Cyber Security
Cyber Security
▪ Cyber Threat:
▪ A malicious act that seeks to damage data, steal data, or disrupt digital
life in general.
▪ It include computer viruses, data breaches, Denial of Service (DoS)
attacks, and other attack vectors.
▪ It aims to gain unauthorized access, damage, disrupt, or steal
information or any other form of sensitive data.
▪ Types of Cyber Threats:
▪ Malware: is a form of malicious software in which any file or program
can be used to harm a computer user.
▪ Ransomware: is another type of malware that involves an attacker
locking the victim's computer system files -- typically through
encryption -- and demanding a payment to decrypt and unlock them.
▪ Social engineering: is an attack that relies on human interaction. It
tricks users into breaking security procedures to gain sensitive
information that is typically protected.
Cyber Security
▪ Phishing: is a form of social engineering where fraudulent email or
text messages that resemble those from reputable or known sources are
sent with the intent to steal sensitive data, such as credit card or login
information.
▪ Insider threats: are security breaches or losses caused by humans --
for example, employees, contractors or customers.
▪ Distributed denial-of-service (DDoS) attacks: are those in
which multiple systems disrupt the traffic of a targeted system, such as
a server, website or other network resource.
▪ By flooding the target with messages, connection requests or
packets, the attackers can slow the system or crash it, preventing
legitimate traffic from using it.
▪ Advanced persistent threats (APTs): are prolonged targeted
attacks in which an attacker infiltrates a network and remains
undetected for long periods of time with the aim to steal data.
Cyber Security
▪ Cyber security:
▪ It is the practice of defending computers, servers, mobile devices,
electronic systems, networks, and data from malicious attacks.
▪ The protection of internet-connected systems such as hardware,
software and data from cyber threats.
▪ The practice is used by individuals and enterprises to protect against
unauthorized access to data centers and other computerized systems.
▪ Common categories of cyber security:
▪ Network security:
▪ practice of securing a computer network from intruders, whether
targeted attackers or opportunistic malware.
▪ Application security:
▪ focuses on keeping software and devices free of threats.
Cyber Security
▪ Information security:
▪ protects the integrity and privacy of data, both in storage and in
transit.
▪ Operational security:
▪ includes the processes and decisions for handling and protecting
data assets.
▪ It includes the permissions users have when accessing a network
and the procedures that determine how and where data may be
stored or shared.
▪ Disaster recovery and business continuity:
▪ define how an organization responds to a cyber-security incident or
any other event that causes the loss of operations or data.
▪ Disaster recovery policies dictate how the organization restores its
operations and information to return to the same operating
capacity as before the event.
Cyber Security
▪ Cyber safety tips - protect yourself against cyberattacks:
▪ Update your software and operating system
▪ Use anti-virus software
▪ Use strong passwords
▪ Do not open email attachments from unknown senders
▪ Do not click on links in emails from unknown senders or unfamiliar
websites
▪ Avoid using unsecure Wi-Fi networks in public places
Security threats from web-
Malware
▪ Malware –
▪ Malware is a malicious software that gets installed in your
device and performs unwanted tasks.
▪ Mainly designed to transmit information about your web
browsing habits to the third party.
▪ Types of malware:
▪ Viruses
▪ Spyware
▪ Trojan Horse
▪ Worms
▪ Adware
Malware
▪ Virus –
▪ Virus is a small program or small code segment that is capable of
attaching itself to existing programs or files and infect them as
well as replicate itself.
▪ Virus enters your device via attached images, greetings,
audio/video files, downloads, etc.
Malware
▪ Spyware –
▪ Spyware is a program that are installed without user’s permission.
▪ It monitors the user’s activities on the internet and transmits that
information to the third party.
▪ Trojan Horse –
▪ A Trojan Horse is a program that appears to be legal & useful but
concurrently does something unexpected like destroying existing
programs and files.
▪ Entering a computer, it performs various tasks like corrupting files
and sending out personal information.
Malware
▪ Worms –
▪ Worms are standalone malware computer programs that
replicates itself in order to spread to other computers.
▪ They make the working of your device slower.
▪ Adware –
▪ Software where advertising banners are displayed while any
program is running.
▪ It automatically downloads to your device while browsing any
website.
▪ It is used by companies for marketing purposes.
Data Privacy & Security
▪ Data Privacy –
▪ Data privacy refers to the proper use and processing of personal data.
▪ It ensures proper use of personal data by giving individuals control
over how their data is accessed, used, or shared.
▪ Personal data may include names, addresses, Social Security numbers,
credit card numbers, financial data, and personal health information.
▪ Tips to protect data privacy (for individuals):
▪ select strong passwords and change them frequently
▪ use multifactor authentication (MFA) or biometric identification for
important accounts
▪ don't click links and buttons within emails
▪ avoid providing personally identifiable information that's unnecessary
or not required
▪ use malware tools and keep those tools updated
▪ use only trusted apps and websites
Data Privacy & Security
▪ Data Security –
▪ Data security is the concept of protecting digital data from theft,
corruption, or unauthorized access throughout its entire lifecycle
of:
▪ Creation
▪ Storage
▪ Use
▪ Sharing
▪ Archiving
▪ Destruction.
▪ Data security involves everything from the physical security of
the storage devices and hardware to administrative access
controls and the security of software applications.
Data Privacy & Security
▪ Types of Data Security –
▪ Access Controls
▪ data security measures includes limiting both physical and digital
access to critical systems and data.
▪ This includes making sure all computers and devices are protected
with mandatory login entry, and that physical spaces can only be
entered by authorized personnel.
▪ Authentication
▪ It refers specifically to accurately identifying users before they have
access to data.
▪ This usually includes things like passwords, PIN numbers, security
tokens, swipe cards, or biometrics.
▪ Backups & Recovery
▪ It refers to a plan to securely access data in the event of system
failure, disaster, data corruption, or breach.
▪ So, we need to backup a copy of the data to recover if needed.
Data Privacy & Security
▪ Data Masking
▪ Information is hidden by obscuring letters and numbers with proxy
characters with the use of data masking software.
▪ The data changes back to its original form only when an authorized
user receives it.
▪ Encryption
▪ It means transforming text characters into an unreadable format
via encryption keys using an encryption algorithm.
▪ Only authorized users with the proper corresponding keys can
unlock and access the information.
▪ Data Resiliency
▪ Resiliency is determined by how well an organization endures or
recovers from any type of failure – from hardware problems to
power shortages and other events that affect data availability.
▪ Speed of recovery is critical to minimize impact.
Data Privacy & Security
▪ Main Elements of Data Security
▪ There are three core elements to data security that all organizations
should adhere to:
▪ Confidentiality
▪ It ensures that data is accessed only by authorized users with the
proper credentials.
▪ Integrity
▪ It ensure that all data stored is reliable, accurate, and not subject to
unwarranted changes.
▪ Availability
▪ It ensures that data is readily — and safely — accessible and
available for ongoing business needs.
Security for Mobile Phones &
Hand-held devices
▪ A smartphone is the most widely used electronic device in daily life for
many of us.
▪ Now, they operate as portable computers, with a vast array of apps for
everything from social networking to online banking.
▪ The extent to which we rely on our phones, plus the amount of data they
contain, means that phone security is crucial.
▪ As our reliance on mobile devices has increased, so too have mobile
security threats.
▪ Some of the main phone security threats include:
▪ Malicious apps and websites
▪ Mobile ransomware
▪ Phishing
▪ Man-in-the-Middle (MitM) attacks
▪ Jailbreaking and rooting
▪ Spyware
Security for Mobile Phones &
Hand-held devices
▪ Smartphone security tips
▪ Keep your phone locked
▪ If your device is stolen, the thief could obtain access to your
personal information. To prevent this, it’s important to have a lock
on your screen in the form of passcode, pattern, fingerprint, or face
recognition.
▪ Create a strong password for your phone and apps
▪ This will make it harder for a hacker to guess them.
▪ If a password attempt fails a certain number of times, the phone
will lock, disable, and in some cases even erase all data.
▪ Be wary of text messages
▪ Text messages are an easy target for mobile malware, so avoid
sending sensitive data such as credit card details or important
private information by text.
▪ Equally, be cautious about text messages you receive.
Security for Mobile Phones &
Hand-held devices
▪ Check your browser for the lock symbol
▪ The lock icon in the browser's address bar indicates that you are on
a secure connection and that the website you are using has an up-
to-date security certificate.
▪ Ensure your apps are from reputable sources
▪ Always download apps from official app stores.
▪ Google and Apple test every app before it is allowed into the Play
Store or App Store.
▪ Cybercriminals create fake mobile apps that mimic trusted brands
so they can obtain users’ confidential information.
▪ Keep your device’s OS up-to-date
▪ Operating system updates protect your device from newly
discovered threats.
▪ To ensure a secure smartphone, it's essential to keep your mobile's
operating system up to date.
Security for Mobile Phones &
Hand-held devices
▪ Connect to secure Wi-Fi
▪ To maximize your safety while using public Wi-Fi, connect to a
virtual private network (VPN).
▪ A VPN encrypts your data, protecting your location and keeping
your information from prying eyes.
▪ Encrypt your data
▪ If your phone is lost or stolen, sensitive information like your
emails, contacts, and financial information could be at risk.
▪ To protect your mobile phone data, you can encrypt it.
▪ Encrypted data is stored in an unreadable form so it can’t be
understood.
▪ Enable remote wiping of your phone
▪ It helps when your phone is lost or stolen.
▪ You can remotely clear your personal data from its memory.
Digital Payment Suraksha
▪ It is an initiative by the Government of India to make the people
know how to safely perform Digital Payments.
▪ India has embarked on an ambitious transformation journey to
realize its vision of a Digital India.
▪ With Government and Industry moving towards a 'Less Cash
Economy', Digital Payment channels have caught momentum and
citizens across the country are adopting various modes of digital
payments.
▪ Data Security Council of India in association with Ministry of
Electronics and Information Technology (MeitY) and Google India
have crafted an awareness campaign to promote 'Digital Payment
Suraksha' to address security and safety best practices while making
digital transactions.
Digital Payment Suraksha
▪ Some key points related to digital payment:
▪ Don’t share your wallet/card details with anyone.
▪ Use latest version of the wallet.
▪ Keep the security features of your phone ON.
▪ Always use strong password. In addition, use OTP.
▪ Periodically change your password.
▪ Don’t use public or open Wi-Fi.
▪ Always keep your login id and password protected.
Netiquettes and Cyber Hygiene
▪ Netiquettes:
▪ Netiquette is a made-up word from the words net and etiquette.
▪ It describes the rules of conduct for respectful and appropriate
communication on the internet.
▪ Netiquette is often referred to as etiquette for the internet.
▪ These are not legally binding rules, but recommended rules of
etiquette.
▪ Cyber Hygiene:
▪ a set of practices organizations and individuals perform regularly
to maintain the health and security of users, devices, networks
and data.
▪ The goal of cyber hygiene is to keep sensitive data secure and
protect it from theft or attacks.
Online educational e-Resources
▪ Online Educational e-Resources:
▪ Any resource available on the Internet in an online educational
environment.
▪ Advantages:
▪ It makes learning accessible to more people
▪ Provides a wide range of resources for all learning styles
▪ Provides instant feedback on work
▪ Emulates a one-to-one teaching style
▪ Types of e-resources:
▪ OER, NDL, SWAYAM, Spoken-Tutorials, Open Courseware, Virtual
Labs, etc.
Online educational e-Resources
▪ Open Educational Resources (OER):
▪ Open educational resources (OER) are teaching, learning, and research
materials intentionally created and licensed to be free for the end user
to own, share, and in most cases, modify.
▪ These are publicly accessible materials and resources for any user to
use, re-mix, improve, and redistribute.
▪ In India:
▪ National Council Of Educational Research and Training (NCERT)
digitized all its textbooks from 1st standard to 12th standard and are
available online for free.
▪ Central Institute of Educational Technology (CIET), a constituent
Unit of NCERT, digitized more than thousand audio and video
programmes presently available at Sakshat Portal, an initiative of
MHRD.
▪ National Repository for Open Educational Resources (NROER)
houses a variety of e-content.
Online educational e-Resources
▪ National Digital Library (NDL):
▪ A digital repository of a vast amount of e-content on multiple
disciplines from primary to PG levels.
▪ It has 4.3 crores content (Text/ Audio/ Video/ Simulation/ Graphics),
harvested from 250 sources; in 300+ languages.
▪ NDL has 55 Lakhs + registered users.
▪ [Link]
▪ SWAYAM:
▪ SWAYAM stands for “Study Webs of Active-Learning for Young
Aspiring Minds”.
▪ It is an Indian government Massive open online course (MOOC)
platform providing educational opportunities for a vast number of
university and college learners.
▪ It has 1900+ courses covering school & higher education, and
around 1.57 Crore students are registered with it.
▪ [Link]
Online educational e-Resources
▪ Spoken-Tutorials:
▪ A Tutorial in IT application which provides self-training in IT fields, like
learning a particular FOSS (Free and Open Source Software) like Linux,
LaTeX, PHP & MySQL, etc.
▪ It is an initiative by the National Mission on Education through
Information and Communication Technology (NMEICT), launched by
Ministry of Education.
▪ The multi-lingual courses provided by it ensure that anybody with a
computer and a desire for learning, can learn from any place, at any time
and in a language of their choice.
▪ [Link]
▪ Virtual Labs:
▪ It has developed Web-enabled curriculum based experiments designed
for remote – operation.
▪ Its 275 labs with 2200+ experiments made 18+ Lakhs students
benefitted.
▪ [Link]