Chapter 1: Cybersecurity - A World of Experts and Criminals
Section no 1.1
(Page [Link])
Many of the world’s original hackers were computer hobbyists, programmers and students during the 60’s. Originally,
the term hacker described individuals with advanced programming skills. Hackers used these programming skills to
test the limits and capabilities of early systems. These early hackers were also involved in the development of early
computer games. Many of these games included wizards and wizardry.
As the hacking culture evolved, it incorporated the lexicon of these games into the culture itself. Even the outside
world began to project the image of powerful wizards upon this misunderstood hacking culture. Books such as Where
Wizards Stay up Late: The Origins of The Internet published in 1996 added to the mystique of the hacking culture.
The image and lexicon stuck. Many hacking groups today embrace this imagery. One of the most infamous hacker
groups goes by the name Legion of Doom. It is important to understand the cyber culture in order to understand the
criminals of the cyber world and their motivations.
Sun Tzu was a Chinese philosopher and warrior in the sixth century BC. Sun Tzu wrote the book titled, The Art of
War, which is a classic work about the strategies available to defeat the enemy. His book has given guidance to
tacticians throughout the ages. One of Sun Tzu’s guiding principles was to know your opponent. While he was
specifically referring to war, much of his advice translates to other aspects of life, including the challenges of
cybersecurity. This chapter begins by explaining the structure of the cybersecurity world and the reason it continues
to grow.
This chapter discusses the role of cyber criminals and their motivations. Finally, the chapter explains how to become
a cybersecurity specialist. These cybersecurity specialists help defeat the cyber criminals that threaten the cyber
world.
Overview of the Cybersecurity Domains (section 1.1)
(page [Link])
There are many data groups that make up the different domains of the “cyber world”. When groups are able to collect
and utilize massive amounts of data, they begin to amass power and influence. This data can be in the form of
numbers, pictures, video, audio, or any type of data that can be digitized. These groups could become so powerful
that they operate as though they are separate powers, creating separate cybersecurity domains.
Companies such as Google, Facebook, and LinkedIn, could be considered to be data domains in our cyber world.
Extending the analogy further, the people who work at these digital companies could be considered cybersecurity
experts.
The word ‘domain’ has many meanings. Wherever there is control, authority, or protection, you might consider that
'area' to be a domain. Think of how a wild animal will protect its own declared domain. In this course, consider a
domain to be an area to be protected. It may be limited by a logical or physical boundary. This will depend on the size
of the system involved. In many respects, cybersecurity experts have to protect their domains according the laws of
their own country.
Examples of Cybersecurity Domains
([Link])
The experts at Google created one of the first and most powerful domains within the broader cyber world of the
Internet. Billions of people use Google to search the web every day. Google has arguably created the world’s largest
data collection infrastructure. Google developed Android, the operating system installed on over 80% of all mobile
devices connected to the Internet. Each device requires users to create Google accounts that can save bookmarks
and account information, store search results, and even locate the device. Click here to see some of the many
services Google currently offers.
Facebook is another powerful domain within the broader Internet. The experts at Facebook recognized that people
create personal accounts every day to communicate with family and friends. In doing so, you are volunteering a great
deal of personal data. These Facebook experts built a massive data domain to enable people to connect in ways that
were unimaginable in the past. Facebook affects millions of lives on a daily basis and empowers companies and
organizations to communicate with people in a more personal and focused manner.
LinkedIn is yet another data domain on the Internet. The experts at LinkedIn recognized that their members would
share information in the pursuit of building a professional network. LinkedIn users upload this information to create
online profiles and connect with other members. LinkedIn connects employees with employers and companies to
other companies worldwide. There are broad similarities between LinkedIn and Facebook.
A look inside these domains reveals how they are constructed. At a fundamental level, these domains are strong
because of the ability to collect user data contributed by the users themselves. This data often includes users’
backgrounds, discussions, likes, locations, travels, interests, friends and family members, professions, hobbies, and
work and personal schedules. Experts create great value for organizations interested in using this data to better
understand and communicate with their customers and employees.
Examples of Cybersecurity Domains
([Link])
The experts at Google created one of the first and most powerful domains within the broader cyber world of the
Internet. Billions of people use Google to search the web every day. Google has arguably created the world’s largest
data collection infrastructure. Google developed Android, the operating system installed on over 80% of all mobile
devices connected to the Internet. Each device requires users to create Google accounts that can save bookmarks
and account information, store search results, and even locate the device. Click here to see some of the many
services Google currently offers.
Facebook is another powerful domain within the broader Internet. The experts at Facebook recognized that people
create personal accounts every day to communicate with family and friends. In doing so, you are volunteering a great
deal of personal data. These Facebook experts built a massive data domain to enable people to connect in ways that
were unimaginable in the past. Facebook affects millions of lives on a daily basis and empowers companies and
organizations to communicate with people in a more personal and focused manner.
LinkedIn is yet another data domain on the Internet. The experts at LinkedIn recognized that their members would
share information in the pursuit of building a professional network. LinkedIn users upload this information to create
online profiles and connect with other members. LinkedIn connects employees with employers and companies to
other companies worldwide. There are broad similarities between LinkedIn and Facebook.
A look inside these domains reveals how they are constructed. At a fundamental level, these domains are strong
because of the ability to collect user data contributed by the users themselves. This data often includes users’
backgrounds, discussions, likes, locations, travels, interests, friends and family members, professions, hobbies, and
work and personal schedules. Experts create great value for organizations interested in using this data to better
understand and communicate with their customers and employees.
Section no 1.2
Who Are the Cyber Criminals?
([Link])
In the early years of the cybersecurity world, the typical cyber criminals were teenagers or hobbyists operating from a
home PC, with attacks mostly limited to pranks and vandalism. Today, the world of the cyber criminals has become
more dangerous. Attackers are individuals or groups who attempt to exploit vulnerabilities for personal or financial
gain. Cyber criminals are interested in everything from credit cards to product designs, and anything with value.
Amateurs
Amateurs, or script kiddies, have little or no skill, often using existing tools or instructions found on the Internet to
launch attacks. Some are just curious, while others try to demonstrate their skills and cause harm. They may be using
basic tools, but the results can still be devastating.
Hackers
This group of criminals breaks into computers or networks to gain access for various reasons. The intent of the break-
in determines the classification of these attackers as white, gray, or black hats. White hat attackers break into
networks or computer systems to discover weaknesses in order to improve the security of these systems. The
owners of the system give permission to perform the break-in, and they receive the results of the test. On the other
hand, black hat attackers take advantage of any vulnerability for illegal personal, financial or political gain. Gray hat
attackers are somewhere between white and black hat attackers. The gray hat attackers may find a vulnerability and
report it to the owners of the system if that action coincides with their agenda. Some gray hat hackers publish the
facts about the vulnerability on the Internet, so that other attackers can exploit it.
The figure gives details about the terms white hat hacker, black hat hacker, and gray hat hacker.
Organized Hackers
These criminals include organizations of cyber criminals, hacktivists, terrorists, and state-sponsored hackers. Cyber
criminals are usually groups of professional criminals focused on control, power, and wealth. The criminals are highly
sophisticated and organized, and may even provide cybercrime as a service. Hacktivists make political statements to
create awareness to issues that are important to them. Hacktivists publically publish embarrassing information about
their victims. State-sponsored attackers gather intelligence or commit sabotage on behalf of their government. These
attackers are usually highly trained and well-funded. Their attacks focus on specific goals that are beneficial to their
government. Some state-sponsored attackers are even members of their nations’ armed forces.
Click here to learn more about hacker profiles.
([Link])
Activity
([Link])
Cyber Criminal Motives
Cyber criminal profiles and motives have changed over the years. Hacking started in the ‘60s with phone freaking (or
phreaking) which refers to using various audio frequencies to manipulate phone systems. In the mid-‘80s, criminals
used computer dial-up modems to connect computers to networks and used password-cracking programs to gain
access to data. Nowadays, criminals are going beyond just stealing information. Criminals can now use malware and
viruses as high tech weapons. However, the greatest motivation for most cyber criminals is financial. Cybercrime has
become more lucrative than the illegal drug trade.
General hacker profiles and motives have changed quite a bit. The figure displays modern hacking terms and a brief
description of each.
Section 1.3
Common Threats to End Users
([Link])
As previously described, there are experts who are innovators and visionaries. They build the different cyber domains
of the Internet. They have the capacity to recognize the power of data and harness it. Then they build their
organizations and provide services, as well as protecting people from cyberattacks. Ideally, cybersecurity
professionals should recognize the threat that data poses if it is used against people.
Threats and vulnerabilities are the main concern of cybersecurity professionals. Two situations are especially critical:
When a threat is the possibility that a harmful event, such as an attack, will occur.
When a vulnerability makes a target susceptible to an attack.
For example, data in the wrong hands can result in a loss of privacy for the owners, can affect their credit, or
jeopardize their career or personal relationships. Identity theft is big business. However, it is not necessarily the
Googles and Facebooks that pose the greatest risk. Schools, hospitals, financial institutions, government agencies,
the workplace and e-commerce pose even greater risks. Organizations like Google and Facebook have the
resources to hire top cybersecurity talent to protect their domains. As more organizations build large databases
containing all of our personal data, the need for cybersecurity professionals increases. This leaves smaller
businesses and organizations competing for the remaining pool of cybersecurity professionals. Cyber threats are
particularly dangerous to certain industries and the records they must maintain.
Types of Personal Records
([Link])
The following examples are just a few sources of data that can come from established organizations.
Medical Records
Going to the doctor’s office results in the addition of more information to an electronic health record (EHR). The
prescription from a family doctor becomes part of the EHR. An EHR includes physical health, mental health, and
other personal information that may not be medically related. For example, an individual goes to counseling as a child
because of major changes in the family. This will be somewhere in his or her medical records. Besides the medical
history and personal information, the EHR may also include information about that person’s family. Several laws
address protecting patient records.
Medical devices, such as fitness bands, use the cloud platform to enable wireless transfer, storage and display of
clinical data like heart rates, blood pressures and blood sugars. These devices can generate an enormous amount of
clinical data that can become part of a medical record.
Education Records
Education records include information about grades, test scores, attendance, courses taken, awards, degrees
awarded, and disciplinary reports. This record may also include contact information, health and immunization records,
and special education records, including individualized education programs (IEPs).
Employment and Financial Records
Employment information can include past employment and performance. Employment records can also include salary
and insurance information. Financial records may include information about income and expenditures. Tax records
could include paycheck stubs, credit card statements, credit rating and banking information.
Threats to Internet Services
([Link])
There are many essential technical services needed for a network, and ultimately the Internet, to operate. These
services include routing, addressing, domain naming, and database management. These services also serve as
prime targets for cyber criminals.
Criminals use packet-sniffing tools to capture data streams over a network. This means that all sensitive data, like
usernames, passwords and credit card numbers, are at risk. Packet sniffers work by monitoring and recording all
information coming across a network. Criminals can also use rogue devices, such as unsecured Wi-Fi access points.
If the criminal sets this up near a public place, such as a coffee shop, unsuspecting individuals may sign on and the
packet sniffer copies their personal information.
Domain Name Service (DNS) translates a domain name, such as [Link], into its numerical IP address.
If a DNS server does not know the IP address, it will ask another DNS server. With DNS spoofing (or DNS cache
poisoning), the criminal introduces false data into a DNS resolver’s cache. These poison attacks exploit a weakness
in the DNS software that causes the DNS servers to redirect traffic for a specific domain to the criminal’s computer,
instead of the legitimate owner of the domain.
Packets transport data across a network or the Internet. Packet forgery (or packet injection) interferes with an
established network communication by constructing packets to appear as if they are part of a communication. Packet
forgery allows a criminal to disrupt or intercept packets. This process enables the criminal to hijack an authorized
connection or denies an individual’s ability to use certain network services. Cyber professionals call this a man-in-the-
middle attack.
The examples given only scratch the surface of the types of threats criminals can launch against Internet and network
services.
Threats to Key Industry Sectors
([Link])
Key industry sectors offer networking infrastructure systems such as manufacturing, energy, communication and
transportation. For example, the smart grid is an enhancement to the electrical generation and distribution system.
The electrical grid carries power from central generators to a large number of customers. A smart grid uses
information to create an automated advanced energy delivery network. World leaders recognize that protecting their
infrastructure is critical to protecting their economy.
Over the last decade, cyberattacks like Stuxnet proved that a cyberattack could successfully destroy or interrupt
critical infrastructures. Specifically, the Stuxnet attack targeted the Supervisory Control and Data Acquisition
(SCADA) system used to control and monitor industrial processes. SCADA can be part of various industrial
processes in manufacturing, production, energy and communications systems. Click here to view more information
about Stuxnet attack.
A cyberattack could bring down or interrupt industry sectors like telecommunication, transportation or electrical power
generation and distribution systems. It could also interrupt the financial services sector. One of the problems with
environments that incorporate SCADA is the fact that designers did not connect SCADA to the traditional IT
environment and the Internet. Therefore, they did not properly consider cybersecurity during the development phase
of these systems. Like other industries, organizations using SCADA systems recognize the value of data collection to
improve operations and decrease costs. The resulting trend is to connect SCADA systems to traditional IT systems.
However, this increases the vulnerability of industries using SCADA systems.
The advanced threat potential that exists today demands a special breed of cyber security experts.
Threats to People’s Way of Life
([Link])
Cybersecurity is the ongoing effort to protect networked systems and data from unauthorized access. On a personal
level, everyone needs to safeguard his or her identity, data, and computing devices. At the corporate level, it is the
employees’ responsibility to protect the organization’s reputation, data, and customers. At the state level, national
security and the citizens’ safety and well-being are at stake.
Cybersecurity professionals are often involved in working with government agencies in identifying and collecting data.
In the U.S., the National Security Agency (NSA) is responsible for intelligence collection and surveillance activities.
The NSA built a new data center just to process the growing volume of information. In 2015, the U.S. Congress
passed the USA Freedom Act ending the practice of collecting U.S. Citizens’ phone records in bulk. The program
provided metadata that gave the NSA information about communications sent and received.
The efforts to protect people’s way of life often conflicts with their right to privacy. It will be interesting to see what
happens to the balance between these rights and the safety of Internet users.
Lab - Explore Social Engineering Techniques
([Link])
In this lab, you will explore social engineering techniques, sometimes called human hacking, which is a broad
category for different types of attacks.
Lab - Explore Social Engineering Techniques
Section 4
internal and External Threats
([Link])
Internal Security Threats
Attacks can originate from within an organization or from outside of the organization, as shown in the figure. An
internal user, such as an employee or contract partner, can accidently or intentionally:
Mishandle confidential data
Threaten the operations of internal servers or network infrastructure devices
Facilitate outside attacks by connecting infected USB media into the corporate computer system
Accidentally invite malware onto the network through malicious email or websites
Internal threats have the potential to cause greater damage than external threats because internal users have direct
access to the building and its infrastructure devices. Internal attackers typically have knowledge of the corporate
network, its resources, and its confidential data. They may also have knowledge of security countermeasures,
policies and higher levels of administrative privileges.
External Security Threats
External threats from amateurs or skilled attackers can exploit vulnerabilities in networked devices, or can use social
engineering, such as trickery, to gain access. External attacks exploit weaknesses or vulnerabilities to gain access to
internal resources.
Traditional Data
Corporate data includes personnel information, intellectual property, and financial data. Personnel information
includes application materials, payroll, offer letters, employee agreements, and any information used in making
employment decisions. Intellectual property, such as patents, trademarks and new product plans, allows a business
to gain economic advantage over its competitors. Consider this intellectual property as a trade secret; losing this
information can be disastrous for the future of the company. Financial data, such as income statements, balance
sheets, and cash flow statements, gives insight into the health of the company.
The Vulnerabilities of Mobile Devices
([Link])
In the past, employees typically used company-issued computers connected to a corporate LAN. Administrators
continuously monitor and update these computers to meet security requirements. Today, mobile devices such as
iPhones, smartphones, tablets, and thousands of other devices, are becoming powerful substitutes for, or additions
to, the traditional PC. More and more people are using these devices to access enterprise information. Bring Your
Own Device (BYOD) is a growing trend. The inability to centrally manage and update mobile devices poses a growing
threat to organizations that allow employee mobile devices on their networks.
The Emergence of the Internet of Things
([Link])
The Internet of Things (IoT) is the collection of technologies that enable the connection of various devices to the
Internet. The technological evolution associated with the advent of the IoT is changing commercial and consumer
environments. IoT technologies enable people to connect billions of devices to the Internet. These devices include
appliances, locks, motors, and entertainment devices, to name just a few. This technology affects the amount of data
that needs protection. Users access these devices remotely, which increases the number of networks requiring
protection.
With the emergence of IoT, there is much more data to be managed and secured. All of these connections, plus the
expanded storage capacity and storage services offered through the Cloud and virtualization, has led to the
exponential growth of data. This data expansion created a new area of interest in technology and business called
“Big Data".
The Impact of Big Data
([Link])
Big data is the result of data sets that are large and complex, making traditional data processing applications
inadequate. Big data poses both challenges and opportunities based on three dimensions:
The volume or amount of data
The velocity or speed of data
The variety or range of data types and sources
There are numerous examples of big corporate hacks in the news. Companies like Target, Home Depot and PayPal
are subjects of highly publicized attacks. As a result, enterprise systems require dramatic changes in security product
designs and substantial upgrades to technologies and practices. Additionally, governments and industries are
introducing more regulations and mandates that require better data protection and security controls to help guard big
data.
SECTION 4 PART 2
Using Advanced Weapons
([Link])
Software vulnerabilities today rely on programming mistakes, protocol vulnerabilities, or system misconfigurations.
The cyber criminal merely has to exploit one of these. For example, a common attack involved constructing an input
to a program in order to sabotage the program, making it malfunction. This malfunction provided a doorway into the
program or caused it to leak information.
There is a growing sophistication seen in cyberattacks today. An advanced persistent threat (APT) is a continuous
computer hack that occurs under the radar against a specific object. Criminals usually choose an APT for business or
political motives. An APT occurs over a long period with a high degree of secrecy using sophisticated malware.
Algorithm attacks can track system self-reporting data, like how much energy a computer is using, and use that
information to select targets or trigger false alerts. Algorithmic attacks can also disable a computer by forcing it to use
memory or by overworking its central processing unit. Algorithmic attacks are more devious because they exploit
designs used to improve energy savings, decrease system failures, and improve efficiencies.
Finally, the new generation of attacks involves intelligent selection of victims. In the past, attacks would select the low
hanging fruit or most vulnerable victims. However, with greater attention to detection and isolation of cyberattacks,
cyber criminals must be more careful. They cannot risk early detection or the cybersecurity specialists will close the
gates of the castle. As a result, many of the more sophisticated attacks will only launch if the attacker can match the
object signature targeted.
Broader Scope and Cascade Effect
([Link])
Federated identity management refers to multiple enterprises that let their users use the same identification
credentials gaining access to the networks of all enterprises in the group. This broadens the scope and increases the
probability of a cascading effect should an attack occur.
A federated identity links a subject’s electronic identity across separate identity management systems. For example,
a subject may be able to log onto Yahoo! with Google or Facebook credentials. This is an example of social login.
The goal of federated identity management is to share identity information automatically across castle boundaries.
From the individual user’s perspective, this means a single sign-on to the web.
It is imperative that organizations scrutinize the identifying information shared with partners. Social security numbers,
names, and addresses may allow identity thieves the opportunity to steal this information from a partner to perpetrate
fraud. The most common way to protect federated identity is to tie login ability to an authorized device.
Safety Implications
([Link])
Emergency call centers in the U.S. are vulnerable to cyberattacks that could shut down 911 networks, jeopardizing
public safety. A telephone denial of service (TDoS) attack uses phone calls against a target telephone network tying
up the system and preventing legitimate calls from getting through. Next generation 911 call centers are vulnerable
because they use Voice-over-IP (VoIP) systems rather than traditional landlines. In addition to TDoS attacks, these
call centers can also be at risk of distributed-denial-of-service (DDoS) attacks that use many systems to flood the
resources of the target making the target unavailable to legitimate users. There are many ways nowadays to request
911 help, from using an app on a smartphone to using a home security system.
Heightened Recognition of Cybersecurity Threats
([Link])
The defenses against cyberattacks at the start of the cyber era were low. A smart high school student or script kiddie
could gain access to systems. Countries across the world have become more aware of the threat of cyberattacks.
The threat posed by cyberattacks now head the list of greatest threats to national and economic security in most
countries.
Section no 5
Addressing the Shortage of Cybersecurity Specialists
([Link])
In the U.S., the National Institute of Standards and Technologies (NIST) created a framework for companies and
organizations in need of cybersecurity professionals. The framework enables companies to identify the major types of
responsibilities, job titles, and workforce skills needed. The National Cybersecurity Workforce Framework categorizes
and describes cybersecurity work. It provides a common language that defines cybersecurity work along with a
common set of tasks and skills required to become a cybersecurity specialist. The framework helps to define
professional requirements in cybersecurity.
The National Cybersecurity Workforce Framework
([Link])
The Workforce Framework categorizes cybersecurity work into seven categories.
Operate and Maintain includes providing the support, administration, and maintenance required to ensure IT system
performance and security.
Protect and Defend includes the identification, analysis, and mitigation of threats to internal systems and networks.
Investigate includes the investigation of cyber events and/or cyber crimes involving IT resources.
Collect and Operate includes specialized denial and deception operations and the collection of cybersecurity
information.
Analyze includes highly specialized review and evaluation of incoming cybersecurity information to determine if it is
useful for intelligence.
Oversight and Development provides for leadership, management, and direction to conduct cybersecurity work
effectively.
Securely Provision includes conceptualizing, designing, and building secure IT systems.
Within each category, there are several specialty areas. The specialty areas then define common types of
cybersecurity work.
The figure displays each of the categories and a brief description of each.
([Link]) activity