0% found this document useful (0 votes)
3 views21 pages

Unit 11 Computer - Security

surface level info of computer security

Uploaded by

binammmm0.0
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views21 pages

Unit 11 Computer - Security

surface level info of computer security

Uploaded by

binammmm0.0
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Computer Security

Dr. Prakash Datt Bhatt


Department of Computer Science and Information Technology
Siddhanath Science Campus, Mahendranagar

March 5, 2025

1 / 20
Outlines
1. Introduction
2. Security Threat and Security Attack
3. Malicious Software
4. Security Services
5. Security Mechanisms
5.1 Cryptography
5.2 Digital Signature
5.3 Firewall
5.4 Users Identification and Authentication
5.5 Intrusion Detection Systems
6. Security Awareness
7. Security Policy
8. Security Services
2 / 20
Introduction I

• The widespread use of computers has resulted in the emergence of a new area of
security, the security of the computer.
• Computer security is needed to protect the computing system and to protect the
data that they store and access.
• The transmission of data through networks (Internet) and communication links has
necessitated the need to protect the data during transmission over the network.
• The term computer security refers to both computer security and network security.

3 / 20
Introduction II

Computer security focuses on the security attacks, security mechanisms and security
services.
• Security attacks are the reasons for breach of security. Security attacks comprise of
all actions that breaches the computer security.
• Security mechanisms are the tools that include the algorithms, protocols or devices,
that are designed to detect, prevent, or recover from a security attack.
• Security services are the services that are provided by a system for a specific kind of
protection to the system resources.

4 / 20
Security Threat and Security Attack

5 / 20
Malicious Software

6 / 20
Security Services

7 / 20
Security Mechanisms

8 / 20
Cryptography

9 / 20
10 / 20
Digital Signature

10 / 20
Firewall

• A firewall is a security mechanism to protect a local network from the threats it may
face while interacting with other networks (Internet).
• A firewall can be a hardware component, a software component, or a combination of
both. It prevents computers in one network domain from communicating directly
with other network domains.
• All communication takes place through the firewall, which examines all incoming
data before allowing it to enter the local network.
• The main purpose of firewall is to protect computers of an organization (local
network) from unauthorized access. Some of the basic functions of firewall are:

11 / 20
Functions of Firewall

• Firewalls provide security by examining the incoming data packets and allowing them
to enter the local network only if the conditions are met.
• Firewalls provide user authentication by verifying the username and password. This
ensures that only authorized users have access to the local network.
• Firewalls can be used to hide the structure and contents of a local network from
external users. Network Address Translation (NAT) conceals the internal network
addresses and replaces all IP addresses on the local network with one or more public
IP addresses.

12 / 20
Types of Firewall

All the data that enter a local network must come through a firewall. The type of firewall
used varies from network to network. The following are the various types of firewalls
generally used:
• Packet filter Firewall
• Circuit Filter Firewall
• Proxy server or Application-level Gateway

13 / 20
Users Identification and Authentication I

• Identification is the process whereby a system recognizes a valid user’s identity.


Authentication is the process of verifying the claimed identity of a user. For example,
a system uses user password for identification.
• The user enters his password for identification. Authentication is the system which
verifies that the password is correct, and thus the user is a valid user.
• Before granting access to a system, the user’s identity needs to be authenticated. If
users are not properly authenticated then the system is potentially vulnerable to
access by unauthorized users.

14 / 20
Users Identification and Authentication II

• If strong identification and authentication mechanisms are used, then the risk that
unauthorized users will gain access to a system is significantly decreased.
• Authentication is done using one or more combinations of—what you have (like
smartcards), what you know (Password), and what you are (Biometrics like
Fingerprints, retina scans).

15 / 20
Security Awareness I

• In order to make the users and people in an organization aware of the security
practices to be followed, regular training programs are conducted in organizations.
• Awareness is also promoted by regular security awareness sessions, videotapes,
newsletters, posters, and flyers.

16 / 20
Security Awareness II

17 / 20
Security Policy I

• Asecuritypolicy is a formal statement that embodies the organization’s overall


security expectations, goals, and objectives with regard to the organization’s
technology, system and information.
• To be practical and implementable, policies must be defined by standards, guidelines,
and procedures. Standards, guidelines, and procedures provide specific interpretation
of policies and instruct users, customers, technicians, management, and others on
how to implement the policies.
• The security policy states what is, and what is not allowed. A security policy must
be comprehensive, up-to-date, complete, delivered effectively, and available to all
staff. A security policy must also be enforceable. To accomplish this, the security
policy can mention that strict action will be taken against employees who violate it,
like disclosing a password.

18 / 20
Security Policy II

• Generally, security policies are included within a security plan. A security plan details
how the rules put forward by the security policy will be implemented. The statements
within a security plan can ensure that each employee knows the boundaries and the
penalties of overstepping those boundaries. For example, some rules could be
included in the security policy of an organization, such as, to log off the system
before leaving the workstation, or not to share the password with other users.
• The security policy also includes physical security of the computers. Some of the
measures taken to ensure the physical security of a computer are—taking regular
backups to prevent data loss from natural calamity, virus attack or theft, securing
the backup media, keeping valuable hardware resources in locked room (like servers),
to avoid theft of systems and storage media.

19 / 20
Thank you
Have a nice day

20 / 20

You might also like