0% found this document useful (0 votes)
19 views4 pages

Understanding Computer Security Basics

Computer security involves protecting information systems, networks, and data from unauthorized access, modification, or destruction, focusing on confidentiality, integrity, and availability (CIA Triad). It encompasses various challenges, concepts, and countermeasures to safeguard assets against vulnerabilities and attacks. A comprehensive security strategy includes defining policies, implementing mechanisms, and ensuring assurance through continuous monitoring and evaluation.

Uploaded by

hadiparvez3722
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
19 views4 pages

Understanding Computer Security Basics

Computer security involves protecting information systems, networks, and data from unauthorized access, modification, or destruction, focusing on confidentiality, integrity, and availability (CIA Triad). It encompasses various challenges, concepts, and countermeasures to safeguard assets against vulnerabilities and attacks. A comprehensive security strategy includes defining policies, implementing mechanisms, and ensuring assurance through continuous monitoring and evaluation.

Uploaded by

hadiparvez3722
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

What is Computer Security?

Computer Security ka matlab hai apni information systems, networks, aur data ko unauthorized access,
modification, ya destruction se protect karna. Iska goal hai ke information ki Confidentiality (raazdaari),
Integrity (sahi aur unchanged data), aur Availability (system hamesha kaam kare) safe rahe.

According to NIST: Computer security is the protection given to an automated information system to
preserve confidentiality, integrity, and availability of resources like hardware, software, firmware, and
data. Yani security sirf data tak limited nahi balki poore system ke har part tak hoti hai.

CIA Triad (Three Core Objectives)


1. Confidentiality: Ye ensure karta hai ke sirf authorized log hi data dekh sakein. Unauthorized log
data access na kar saken.
Example: Student grade report sirf student aur teacher dekh sakte hain.
High Confidentiality: Grades, medical data (agar leak ho jaye to legal issue).
Medium: Enrollment data (thoda sensitive).
Low: Public directory (kam sensitive).

2. Integrity: Data correct aur unchanged rahe. Agar koi malicious banda data badal de to result galat
ho jata hai.
Example: Hospital allergy data badalne se jaan ka khatra ho sakta hai.
High: Patient data, Medium: Forum posts, Low: Online poll results.

3. Availability: System accessible rahe jab zarurat ho.


Example: Bank authentication service down ho gaya to users kaam nahi kar sakte.
High: Critical services, Medium: University website, Low: Telephone directory lookup.

Beyond CIA Triad (Additional Concepts)


Authenticity: Information asli source se aayi ho. Example: Email waqai original sender ka ho.
Accountability: Har action traceable ho. Kisne kya kiya record hona chahiye. Ye non-repudiation aur
investigation ke liye zaroori hota hai.

Challenges in Computer Security (Detailed)


1. Not Simple: Security ke concepts simple lagte hain lekin unke mathematical aur technical
mechanisms complex hote hain.
2. Attackers Think Differently: Attackers nayi soch aur unexpected tareeqe se attack karte hain.
3. Counterintuitive Mechanisms: Multi-step logins pehle complex lagte hain par zaroori hote hain.
4. Placement of Security: Decide karna padta hai security kaha implement karni hai (network, system,
ya application).
5. Secret Management: Encryption keys aur passwords secure rakhna sabse tough part hai.
6. Battle of Wits: Attackers ko sirf ek weakness chahiye, defenders ko har jagah defense lagani padti
hai.
7. Security Investment Paradox: Log tabhi security pe paisa lagate hain jab koi attack ho jaye.
8. Constant Monitoring: Security ek continuous process hai; monitoring aur updates zaroori hain.
9. Security as an Afterthought: System design ke baad add karna mushkil hota hai.
10. Usability vs Security: Strong security kabhi kabhi system ko mushkil bana deti hai (users
frustrated ho jate hain).

Important Security Terms


Adversary (Threat Agent): Wo banda jo system ko attack kare.
Attack: Jab threat action me badal jaye.
Countermeasure: Protection measure (e.g., antivirus, firewall).
Risk: Loss hone ki probability (threat + vulnerability).
Security Policy: Rules jo define karte hain system ko kaise protect karna hai.
Asset: Valuable resource (data, system, network).
Threat: Potential danger jo exploit kar sakta hai.
Vulnerability: Weakness system me jahan se attack ho sakta hai.

Assets of a Computer System


1. Hardware: Threats – Theft, damage. Countermeasure – Physical locks, CCTV, restricted access.
2. Software: Threats – Virus, deletion, piracy. Countermeasure – Backup, antivirus, updates.
3. Data: Threats – Unauthorized access, deletion, modification. Countermeasure – Encryption, access
control.
4. Network: Threats – Eavesdropping, message modification, DoS. Countermeasure – Secure
protocols, authentication, firewalls.

Vulnerabilities and Attacks


Vulnerability Types:
- Corruption (Integrity issue): Data modify ho jata hai.
- Leakage (Confidentiality issue): Data unauthorized logon tak chala jaye.
- Unavailability (Availability issue): System down ho jaye.

Attack Categories:
1. Passive Attacks: Data sirf read karte hain (eavesdropping, traffic analysis). Hard to detect. Defense
– Encryption.
2. Active Attacks: Data change karte hain (Replay, Masquerade, Modification, DoS). Hard to prevent,
so detection + recovery use hoti hai.

Countermeasures (Protection Methods)


1. Prevention: Attack hone se pehle rokna (firewall, passwords, access control).
2. Detection: Attack hone par pehchan na (intrusion detection systems).
3. Recovery: Damage ke baad system restore karna (backup, restore, patching).

Even after protection, thoda residual risk hamesha rehta hai.

FIPS 200 – 17 Functional Security Requirements (Summary + Explanation)


1. Access Control: Sirf authorized logon ko access dena.
2. Awareness & Training: Users ko security ke bare me educate karna.
3. Audit & Accountability: System activity record karna taake misuse trace ho.
4. Certification & Assessment: Regularly system security test karna.
5. Configuration Management: Secure system settings maintain karna.
6. Contingency Planning: Backup & recovery plans banaye rakhna.
7. Identification & Authentication: Users ki identity verify karna.
8. Incident Response: Attack hone par handle karna aur report karna.
9. Maintenance: System updates securely karna.
10. Media Protection: Data storage devices protect karna.
11. Physical Protection: Facilities aur equipment secure karna.
12. Planning: Security plans document karna.
13. Personnel Security: Employees trustworthy hone chahiye.
14. Risk Assessment: Regularly nayi threats ka analysis karna.
15. System Acquisition: Naye systems me security include karna.
16. System & Communication Protection: Data transmission secure karna.
17. System & Information Integrity: Malware se protection aur system flaws fix karna.

Security Design Principles (Detailed Explanation)


1. Economy of Mechanism: Design simple aur chhota rakho.
2. Fail-Safe Defaults: Default deny access, safety first.
3. Complete Mediation: Har access request verify karo.
4. Open Design: Algorithm public ho sakta hai, key secret rehni chahiye.
5. Separation of Privilege: Multi-factor authentication (e.g., password + OTP).
6. Least Privilege: User ko sirf zarurat ke mutabiq rights do.
7. Least Common Mechanism: Shared resources minimize karo.
8. Psychological Acceptability: Easy to use security (users confuse na hon).
9. Isolation: Critical aur public data ko separate rakho.
10. Encapsulation: Internal details hide karo (OOP style).
11. Modularity: System ko modules me divide karo.
12. Layering (Defense in Depth): Multiple security layers lagao.
13. Least Astonishment: User interface predictable aur simple rakho.

Attack Surface & Attack Trees


Attack Surface: System ke wo sab entry points jahan se attacker ghus sakta hai (open ports, weak
passwords, human error).
Types: Network, Software, Human.

Attack Trees: Ek diagram hota hai jahan attacker ka main goal (root) aur sub-goals (branches) show
kiye jate hain. Example: Bank account hack karne ke liye — password steal, phishing, malware, etc.

Overall Computer Security Strategy


Security ek 3-step process hai:

1. Policy (What to protect?): Define karna ke kya cheez secure karni hai (CIA Triad).
2. Mechanisms (How to protect?): Implement karna (encryption, firewalls, monitoring).
3. Assurance (Does it work?): Testing, evaluation aur verification karna ke system waqai secure hai
ya nahi.

Conclusion: Security ek continuous process hai. Goal ye nahi ke 100% protection mile, balki risk ko
minimum level par lana hai.

You might also like