0% found this document useful (0 votes)
8 views13 pages

Cybersecurity Risks and Mitigation Strategies

This document presents a summary of a paper on computer security. It includes an introduction to the topic, recommendations for avoiding cyber attacks, a table with common ports and applications, an analysis of cases of cyber threats, and protection strategies. Finally, it presents the results of a port scan on a corporate network.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views13 pages

Cybersecurity Risks and Mitigation Strategies

This document presents a summary of a paper on computer security. It includes an introduction to the topic, recommendations for avoiding cyber attacks, a table with common ports and applications, an analysis of cases of cyber threats, and protection strategies. Finally, it presents the results of a port scan on a corporate network.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

NOMBRE:

Alexander Pérez Feliz

ENROLLMENT:

201803811

SUBJECT:

Computer security

THEME:

Unit II Work

FACILITATOR:

Maria A. Sosa S.

30 de Enero del 2021


Santo Domingo, Dominican Republic.
Introduction

In this work, we will see how there will always be the risk of being a victim of
a cyberattack, which can cause damage to the company's image or
information subtractions, even causing legal situations as well as
also economic losses, for the above reasons it is necessary to know the
risks, measure them and evaluate them to prevent them, applying policies to mitigate them
risks, implementing appropriate security measures, in our networks and in
access to information.
We also want to make some important recommendations, which from
our point of view is essential to avoid being a victim of some of
the most used attacks or vulnerabilities by cybercrime, including the
find the following:

Always keep the application versions up to date.


2. Download from the official repositories (AppStore or Google)
Play) or failing that from the company's official and verified page.
3. Have robust security solutions to keep monitored the
activity of the devices at all their layers.
4. Have security solutions also on mobile devices.
5. Always check where personal information is entered or
private.
6. Avoid accessing links that arrive through messaging services with
offers or messages of dubious origin.
Present in a table themost used ports and applications
Associated with these.

Analysis of real-life cases in which it is possible to visualize some of the


most common threats. Present your point of view you must include the
following elements:

Among the most common methods used by cybercriminals to attack


to people and company networks to steal information, whether it is
financial or of any other type, we will now mention the most
used:
Among these, we want to mention the following:

NAME OF THE THREAT DESCRIPTION OF THE ATTACK


Commonly known as virus
computer scientist, allows to perform
Malware or malicious code different actions to an attacker.
From generic threats through
the use of trojans, to attacks
precision guided, with objectives
specific and designed for assault
devices, configurations o
specific network components.
They use persuasion techniques that
Social engineering they take advantage of the goodwill and lack
of the victim's precaution to
obtain sensitive information or
confidential.
Coordinated attacks directed at
against a company or organization,
APT or Advanced Persistent Threats they are trying to steal or leak
Advanced information without being identified. It
they usually help with techniques of
social engineering and they are difficult to
detect
Also called denial of
DoS Attack service, is an attack on a system
of computers or network, that causes
that a service or resource be
inaccessible to legitimate users.
The more known son the
Identity theft IP spoofing, ARP spoofing, DNS spoofing,
web and email spoofing
electronic and even of networks
social
Reference link for the information
[Link]
sights
[Link]
computer science/
[Link]
information-systems/
[Link]
avoid them
Investing in security
information-is-avoiding-losses-of-money-and-corporate-reputation/

In a quarter the contributions regarding the found case.


Cyber Attack in the Dominican Republic during the Covid-19 pandemic.

The health situation in our country has been exploited by the


cybercriminals to try to access personal, business data and
banking, through social engineering and misinformation. Since
The pandemic affected our island until the month of July with Botnet infections.
increased by 46%.

Between March and July 20 of this year, 1,450,340 attacks were recorded.
Botnet infections, while in the same period of 2019 the attacks of
this type was 996,697, according to data from the National Cybersecurity Center
(CNCS). According to CNCS data, the activity that showed an increase of
593% between March and April of this year compared to the same date in 2019.
It went from 228 detected phishing links in March 2020 to 1,580 in May of
same year.

Finally, according to Google data, in recent months there have been


sent more than 100 million spam emails to accounts on its service, being the
phishing the main channel used by cyber attackers to send codes
and malicious links for information theft.
Strategies to consider to avoid and protect oneself from these
threats.

To mitigate the risks and protect ourselves from these threats, it is advisable
always maintain a posture of 'cyber hygiene' and keep our devices
updated, in addition to avoiding downloading or accessing dubious links
origin.
It is also advisable that when making online payments, it should always be done through
from the channels established by the businesses, as well as using applications of
trust for virtual meetings, applying security and control measures
of privacy that different platforms offer.

Make aPort Scannerin the network of a company and presents the following
elements:
Network exploration.
Creation of a Favorites list of teams for regular use
Identify the list of ports
Radmin and Advanced Port Scanner

Network devices.
It is a device that enables communication with connected devices.
yes and it also allows sharing resources between two or more computers.
Shared folders and FTP servers
The remote control of computers (via RDP and Radmin)

RDP.

RDP is the acronym for Remote Desktop Protocol.


Remote in Spanish. RDP is a technology developed by Microsoft and
que facilita el control remoto de una computadora con Windows sin
the need to be in front of her. This function, very simple and easy to
implement in computer parks of a company or office, it has
their pros and cons, of course.

The remote desktop technology that Windows uses by default is not


bad by itself. The problem is that, on one hand, it is activated.
even if we don't need it and, on the other hand, the password defined by
defect is rather weak. Hence, cybercriminals search for
Internet systems with RDP connected and use brute force attacks
to find out the chosen password.

Radmin (also known as Remote Administrator) is one of the


most well-known remote control programs. Radmin stands out
especially for the quality of the image received in real time, and the
reduced response time, as long as the Internet connection is
fast.
In addition to controlling the screen, you can also execute line of
commands, access the files, start a text and voice chat,
turn off the system, transfer the contents of the client's clipboard to
guest and much more.
This tool also features built-in security functions.
made to measure and all transmitted data is protected by
AES encryption of 256 bits. Since it was developed 17 years ago,
no vulnerability has ever been found.
Conclusion

In conclusion, we must be aware that it is almost impossible to maintain


all risks under control, because there will be threats that we will not be able to
control. To do this, it is necessary to always be protected with a good plan of
security and cyber risk.

You might also like