Cyber Security Digital Forensics CSE - 4207
Cyber Security & Digital Forensics
CSE - 4207
Lecture - 01
Dr. Md. Alam Hossain
Professor
Jashore University of Science & Technology
Outline
Outline
• The Security Mindset
• Meet the Adversary
• Security and Standards Organizations
• Key Security Concepts
• Levels of Impact
• Computer Security Challenges
• Aspects of Security
• Passive Attacks
• Active Attacks
• Model for Network Security
• Model for Network Access Security
2
The Security Mindset
The Security Mindset
• “Security requires a particular mindset. Security
professionals --at least the good ones --see the
world differently. They can't walk into a store
without noticing how they might shoplift. They
can't use a computer without wondering about the
security vulnerabilities. They can't vote without
trying to figure out how to vote twice. They just
can't help it.”
— Bruce Schneier
3
Meet the Adversary
Meet the Adversary
• “Computer security studies
how systems behave in the
presence of an adversary.”
• The adversary - the attacker/
the bad guy
• An intelligence that actively
tries to cause the system to
misbehave.
4
Know Your Enemy
Know Your Enemy
• The art of war teaches us to rely not on the
likelihood of the enemy's not coming, but on our
own readiness to receive him; not on the chance
of his not attacking, but rather on the fact that we
have made our position unassailable.
—The Art of War, Sun Tzu
5
Thinking Like an Attacker
Thinking Like an Attacker
• Look for weakest links –easiest to attack.
– Identify assumptions that security depends on.
Are they false?
– Think outside the box: Not constrained by
system designer’s worldview.
6
Find the Code
Find the Code
7
• What are some security systems you
interact with in everyday life?
8
Security and Standards Organizations
Security and Standards Organizations
• National Institute of Standards & Technology
(NIST)
• Internet Society (ISOC)
• International Telecommunication Union
Telecommunication Standardization Sector (ITU-T)
• International Organization for Standardization
(ISO)
9
Key Security Concepts
Key Security Concepts
10
Levels of Impact
Levels of Impact
• Can define 3 levels of impact from a
security breach
– Low
– Moderate
– High
11
Examples of Security Requirements
Examples of Security Requirements
• Confidentiality – student grades
• Integrity – patient information
• Availability – authentication service
12
Computer Security Challenges
Computer Security Challenges
1. not simple
2. must consider potential attacks
3. procedures used counter-intuitive
4. involve algorithms and secret info
5. must decide where to deploy mechanisms
6. battle of wits between attacker / admin
7. not perceived on benefit until fails
8. requires regular monitoring
9. too often an after-thought
10. regarded as impediment to using system
13
Aspects of Security
Aspects of Security
• consider 3 aspects of information security:
– security attack
– security mechanism
– security service
• note terms
– threat –a potential for violation of security
– attack –an assault on system security, a
deliberate attempt to evade security services
14
Passive Attacks
Passive Attacks
15
Active Attacks
Active Attacks
16
Security Services
Security Services
• X.800:
– “a service provided by a protocol layer of
communicating open systems, which ensures
adequate security of the systems or of data
transfers”
• RFC 2828:
– “a processing or communication service
provided by a system to give a specific kind of
protection to system resources”
17
Model for Network Security
Model for Network Security
18
Model for Network Security
Model for Network Security
• Using this model requires us to:
1. Design a suitable algorithm for the security
transformation
2. Generate the secret information (keys) used by
the algorithm
3. Develop methods to distribute and share the
secret information
4. Specify a protocol enabling the principals to use
the transformation and secret information for a
security service
19
Model for Network Access Security
Model for Network Access Security
20
Model for Network Access Security
Model for Network Access Security
• Using this model requires us to:
1. Select appropriate gatekeeper functions to
identify users
2. Implement security controls to ensure only
authorized users access designated information
or resources
21
Thank You
Thank You
22