Course Content
Fundamentals
UNIT STANDARD RANGE Reports including Board Reports, Proposals, Budgets, Flash reports, Strategic Plans? Techniques for compiling reports including structure and style of business reports, format and layout, use of business terminology, UNIT STANDARD OUTCOME HEADER The demonstrated ability to make decisions and con Specific Outcomes and Assessment Criteria: SPECIFIC OUTCOME 1 The demonstrated ability to make decisions and consider options when: OUTCOME NOTES Relating the purpose and content of a range of reports to the information needs of business? Recognising appropriate information resources and organisational procedures for obtaining and distributing confidential information? Applying a range of techniques for compiling reports, ensuring content and format are appropriate to information requirements and that reporting deadlines are met? Liaising with relevant parties and verifying reported information is in accordance with requirements, compiling and distributing additional commentary/information where required
0/8
NATIONAL CERTIFICATE: INFORMATION TECHNOLOGY: SYSTEMS SUPPORT: SAQA 48573 -LEVEL 5- 147 CREDITS


SPECIFIC OUTCOME 1.

Understand the organisation`s Security Policy.

Learning Outcomes

· 1. Organisation`s Security Policy is located.

· 2. The organisation`s Security Policy is read and questions relating to issues that are unclear are addressed.

1.1 Understand the organisation`s Security Policy.

Organization of information security

Objective • The organization’s administrative structure and its relationships with external parties should promote effective management of all aspects of information

 

security.  This includes maintaining the security of the organization’s information, its information processing facilities, and any information or facilities that are accessed, processed, communicated to or managed by external parties.

Management commitment • Management at all levels should actively support security within the organization with clear direction, demonstrated commitment, and explicit acknowledgement of information security responsibilities.  This could include:

  • clear direction and visible support for information security initiatives, including providing appropriate resources for information security controls;
  • coordination of information security efforts across the organization, including designation of information security officer(s) and committee(s);
  • assuring formulation, review and approval of appropriate organization-wide information security policy;
  • periodic reviews of the effectiveness of information security policy, including external review as appropriate, and updating of the policy as needed; and
  • appropriate management controls over new information facilities, systems and capabilities, including the planning for such facilities.

Allocation of responsibilities • All information security responsibilities should be clearly defined.  This could include:

  • identification and clear definition of assets and associated security controls for each information facility; and
  • identification of the individual or individuals responsible for security for each information facility.

Coordination of efforts • Information security activities should be coordinated by representatives from different parts of the organization with relevant security roles and job functions.  This could include:

  • ensuring that all information security controls are executed in compliance with the organization’s information privacy and security policies;
  • coordinated efforts to assess the adequacy of implemented controls, and to recommend additional measures based on the assessments;
  • proposing refinements to assessment methodologies and processes (e.g., risk assessment) subject to management approval;
  • evaluating information security incident managementdata from across the organization, reporting these data to appropriate management, and recommending appropriate action based on the data;
  • identifying significant threat and vulnerability changes, both internal and external, and recommending appropriate action; and
  • promoting security awareness and training for all persons affiliated with the organization.

Authorization processes • A management authorization process for new information processing facilities and capabilities, or for significant changes to existing facilities and capabilities, should be defined and implemented.  This could include:

  • formal approval of purpose and use for each new system, or for existing systems that are materially changed;
  • certification that hardware/software used by the new (or changed existing) system meets organizational standards;
  • approval of any non-standard functions, locations, or users, including approval of any personal, privately-owned or extra-organizational hardware/software/facilities to be used; and
  • certification that the new (or changed existing) system complies with all applicable security controls mandated by the security policy.

Confidentiality and non-disclosure agreements • Requirements for confidentiality and non-disclosure agreements (C/NDA) should reflect the organization’s needs for protection of information.  Such agreements should be periodically reviewed.  This could include:

  • definition of the information, information type(s) or information system(s) to be protected;
  • C/NDA agreements for that information rendered in clear, legally-enforceable terms, that accord with all relevant statutory-regulatory and private certificatory authorities;
  • responsibilities of signatories, including limitations on use or disclosure of information and adherence to security controls;
  • terms of ownership of information, including any trade secret or intellectual property requirements;
  • expected duration of the agreement;
  • required actions when the agreement is terminated, including requirements to return or destroy information;
  • right to monitor compliance with the agreement;
  • processes for reporting of and notice of breaches; and
  • expected actions to be taken in the event of a breach.

Contacts with authorities • Appropriate contacts with external authorities should be maintained.  This could include:

  • development of policies, procedures and contact lists that specify when and by whom external authorities should be contacted;
  • specification of the timing and manner in which breaches shall be communicated to external authorities, to ensure appropriate reporting.

Contacts with special interest groups • Appropriate contacts with special interest groups or other specialist security forums and professional associations should be maintained.

Contacts and contracts with external parties • Agreements with third parties that involve accessing, processing, communicating or managing the organization’s information or information processing facilities should cover all relevant security requirements.  Content of such agreements could include:

  • the applicable information security policy or policies of all contracting organizations;
    necessary controls to ensure compliance with these policies;
  • requirements for user and system administrator awareness and training efforts;
  • responsibilities related to hardware/software selection and configuration;
  • a clear and specific process of change management;
  • a clear and specific process of incident management, including requirements for reporting, notification and investigation;
  • problem resolution processes, including escalation steps;
  • overall reporting structure, report contents and frequency, and reporting formats;
  • levels of acceptable/unacceptable service and service continuity;
  • definitions of verifiable performance criteria;
  • rights to monitor and audit activities;
  • intellectual property rights and ownership of data;
  • policies regarding subcontractors; and
  • conditions for renegotiation/termination of the agreements.

Contacts and contracts with customers • All identified security requirements should be addressed before giving customers access to the organization’s information or assets.  Control considerations are similar to those for other external parties.

Independent review of information security • The organization’s approach to managing information security and its implementation should be reviewed independently at planned intervals, and when there are significant changes to internal structure or the external environment

 

  • Some of the most common types of violations include:
  • Breach of Confidentiality – Theft of private or confidential information, such as credit-card numbers, trade secrets, patents, secret formulas, manufacturing procedures, medical information, financial information, etc.
  • Breach of Integrity – Unauthorized modificationof data, which may have serious indirect consequences. For example a popular game or other program’s source code could be modified to open up security holes on users systems before being released to the public.
  • Breach of Availability – Unauthorized destructionof data, often just for the “fun” of causing havoc and for bragging rites. Vandalism of web sites is a common form of this violation.
  • Theft of Service – Unauthorized use of resources, such as theft of CPU cycles, installation of daemons running an unauthorized file server, or tapping into the target’s telephone or networking services.
  • Denial of Service, DOS – Preventing legitimate users from using the system, often by overloading and overwhelming the system with an excess of requests for service.
    • One common attack is masquerading, in which the attacker pretends to be a trusted third party. A variation of this is the man-in-the-middle, in which the attacker masquerades as both ends of the conversation to two targets.
    • A replay attackinvolves repeating a valid transmission. Sometimes this can be the entire attack, ( such as repeating a request for a money transfer ), or other times the content of the original message is replaced with malicious content.

Standard security attacks. 

There are four levels at which a system must be protected:

  1. Physical – The easiest way to steal data is to pocket the backup tapes. Also, access to the root console will often give the user special privileges, such as rebooting the system as root from removable media. Even general access to terminals in a computer room offers some opportunities for an attacker, although today’s modern high-speed networking environment provides more and more opportunities for remote attacks.
  2. Human – There is some concern that the humans who are allowed access to a system be trustworthy, and that they cannot be coerced into breaching security. However more and more attacks today are made via social engineering, which basically means fooling trustworthy people into accidentally breaching security.
  • Phishinginvolves sending an innocent-looking e-mail or web site designed to fool people into revealing confidential information. E.g. spam e-mails pretending to be from e-Bay, PayPal, or any of a number of banks or credit-card companies.
  • Dumpster Divinginvolves searching the trash or other locations for passwords that are written down. ( Note: Passwords that are too hard to remember, or which must be changed frequently are more likely to be written down somewhere close to the user’s station. )
  • Password Crackinginvolves divining users passwords, either by watching them type in their passwords, knowing something about them like their pet’s names, or simply trying all words in common dictionaries. ( Note: “Good” passwords should involve a minimum number of characters, include non-alphabetical characters, and not appear in any dictionary ( in any language ), and should be changed frequently. Note also that it is proper etiquette to look away from the keyboard while someone else is entering their password. )
    1. Operating System – The OS must protect itself from security breaches, such as runaway processes ( denial of service ), memory-access violations, stack overflow violations, the launching of programs with excessive privileges, and many others.
    2. Network – As network communications become ever more important and pervasive in modern computing environments, it becomes ever more important to protect this area of the system. ( Both protecting the network itself from attack, and protecting the local system from attacks coming in through the network. ) This is a growing area of concern as wireless communications and portable devices become more and more prevalent.

 


SPECIFIC OUTCOME 2.

Manage security of desktop computers connected to the system.

Learning Outcomes

· 1. Desktop computers are scanned for viruses.

· 2. Viruses found are recorded and removed according to company`s standards, procedures and Security Policy.

· 3. Desktop computers are monitored for illegal software.

· 4. Incidences of illegal software are recorded.

· 5. Recording of viruses and illegal software are reported according to company`s standards and procedures.

2.1 Manage security of desktop computers connected to the system

If you connect to the Internet, allow other people to use your computer, or share files with others, you should take steps to protect your computer from harm. Why? Because there are computer criminals (sometimes called hackers) who attack other people’s computers. These people can attack directly, by breaking into your computer through the Internet and stealing your personal information, or indirectly, by creating malicious software to harm your computer.  Fortunately, you can help protect yourself by taking a few simple precautions. This article describes the threats and what you can do to defend against them.

Protect your computer

These are ways to help protect your computer against potential security threats:

  • A firewall can help protect your computer by preventing hackers or malicious software from gaining access to it.
  • Virus protection. Antivirus software can help protect your computer against viruses, worms, and other security threats.
  • Spyware and other malware protection. Antispyware software can help protect your computer from spyware and other potentially unwanted software.
  • Windows Update. Windows can routinely check for updates for your computer and install them automatically.

 

Use a firewall

A firewall is software or hardware that checks information coming from the Internet or a network and then either turns it away or allows it to pass through to your computer, depending on your firewall settings. In this way, a firewall can help prevent hackers and malicious software from gaining access to your computer.

Windows Firewall is built into Windows and is turned on automatically.

 

How a firewall works

If you run a program such as an instant messaging program or a multiplayer network game that needs to receive information from the Internet or a network, the firewall asks if you want to block or unblock (allow) the connection. If you choose to unblock the connection, Windows Firewall creates an exception so that the firewall won’t bother you when that program needs to receive information in the future.

Use virus protection

Viruses, worms, and Trojan horses are programs created by hackers that use the Internet to infect vulnerable computers. Viruses and worms can replicate themselves from computer to computer, while Trojan horses enter a computer by hiding inside an apparently legitimate program, such as a screen saver. Destructive viruses, worms, and Trojan horses can erase information from your hard disk or completely disable your computer. Others don’t cause direct damage, but worsen your computer’s performance and stability.

Antivirus programs scan email and other files on your computer for viruses, worms, and Trojan horses. If one is found, the antivirus program either quarantines (isolates) it or deletes it entirely before it damages your computer and files.

Because new viruses are identified every day, it’s important to use an antivirus program with an automatic update capability. When the program is updated, it adds new viruses to its list of viruses to check for, helping to protect your computer from new attacks. If the list of viruses is out of date, your computer is vulnerable to new threats. Updates usually require an annual subscription fee. Keep the subscription current to receive regular updates.

Warning

  • If you don’t use antivirus software, you expose your computer to damage from malicious software. You also run the risk of spreading viruses to other computers.

Use spyware protection

Spyware is software that can display advertisements, collect information about you, or change settings on your computer, generally without appropriately obtaining your consent. For example, spyware can install unwanted toolbars, links, or favorites in your web browser, change your default home page, or display pop-up ads frequently. Some spyware displays no symptoms that you can detect, but it secretly collects sensitive information, such as the websites you visit or the text you type. Most spyware is installed through free software that you download, but in some cases simply visiting a website results in a spyware infection.

To help protect your computer from spyware, use an antispyware program. This version of Windows has a built-in antispyware program called Windows Defender, which is turned on by default. Windows Defender alerts you when spyware tries to install itself on your computer. It also can scan your computer for existing spyware and then remove it.

Because new spyware appears every day, Windows Defender must be regularly updated to detect and guard against the latest spyware threats. Windows Defender is updated as needed whenever you update Windows. For the highest level of protection, set Windows to install updates automatically (see below).

Update Windows automatically

Microsoft regularly offers important updates to Windows that can help protect your computer against new viruses and other security threats. To ensure that you receive these updates as quickly as possible, turn on automatic updating. That way, you don’t have to worry that critical fixes for Windows might be missing from your computer.

Updates are downloaded behind the scenes when you’re connected to the Internet. The updates are installed at 3:00 A.M. unless you specify a different time. If you turn off your computer before then, you can install updates before shutting down. Otherwise, Windows will install them the next time you start your computer.

To turn on automatic updating

  1. Open Windows Update by clicking the Start button . In the search box, type Update, and then, in the list of results, click Windows Update.
  2. Click Change settings.
  3. Make sure Install updates automatically (recommended) is selected.

Windows will install important updates for your computer as they become available. Important updates provide significant benefits, such as improved security and reliability.

  1. Under Recommended updates, make sure the Give me recommended updates the same way I receive important updates check box is selected, and then click OK.

Recommended updates can address non-critical problems and help enhance your computing experience.  If you’re prompted for an administrator password or confirmation, type the password or provide confirmation.

Install the latest version of your web browser and keep it up to date

Using the latest version of your web browser and keeping your browser up to date are two of the best ways to prevent trouble online. In most cases, the latest version of a web browser contains security fixes and new features that can help protect your computer and your privacy while you’re online.

Also, many web browsers offer security updates periodically. So be sure to install updates for your browser whenever they’re available.

If you have Internet Explorer, you can get updates for it automatically using Windows Update. If your computer isn’t set up to automatically receive updates, you can manually request these updates by using Internet Explorer. Click the Safety button, and then click Windows Update . Follow the instructions on the screen to check for updates.

Turn on your browser’s security features

Many web browsers have security features that help you browse the web safely. So it’s a good idea to find out what security features your browser has and make sure they’re enabled.

 

Use a standard user account

When you log on to your computer, Windows grants you a certain level of rights and privileges depending on what kind of user account you have. There are three different types of user accounts: standard, administrator, and guest.

Although an administrator account provides complete control over a computer, using a standard account can help make your computer more secure. That way, if other people (or hackers) gain access to your computer while you’re logged on, they can’t tamper with the computer’s security settings or change other user accounts. You can check your account type after you log on by doing the following:

 

Tips for safely using email and the web

  • Use caution when opening email attachments. Email attachments (files attached to email messages) are a primary source of virus infection. Never open an attachment from someone you don’t know. If you know the sender but weren’t expecting an attachment, verify that the sender actually sent the attachment before you open it.
  • Guard your personal information carefully. If a website asks for a credit card number, bank information, or other personal information, make sure you trust the website and verify that its transaction system is secure.
  • Be careful when clicking hyperlinks in email messages. Hyperlinks (links that open websites when you click them) are often used as part of phishing and spyware scams, but they can also transmit viruses. Only click links in email messages that you trust.
  • Only install add-ons from websites that you trust. Web browser add-ons allow webpages to display things like toolbars, stock tickers, video, and animation. However, add-ons can also install spyware or other malicious software. If a website asks you to install an add-on, make sure that you trust it before doing so.

 

 

 

Viruses

  • A virus is a fragment of code embedded in an otherwise legitimate program, designed to replicate itself ( by infecting other programs ), and ( eventually ) wreaking havoc.
  • Viruses are more likely to infect PCs than UNIX or other multi-user systems, because programs in the latter systems have limited authority to modify other programs or to access critical system structures ( such as the boot block. )
  • Viruses are delivered to systems in a virus dropper, usually some form of a Trojan Horse, and usually via e-mail or unsafe downloads.
  • Viruses take many forms ( see below. ) Figure 15.5 shows typical operation of a boot sector virus:
  • Some of the forms of viruses include:
  • File – A file virus attaches itself to an executable file, causing it to run the virus code first and then jump to the start of the original program. These viruses are termed parasitic, because they do not leave any new files on the system, and the original program is still fully functional.
  • Boot – A boot virus occupies the boot sector, and runs before the OS is loaded. These are also known as memory viruses, because in operation they reside in memory, and do not appear in the file system.
  • Macro – These viruses exist as a macro ( script ) that are run automatically by certain macro-capable programs such as MS Word or Excel. These viruses can exist in word processing documents or spreadsheet files.
  • Source codeviruses look for source code and infect it in order to spread.
  • Polymorphic viruses change every time they spread – Not their underlying functionality, but just their signature, by which virus checkers recognize them.
  • Encrypted viruses travel in encrypted form to escape detection. In practice they are self-decrypting, which then allows them to infect other files.
  • Stealth viruses try to avoid detection by modifying parts of the system that could be used to detect it. For example the read( ) system call could be modified so that if an infected file is read the infected part gets skipped and the reader would see the original unadulterated file.
  • Tunnelingviruses attempt to avoid detection by inserting themselves into the interrupt handler chain, or into device drivers.
  • Multipartiteviruses attack multiple parts of the system, such as files, boot sector, and memory.
  • Armored viruses are coded to make them hard for anti-virus researchers to decode and understand. In addition many files associated with viruses are hidden, protected, or given innocuous looking names such as “…”.
    • In 2004 a virus exploited three bugs in Microsoft products to infect hundreds of Windows servers ( including many trusted sites ) running Microsoft Internet Information Server, which in turn infected any Microsoft Internet Explorer web browser that visited any of the infected server sites. One of the back-door programs it installed was a keystroke logger, which records users keystrokes, including passwords and other sensitive information.
    • There is some debate in the computing community as to whether a monoculture, in which nearly all systems run the same hardware, operating system, and applications, increases the threat of viruses and the potential for harm caused by them.


SPECIFIC OUTCOME 3.

Maintain security systems for a multi-user computer system.

Learning Outcomes

· 1. Back-ups are determined and stored according to organisational guidelines.

· 2. Back-ups are restored according to organisation`s standards, procedures and Security Policy.

· 3. Configuration changes are made to the security systems according to organisation requirements.

· 4. Changes to the security systems are authorised and implemented according to organisation standards, procedures and Security Policy.

· 5. Changes to the security systems maintain the integrity and security of the system.

 

3.1 Maintain security systems for a multi-user computer system

 

Types of Backing up Options

Types of back-up

Various back-up techniques are available.  For example:

· Grandfather, Father and Son’: This method is used for all types of copying.  The principle is that each version of the back-up data contains a small number of changes from the previous version.  So for example if you are working on a file the first version if the ‘Grandfather’.  When you make some changes to it the second is saved as the ‘Father’.  The next day when you open the file and make some more changes you might save it as ‘Son’.

· Full Media Copy: This method is where the entire contents of a disk, tape or drive are copied to another disk, tape or drive.  When backing up in this way everything is copied – the operating system, utilities, applications and files / data.

· File copy: This method is when files are individually saved.  The advantage is that because of the moderate amount of data being saved the costs of back-up media is reduced and less time is required to save or restore the data.

· Record-by-Record: This method is used in on-line updating of data.  The way it works is that after a change to a record the previous version is saved and the new record replaces it on the main data file.  This allows previous versions to be restored if required.  Only a small amount of data is stored and restored so costs are low.

 

 

Find out and record what type of back up system is used by the establishment.

 

5.2 Backing up Material

Material

You can back-up onto the following:

· Magnetic tape: This is considered reliable if properly cared for and can hold a large amount of data.

· Exchangeable magnetic disks: These disks range in size and have very high data transfer rates.  They are vulnerable to accidental damage and dust and therefore need to be handled with care.

· Removable cartridge disks: These are sealed disks that require an additional drive in order to run.

· Floppy disks: These are used for immediate copying and longer-term back up of data.  However there capacity is low and speed of access is slow.  Floppy disks can also become corrupt and data can be lost in this way.

· Videotape: This has not been exploited as yet.  They are able to hold large amounts of data and are relatively cheap.

· Optical disks: These are capable of holding large amounts of data.  They are often referred to as CD-ROM or CD’s and can be written to by users.  Two types of CD’s are available: the one you can copy files to only once and the other is a re-writable CD, which means you can erase old data and copy new data onto the CD.

Importance / Implications

It is important to back-up for the following reason:

· Mechanical or electronic failure could mean that you loose important data.  Re-inputting the data is costly to the establishment, both in time taken to do it and in delays in providing services and / or products.  Furthermore the loss of information could also inconvenience guests – delays in billing, incorrect billing, etc, which could result in loss of revenue.

 

Find out and record what type of back up material is used by your establishment.

 

Backing up Procedures

 

Discuss with a colleague/shift leader the back-up procedure relevant to the establishment.

 

Procedure

It is critical that you back up the computer from time to time. The back-up routine will depend on the system on which you are working.

If you are working on the Front Office computer system, there is a daily and a weekly back-up procedure that is described in the Front of House standards.

With a stand-alone desktop computer, your back-up procedures might involve the use of floppy disks, tape streamers, cd-roms or internet backup.

 

1) Explain some problems that occur from not backing up information.

2) What procedures are used by your establish to back up information.

 

Self Assessment 03

 

Instructions

· In the following assessment you will be required to answer all questions.

· You are required to obtain 100% to pass.

· Obtain feedback from your Assessor on the accuracy of your answers.

· If you do not obtain the pass mark, revise all the learning material and redo the question.

 

 

Cryptography as a Security Tool

  • Within a given computer the transmittal of messages is safe, reliable and secure, because the OS knows exactly where each one is coming from and where it is going.
  • On a network, however, things aren’t so straightforward – A rogue computer ( or e-mail sender ) may spoof their identity, and outgoing packets are delivered to a lot of other computers besides their ( intended ) final destination, which brings up two big questions of security:
  • Trust – How can the system be sure that the messages received are really from the source that they say they are, and can that source be trusted?
  • Confidentiality – How can one ensure that the messages one is sending are received only by the intended recipient?
    • Cryptography can help with both of these problems, through a system of secretsand  In the former case, the key is held by the sender, so that the recipient knows that only the authentic author could have sent the message; In the latter, the key is held by the recipient, so that only the intended recipient can receive the message accurately.
    • Keys are designed so that they cannot be divined from any public information, and must be guarded carefully. ( Asymmetric encryption involve both a public and a private key. )

 

Encryption

  • The basic idea of encryption is to encode a message so that only the desired recipient can decode and read it. Encryption has been around since before the days of Caesar, and is an entire field of study in itself. Only some of the more significant computer encryption schemes will be covered here.
  • The basic process of encryption is shown in Figure 15.7, and will form the basis of most of our discussion on encryption. The steps in the procedure and some of the key terminology are as follows:
  1. The senderfirst creates a message, m in plaintext.
  2. The message is then entered into an encryption algorithm, E,along with the encryption key, Ke.
  3. The encryption algorithm generates the ciphertext, c, = E(Ke)(m).For any key k, E(k) is an algorithm for generating ciphertext from a message, and both E and E(k) should be efficiently computable functions.
  4. The ciphertext can then be sent over an unsecure network, where it may be received by
  5. The recipiententers the ciphertext into a decryption algorithm, D, along with the decryption key, Kd.
  6. The decryption algorithm re-generates the plaintext message, m, = D(Kd)(c). For any key k, D(k) is an algorithm for generating a clear text message from a ciphertext, and both D and D(k) should be efficiently computable functions.
  7. The algorithms described here must have this important property: Given a ciphertext c, a computer can only compute a message m such that c = E(k)(m) if it possesses D(k). ( In other words, the messages can’t be decoded unless you have the decryption algorithm and the decryption key. )

Figure 15.7 – A secure communication over an insecure medium. 

Symmetric Encryption

 

 

 

 

  • Withsymmetric encryption the same key is used for both encryption and decryption, and must be safely guarded. There are a number of well-known symmetric encryption algorithms that have been used for computer security:
  • The Data-Encryption Standard, DES, developed by the National Institute of Standards, NIST, has been a standard civilian encryption standard for over 20 years. Messages are broken down into 64-bit chunks, each of which are encrypted using a 56-bit key through a series of substitutions and transformations. Some of the transformations are hidden ( black boxes ), and are classified by the U.S. government.
  • DES is known as a block cipher, because it works on blocks of data at a time. Unfortunately this is a vulnerability if the same key is used for an extended amount of data. Therefore an enhancement is to not only encrypt each block, but also to XOR it with the previous block, in a technique known as cipher-block chaining.
  • As modern computers become faster and faster, the security of DES has decreased, to where it is now considered insecure because its keys can be exhaustively searched within a reasonable amount of computer time. An enhancement called triple DESencrypts the data three times using three separate keys ( actually two encryptions and one decryption ) for an effective key length of 168 bits. Triple DES is in widespread use today.
  • The Advanced Encryption Standard, AES, developed by NIST in 2001 to replace DES uses key lengths of 128, 192, or 256 bits, and encrypts in blocks of 128 bits using 10 to 14 rounds of transformations on a matrix formed from the block.
  • The twofish algorithm, uses variable key lengths up to 256 bits and works on 128 bit blocks.
  • RC5 can vary in key length, block size, and the number of transformations, and runs on a wide variety of CPUs using only basic computations.
  • RC4 is a stream cipher, meaning it acts on a stream of data rather than blocks. The key is used to seed a pseudo-random number generator, which generates a keystreamof keys. RC4 is used in WEP, but has been found to be breakable in a reasonable amount of computer time.

Asymmetric Encryption

  • With asymmetric encryption, the decryption key, Kd, is not the same as the encryption key, Ke, and more importantly cannot be derived from it, which means the encryption key can be made publicly available, and only the decryption key needs to be kept secret. ( or vice-versa, depending on the application. )
  • One of the most widely used asymmetric encryption algorithms isRSA, named after its developers – Rivest, Shamir, and Adleman.
  • RSA is based on two large prime numbers, p and q, ( on the order of 512 bits each ), and their product
  • Ke and Kd must satisfy the relationship:
    ( Ke * Kd ) % [ ( p – 1 ) * ( q – 1 ) ] = = 1
  • The encryption algorithm is:
    c = E(Ke)(m) = m^Ke % N
  • The decryption algorithm is:
    m = D(Kd)(c) = c^Kd % N
    • An example using small numbers:
  • p = 7
  • q = 13
  • N = 7 * 13 = 91
  • ( p – 1 ) * ( q – 1 ) = 6 * 12 = 72
  • Select Ke < 72 and relatively prime to 72, say 5
  • Now select Kd, such that ( Ke * Kd ) % 72 = = 1, say 29
  • The public key is now ( 5, 91 ) and the private key is ( 29, 91 )
  • Let the message, m = 42
  • Encrypt: c = 42^5 % 91 = 35
  • Decrypt: m = 35^29 % 91 = 42

Figure 15.8 – Encryption and decryption using RSA asymmetric cryptography 

  • Note that asymmetric encryption is much more computationally expensive than symmetric encryption, and as such it is not normally used for large transmissions. Asymmetric encryption is suitable for small messages, authentication, and key distribution, as covered in the following sections.

Authentication

  • Authentication involves verifying the identity of the entity who transmitted a message.
  • For example, if D(Kd)(c) produces a valid message, then we know the sender was in possession of E(Ke).
  • This form of authentication can also be used to verify that a message has not been modified
  • Authentication revolves around two functions, used for signatures ( orsigning ), and verification: 
  • A signing function, S(Ks)that produces an authenticator, A, from any given message m.
  • A Verification function, V(Kv,m,A)that produces a value of “true” if A was created from m, and “false” otherwise.
  • Obviously S and V must both be computationally efficient.
  • More importantly, it must not be possible to generate a valid authenticator, A, without having possession of S(Ks).
  • Furthermore, it must not be possible to divine S(Ks) from the combination of ( m and A ), since both are sent visibly across networks.
    • Understanding authenticators begins with an understanding of hash functions, which is the first step:
  • Hash functions, H(m)generate a small fixed-size block of data known as a message digest, or hash value from any given input data.
  • For authentication purposes, the hash function must be collision resistant on m. That is it should not be reasonably possible to find an alternate message m’ such that H(m’) = H(m).
  • Popular hash functions are MD5, which generates a 128-bit message digest, and SHA-1, which generates a 160-bit digest.
    • Message digests are useful for detecting ( accidentally ) changed messages, but are not useful as authenticators, because if the hash function is known, then someone could easily change the message and then generate a new hash value for the modified message. Therefore authenticators take things one step further by encrypting the message digest.
    • A message-authentication code, MAC, uses symmetric encryption and decryption of the message digest, which means that anyone capable of verifying an incoming message could also generate a new message.
    • An asymmetric approach is the digital-signature algorithm, which produces authenticators called digital signatures.In this case Ks and Kv are separate, Kv is the public key, and it is not practical to determine S(Ks) from public information. In practice the sender of a message signs it ( produces a digital signature using S(Ks) ), and the receiver uses V(Kv) to verify that it did indeed come from a trusted source, and that it has not been modified.
    • There are three good reasons for having separate algorithms for encryption of messages and authentication of messages:
  1. Authentication algorithms typically require fewer calculations, making verification a faster operation than encryption.
  2. Authenticators are almost always smaller than the messages, improving space efficiency. (?)
  3. Sometimes we want authentication only, and not confidentiality, such as when a vendor issues a new software patch.
    • Another use of authentication is non-repudiation, in which a person filling out an electronic form cannot deny that they were the ones who did so.

Key Distribution

  • Key distribution with symmetric cryptography is a major problem, because all keys must be kept secret, and they obviously can’t be transmitted over unsecure channels. One option is to send them out-of-band, say via paper or a confidential conversation.
  • Another problem with symmetric keys, is that a separate key must be maintained and used for each correspondent with whom one wishes to exchange confidential information.
  • Asymmetric encryption solves some of these problems, because the public key can be freely transmitted through any channel, and the private key doesn’t need to be transmitted anywhere. Recipients only need to maintain one private key for all incoming messages, though senders must maintain a separate public key for each recipient to which they might wish to send a message. Fortunately the public keys are not confidential, so this key-ringcan be easily stored and managed.
  • Unfortunately there are still some security concerns regarding the public keys used in asymmetric encryption. Consider for example the following man-in-the-middle attack involving phony public keys:

 

 

A man-in-the-middle attack on asymmetric cryptography. 

  • One solution to the above problem involves digital certificates, which are public keys that have been digitally signed by a trusted third party. But wait a minute – How do we trust that third party, and how do we know theyare really who they say they are? Certain certificate authorities have their public keys included within web browsers and other certificate consumers before they are distributed. These certificate authorities can then vouch for other trusted entities and so on in a web of trust, as explained more fully in section 15.4.3

 


SPECIFIC OUTCOME 4.

Manage security systems for a multi-user computer system.

Learning Outcomes

· 1. Internal and external resources are used to identify and update security gaps.

· 2. Security exposures and violations are identified, and action is taken according to organisation requirements and Security Policy.

· 3. Access is provided according to organisation requirements and Security Policy.

· 4. Monitoring and tuning of the security system ensures the operation and performance meets the manufacturer`s and organisation specifications.

· 5. Monitoring and tuning of the security system ensures the operation and performance are in line with Security Policy.

4.1 Manage security systems for a multi-user computer system.

 

Implementing Security Defenses

Security Policy

  • A security policy should be well thought-out, agreed upon, and contained in a living document that everyone adheres to and is updated as needed.
  • Examples of contents include how often port scans are run, password
  • Intrusion Detection
  • Intrusion detection attempts to detect attacks, both successful and unsuccessful attempts. Different techniques vary along several axes:
  • The time that detection occurs, either during the attack or after the fact.
  • The types of information examined to detect the attack(s). Some attacks can only be detected by analyzing multiple sources of information.
  • The response to the attack, which may range from alerting an administrator to automatically stopping the attack ( e.g. killing an offending process ), to tracing back the attack in order to identify the attacker.
    • Another approach is to divert the attacker to a honeypot, on a The idea behind a honeypot is a computer running normal services, but which no one uses to do any real work. Such a system should not see any network traffic under normal conditions, so any traffic going to or from such a system is by definition suspicious. Honeypots are normally kept on a honeynet protected by a reverse firewall, which will let potential attackers in to the honeypot, but will not allow any outgoing traffic. ( So that if the honeypot is compromised, the attacker cannot use it as a base of operations for attacking other systems. ) Honeypots are closely watched, and any suspicious activity carefully logged and investigated.
  • Intrusion Detection Systems, IDSs, raise the alarm when they detect an intrusion. Intrusion Detection and Prevention Systems, IDPs, act as filtering routers, shutting down suspicious traffic when it is detected.
  • There are two major approaches to detecting problems:
  • Signature-Based Detection scans network packets, system files, etc. looking for recognizable characteristics of known attacks, such as text strings for messages or the binary code for “exec /bin/sh”. The problem with this is that it can only detect previously encountered problems for which the signature is known, requiring the frequent update of signature lists.
  • Anomaly Detectionlooks for “unusual” patterns of traffic or operation, such as unusually heavy load or an unusual number of logins late at night.
    • The benefit of this approach is that it can detect previously unknown attacks, so called zero-day attacks.
    • One problem with this method is characterizing what is “normal” for a given system. One approach is to benchmark the system, but if the attacker is already present when the benchmarks are made, then the “unusual” activity is recorded as “the norm.”
    • Another problem is that not all changes in system performance are the result of security attacks. If the system is bogged down and really slow late on a Thursday night, does that mean that a hacker has gotten in and is using the system to send out SPAM, or does it simply mean that a CS 385 assignment is due on Friday? 🙂
    • To be effective, anomaly detectors must have a very low false alarm ( false positive )rate, lest the warnings get ignored, as well as a low false negative rate in which attacks are missed.

 

Virus Protection

  • Modern anti-virus programs are basically signature-based detection systems, which also have the ability ( in some cases ) of disinfectingthe affected files and returning them back to their original condition.
  • Both viruses and anti-virus programs are rapidly evolving. For example viruses now commonly mutate every time they propagate, and so anti-virus programs look for families of related signatures rather than specific ones.
  • Some antivirus programs look for anomalies, such as an executable program being opened for writing ( other than by a compiler. )
  • Avoiding bootleg, free, and shared software can help reduce the chance of catching a virus, but even shrink-wrapped official software has on occasion been infected by disgruntled factory workers.
  • Some virus detectors will run suspicious programs in a sandbox, an isolated and secure area of the system which mimics the real system.
  • Rich Text Format, RTF, files cannot carry macros, and hence cannot carry Word macro viruses.
  • Known safe programs ( e.g. right after a fresh install or after a thorough examination ) can be digitally signed, and periodically the files can be re-verified against the stored digital signatures. ( Which should be kept secure, such as on off-line write-only medium. )

 

 

 

Tripwire Filesystem ( New Sidebar )

  • The tripwire filesystem monitors files and directories for changes, on the assumption that most intrusions eventually result in some sort of undesired or unexpected file changes.
  • The tw.config file indicates what directories are to be monitored, as well as what properties of each file are to be recorded. ( E.g. one may choose to monitor permission and content changes, but not worry about read access times. )
  • When first run, the selected properties for all monitored files are recorded in a database. Hash codes are used to monitor file contents for changes.
  • Subsequent runs report any changes to the recorded data, including hash code changes, and any newly created or missing files in the monitored directories.
  • For full security it is necessary to also protect the tripwire system itself, most importantly the database of recorded file properties. This could be saved on some external or write-only location, but that makes it harder to change the database when legitimate changes are made.
  • It is difficult to monitor files that are supposed to change, such as log files. The best tripwire can do in this case is to watch for anomalies, such as a log file that shrinks in size.


SPECIFIC OUTCOME 5.

Review security systems for a multi-user computer system.

Learning Outcomes

· 1. Security needs of the organisation are reviewed.

· 2. Software is used to evaluate and report on the security in place in the systems.

· 3. In-built security and access features of the systems operating system are reviewed.

· 4. The file security categorisation scheme is reviewed.

· 5. Control methods used on the system are reviewed.

· 6. Module and system-wide controls are reviewed.

· 7. The review procedure meets organisation standards and procedures.

· 8. The review recommends improvements that need to be made to the security system.

5.1 Review security systems for a multi-user computer system.

 

Vulnerability Assessment

  • Periodically examine the system to detect vulnerabilities.
  • Port scanning.
  • Check for bad passwords.
  • Look for suid programs.
  • Unauthorized programs in system directories.
  • Incorrect permission bits set.
  • Program checksums / digital signatures which have changed.
  • Unexpected or hidden network daemons.
  • New entries in startup scripts, shutdown scripts, cron tables, or other system scripts or configuration files.
  • New unauthorized accounts.
    • The government considers a system to be only as secure as its most far-reaching component. Any system connected to the Internet is inherently less secure than one that is in a sealed room with no external communications.
    • Some administrators advocate “security through obscurity”, aiming to keep as much information about their systems hidden as possible, and not announcing any security concerns they come across. Others announce security concerns from the rooftops, under the theory that the hackers are going to find out anyway, and the only one kept in the dark by obscurity are honest administrators who need to get the word.


SPECIFIC OUTCOME 6.

Provide technical support for the use of security systems for a multi-user computer system.

Learning Outcomes

· 1. User problems relating to the security system are identified and resolved following organisation procedures.

· 2. Advice on the use of a security system is provided according to organisation requirements.


SPECIFIC OUTCOME 6.

Provide technical support for the use of security systems for a multi-user computer system.

Learning Outcomes

· 1. User problems relating to the security system are identified and resolved following organisation procedures.

· 2. Advice on the use of a security system is provided according to organisation requirements.

6.1 Provide technical support for the use of security systems for a multi-user computer system.

 

Auditing, Accounting, and Logging

  • Auditing, accounting, and logging records can also be used to detect anomalous behavior.
  • Some of the kinds of things that can be logged include authentication failures and successes, logins, running of suid or sgid programs, network accesses, system calls, etc. In extreme cases almost every keystroke and electron that moves can be logged for future analysis. ( Note that on the flip side, all this detailed logging can also be used to analyze system performance. The down side is that the logging also affectssystem performance ( negatively! ), and so a Heisenberg effect applies. )
  • “The Cuckoo’s Egg” tells the story of how Cliff Stoll detected one of the early UNIX break ins when he noticed anomalies in the accounting records on a computer system being used by physics researchers.

 

Firewalling to Protect Systems and Networks

  • Firewalls are devices ( or sometimes software ) that sit on the border between two security domains and monitor/log activity between them, sometimes restricting the traffic that can pass between them based on certain criteria.
  • For example a firewall router may allow HTTP: requests to pass through to a web server inside a company domain while not allowing telnet, ssh, or other traffic to pass through.
  • A common architecture is to establish a de-militarized zone, DMZ, which sort of sits “between” the company domain and the outside world, as shown below. Company computers can reach either the DMZ or the outside world, but outside computers can only reach the DMZ. Perhaps most importantly, the DMZ cannot reach any of the other company computers, so even if the DMZ is breached, the attacker cannot get to the rest of the company network. ( In some cases the DMZ may have limited access to company computers, such as a web server on the DMZ that needs to query a database on one of the other company computers. )

Figure 15.10 – Domain separation via firewall. 

  • Firewalls themselves need to be resistant to attacks, and unfortunately have several vulnerabilities:
  • Tunneling, which involves encapsulating forbidden traffic inside of packets that are allowed.
  • Denial of service attacks addressed at the firewall itself.
  • Spoofing, in which an unauthorized host sends packets to the firewall with the return address of an authorized host.
    • In addition to the common firewalls protecting a company internal network from the outside world, there are also some specialized forms of firewalls that have been recently developed:
  • A personal firewallis a software layer that protects an individual computer. It may be a part of the operating system or a separate software package.
  • An application proxy firewallunderstands the protocols of a particular service and acts as a stand-in ( and relay ) for the particular service. For example, and SMTP proxy firewall would accept SMTP requests from the outside world, examine them for security concerns, and forward only the “safe” ones on to the real SMTP server behind the firewall.
  • XML firewallsexamine XML packets only, and reject ill-formed packets. Similar firewalls exist for other specific protocols.
  • System call firewallsguard the boundary between user mode and system mode, and reject any system calls that violate security policies.

 

 

Exercise Files
SAQA_-114069___-_Learner_Guide.docx
Size: 971.69 KB
SAQA-114069_-___Learner_Workbook.docx
Size: 53.56 KB
SAQA-114069_-_Practical_task.docx
Size: 37.21 KB
SAQA-114069_-Summative_Assessments.docx
Size: 74.85 KB