0% found this document useful (0 votes)
24 views10 pages

Cyber Security Fundamentals and Practices

The document provides an overview of cybersecurity, emphasizing its importance in protecting networks and devices from cyber threats. It discusses the need for cybersecurity due to increasing cyber-attacks, outlines common techniques and steps for effective security management, and categorizes types of cybersecurity. Additionally, it defines key terms related to threats and vulnerabilities, and highlights the differences between them.

Uploaded by

chandan10mehta
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
24 views10 pages

Cyber Security Fundamentals and Practices

The document provides an overview of cybersecurity, emphasizing its importance in protecting networks and devices from cyber threats. It discusses the need for cybersecurity due to increasing cyber-attacks, outlines common techniques and steps for effective security management, and categorizes types of cybersecurity. Additionally, it defines key terms related to threats and vulnerabilities, and highlights the differences between them.

Uploaded by

chandan10mehta
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

-Prof.

Atul Thaware(FoST,SAS)

Unit-I
Security Basics
Introduction to Cyber Security

Cyber Security is a process that's designed to protect networks and devices from
external threats. Businesses typically employ Cyber Security professionals to protect
their confidential information, maintain employee productivity, and enhance customer
confidence in products and services. Cyber security is the protection of Internet-
connected systems, including hardware, software, and data from cyber-attacks.

It is made up of two words one is cyber and other is security.

Cyber is related to the technology which contains systems, network and programs or data.

Whereas security related to the protection which includes systems security, network
security and application and information security.

Need of Cyber Security

Cyber security becomes so important in our predominant digital world

Cyber-attacks can be extremely expensive for businesses to endure.

In addition to financial damage suffered by the business, a data breach can also inflict
untold reputational damage.

Cyber-attacks these days are becoming progressively destructive. Cybercriminals are


using more sophisticated ways to initiate cyber-attacks.

Regulations such as GDPR are forcing organizations into taking better care of the
personal data they hold.

Elements of Information Technology:


The elements of information technology include software, hardware, networking, databases,
cybersecurity, and artificial intelligence (AI).
Software
• The programs and applications that run on hardware
• Includes operating systems, productivity tools, and CRM systems
-Prof. Atul Thaware(FoST,SAS)

• System software manages the hardware, while application software helps users perform
tasks
Networking
• The physical components that connect devices and enable data transmission
• Includes routers, switches, firewalls, and cables
Cybersecurity
• The protection of systems and data from unauthorized access and attacks
• Uses tools like firewalls and encryption
Databases
• The IT systems and software used to store, organize, and retrieve data
• Includes MySQL, NoSQL, relational database management systems, and MongoDB
Artificial intelligence
• The advanced technology that enables computers to learn from data and perform tasks
that typically require human intelligence
Infrastructure
• The physical components essential for an IT system
• Includes hardware, network, and circuitry of equipment
Computers
• The devices that process information in a meaningful way
• Found in smartphones, ovens, and grocery store kiosks

Security Policy:
Cybersecurity plays a crucial role in the digital world. Securing information and data has
become one of the most important challenges in the present day. Whenever we expect
cybersecurity the primary thing that involves our mind is cyber crimes which are increasing
immensely day by day. Various Governments and Organizations are taking many measures to
stop these cybercrimes. Besides various measures, cybersecurity remains a massive concern to
several.
Cyberspace is a complex environment consisting of interactions between people, software,
and services, supported by the worldwide distribution of information and communication
technology (ICT) devices and networks.
Insider threats affect more than 34% of organizations worldwide each year because of this,
cybersecurity needs to be a top priority and concern for all employees within a company, not
just the senior management and IT staff. Employees are frequently the weakest point in a
company’s security strategy because they unintentionally click on malicious links and
-Prof. Atul Thaware(FoST,SAS)

attachments, share passwords, and fail to encrypt sensitive files. A cybersecurity policy that
details each employee’s obligations for safeguarding the organization’s systems and data is a
useful tool for educating staff members about the significance of security.

Common cybersecurity techniques:


• Firewalls:
Network security devices that filter incoming and outgoing traffic to protect against
unauthorized access.
• Intrusion detection/prevention systems (IDS/IPS):
Monitor network traffic for malicious activity and can take actions to block attacks.
• Anti-malware software:
Detects and removes malicious software like viruses, ransomware, and Trojans.
• Email filtering:
Filtering spam emails and attachments to prevent phishing attacks.
• Password management tools:
Enforcing strong password policies and managing user credentials securely.
• Data backups:
Regularly backing up critical data to enable recovery in case of a system failure or cyber attack.
• Security awareness training:
Educating employees about common cyber threats and best practices to protect sensitive
information.
• Network segmentation:
Dividing a network into smaller, isolated segments to limit the spread of attacks.
• Endpoint security:
Protecting individual devices like laptops and desktops with antivirus software and security
configurations.

Cyber Security Steps


1 .Risk management regime
Assess the risks to your organisation’s information and systems by embedding an appropriate
risk management regime. This should be supported by the Board and senior managers. Ensure
that all employees, contractors and suppliers are aware of the approach and any applicable risk
boundaries.
-Prof. Atul Thaware(FoST,SAS)

2. Secure configuration
Having an approach to identify baseline technology builds and processes for ensuring
configuration management can greatly improve the security of systems.
You should develop a strategy to remove or disable unnecessary functionality from systems,
and to quickly fix known vulnerabilities, usually via patching. Failure to do so is likely to result
in increased risk of compromise of systems and information.
3. Network security
Connections from your networks to the Internet and other partner networks, expose your
systems and technologies to a potential attack.
Reduce the chances of your systems and technologies being attacked by creating and
implementing simple policies and appropriate architectural and technical responses. Your
organisation's networks almost certainly span many sites and the use of mobile or remote
working, and cloud services, makes defining a fixed network boundary difficult. Rather than
focusing purely on physical connections, think about where your data is stored and processed,
and where an attacker would have the opportunity to interfere with it.
4. Managing user privileges
If users are provided with unnecessary system privileges or data access rights, then the risk of
misuse or compromise is increased. All users should be provided with a reasonable (but
minimal) level of system privileges and rights needed for their role. The granting of highly
elevated system privileges should be carefully controlled and managed. This principle is
sometimes referred to as ‘least privilege’.
5. User education and awareness
Users have a critical role to play in their organisation’s security. It is important to educate staff
on the potential cyber risks, to ensure users can do their job as well as help keep the organisation
secure.
6. Incident management
All organisations will experience security incidents at some point.
Investment in creating effective incident management policies and processes will help to
improve resilience, support business continuity, improve customer and stakeholder confidence
and potentially reduce any impact. You should identify recognised sources (internal or external)
of specialist incident management expertise.
7. Malware prevention
Malicious software, or malware is an umbrella term to cover any code or content that could
have a malicious, undesirable impact on systems. Any exchange of information carries with it
a degree of risk that malware might be exchanged, this could seriously impact your systems
and services. The risk may be reduced by developing and implementing appropriate anti-
malware policies.
8. Monitoring
-Prof. Atul Thaware(FoST,SAS)

System monitoring aims to detect actual or attempted attacks on systems and business services.
Good monitoring is essential in order to effectively respond to attacks. In addition, monitoring
allows you to ensure that systems are being used appropriately in accordance with
organisational policies. Monitoring is often a key capability needed to comply with legal or
regulatory requirements.
9. Removable media controls
Produce a policy to control all access to removable media. Limit media types and use. Scan all
media for malware before importing onto the corporate system.
10. Home and mobile working
Mobile working and remote system access offers great benefits, but exposes new risks that
need to be managed. Risk based policies and procedures that support mobile working or remote
access to systems that are relevant to users, as well as service providers should be created. Train
users on the secure use of their mobile devices in the environments they are likely to be working
in.

Categories:
Ten types of cybersecurity
Many types of cybersecurity are employed to protect digital systems from malicious and
accidental threats. It is helpful to understand the ten most commonly referenced types of
cybersecurity.
1. Application security
Application security prevents unauthorized access and use of applications and connected data.
Because most vulnerabilities are introduced during the development and publishing stages,
application security includes many types of cybersecurity solutions to help identify flaws
during the design and development phases that could be exploited and alert teams so they can
be fixed.
Despite best efforts, flaws do slip through the cracks. Application security also helps protect
against these vulnerabilities.
A subset of application security is web application security. It focuses on protecting web
applications, which are frequently targeted by cyber attacks.
2. Cloud security
Cloud security focuses on protecting cloud-based assets and services, including applications,
data, and infrastructure. Most cloud security is managed as a shared responsibility between
organizations and cloud service providers.
In this shared responsibility model, cloud service providers handle security for the cloud
environment, and organizations secure what is in the cloud. Generally, the responsibilities are
divided as shown below.
3. Critical infrastructure security
Special security processes and types of cybersecurity solutions are used to protect the
-Prof. Atul Thaware(FoST,SAS)

networks, applications, systems, and digital assets depended on by critical infrastructure


organizations (e.g., communications, dams, energy, public sector, and transportation). Critical
infrastructure has been more vulnerable to cyber attacks that target legacy systems, such as
SCADA (supervisory control and data acquisition) systems. While critical infrastructure
organizations use many of the same types of cybersecurity as other subcategories, it is often
deployed in different ways.
4. Data security
A subset of information security, data security combines many types of cybersecurity solutions
to protect the confidentiality, integrity, and availability of digital assets at rest (i.e., while being
stored) and in motion (i.e., while being transmitted).
5. Endpoint security
Desktops, laptops, mobile devices, servers, and other endpoints are the most common entry
point for cyber attacks. Endpoint security protects these devices and the data they house. It also
encompasses other types of cybersecurity that are used to protect networks from cyberattacks
that use endpoints as the point of entry.
6. IoT (Internet of Things) security
IoT security seeks to minimize the vulnerabilities that these proliferating devices bring to
organizations. It uses different types of cybersecurity to detect and classify them, segment
them to limit network exposure, and seek to mitigate threats related to unpatched firmware
and other related flaws.
7. Mobile security
Mobile security encompasses types of cybersecurity used to protect mobile devices (e.g.,
phones, tablets, and laptops) from unauthorized access and becoming an attack vector used to
get into and move networks.
8. Network security
Network security includes software and hardware solutions that protect against incidents that
result in unauthorized access or service disruption. This includes monitoring and responding to
risks that impact network software (e.g., operating systems and protocols) and hardware (e.g.,
servers, clients, hubs, switches, bridges, peers, and connecting devices).
The majority of cyber attacks start over a network. Network cybersecurity is designed to
monitor, detect, and respond to network-focused threats.
9. Operational security
Operational security covers many types of cybersecurity processes and technology used to
protect sensitive systems and data by establishing protocols for access and monitoring to detect
unusual behavior that could be a sign of malicious activity.
10. Zero trust
The zero trust security model replaces the traditional perimeter-focused approach of building
walls around an organization’s critical assets and systems. There are several defining
characteristics of the zero trust approach, which leverages many types of cybersecurity.
-Prof. Atul Thaware(FoST,SAS)

Model of Network Security

Fig. Model of Network Security

Basic Tasks

This general model shows that there are four basic tasks in designing a particular
security service:

1. Design an algorithm for performing the security-related


transformation. The algorithm should be such that an opponent
cannot defeat its purpose.

2. Generate the secret information to be used with the algorithm.

3. Develop methods for the distribution and sharing of the secret


information.

4. Specify a protocol to be used by the two principals that makes


use of the security algorithm and the secret information to achieve
a particular security service.

Basic Terminology in Network Security :


-Prof. Atul Thaware(FoST,SAS)

• Unauthorized access − An unauthorized access is when someone gains access to a


server, website, or other sensitive data using someone else's account details.
• Hacker − Is a Person who tries and exploits a computer system for a reason which can
be money, a social cause, fun etc.
• Threat − Is an action or event that might compromise the security.
• Vulnerability − It is a weakness, a design problem or implementation error in a system
that can lead to an unexpected and undesirable event regarding security system.
• Attack − Is an assault on the system security that is delivered by a person or a machine
to a system. It violates security.
• Antivirus or Antimalware − Is a software that operates on different OS which is used
to prevent from malicious software.
• Social Engineering − Is a technique that a hacker uses to stole data by a person for
different for purposes by psychological manipulation combined with social scenes.
• Virus − It is a malicious software that installs on your computer without your consent
for a bad purpose.
• Firewall − It is a software or hardware which is used to filter network traffic based on
rules.
Threats and Vulnerability:
Threat :
A cyber threat is a malicious act that seeks to steal or damage data or discompose the digital
network or system. Threats can also be defined as the possibility of a successful cyber attack
to get access to the sensitive data of a system unethically. Examples of threats
include computer viruses, Denial of Service (DoS) attacks, data breaches, and even
sometimes dishonest employees.
Types of Threat
Threats could be of three types, which are as follows:
1. Intentional- Malware, phishing, and accessing someone’s account illegally, etc. are
examples of intentional threats.
2. Unintentional- Unintentional threats are considered human errors, for example,
forgetting to update the firewall or the anti-virus could make the system more
vulnerable.
3. Natural- Natural disasters can also damage the data, they are known as natural threats.
Vulnerability :
In cybersecurity, a vulnerability is a flaw in a system’s design, security procedures, internal
controls, etc., that can be exploited by cybercriminals. In some very rare cases, cyber
vulnerabilities are created as a result of cyberattacks, not because of network
-Prof. Atul Thaware(FoST,SAS)

misconfigurations. Even it can be caused if any employee anyhow downloads a virus or a social
engineering attack.
Types of Vulnerability
Vulnerabilities could be of many types, based on different criteria, some of them are:
1. Network- Network vulnerability is caused when there are some flaws in the network’s
hardware or software.
2. Operating system- When an operating system designer designs an operating system
with a policy that grants every program/user to have full access to the computer, it
allows viruses and malware to make changes on behalf of the administrator.
3. Human- Users’ negligence can cause vulnerabilities in the system.
4. Process- Specific process control can also cause vulnerabilities in the system.
Real World Examples of Threat, Vulnerability and Risk in Computer Network
Threats
1. The WannaCry Ransomware Attack in 2017 used flaws in Microsoft Windows by
encrypting data and demand ransom payments from users.
2. Phishing Attacks, is the attack where the attacker uses email to tricks users into
disclosing their personal information that leads to data breaches or financial loss.
3. A malicious code was inserted into SolarWinds Orion software by the hackers that made
it’s supply chain security vulnerable.
Vulnerabilities
1. A bug in the OpenSSL cryptographic package allowed attackers to access sensitive data
from different sites using this package.
2. In 2018, critical vulnerabilities was found in modern processors permitted unauthorized
access to data stored in memory.
3. A multiple zero-day vulnerabilities, together referred as ProxyLogon, allowed
attackers to inject malware in Microsoft Exchange Server, which made it possible for
the hackers to access email accounts.

Difference Between Threat, Vulnerability, and Risk


-Prof. Atul Thaware(FoST,SAS)

Threat Vulnerability

Take advantage of vulnerabilities in


Known as the weakness in hardware, software, or
the system and have the potential to
designs, which might allow cyber threats to happen.
steal and damage data.

Generally, can’t be controlled Can be controlled

It may or may not be intentional. Generally, unintentional

Vulnerability management is a process of


Can be blocked by managing the identifying the problems, then categorizing them,
vulnerabilities prioritizing them, and resolving the vulnerabilities
in that order

Can be detected by anti-virus Can be detected by penetration testing hardware and


software and threat detection logs many vulnerability scanners

Thank you ….

You might also like