<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>Revision Chapter 7 &amp; 8 by Hafizah Zainuddin</title>
      <link>https://padlet.com/HafizahZainuddin/mqtswz4jyhhn</link>
      <description>Class :  AM228 4A,
Lect : Madam Sri Yusmawati</description>
      <language>en-us</language>
      <pubDate>2018-12-24 04:59:10 UTC</pubDate>
      <lastBuildDate>2018-12-24 05:45:14 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>Question 1</title>
         <author>HafizahZainuddin</author>
         <link>https://padlet.com/HafizahZainuddin/mqtswz4jyhhn/wish/316590468</link>
         <description><![CDATA[<div><strong>Briefly explain the following computer crimes. <br></strong><br></div><div>a) Sniffer <br>Allows individuals to capture data as it is transmitted over a network. This technique is used by network professionals to diagnose network issues, and by malicious users to capture unencrypted data, like passwords and usernames. If this information is captured in transit, a user can gain access to a system or network.<br><br></div><div>b) Phishing <br>Cyber-attack that uses disguised email as a weapon. The goal is to trick the email recipient into believing that the message is something they want or need a request from their bank, for instance, or a note from someone in their company and to click a link or download an attachment.<br><br></div><div>c) Pharming <br>Scamming practice in which malicious code is installed on a personal computer or server, misdirecting users to fraudulent Web sites without their knowledge or consent. Pharming has been called "phishing without a lure.<br><br></div><div>d) Spoofing <br>A type of scam where an intruder attempts to gain unauthorized access to a user's system or information by pretending to be the user. The main purpose is to trick the user into releasing sensitive information in order to gain access to one's bank account, computer system or to steal personal information, such as passwords.</div><div> </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-24 05:03:37 UTC</pubDate>
         <guid>https://padlet.com/HafizahZainuddin/mqtswz4jyhhn/wish/316590468</guid>
      </item>
      <item>
         <title>Question 2</title>
         <author>HafizahZainuddin</author>
         <link>https://padlet.com/HafizahZainuddin/mqtswz4jyhhn/wish/316590578</link>
         <description><![CDATA[<div><strong>a) Distinguish the TWO (2) methods for encrypting network traffic on the Web.</strong><br><br></div><div>Secure Sockets Layer (SSL) and successor Transport Layer Security (TLS) enables client &amp; server computers to manage encryption &amp; decryption activities; so they communicate with each other during a secure web session. </div><div><br>Secure Hypertext Transfer Protocol (SHTTP) is used for encrypting data flowing over the Internet but it is limited to individual messages, whereas SSL &amp; TLS are designed to establish a secure connection between 2 computers.<br><br><strong>b) Briefly explain the following terms<br></strong><br></div><div>i. Cyber warfare:<br> State-sponsored activity designed to cripple &amp; defeat another state or nation by penetrating its computers or networks for the purposes of causing damage &amp; disruption.<br><br></div><div>ii. Computer Forensic:<br> Scientific collection, examination, authentication, preservation, and analysis of data from computer storage media for use as evidence in court of law and it includes recovery of ambient and hidden data.</div><div> </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-24 05:08:27 UTC</pubDate>
         <guid>https://padlet.com/HafizahZainuddin/mqtswz4jyhhn/wish/316590578</guid>
      </item>
      <item>
         <title></title>
         <author>HafizahZainuddin</author>
         <link>https://padlet.com/HafizahZainuddin/mqtswz4jyhhn/wish/316590657</link>
         <description><![CDATA[<div><strong>QUESTION 3<br>a) Briefly explain these THREE (3) tools.<br><br></strong>i) Firewall<br>A combination of hardware and software that prevents unauthorized users from accessing private networks which technologies include Static packet filtering, stateful inspection, network address translation (NAT)<br><br>ii) Intrusion detection system<br>To<strong> </strong>monitors hot spots on corporate networks to detect and deter intruders and examines events as they are happening to discover attacks in progress.<br><br>iii)Antivirus software<br>It checks computers for presence of malware and can often eliminate it as well. It requires continual updating. <br><br><strong>b) Contrast between General Controls and Application Controls.</strong><br>i) General Controls<strong> <br></strong>These are policies and procedures that relate to many applications and support the effective functioning of application controls by helping to ensure the continues proper operation of information systems. It governs design, security and use of computer programs and security of data. It basically applies to all computerized applications. Example of the type are implementation controls and software controls.<br><br>ii) Application Controls<strong><br></strong>Application controls are the controls specific to a particular accounting application. It is a specific control unique to each computerized applications such as payroll or order processing. It includes automated and manual procedures and IPO controls. Example of the type are input and output controls.<br><br><strong>QUESTION 4 <br>Malicious Software programs are referred to as Malware. Describe FOUR (4) types of malicious software.<br></strong><br></div><div>i) SQL injection attacks<br>Hackers submit data to web forms that exploit site's unprotected software and sends rogue SQL query to database.<br><br></div><div>ii)Virus<br>A rogue software  programs that attaches itself to other software programs or data files in order to be executed<br><br></div><div>iii)Worm <br>An independent programs that copy themselves from one computer to other computers over a network<br><br></div><div>iv) Trojan horses <br>A software that appears benign but does something other than expected. it is also a program in which malicious or harmful code is contained inside apparently harmless programming or data in such a way that it can get control and do its chosen form of damage, such as ruining the certain area on your hard disk. <br><br> <br><strong>QUESTION 5 <br>a) Nowadays securing information systems has become an important issue in organization to protect itself against computer crime. Define computer crime and provide an appropriate example. <br></strong>Computer crime means any<strong> </strong>violations of criminal law that involves knowledge of computer technology for their perpetration, investigation, or prosecution. Some examples are breaching confidentiality of protected computerized data and accessing a computer system without authority. <br><br><strong>b) Briefly explain THREE (3) reasons why information systems are vulnerable to destruction, error and abuse?</strong><br><br>i) internet vulnerabilities <br>The network is open to anyone and the internet is designed to be an open system and make internal corporate systems more vulnerable to actions from outsiders.<br>ii) wireless security challenges<strong><br></strong>Many wifi networks can be easily penetrated easily by intruders using sniffer program to obtain an address to access the resources of a network without authorization.<br>ii) malware<strong><br></strong>Represented in the form of a computer virus, a worm and Trojan Horse. Computer viruses and worms can spread rampantly from system to system, clogging computer memory or destroying programs and data<br><br><strong>c) Discuss the THREE (3) most important tools and technology for safeguarding information resources <br></strong>i)Firewall<br>it is combination of hardware and software that prevents unauthorized users from accessing private networks<br><br>ii)Intrusion detection systems<br>it monitors hot spots on corporate networks to detect and deter intruders. it also examines events as they are happening to discover attacks in progress<br><br>iii)antivirus and anti-spyware software<br>it checks  computers  for presence of malware and can often eliminate it as well ad it also require continual updating<br><br><strong>QUESTION 6<br>a)Identity management software automates the process of keeping track of all information systems users and their system privileges, assigning each user a unique digital identity for accessing each system. Define authentication.</strong></div><div> </div><div>Authentication is the technique by which a system checks the identification of a end User who wants to access it. Since entrance or access control is normally based on the identification of the user who demands access to a resource. Authentication is essential to effective security. <br><br><strong>b)Four types of authentication technologies <br></strong>i) Password Based Technologies<strong> </strong>which is<strong> </strong>the most common form of authentication. Password may be of any form (String of alphabets, numbers and special characters). This password is necessarily to be known by the entity or the thing or a person that is being authenticated.</div><div>ii) E-Token Based Technologies which is a small device that develop/generates a new odd/random value every time it is used. This random value becomes the basis for authentication (an alternative to a password). It can be implemented on a USB key fob or on a smart card. Data is protected on the device itself.<br>iii) Biometric Based Technologies which is an authentication mention to the realization/recognition/identification of humans by their personality/characteristics such as Face, fingerprint, human voice, Retina, Iris pattern of the eye, vein pattern etc. It's used in computer science as a form of realization/recognition and access control. <br>iv) Two Factor Authentication also known as multi-step verification, which adds another layer of security, supplementing the username and password model with a code that only a specific user has access to (typically sent to something they have immediately to hand). </div><div><br><strong>QUESTION 7 <br>a)Describe ransomware. </strong></div><div><strong> </strong>Ransomware is proliferating on both desktop &amp; mobile devices that try to extort money from users by taking control of their computers or displaying annoying pop-up messages such as CryptoLocker that encrypts an infected computer files, forcing users to pay hundreds of dollars to regain access.<br><br><strong>b) State how do we prevent and protect our computer from ransomware. </strong><br>i) Make sure one must installed up to date anti-malware or anti virus tool<br>ii) Scan attachments<br>iii) Ask before you open the email<br><br><strong>c) Discuss the effects of computer crime to an organization.</strong><br>i)  Reputational damage</div><div>Trust is an essential element of customer relationship. Computer crime can damage business' reputation and erode the trust that customers have for the organization. This could potentially lead to loss of customer, loss of sales and reduction in profits<br><br></div><div><strong> </strong>ii) Legal consequences of computer crime</div><div>Data protection and privacy laws require organizations to manage the security of all personal data they hold whether on the staff or their customers. If this data is accidentally or deliberately compromised, and they have failed to deploy appropriate security measures, they may face fines and regulatory sanctions.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-24 05:13:39 UTC</pubDate>
         <guid>https://padlet.com/HafizahZainuddin/mqtswz4jyhhn/wish/316590657</guid>
      </item>
      <item>
         <title>PART B CHAPTER 7 QUESTION</title>
         <author>HafizahZainuddin</author>
         <link>https://padlet.com/HafizahZainuddin/mqtswz4jyhhn/wish/316590807</link>
         <description><![CDATA[<div><strong>1. Security isn’t simply a technology issue, it’s a business issue. Discuss.</strong></div><div>·       Security is no longer just a technology issue, it is also a business issue as well because majority of the companies out there today rely on computer systems to keep their employees information secure as well as their customers’ information, sales transactions, and the details on their vendors, their success is dependent on the secureness of this information. For a non-technologies business especially, they need to understand enough about security that they can take ownership of security approval processes. Ultimately it is because the business themselves that will bear the consequences of a poorly secured system. It is difficult to say that a case of internal fraud or financial misstatement is a purely IT issue. However, such incidents are preventable through a well-defined security structures allocated to the appropriate business users. Since the business bears the risk it is logical that they should be fully engaged in the design of the solutions to prevent the occurrence of such risks. Without adequate understanding and design of the computer security structures, users are not able to use the functions that they require in order to run the business processes. If incorrectly designed, the same security structures will allow users access data and functions that they should not be using including system administration functions, access to sensitive personal data or commercially sensitive data such as sales figures.</div><div> </div><div><strong>2. Who poses the biggest security threat: insiders or outsiders?</strong></div><div>·       While an organization usually faces more external threats, the reality is that organizations need to be just as concerned about the insider threat. An insider attack is one of the biggest threats faced by organizations since these types of hacks can be very difficult for IT teams to identify. This is because an insider – whether he’s an employee or a contractor – is already entrusted with authorized access to at least some systems and applications on a corporate network. It can be very hard for those in IT to decipher whether he’s just performing his regular job tasks, or carrying out something sinister. An angry employee who already has access to company files could be secretly leaking documents to competitors, or he could be sabotaging systems or corrupting data because he is miffed at his employer. The same could be said about former employees, who often retain access to the network even long after leaving the organization.</div><div> </div><div><strong>3. Suppose your business had an e-commerce Web site where it sold goods</strong> and accepted credit card payments. Discuss the major security threats to this Web site and their potential impact. What can be done to minimize these threats?</div><div>·       Malware which is the malicious software that attackers insert into the web files or pages once they have gained access to the site. Malware may be found on an individual’s computer if they have themselves fallen victim to a phishing attack or otherwise been compromised, or it may be inserted directly onto the website after a successful SQL injection or if administrative account access has been granted to a harmful entity. As with software, malware can perform an extremely wide range of activities, from turning the computer into a botnet that can be part of a DDoS attack, to stealing credit card and account information from the website users. One type of malware that targeted Magento site was able to take credit card information and store it in images so that the attacker could easily access it without flags being raised. In order to minimize these threats, ones need to update the computer operating systems and patch regularly in order to defend against malware and phishing. This will help prevent vulnerabilities from being exploited and help detect and block threats from entering the system.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-24 05:20:42 UTC</pubDate>
         <guid>https://padlet.com/HafizahZainuddin/mqtswz4jyhhn/wish/316590807</guid>
      </item>
      <item>
         <title>CASE STUDY The Loming Threat of Cyber</title>
         <author>HafizahZainuddin</author>
         <link>https://padlet.com/HafizahZainuddin/mqtswz4jyhhn/wish/316590870</link>
         <description><![CDATA[<div><strong>1. Is cyberwarfare a serious problem? Why or why not?</strong></div><div>·       Yes, cyber-warfare is a serious problem because it is more complex than conventional warfare. Although the many potential targets are military a country’s power grids, financial systems, and a communication network can also be crippled. Non-state actors such as terrorist ore criminal groups can mount attacks, and it is often difficult to tell who is responsible. Nations must constantly to be on the alert for new malware and other technologies that could be used against them, and some of these technologies develop by skilled hacker groups are openly for sale to interested government. it can make one of the government destroy in term of their financial or education. it is a serious matter to be look and must been solved because there are a lot of hackers that can obtain others government information.</div><div> </div><div><strong>2. What solutions are available for this problem? Do you think they will be effective? Why or why not?</strong></div><div>·       Because the whole issue of cyberspace and the problems and damage it can cause is quite new and is still on the rise, many things have not yet been internationally agreed on and many states take different measures. Cyber attacks can be prevented with two different types of measures: The first type intending to prevent states from carrying out cyber attacks and the second type being measures to increase security of the networks which have the highest risk of being attacked. Most states have laws regulating computer crimes done by individuals or non-state actors to hopefully prevent any cyber attacks but other states are not bound to any rules yet. They would only have to be aware of the reaction of the attacked country. Besides definitions of cyber warfare and information warfare and other important terms, an internationally agreed list of computer crimes or rules should therefore be established, maybe in combination with an organization monitoring the cyberspace, with large and serious consequences against states violating these rules. </div><div> </div><div>·       In contrast, the strength of a security system is not always the most important part as the potential strength of attacks is steadily growing, sometimes it’s more important to take different measures. Two very controversial ideas are the kill switch and the electrical wall. The kill switch could shut down the internet of certain areas, whether it is only concerning a company, a city or a whole country, in case of serious cyber attacks. The electrical wall intends to inspect every data package coming into the country’s network and compares it to known signatures and in case of a match do not let them through. Both these ideas can be very useful and even save lives, however, if used by the wrong person or government, they can violate basic human rights by censoring certain parts of the internet. Therefore such measures have to be evaluated very carefully and include certain restrictions. In general all states should consider their possibilities with care as the internet is a symbol for freedom and a state interfering with the internet could lead to protest of the civilians. Because the internet connects everyone worldwide, each state is equally affected. Cooperations between countries and international agreements could therefore prove very useful leaving only non-state actors as a possible cyber threat.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-24 05:23:04 UTC</pubDate>
         <guid>https://padlet.com/HafizahZainuddin/mqtswz4jyhhn/wish/316590870</guid>
      </item>
   </channel>
</rss>
