CN Module-5
CN Module-5
Business secrets
Government and ins tu onal records
Protec ng this data from cyber threats is a cri cal requirement.
Network security ensures that:
Only authorized users can access data
Data is not altered or destroyed unlawfully
Network services remain available to legi mate users
MODULE 5
2. Phishing
Phishing is an a ack where a ackers trick users into revealing:
Passwords
Credit card details
Login creden als
This is o en done using fake emails or websites that appear genuine.
Most systems are connected to the Internet In a DoS a ack, a ackers flood a network or server with excessive traffic, making it
unavailable to legi mate users.
Cyber a acks are increasing in frequency and complexity
In DDoS, the a ack comes from mul ple compromised systems.
Data breaches cause financial loss and reputa on damage
Legal and ethical responsibili es require data protec on
4. Unauthorized Access
Without proper security, networks become vulnerable to a acks that can completely
disrupt opera ons. This occurs when an a acker gains access to a system without permission, o en by:
Guessing passwords
A security threat is any poten al danger that can exploit a weakness in a system and cause
harm to data, resources, or services. 5. Man-in-the-Middle A ack
Threats can be inten onal (caused by a ackers) or uninten onal (caused by human error or In this a ack:
system failure).
The a acker secretly intercepts communica on
Data is read or modified before reaching the receiver
5. Lack of encryp on
6. Human errors
Threat vs Vulnerability
2. Security Services
3. Unpatched opera ng systems What ac ons an authen cated user is allowed to perform
3. Confiden ality
Integrity
Confiden ality ensures that:
Data is accessible only to authorized users Confidentiality
Message
Achieved using: Authentication
Security services
Encryp on
Nonrepudiation
Secure communica on protocols
Entity
Authentication
4. Integrity
Computer system
Integrity ensures that:
authentication authorization
Data is not altered during transmission or storage module module
principal
Techniques used: yes/no
?
ed
aut
yes/no
iz
request
hen
or
au
?
perform action
Checksums
OK
guard perform
Digital signatures action object
audit trail
log
5. Non-Repudia on
Non-repudia on ensures that:
A sender cannot deny sending a message
CYBERSECURITY -INFOSEC CIA TRIAD
Used in: Safeguarding the accuracy
and completeness of
Online transac ons information and processing
methods.
Legal communica ons
Includes the detection of alterations
that occurred in storage, transit,
process....
6. Availability Integrity
Ensuring that information Ensuring that authorized
Availability ensures that: only those have
A
is accessible to users access to
C
Network services are accessible when needed access. assets when required.
Information
Includes: Includes controls for:
Achieved through: Protection from
Security
unauthorized access and (System) Acceptable level of performance
Fault tolerance
Redundancy use; A
Prevention of data loss and
Protecting data on systems,
destruction
in transit, in proces5...
Reliable backups, redundancy,...
Backup systems Confidentiality Availability
Example
3.3 Integrity
Online banking services should be available 24/7.
Meaning
Integrity ensures that data remains accurate and unchanged during storage or transmission.
CIA Triad Summary
Principle Focus
Threats to Integrity
Confiden ality Data privacy
Unauthorized modifica on
Malware Integrity Data accuracy
Limita ons:
Cannot inspect packet content
Less secure
o Blocked Advantages:
Firewall decisions are based on: Protects against applica on-level a acks
Direc on of traffic
5.5 Advantages and Limita ons of Firewalls
1. Transport Mode
Encrypts only payload
Header remains unchanged
Used in host-to-host communica on
2. Tunnel Mode
Encrypts en re IP packet
New IP header added
Used in VPNs
3. Security Associa on (SA) Scope Web traffic Applica on data All IP traffic
Defines security parameters Encryp on Yes Yes Yes
Includes encryp on algorithm and keys
VPN support No No Yes