0% found this document useful (0 votes)
3 views33 pages

Day_1_MT_Course Introduction

The document outlines a cybersecurity training course led by Ahmed Didouh, covering fundamental concepts, security goals, common threats, and famous real-world attacks. It consists of 16 modules over four days, including both theoretical and hands-on sessions, culminating in a final exam. Key topics include the CIA triad (Confidentiality, Integrity, Availability), types of threats, and notable cybersecurity incidents.

Uploaded by

abulazizse
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views33 pages

Day_1_MT_Course Introduction

The document outlines a cybersecurity training course led by Ahmed Didouh, covering fundamental concepts, security goals, common threats, and famous real-world attacks. It consists of 16 modules over four days, including both theoretical and hands-on sessions, culminating in a final exam. Key topics include the CIA triad (Confidentiality, Integrity, Availability), types of threats, and notable cybersecurity incidents.

Uploaded by

abulazizse
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

NCA Sponsored Training

Day 1 – Morning Session (Theory)

Introduction to Cybersecurity

Ahmed Didouh
Madinah
12/01/2026

[Link]
Who am I?
Outline

1. Course Introduction
• Objectives
• Structure
• Final Exam

2. Introduction to Cybersecurity
• What is Cybersecurity?
• Security Goals
• Common Threats

3. Famous Real-world Attacks


Course Introduction - Objectives

The objective of this course is to expose the students to


fundamentals, applications and technologies related to
cybersecurity, providing the methodological basis, skills,
and expertise to further progress in the cybersecurity
domain.
Course Introduction - Structure

• 16 modules (8 theory, 8 hands-on) over 4 days


• 4 modules per day
• Final exam on the 5th day

Subjects:
• Introduction to Cybersecurity
• Cryptography
• Authentication (Password Security)
• Network Security
• Web Security
• Social Engineering
Introduction to Cybersecurity

What is Security?
Security refers to freedom from, or resilience against,
potential harm from external forces.
Beneficiaries of security may be persons and social groups,
objects and institutions, ecosystems, and any other entity or
phenomenon vulnerable to unwanted change by its
environment.
Introduction to Cybersecurity

What is Cybersecurity?

Security, in Information Technology (IT), is the defense of


digital information and IT assets against internal and
external, malicious and accidental threats.
Important Terms

• Asset: Stuff we care about, such as • Exploit: A technique that takes advantage of
information, software, hardware, bandwidth, a specific vulnerability to achieve some effect
reputation, privacy, money, etc. on an asset.

• Threat: The potential for an occurrence that • Attacker: A human (so far) who exploits a
would cause an undesirable effect on an vulnerability
asset. Threats are often evaluated with
respect to the CIA triad..
• Controls or countermeasures: action,
device, procedure, or technique to remove or
• Vulnerability: A weakness in a system that reduce a vulnerability
allows a threat to affect an asset.
Kinds of Threats
Why Do Computer Attacks Occur?

• Who are the attackers? • Why they do it?

• Criminals • Profit
• Crime organizations
• Rogue states
• Fun
• Industrial espionage
• Angry employees
• Bored teenagers • Fame
Attacker Goals

Why are our systems and networks attacked?


• Steal our information or gather information
• Steal our money
• Use our hardware, software, or other assets
• Destroy or deny use of our assets (data, information
systems, physical resources)
• Corrupt our information
• Harm reputations, make a statement
• Prepare for future action (e.g., botnets)
• Just to see if it can be done
• Penetration testing
Attack Phases

1. Probe: passive and active 3. Persist: maintain access


reconnaissance
• Compromised accounts, backdoors,
rootkits, bots
2. Penetrate: gain initial access • Covering tracks

• Software vulnerabilities
4. Propagate: spread up and out
• Weak passwords or configurations
• Credential stealing, social • Privilege escalation
engineering, insiders • Extend to other systems or networks

5. Profit: achieve attack goals


Computer Security Issues

• Malware • Social Engineering


• Ransomware • Phishing
• Spyware • Baiting
• Adware • Pretexting
• Trojans • Tailgating
• Worm • Honeytrap
• Rootkits • Smishing
• Keyloggers
• Virus
• Zero-day
• Distributed Denial • Botnet
of Service • Identity Theft
Why do these attacks happen?

• Software/computer systems are buggy

• Users make mistakes

• Technological factors
• Unsafe program languages
• Software are complex, dynamic, and increasingly so
• Making things secure are hard
• Security may make things harder to use
Software Threat Lifecycle

Software Developer
Why Does This Happen?

• Economic factors
• Lack of incentives for secure software
• Security is difficult, expensive, and takes time

• Human factors
• Lack of security training for software engineers
• Largely uneducated population
Cybersecurity Goals – The CIA Triad

• Confidentiality
• Keeping data and resources hidden

• Integrity
• Data integrity (integrity)
• Origin integrity (authentication)

• Availability
• Enabling access to data and resources
Confidentiality

Protecting information from disclosure to unauthorized entities.

How:

• Encryption
• Access Control
• Authentication
Confidentiality - Example

Eavesdropping
Confidentiality - Example

• Only use encrypted


wireless channels

• WPA3 (January 2018) is


the current WiFi standard

• Always use https://


(SSL/TLS) in your browser

Encrypted Channel • Use encrypted email if


possible
Integrity

The property that information


has not be altered in an
unauthorized way.

How:

• Checksums
• Error Correcting Codes
• Hashing
Integrity - Example
Availability

For any information system to serve its purpose, the


information must be available when it is needed.

How:

• Physical Protections
• Computational
Redundancies
Availability - Example

• A cyberattack in which the perpetrator


aims to make a machine or a network
resource unavailable to its intended
users.

• Leverages a network of compromised


computers (BotNets, Zombie
Computers) to send huge amounts of
data (random data or legitimate
requests) to overwhelm the target.
CIA - Recap

Example Threats Example Countermeasures


Confidentiality
Packet Sniffing Encryption
File Grabbing Access Control
Integrity
Spoofed Email Digital Signature
Disk Drive Corruption Backups
Availability
Denial of Service Attack Firewall, Redundancies
Power Failure Backup Power Supplies
More definitions

Policy
• A statement of what is and what is not allowed
• Divides the world into secure and non-secure
states
• A secure system starts in a secure state. All
transitions keep it in a secure state.

Mechanism
• A method, tool, or procedure for enforcing a
security policy
More Definitions

Assurance Example:
• Evidence of how much to trust a system • Why do you trust Aspirin from a major
manufacturer?
• Evidence can include – FDA certifies the aspirin recipe
– Factory follows manufacturing
• System specifications standards
• Design – Safety seals on bottles
• Implementation
• Analogy to software assurance
• Mappings between the levels
Type of “hackers” (most common)

Black Hat White Hat Red Hat

Malicious hacker Ethical “hacker” 2 definitions:


Steal data Cybersecurity specialist One that targets Linux
Monetary damage, etc Protector Vigilante
Top Cybersecurity Threats in 2025

[Link]
Biggest Data Breaches

1) Yahoo August 2013 4) Weibo March 2020


• 3 Billion Accounts • 538 Million User Accounts

2) Alibaba November 2019 5) Facebook April 2019


• 1.1 Billion pieces of user data, including • Information related to more than 530 million
usernames and mobile numbers Facebook users and included phone
numbers, account names, and Facebook IDs
3) LinkedIn June 2021 6) Marriot September 2018
• Data associated with 700 Million users • Data associated with 500 Million users
Biggest Ransomware Attacks

1) NotPetya 2017 4) Locky March 2020


• phishing emails distributing a macro in a
• Physhing
Word document
• Estimated Monetary Impact $10 billion
• Estimated Monetary Impact $1 billion
2) Wannacry 2017 5) Ryuk 2018-present
• vulnerability in SMB protocol • initial compromise, usually TrickBot infection
• Estimated Monetary Impact $4 billion • Estimated Monetary Impact $150 million

3) GrandCrab 2018/2019 6) REvil 2019/2021


• Phishing • zero-day vulnerability
• Estimated Monetary Impact $2 billion • Estimated Monetary Impact $70 million
Worst Phishing Attacks in History

1) Facebook/Google Scam
2017
• carefully crafted phishing emails with fake invoices, contracts and letters to
employees at both these tech giants, falsely billing them for millions of dollars over
a period of two years between 2013 to 2015.

2) NotPetya 2017
• In June 2017, the world woke up to the most devastating cyberattack in history that
spread across the planet like wildfire, ushering in a new era of cyber warfare.

3) Ukrainian Powe Grid


• In December 2015, a Ukrainian electricity distribution company, became the
world’s first power grid provider to be taken down in a cyberattack. The threat
actors were able to attack the target and force a blackout through a phishing email.
Do you have any questions?

[Link] Follow us @rc3kaust

You might also like