0% found this document useful (0 votes)
4 views14 pages

Week3 Tutorial Withans

The document covers key concepts in cybersecurity, including DDoS attacks, pass-the-hash attacks, lateral movement, and privilege escalation. It emphasizes the importance of security policies, their characteristics, and the necessity for regular updates. Additionally, it discusses application whitelisting and provides tasks related to UOW's IT security policies and guidelines.

Uploaded by

cjj040223
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views14 pages

Week3 Tutorial Withans

The document covers key concepts in cybersecurity, including DDoS attacks, pass-the-hash attacks, lateral movement, and privilege escalation. It emphasizes the importance of security policies, their characteristics, and the necessity for regular updates. Additionally, it discusses application whitelisting and provides tasks related to UOW's IT security policies and guidelines.

Uploaded by

cjj040223
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CSIT302 Cybersecurity

Week 3 – Tutorial

This slide is copyrighted. It must not be distributed without


permission from UOW
1
Practice Questions
• What are the main aims for DDoS attacks?
The main aims for DDoS attacks are normally either to bring down a server or
to create a diversion in order to commit another malicious act such as stealing
data.

This slide is copyrighted. It must not be distributed without


permission from UOW
2
Practice Questions
• What is the pass-the-hash attack?
An attack based on the exploitation that in some systems, it is possible to
present the password hash instead of a plaintext password.

This slide is copyrighted. It must not be distributed without


permission from UOW
3
Practice Questions
• What does lateral movement mean?
Attackers’ movement from a device to a device after the initial intrusion.

This slide is copyrighted. It must not be distributed without


permission from UOW
4
Practice Questions
• What does “wireshark” do?
It is a sniffing tool that captures packets and provide analyses on them.

This slide is copyrighted. It must not be distributed without


permission from UOW
5
Practice Questions
• What does privilege escalation mean?
Privilege escalation is the act of exploiting a bug, design flaw or configuration
oversight in an operating system or software application to gain elevated
access to resources that are normally protected from an application or user.

This slide is copyrighted. It must not be distributed without


permission from UOW
6
Practice Questions
• How does horizontal privilege escalation differ from vertical privilege
escalation?
In horizontal privilege escalation, the attacker uses a normal account to
access the accounts of other normal users while in the vertical privilege
escalation the attacker is able to obtain a higher level of access than an
administrator or system developer intended.

This slide is copyrighted. It must not be distributed without


permission from UOW
7
Practice Questions
• Why is security policy a living document?
As it needs to be revised and updated, regularly or on-demand.

This slide is copyrighted. It must not be distributed without


permission from UOW
8
Practice Questions
• What are the characteristics of policy? List and explain at least two of
them.
[Any two of the following]
It sets high-level expectation and will be used to guide decisions and achieve
outcomes.
It is for all participants so It cannot be too technical.
It must be enforced by a proper authority.

This slide is copyrighted. It must not be distributed without


permission from UOW
9
Practice Questions
• What is the most important item the standard should provide?
The standard document must provide enough technical details to give a
accurate and detailed explanation of requirements.

This slide is copyrighted. It must not be distributed without


permission from UOW
10
Security Policy in Practice: UOW IT Policy
• Task 1: We have learned various aspects of security policy. UOW has a
set of security policies regarding IT. They are available at
[Link]
Let’s have a look at the above site and see what kind of policy documents
UOW have in relation to IT.
Among one of the policies, pick “CYBER SECURITY POLICY”. What does it
include?
 Does it have a well-defined scope?
 Does it include procedure, standard and guidelines? What are they?
 UOW has additional website for Cybersecurity guidelines:
[Link]

This slide is copyrighted. It must not be distributed without


permission from UOW
11
Security Policy in Practice: UOW IT Policy
Now take a look at “IT SERVER SECURITY POLICY”. -
[Link]
 What is the scope of this policy? Can you find something interesting? Why do you think
the scope be defined as such?
 What hardening practices are recommended in the policy?

This slide is copyrighted. It must not be distributed without


permission from UOW
12
More on Whitelisting
• Task 2: Investigate the NIST document on application whitelisting
[Link]
[Link]
How does the document define “application whitelist”?
How does whitelisting program behave differently from antivirus program?
 Whitelisting program: Permit known good activity and block all other.
 Antivirus program: Block known bad activity and permit all other.
What are the file and folder attributes, on which application whitelisting can
be based?
 File path, filename, file size, digital signature, cryptographic hash

This slide is copyrighted. It must not be distributed without


permission from UOW
13
More on Whitelisting
• Task 3: Answer the following (review) questions.
List (at least) four items security policy should include:
 Policy (principals), scope, standards (or relevant laws), procedures, guidelines
Why is the security awareness training important?
When a policy enforcement is based on a network architecture, what should
be considered? List at least four of them.
What do Domain, OU and GPO mean in Active Directory?
Domain is a collection of Objects within Active Directory network.
OU is a subdomain which is a container for Objects.
GPO is a collection of settings that define what a system will look like and how
it will behave for a defined group of users
This slide is copyrighted. It must not be distributed without
permission from UOW
14

You might also like