Chapter 11
Answer 1:
Answer 2:
Vulnerabilities are the gateways by which threats are manifested" .In other words, a
system compromise can occur through a weakness found in a system. A
vulnerability assessment is a search for these weaknesses/exposures in order to
apply a patch or fix to prevent a compromise.
There is some disagreement on the proper vulnerability reporting protocol. First,
BugTraq publishes the exploit scripts. But other organizations, such as CERT,
FIRST, and NIPC publish vulnerabilities without the exploit scripts. Each has their
reasons for doing so. The difference in opinion is due to the fact that many attackers
exploit the newly published vulnerabilities. Second, a person should act responsibly
after discovering a vulnerability. Before releasing the problem to the public, they
should give the vendor ample time to provide a patch. Releasing the problem to the
public too soon can cause an increase in malicious behavior. In light of this
difference of opinion, committees have been formed by security-industry leaders
to standardize security practices. One event, held in November 2000, was the
Security Vulnerability Summit , a gathering of thirty industry leaders "to identify and
discuss the principal issues surrounding security vulnerability disclosures". The goal
of the Summit was to "create a clear, timely, and predictable process by which
customers, vendors, government organizations and other key parties can be alerted
to potential security threats and take the appropriate measures to protect their digital
assets".
One of the problems in the vulnerability reporting process is that receivers involved
may have a negative attitude towards reporting software vulnerabilities. They do not
necessarily see any value in supporting the development of the reporting process.
The reports may not be taken seriously. For this reason it is important to have a
closer look at the information reception and processing theories that consider
attitudes and attitude change. The information-integration theory explains how
people accumulate and
organize information about some person, object, situation, or idea to form attitudes
toward a concept. The theory states that all information has the potential of affecting
one's attitudes. However, the degree to which it does so depends on two variables:
valence and weight assigned to the information. Valence is the degree to which the
information is viewed as supporting one's beliefs or not. If the information supports
one’s beliefs, the new information is seen as positive. Otherwise it is seen to be
negative. The weight assigned to the information is the importance of the information
to the receiver.
Attitudes differ from beliefs in that they are evaluative. Attitudes are learned as part
of one's concept formation. They may change as new learning occurs throughout life.
Behavior results in part from intentions, a complex outcome of [Link]
theories claim that people are more comfortable with consistency than inconsistency.
Therefore consistency can be seen as the primary principle that organizes cognitive
processing. Attitude change can result from information that disrupts this balance.
Rokeach (1968) has formed a theory of behavior based on beliefs, attitudes and
values. Beliefs are the various statements people make about the world. Beliefs can
be organized hierarchically. The most important of them form the core of the belief
system. More insignificant beliefs lie at the periphery of the system. Core beliefs are
difficult to change and change in them has a great impact on the whole system.
Various beliefs toward an issue form an attitude. Rokeach (1968, 112) defines an
attitude as follows: “An attitude is a relatively enduring organization of beliefs around
an object or situation predisposing one to respond in some preferential manner”.
Attitudes are even more difficult to change. Related to the vulnerability reporting
process the interesting part of the theory is that Rokeach states that there are two
kinds of attitudes: those toward an object and those toward a situation. These must
always be considered together. For example, a person may consider that
vulnerabilities should always be handled with care, but he might still support full
disclosure because of the context in which the vulnerabilities are handled, i.e., the
situation. One of the most popular information processing theories today is the
elaboration likelihood theory. It was developed by Petty and Cacioppo in 1986.
According to this theory the likelihood of elaboration, or the likelihood of critical
interpretation of the content of the message, depends on the way a
person processes the information. Critical thinking occurs if the person processes
the information while concentrated. This means that they use the central route of
their cognition when processing information. If the receiver is not concentrated, they
process the information in the peripheral route. Factors that influence the degree of
elaboration are for example motivation, ability to elaborate and the receiver's
predisposition. This phenomenon may have an effect on the vulnerability reporting
process because the receiver may not be concentrated when they receive the
message. When reading dozens of emails daily, a receiver may not fully understand
the meaning of a vulnerability report. This is especially the case if they have no
previous experience in the field.
Answer 3:
Yes i will hire Goli.
If Goli tells me about a vulnerability in your system and offering to help you fix it i will accept
the offer, because the computer these days are very susceptible to hacking, and if Goli can
rectify anything to protect the information on my system, I will accept the offer.
Answer 4:
i won't share files with anonymous on platform like napster . my reasons are of security and
its illegal because in 2000 US supreme has court has found napster is infinging copyright
material so its seems illegal . for security anyone could attach their attack with music files
and i could be easily attacked.
Answer 5:
While not only is this considered stealing internet service, the use of someone else's
unprotected network opens your own computer up to potential threats, such as viruses and
identity theft. This is an ethically unsound action that will not only hurt the internet provider,
but could possibly hurt you in the process.
Also, imagine what would happen if thousands or millions of people decided to do this - that
would mean less money building up the GDP, less money circulating to help our economy
recover.
Answer 6:
a) The speculates on the ethics of informing an owner about vulnerabilities over the
network. The node is actual probable victim a future crime, it not only ethical highly
advisable about the issue.
b) The problem speculates the ethics informing local administrator or security officer
a vulnerable system the network. The actual point of administrator is control in this
case. It is advisable and ethical to inform him r her the issue about possible, is also
advisable suggest future of action.
c) The speculates the ethics of exploiting a minor vulnerability the network. The
owner of the node is actual probable victim of a future infraction to advisable to
inform him the issue the given consent be deemed ethical exploit vulnerability for
owner information and knowledge possible threats.
d) The speculates the ethics minor vulnerability the network. The owner of the node
is the acutal probable victim a future infraction to inform him the issue. It is unethical
exploit without consent vulnerability the action is illegal and similar to hacking.
e) The speculates the ethics of exploiting minor vulnerability the network. The owner
of the node is the acutal probable victim a future infraction to inform him the issue.
And selling him further details borders of ethicality. It is the owner has already
informed the vulnerability has a choice her or she of obtaining future services. Thus,
detailed selling data is still ethical.
f) The problem speculates on the ethics of fixing vulnerabilities without consent over
the network. Since the onwer of he nodes is the actual probable victim of a future
infraction, it is advisable and unethical to exploit vulnerability without consent the
purpose is honorable and noble.
Answer 8:
2. A) It is one of the work of Internet Service Proiders to manage good DNS servers,
to allow proper and quick response to and from the Internet in doing so, if ISP
considers it to track every HTTP exchange from all its customers such that a better
and relevant services can be provided to the customers. The main reason the
Internet Service Providers started to track down the HTTP exchange here is to
ascertain a better service to their customers, this behavior can be considered ethical,
since an optimization is on it's way in favour of customers provided confidentiality of
data obtained by ISP must be maintained.
2.B) If ISP starts to track down the HTTP exchange to derive revenue by selling the
data to advertisers, is an unethical behavior, since the confidential information of the
customers is shared without their consents as well as the biased behavior that must
have to be one of the ethics of ISP will be violated, since by selling the proprietary
information to some of the selected sites or advertisers, he is becoming unbiased
towards the other available over the Internet
2.C) In the case of Government Analysis, the sharing of information can be done,
because by dong so a series of outcomes can be produced in favour of customers
and it is for certain that the information is under a security of well known authority,
that is trying to work good something out of the details provided, in this case make
availablity of Traffic Records for governmnet analysis, thus providing the possibility
of an improvement in traffic and road networking systems currently there.
Answer 10:
This case concerns decide first howmuch business is going when red is a king of kingdom
and his nameusing. It is only one person's decision and availability ofqualitative response
from people we have to take. The personinvolved is permitted to access given for business
for a certainpurpose. Many organizations feel unwritten standard of behaviourthat governs
the actions of people who have legitimate access to amaintaining/organizing the system The
ethical issues involvedin this case can lead to an understanding of that unwrittenstandard.
Answer 12: