<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>My dazzling shelf by Arisha Haizad</title>
      <link>https://padlet.com/arishaonyang/vuv666scmzl9</link>
      <description>Made with mirth</description>
      <language>en-us</language>
      <pubDate>2018-12-28 15:14:18 UTC</pubDate>
      <lastBuildDate>2026-02-01 08:48:15 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url>https://padlet-assets.s3.amazonaws.com/icons/Hearts.png</url>
      </image>
      <item>
         <title></title>
         <author>arishaonyang</author>
         <link>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797482</link>
         <description><![CDATA[<div>Allies. Preventing terrorist or cyberwar attacks may require examining some email messages from other countries or giving intelligence agencies more access to networks or Internet service providers.<br> <br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-28 15:28:07 UTC</pubDate>
         <guid>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797482</guid>
      </item>
      <item>
         <title>QUESTION 1</title>
         <author>arishaonyang</author>
         <link>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797506</link>
         <description><![CDATA[<div><strong>Briefly explain the following computer crimes. </strong></div><div><strong><em><mark>a)</mark></em></strong><em><mark> </mark></em><strong><em><mark>Sniffer</mark></em></strong><strong><mark> </mark></strong><strong><br></strong><br></div><div><strong>Sniffer</strong> allows individuals to capture data as it is transmitted over a network. This technique is used by network professionals to diagnose network issues, and by malicious users to capture unencrypted data, like passwords and usernames. If this information is captured in transit, a user can gain access to a system or network.<br><br></div><div><strong><em><mark>b)</mark></em></strong><em><mark> </mark></em><strong><em><mark>Phishing </mark></em></strong><strong><br></strong><br></div><div><strong>Phishing</strong> is a cyber-attack that uses disguised email as a weapon. The goal is to trick the email recipient into believing that the message is something they want or need a request from their bank, for instance, or a note from someone in their company and to click a link or download an attachment.<br><br></div><div><strong><em><mark>c)</mark></em></strong><em><mark> </mark></em><strong><em><mark>Pharming</mark></em></strong><strong><mark> </mark></strong><strong><br></strong><br></div><div><strong>Pharming</strong> is a scamming practice in which malicious code is installed on a personal computer or server, misdirecting users to fraudulent Web sites without their knowledge or consent. Pharming has been called "phishing without a lure.<br><br></div><div><strong><em><mark>d) Spoofing</mark></em></strong><strong><mark> </mark></strong><strong><br></strong><br></div><div><strong>Spoofing</strong> is a type of scam where an intruder attempts to gain unauthorized access to a user's system or information by pretending to be the user. The main purpose is to trick the user into releasing sensitive information in order to gain access to one's bank account, computer system or to steal personal information, such as passwords.</div><div><br></div><div> </div><div> </div><div> </div><div> </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-28 15:28:36 UTC</pubDate>
         <guid>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797506</guid>
      </item>
      <item>
         <title>QUESTION 2</title>
         <author>arishaonyang</author>
         <link>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797527</link>
         <description><![CDATA[<div><strong><em><mark>a) Distinguish the TWO  methods for encrypting network traffic on the Web. </mark></em></strong><strong><br></strong><br></div><div>1)<strong>Secure Sockets Layer (SSL)</strong>: SSL and its successor <strong>Transport Layer Security (TLS)</strong> enable client and server computers to establish a secure connection session and manage encryption and decryption activities.<br><br></div><div><em><mark>2) </mark></em><strong><em><mark>Secure Hypertext Transfer Protocol (S-HTTP)</mark></em></strong> is another protocol used for encrypting data flowing over the Internet, but it is limited to individual messages.</div><div><br><br></div><div><strong><em><mark> b) Briefly explain the following terms</mark></em></strong><strong><br></strong><br></div><div><strong>i. Cyber warfare</strong><br><br></div><div>Cyber warfare refers to the use of digital attacks like computer viruses and hacking -- by one country to disrupt the vital computer systems of another, with the aim of creating damage, death and destruction. Future wars will see hackers using computer code to attack an enemy's infrastructure, fighting alongside troops using conventional weapons like guns and missiles.<br><br></div><div><strong>ii Computer Forensic </strong><br><br></div><div>Computer forensics is the practice of collecting, analyzing and reporting on digital data in a way that is legally admissible. It can be used in the detection and prevention of crime and in any dispute where evidence is stored digitally. Computer forensics follows a similar process to other forensic disciplines, and faces similar issues.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-28 15:29:13 UTC</pubDate>
         <guid>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797527</guid>
      </item>
      <item>
         <title>QUESTION 3</title>
         <author>arishaonyang</author>
         <link>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797691</link>
         <description><![CDATA[<div><strong><em><mark>a) Without protection against malware and intruders, connecting to the Internet could be very dangerous.  Firewalls, intrusion detection system and antivirus software have become the tools to overcome this problem.  Briefly explain these THREE (3) tools</mark></em></strong><em><mark>.</mark></em></div><div><br></div><div><strong>1)</strong> <strong>Firewall <br></strong><br></div><div>A firewall is a network security device that monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules. They establish a barrier between secured and controlled internal networks that can be trusted and untrusted outside networks, such as the Internet. A firewall can be hardware, software, or both.<br><br></div><div><strong>2)Intrusion detection system<br></strong><br></div><div>An intrusion detection system (IDS) is a system that monitors network traffic for suspicious activity and issues alerts when such activity is discovered. While <a href="https://searchsecurity.techtarget.com/definition/network-behavior-anomaly-detection">anomaly detection</a> and reporting is the primary function, some intrusion detection systems are capable of taking actions when malicious acitivity or anomalous traffic is detected, including blocking traffic sent from suspicious <a href="https://searchwindevelopment.techtarget.com/definition/IP-address">IP addresses</a>.<br><br></div><div><strong>3)Antivirus software<br></strong><br></div><div>Antivirus software is a type of <a href="https://techterms.com/definition/utility">utility</a> used for scanning and removing <a href="https://techterms.com/definition/virus">viruses</a> from your computer. While many types of antivirus (or "anti-virus") programs exist, their primary purpose is to protect computers from viruses and remove any viruses that are found. Most antivirus programs include both automatic and manual scanning capabilities.<br><br></div><div><em>b)     Information systems controls is one of the components of an organizational framework for security and control.  Information systems controls consist of two - general and application control.  A company must know how and where to deploy security tools and security personnel must know what controls a company must have in place to protect its information system</em><strong>. <br></strong><br></div><div><strong><em><mark>Contrast between General Controls and Application Controls</mark></em></strong><strong>. </strong></div><div><br></div><ul><li><strong>General control</strong></li></ul><div>General structure. They help ensure the reliability of data generated by IT systems and support the assertion that systems operate as intended and that output is reliable. Usually include the following types of controls: </div><div>·  Control environment, or those controls designed to shape the corporate culture or "<a href="https://en.wikipedia.org/wiki/Tone_at_the_top">tone at the top</a>."<br><br></div><div>·  <a href="https://en.wikipedia.org/wiki/Change_management">Change management</a> procedures - controls designed to ensure the changes meet business requirements and are authorized.<br><br></div><div>· <a href="https://en.wikipedia.org/wiki/Source_code">Source code</a>/<a href="https://en.wikipedia.org/wiki/Document">document</a> <a href="https://en.wikipedia.org/wiki/Version_control">version control</a> procedures - controls designed to protect the integrity of program code<br><br></div><div>·  <a href="https://en.wikipedia.org/wiki/Software_development_life_cycle">Software development life cycle</a> standards - controls designed to ensure IT projects are effectively managed.<br><br></div><ul><li><strong>Application control</strong></li></ul><div><br></div><div>Application controls are fully automated (i.e., performed automatically by the systems) designed to ensure the complete and accurate processing of data, from input through output. These controls vary based on the business purpose of the specific application. These controls may also help ensure the privacy and security of data transmitted between applications. Categories of IT application controls may include: <br><br></div><div>·Completeness checks - controls that ensure all records were processed from initiation to completion.<br><br></div><div>· Validity checks - controls that ensure only valid data is input or processed.<br><br></div><div>· Identification - controls that ensure all users are uniquely and irrefutably identified.<br><br></div><div>· Authentication - controls that provide an authentication mechanism in the application system.<br><br></div><div> </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-28 15:32:45 UTC</pubDate>
         <guid>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797691</guid>
      </item>
      <item>
         <title>QUESTION 4</title>
         <author>arishaonyang</author>
         <link>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797814</link>
         <description><![CDATA[<div> </div><div><strong>Malicious Software programs are referred to as Malware. Describe FOUR (4) types of malicious software. (8 marks) </strong></div><div><strong> </strong></div><div>1)      <mark> </mark><strong><mark>Spyware</mark></strong><br>Spyware is any technology that aids in gathering information about a person or organization without their knowledge. On the Internet (where it is sometimes called a Spybot or tracking software), Spyware is programming that is put in someone's computer to secretly gather information about the user and relay it to advertisers or other interested parties. Spyware can get in a computer as a software virus or as the result of installing a new program.</div><div>2)     <mark> </mark><strong><mark> Virus</mark></strong><br> A virus is a program or programming code that replicates by being copied or initiating its copying to another program, computer boot sector or document. Viruses can be transmitted as attachments to an e-mail note or in a downloaded file, or be present on a diskette or CD</div><div>3)      <strong><mark> Worm</mark></strong><br>A worm is a self-replicating virus that does not alter files but duplicates itself. It is common for worms to be noticed only when their uncontrolled replication consumes system resources, slowing or halting other tasks.</div><div>4)      <strong><mark> Logic bomb</mark></strong><br>A logic bomb is programming code, inserted surreptitiously or intentionally, that is designed to execute (or "explode") under circumstances such as the lapse of a certain amount of time or the failure of a program user to respond to a program command. It is in effect a delayed-action computer virus or Trojan horse. A logic bomb, when "exploded," may be designed to display or print a spurious message, delete or corrupt data, or have other undesirable effects.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-28 15:35:53 UTC</pubDate>
         <guid>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797814</guid>
      </item>
      <item>
         <title>QUESTION 5</title>
         <author>arishaonyang</author>
         <link>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797823</link>
         <description><![CDATA[<div><strong><mark>Security isn’t simply a technology issue, it’s a business issue. Discuss.</mark></strong><strong><br></strong><br></div><div>Most large organizations have their own local computer network, or intranet, that links their computers together to share resources and support the communications of employees and others with a legitimate need for access. Almost all of these networks are connected to the Internet and allow employees to go "online." Information technology security is controlling access to sensitive electronic information so only those with a legitimate need to access it are allowed to do so. This seemingly simple task has become a very complex process with systems that need to be continually updated and processes that need to constantly be reviewed. There are three main objectives for information technology security: confidentiality, integrity, and availability of data to the organization. For example last year, stuxnet 20 times more complicated virus code capabilities. For example it can turn off oil pipeline, It also have a real clearance that stolen from most capable technologies company in the word. It is also known as a zero days. Which data can be sold at net market for 100 000 dolar. So stuxnet took advantage of twenty zero days.</div><div> </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-28 15:36:01 UTC</pubDate>
         <guid>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797823</guid>
      </item>
      <item>
         <title>QUESTION 6</title>
         <author>arishaonyang</author>
         <link>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797825</link>
         <description><![CDATA[<div><strong> </strong><strong><em><mark>Who poses the biggest security threat: insiders or outsiders?</mark></em></strong><br><br></div><div> motive changes when the source of the attack is discovered, with outsiders far more likely to be incentivised by financial gains than insiders. While outsiders use DDoS attacks or malicious USB drops, insiders have knowledge of systems, can physically steal data and, more often than many would care to admit, cause problems due to basic human error. People should aware to whom they should give their information and don not share any unnecessary information unless you have to and unless you trust that person. This is because, Sony PlayStation hacked; Data stolen from 77 million users. <br><br></div><div> <br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-28 15:36:06 UTC</pubDate>
         <guid>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797825</guid>
      </item>
      <item>
         <title>QUESTION 7</title>
         <author>arishaonyang</author>
         <link>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797830</link>
         <description><![CDATA[<div><strong><em><mark>Suppose your business had an e-commerce Web site where it sold goods and accepted credit card payments. Discuss the major security threats to this Web site and their potential impact. What can be done to minimize these threats? </mark></em></strong></div><div> </div><div>According to zappos which is one of the biggest online retailer company urges the customer to change their password because the hacker might know all the information for example, name, address, 4 digit of the last credit card, phone number and other. So zappos have sent email to 24 million customer to change their password to avoid hacker know more about their information.</div><div> </div><div> <br><br></div><div><strong> </strong></div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-28 15:36:13 UTC</pubDate>
         <guid>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797830</guid>
      </item>
      <item>
         <title>CASE STUDY</title>
         <author>arishaonyang</author>
         <link>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797834</link>
         <description><![CDATA[<div><strong><em><mark>1. Is cyberwarfare a serious problem? Why or why not?</mark></em></strong></div><div> </div><div>Cyberwarfare is a serious problem  because Non-state actors such as terrorist ore criminal groups can mount attacks, and it is often difficult to tell who is responsible. Cyberwarfare poses a unique and daunting set of challenges for security experts, not only in detecting and preventing intrusions but also in tracking down perpetrators and bringing them to justice. Less than two weeks later, Qatari natural gas company, Rasgas, was forced to shut down its website and e-email systems in an attack initially also attributed to Shammon. An investigative team concluded it was likely a copycat attack trying to look like the same perpetrator. U.S. government officials blamed Iranian hacker. Israeli officials attributed both attacks to Iran’s Cyber Corps, formed after Stuxnet. Previously released malware is recoverable and can be adapted and reused by both nation-state foes and unaffiliated cyber criminals. Stuxnet code has been adapted for use in financial cybercrime. Another drawback is uncontrollability. About 60 percent of known Stuxnet infections were in Iran, but 18 percent were in Indonesia, 8 percent in India, and the remaining 15 percent scattered around the world. In November 2012, Chevron admitted that its network had been infected with Stuxnet shortly after spread beyond Iran. So cyberwarfare is a serious problem because it can lead to other country from attack each other due to this virus that being spread.</div><div> </div><div> </div><div> </div><div> </div><div><strong><em><mark>2. What solutions are available for this problem? Do you think they will be effective? Why or why not?</mark></em></strong></div><div><strong> </strong></div><div>Congress is considering legislation that would require all critical infrastructure companies to meet newer, tougher cybersecurity standards. As cyberwarfare technologies develop and become more advanced, the standards imposed by this legislation will likely be insufficient to defend against attacks.</div><div>·         Secretary of Defense Gates ordered the creation of Cybercom, the first headquarters designed to coordinate government cybersecurity efforts. It was activated in May 2010. It will coordinate the operation and protection of military and Pentagon computer networks. It will coordinate efforts to restrict access to government computers and protect systems that run the stock exchanges, clear global banking transactions, and manage the air traffic control system. Its ultimate goal will be to prevent catastrophic cyberattacks against the U.S. Some insiders suggest that it might not be able to effectively organize the governmental agencies without direct access to the President, which it currently lacks.</div><div><br> <br> </div><div>·         Because spy agencies like the CIA are prohibited by law from acting on American soil, some people are proposing to entrust some of the cyberwarfare work to private defense contractors. There is no effective way for a domestic agency to conduct computer operations without entering prohibited networks within the U.S. or even conduct investigations in countries that are American allies. Preventing terrorist or cyberwar attacks may require examining some email messages from other countries or giving intelligence agencies more access to networks or Internet service providers.</div><div><strong> </strong></div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-28 15:36:18 UTC</pubDate>
         <guid>https://padlet.com/arishaonyang/vuv666scmzl9/wish/316797834</guid>
      </item>
   </channel>
</rss>
