commerce website can be faced with security threats such as fraud incidents that include credit card fraud, which exposes the website to threat from clients and any other external sources and internal fraud. Such transactions can also be introduced into the system by hackers or Trojan Horses, which resemble the real customers’ transactions. To prevent fraud, Fraud scoring must be used. Other than that, alicious software and computer viruses are some of the biggest security threats to any E-commerce website. Viruses are normally from external sources and can corrupt files on website if introduced into the internal network. Viruses can completely destroy a computer system and disrupt the operations of the website. Trojan horse is malicious software that has the ability to capture the clients’ information, before any encryption software can take effect. They can also impersonate a customer and pass over bad and malicious codes into the server running the website. To avoid these viruses, users should exercise reasonable precautions in order to minimize the introduction and spread of computer viruses. Virus scanning software should be used to check any software downloaded from the Internet or obtained from any questionable sources.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-24 05:20:21 UTC</pubDate>
         <guid>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590799</guid>
      </item>
      <item>
         <title>Question 6</title>
         <author>pianhafiyyan</author>
         <link>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590805</link>
         <description><![CDATA[<div><strong>a) Authentication is the process of identifying an individual, usually based on a username and password. In security systems, authentication is distinct from authorization, which is the process of giving individuals access to system objects based on their identity</strong>.</div><div> </div><div><strong>b) i) Password Based Technologies</strong></div><div>-Password may be of any form such as string of alphabets, numbers and special characters. This password is necessarily to be known by the entity or a person that is being authenticated.<br><br></div><div><strong>ii)</strong> <strong>Certificate Based Technologies</strong></div><div>It is a digital document which digitally signed by a reliable third party known as the Certificate Authority (CA). Then these Digital Certificates can be reused for user authentication. Certificate based authentication is stable as compared to password based authentication.<br><br></div><div><strong>iii) E-Token Based Technologies</strong></div><div>An E-Token authentication is a small device that develop/generates a new odd/random value every time it is used. This random value becomes the basis for authentication such as an alternative to a password. It can be implemented on a USB key fob or on a smart card. Data is protected on the device itself.<br><br></div><div><strong>iv)</strong>  <strong>Biometric Based Technologies</strong></div><div>Biometric authentication mention is the recognition or identification of humans by their personality or characteristics such as Face, fingerprint, human voice, retina, iris pattern of the eye, vein pattern etc. It's used in computer science as a form of realization or recognition and access control. It is also used to find or select persons in groups that are under consideration.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-24 05:20:32 UTC</pubDate>
         <guid>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590805</guid>
      </item>
      <item>
         <title>CASE STUDY The Loming Threat of Cyber</title>
         <author>pianhafiyyan</author>
         <link>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590955</link>
         <description><![CDATA[<div><strong>1. Is cyberwarfare a serious problem? Why or why not?</strong></div><div>·       Yes, cyber-warfare is a serious problem because it is more complex than conventional warfare. Although the many potential targets are military a country’s power grids, financial systems, and a communication network can also be crippled. Non-state actors such as terrorist ore criminal groups can mount attacks, and it is often difficult to tell who is responsible. Nations must constantly to be on the alert for new malware and other technologies that could be used against them, and some of these technologies develop by skilled hacker groups are openly for sale to interested government. it can make one of the government destroy in term of their financial or education. it is a serious matter to be look and must been solved because there are a lot of hackers that can obtain others government information.</div><div> </div><div><strong>2. What solutions are available for this problem? Do you think they will be effective? Why or why not?</strong></div><div>·       Because the whole issue of cyberspace and the problems and damage it can cause is quite new and is still on the rise, many things have not yet been internationally agreed on and many states take different measures. Cyber attacks can be prevented with two different types of measures: The first type intending to prevent states from carrying out cyber attacks and the second type being measures to increase security of the networks which have the highest risk of being attacked. Most states have laws regulating computer crimes done by individuals or non-state actors to hopefully prevent any cyber attacks but other states are not bound to any rules yet. They would only have to be aware of the reaction of the attacked country. Besides definitions of cyber warfare and information warfare and other important terms, an internationally agreed list of computer crimes or rules should therefore be established, maybe in combination with an organization monitoring the cyberspace, with large and serious consequences against states violating these rules. </div><div> </div><div>·       In contrast, the strength of a security system is not always the most important part as the potential strength of attacks is steadily growing, sometimes it’s more important to take different measures. Two very controversial ideas are the kill switch and the electrical wall. The kill switch could shut down the internet of certain areas, whether it is only concerning a company, a city or a whole country, in case of serious cyber attacks. The electrical wall intends to inspect every data package coming into the country’s network and compares it to known signatures and in case of a match do not let them through. Both these ideas can be very useful and even save lives, however, if used by the wrong person or government, they can violate basic human rights by censoring certain parts of the internet. Therefore such measures have to be evaluated very carefully and include certain restrictions. In general all states should consider their possibilities with care as the internet is a symbol for freedom and a state interfering with the internet could lead to protest of the civilians. Because the internet connects everyone worldwide, each state is equally affected. Cooperations between countries and international agreements could therefore prove very useful leaving only non-state actors as a possible cyber threat.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-24 05:28:28 UTC</pubDate>
         <guid>https://padlet.com/pianhafiyyan/bn8t6ddvo46o/wish/316590955</guid>
      </item>
   </channel>
</rss>
