LECTURE 1 a ) Secuirty Fundamentals
LECTURE 1 a ) Secuirty Fundamentals
Security Fundamentals
Learning Objectives
2
THE IMPORTANCE OF
SECURITY
3
Bad News
4
Hackers
5
Why The Increase In Attacks?
1. Speed of attacks
2. More sophisticated attacks
3. Simplicity of attack tools
4. Faster detection weaknesses
5. Delays in user patching
6. Distributed attacks
7. User confusion
6
User Confusion
7
User Misconceptions
8
The Importance of Security
9
Security Threats
10
COMMON PHYSICAL AND
DIGITAL SECURITY METHODS
11
Physical Security
1. Lock doors
2. Badges
3. Key fobs
4. RFID badges
5. RSA token – performs two-factor authentication
for a user to a network resource
6. Securing physical documents and passwords
7. Destroying documents
12
Biometrics
13
Smart Cards
14
Digital Security
1. Antivirus
2. Antispyware
3. User authentication/strong passwords
4. Firewalls
5. Directory/folder permissions
15
Strong Passwords
1. Difficult to break
2. Have at least 15 characters but 6-8 characters is
average
3. Should be a random combination of letters, numbers,
and special characters
4. Should be replaced with new passwords at least
every
30-60 days
5. Should not be reused for 12 months
6. Should not be duplicated passwords or used for
multiple
accounts
16
Firewall
17
DIGITAL SECURITY THREATS
18
Malware
19
Virus
20
Worm
21
Trojan Horse
22
Rootkit
23
Zombies & Botnets
25
Grayware , Adware, and Spyware
26
Social Engineering
27
Social Engineering
28
Phishing
29
Recognize Phishing Attacks
30
Recognize Phishing Attacks
31
Be Aware
32
Lecture Summary
33
Technical Terms
35
Technical Terms
15. DoS – Denial of Service. Prevents users from accessing normal services by
sending enough requests to overload a resource or even stopping its
operation.
16. Ping of Death – A series of repeated pings intended to crash the receiving
computer.
17. E-mail Bomb – A large quantity of e-mail that overwhelms the e-mail server
preventing users from accessing legitimate e-mail.
18. DDoS – Distributed Denial of Service. An attack launched from many
computers (Botnet)
19. Grayware – A general classification for applications that behave in a
manner that is annoying or undesirable.
20. Adware – Software that automatically plays, displays, or downloads
advertising material to a computer after the software is installed on it or
while the application is being used.
36
Technical Terms
37
END