0% found this document useful (0 votes)
28 views40 pages

Automated Attack Tools in Cybersecurity

The document introduces the topic of network security. It discusses that network security refers to the measures taken by organizations to secure their computer networks and data. It aims to secure confidentiality and accessibility of data and networks. The document then provides an overview of some key aspects of network security, including the different levels (physical, technical, administrative), types (antivirus software, firewalls, application security), and some key terminology (asset, vulnerability, threat, risk, countermeasure). It also briefly outlines the course chapters that will be covered.

Uploaded by

Official Aminho
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
28 views40 pages

Automated Attack Tools in Cybersecurity

The document introduces the topic of network security. It discusses that network security refers to the measures taken by organizations to secure their computer networks and data. It aims to secure confidentiality and accessibility of data and networks. The document then provides an overview of some key aspects of network security, including the different levels (physical, technical, administrative), types (antivirus software, firewalls, application security), and some key terminology (asset, vulnerability, threat, risk, countermeasure). It also briefly outlines the course chapters that will be covered.

Uploaded by

Official Aminho
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Network Security

CHAPTER ONE: INTRODUCTION TO NETWORK SECURITY

LECTURER: KHALID GABBAL


Course Chapters: Course Evaluation:
Chapter One: Introduction to Network security
Final Exam: 60%
Chapter Two: Malware, Vulnerability and Threats.
Mid Exam: 20%
Chapter Three: Wireless network Security
Assignments: 10%
Chapter Four: Firewalls and Internet security
Attendance: 10%
Chapter Five: Network Security & Disaster recovery
Chapter Six: Transport layer security (Web-security)

LECTURER: KHALID GABBAL


Security?
 In the broadest sense security can be defined as the protection of assets.
There are three main aspects to security:
 Prevention
 Detection
 Reaction.
 Consider security in the traditional sense – for example, securing your house against
burglary. You may take steps to prevent a burglary such as locking the doors and windows
and installing a burglar alarm. If a burglary did occur, you would be able to detect this
because items would be missing and the burglar may have caused damage to your house
while breaking in. You might react to the burglary by reporting it to the police, working out
what had been stolen and making an insurance claim.

LECTURER: KHALID GABBAL


Introduction to Network Security
Network Security refers to the measures taken by any enterprise or organization to secure its computer
network and data using both hardware and software systems. This aims at securing the confidentiality and
accessibility of the data and network. Every company or organization that handles large amount of data, has a
degree of solutions against many cyber threats.
 The most basic example of Network Security is password protection where the user of the network oneself
chooses. In the recent times, Network Security has become the central topic of cyber security with many
organizations inviting applications of people who have skills in this area.
The network security solutions protect various vulnerabilities of the computer systems such as:
1. Users:
2. Locations
3. Data:
4. Devises:
5. Applications:
LECTURER: KHALID GABBAL
Difference between
 Network Security:
Network Security is the measures taken by any enterprise or organization to secure
its computer network and data using both hardware and software systems. This aims
at securing the confidentiality and accessibility of the data and network. Every
company or organization that handles large amount of data, has a degree of solutions
against many cyber threats.
Cyber Security:
Cyber Security is the measures to protect our system from cyber attacks and
malicious attacks. It is basically to advance our security of the system so that we can
prevent unauthorized access of our system from attacker. It protects the cyberspace
from attacks and damages. Cyberspace can be hampered by inherent vulnerabilities
that cannot be removed sometimes.

LECTURER: KHALID GABBAL


NETWORK SECURITY CYBER SECURITY

1. It protects the data residing in the devices


1. It protects the data flowing over the
and servers.
network.
2. It is a subset of information security.
2. It is a subset of cyber security.
3. It protects anything in the cyber realm.
3. It protects anything in the network realm.
4. It deals with the protection from cyber
4. It deals with the protection from DOS
attacks.
attacks.
5. Cyber Security strikes against cyber crimes
5. Network Security strikes against Trojans.
and cyber frauds.
6. It includes viruses and worms.
6. It includes phishing and pre-texting.
7. Network security ensures to protect the
7. Cyber security ensures to protect entire
transit data only.
digital data.
8. It secures the data travelling across the
8. It deals with the protection of the data
network by terminals.
resting.

LECTURER: KHALID GABBAL


Security Terminology
Asset: Vulnerability
 Anything that is valuable to  Weakness which allows attacker to reduce the
security assurance.
organization (that is to be
protected) Vulnerability can be found in
 Can include property, people, Protocols
and information/data that have Operating Systems
value to the company. Applications
 Institution records, client System Design
information, propriety software
Poor network design
and so on.
Hardware

LECTURER: KHALID GABBAL


Security terminology cont,..
THREAT
 Event which causes damage to systems,
exploiting a vulnerability.
COUNTERMEASURE
 Physical ( Fire, water, Earthquake)
 Reducing or eliminating the vulnerability
 Malicious codes ( Virus, Trojan, Malware) or potential risk.
 Phishing & Social Engineering.
RISK
 The Probability of a threat or event to happen
 Potential to unauthorized access to asset.
 Potential to destruction/damage of asset.
LECTURER: KHALID GABBAL
Network Security : Working
 The basic principle of network security is protecting
huge stored data and network in layers that ensures a
bedding of rules and regulations that have to be
acknowledged before performing any activity on the data.
 These levels are:
1. Physical
2. Technical
3. Administrative
LECTURER: KHALID GABBAL
Levels of network security:
 Physical Network Security: This is the most basic level that includes protecting the data
and network though unauthorized personnel from acquiring the control over the
confidentiality of the network. These includes external peripherals and routers might be
used for cable connections. The same can be achieved by using devices like bio-metric
systems.
 Technical Network Security: It primarily focusses on protecting the data stored in the
network or data involved in transitions through the network. This type serves two purposes.
One, protection from the unauthorized users and the other being protection from
malicious activities.
 Administrative Network Security:
This level of network security protects user behavior like how the permission has been
granted and how the authorization process takes place. This also ensures the level of
sophistication the network might need for protecting it through all the attacks.

LECTURER: KHALID GABBAL


LECTURER: KHALID GABBAL
Types of Network Security:
 Network security acts as a wall between your network and any malicious activity. This wall will
remain penetrable until you choose for the best solution to protect it. The following types of network
security help you understand which one suits your organization better than the others (based on your
organization’s requirements).
1: Antivirus and Antimalware Software:
 Before directly hopping on to this type of network security, it’s important to know the basic
difference between a “virus” and a “malware.” Virus is a specific term defining a kind of malware
which replicates and spreads across the network, whereas malware is an umbrella term used for
all kinds of malicious code. Everything including viruses, worms, adware, nagware, Trojans,
ransomware, and spyware fall under the category of malware.
 The anti-malware and antivirus (can detect only viruses, unlike anti-malware) software scan for
malware and viruses on entry, it later removes the threat and fixes the damage. First antivirus software
programs used signature-based malware detection approach to look for a pattern (referred to as
signatures) in network traffic or malicious sequences used by malware. It offered good protection from
numerous threats, other than being, fast, easily available, and easy to run.
LECTURER: KHALID GABBAL
Application Security
 Application Security: The name mentions it all. Application security
is software meant to secure the loopholes of your application from the
criminals. It broadly tracks the procedure of finding your application’s
vulnerabilities followed by fixing and preventing them from any
cyberattack. It uses software, hardware, and processes to keep your
assets intact.

LECTURER: KHALID GABBAL


 DLP
Data Loss Prevention (DLP) technology is responsible for securing the communication
network of an organization in order to protect its sensitive data. These days, employees of
an organization are prohibited to upload, forward, or sometimes to print critical
information in an unprotected manner.
 Email Security
Email gateways are a popular medium for the spread of malware, spams, and mainly
phishing attacks. To top it all, social engineering methodologies make these threats appear
genuine and sophisticated. An email application security secures the access and data of an
email account by blocking incoming attacks and controlling the outbound messages.
 Endpoint Security
In network security, endpoint security or endpoint protection technology protects a
corporate network when accessed from different remote devices. This remote access poses
as a potential entry point for security threats.

LECTURER: KHALID GABBAL


Firewalls and IDS
 Firewalls: Network security firewalls monitor the incoming and the outgoing traffic based on a set
of predefined rules. It is a barrier that separates trusted networks from untrusted ones. Hardware,
software, or both can serve as a firewall. Firewall
 Firewalls are used to prevent unauthorized Internet users from accessing private networks
connected to the Internet. All messages are entering or leaving the intranet pass through the firewall.
The firewall examines each message and blocks those that do not meet the specified security criteria.
IDS and IPS: Intrusion Detection System (IDS) is a software application that looks for malicious
activity or a policy violation over a network or system, whereas Intrusion Prevention System (IPS)
is a network threat prevention technology that actively scans network traffic flow to detect potential
threats (or vulnerability exploits) and respond to them accordingly.
 Like, the firewall protects an organization sensitive data from malicious attacks over the Internet,
the Intrusion detection system alerts the system administrator in the case when someone tries to break
in the firewall security and tries to have access on any network in the trusted side.

LECTURER: KHALID GABBAL


Some of the important security technologies used in the
cybersecurity are described below-
Firewall
 Firewall is a computer network security system
designed to prevent unauthorized access to or from
a private network. It can be implemented as
hardware, software, or a combination of both.
 Firewalls are used to prevent unauthorized
Internet users from accessing private networks
connected to the Internet. All messages are
entering or leaving the intranet pass through the
firewall. The firewall examines each message and
blocks those that do not meet the specified security
criteria.

LECTURER: KHALID GABBAL


Packet filtering
 Packet filtering firewalls examine header information
of a data packets that come into a network. This firewall
installed on TCP/IP network and determine whether to
forward it to the next network connection or drop a
packet based on the rules programmed in the firewall.
 It scans network data packets looking for a violation of
the rules of the firewalls database. Most firewall often
based on a combination of:
♦ Internet Protocol (IP) source and destination address.
♦ Direction (inbound or outbound).
♦ Transmission Control Protocol (TCP) or User
Datagram Protocol (UDP) source and destination port
requests.
LECTURER: KHALID GABBAL
Benefits of using firewalls
 It stops attacks on your network from external networks and agents.
 It acts as a filter and keeps away the non-authoritative users.
 It permits monitoring the network security and alarms its users
when any malicious activity is detected.
IT also observes as well as records services used by WWW (World
Wide Web), FTP (File Transfer Protocol), and some other commonly
used protocols.
 It also blocks or un-block those inbound and outbound packets.

LECTURER: KHALID GABBAL


Mobile Device Security:

 All security measures that are designed to protect data, either stored on or
transmitted by mobile devices (such as smartphones, laptops, and tablets) fall
under the Mobile Device Security type.
 With IT organizations switching to mobile devices for the support of corporate
applications, it is important to control the devices accessing your network.

LECTURER: KHALID GABBAL


Network Security concepts:

 The primary goal of


network security are
Confidentiality, Integrity,
and Availability.
 These three pillars of
Network Security are often
represented as CIA
triangle.

LECTURER: KHALID GABBAL


CIA TRIAD

LECTURER: KHALID GABBAL


Breach of security levels of impact

LECTURER: KHALID GABBAL


Challenges of Securing Information
 Universally connected devices. It is virtually unheard of today for a computer to not be
connected to the Internet. Although this greatly expands the functionality of that device, it
also makes it easy for an attacker halfway around the world to silently launch an attack on
any connected device.
 Increased speed of attacks. With modern tools at their disposal, attackers can quickly
scan thousands of systems to find weaknesses and launch attacks with unprecedented speed.
Many tools can even initiate new attacks without any human participation, thus increasing
the speed at which systems are attacked.
Greater sophistication of attacks. Attackers today use common Internet tools and
protocols to send malicious data or commands to strike computers, making it difficult to
distinguish an attack from legitimate traffic. Other attack tools vary their behavior so the
same attack appears differently each time, further complicating detection.

LECTURER: KHALID GABBAL


 Availability and simplicity of attack
tools. Whereas in the past an attacker
needed to have an extensive technical
knowledge of networks and computers
as well as the ability to write a program
to generate the attack, that is no longer
the case. Today’s attack tools do not
require any sophisticated knowledge.
 In fact, many of the tools have a
graphical user interface (GUI) that
allows the user to select options easily
from a menu, as seen in this Figure.
These tools are freely available or can
be purchased from other attackers at a
low cost.

LECTURER: KHALID GABBAL


 Faster detection of vulnerabilities.
Weakness in software can be more quickly
uncovered and exploited with new software
tools and techniques.
 Delays in patching. Hardware and software
vendors are overwhelmed trying to keep pace
with updating their products against attacks.
 One anti-virus software vendor receives
over 200,000 submissions of potential
malware each month.16% At this rate, the
anti-virus vendors would have to update and
distribute their updates every 10 minutes to
keep users protected. The delay in vendors
patching their own products adds to the
difficulties in defending against attacks.

LECTURER: KHALID GABBAL


 Weak patch distribution. Users are unaware that a security update even exists
for a product, and usually it requires downloading and installing the latest
version of the product instead of only installing a smaller patch. For these
reasons, attackers today are focusing more on uncovering and exploiting
vulnerabilities on these products.
 Distributed attacks. Attackers can use tens of thousands of computers under
their control in an attack against a single server or network. This “many against
one” approach makes it virtually impossible to stop an attack by identifying and
blocking a single source.
 User confusion. Increasingly, users are called upon to make difficult security
decisions regarding their computer systems, sometimes with little or no
information to guide them. It is not uncommon for a user to be asked security
questions such as, Do you want to view only the content that was delivered
securely?, Is it safe to quarantine this attachment?, or Do you want to install this
add-on? With little or no direction, users are inclined to provide answers to
questions without understanding the security risks.

LECTURER: KHALID GABBAL


OSI Security architecture:
 Security Attack:
- Any action that compromises the security of information owned by an
organization
 Security mechanism:
- A process that is designed to detect, prevent or recover from a security attack.
 Security service:
- A processing or communication service that enhances the security of the data
processing systems and the information transfers of an organization.
- Intended to counter security attacks, and they make use of one or more security
mechanisms to provide the service.
LECTURER: KHALID GABBAL
Threats and Attacks:
 Threat :
A potential for violation of security, which exists when there is a
circumstance, capability, action, or event that could breach security
and cause harm. That is, a threat is a possible danger that might
exploit a vulnerability.
 Attack:
An assault on system security that derives from an intelligent threat;
that is, an intelligent act that is a deliberate attempt to evade security
services and violate the security policy of a system.

LECTURER: KHALID GABBAL


Network threats

LECTURER: KHALID GABBAL


Network security attacks
A network attack can be defined as any method, process, or means used to maliciously
attempt to compromise network security. Network security is the process of preventing
network attacks across a given network infrastructure, but the techniques and methods
used by the attacker further distinguish whether the attack is an active cyber attack, a
passive type attack, or some combination of the two. 
Let’s consider a simple network attack example to understand the difference between
active and passive attack.
=> Active Attacks
An active attack is a network exploit in which attacker attempts to make changes to
data on the target or data en route to the target.

LECTURER: KHALID GABBAL


Active Attack

 Active network attacks are often


aggressive, blatant attacks that
victims immediately become
aware of when they occur.
 Active attacks are highly
malicious in nature, often locking
out users, destroying memory or
files, or forcefully gaining access
to a targeted system or network. 

LECTURER: KHALID GABBAL


Passive Attacks
A passive attack is a network attack in which a system
is monitored and sometimes scanned for open ports
and vulnerabilities, but does not affect system
resources.
 So, the purpose of the passive attack is to gain
access to the computer system or network and to
collect data without detection.
 So, network security includes implementing
different hardware and software techniques necessary
to guard underlying network architecture. With the
proper network security in place, you can detect
emerging threats before they infiltrate your network
and compromise your data.

LECTURER: KHALID GABBAL


Who Are the Attackers?
The types of individuals behind computer attacks are generally divided into several
categories. These include hackers, script kiddies, spies, insiders, cybercriminals, and
cyber-terrorists.
Hackers In the past, the term hacker was commonly used to refer to a person who uses
advanced computer skills to attack computers. White hat hackers said that their goal was only
to expose security flaws and not steal or corrupt data. Although breaking into another
computer system is illegal, they considered it acceptable as long as they did not commit theft,
vandalism, or breach any confidentiality while trying to improve security by seeking out
vulnerabilities. In contrast, the term black hat hackers was used to refer to attackers whose
motive was malicious and destructive.
 However, today the term hacker has been replaced with the more generic term attacker,
without any attempt to distinguish between the motives. Although “hacker” is often used by
the mainstream media to refer to an attacker, this term is no longer commonly used by the
security community.
LECTURER: KHALID GABBAL
Types of Hackers
 Most people in digital world agree there are three main types of hackers:

1. Black hat hacker;


2. White hat hacker;
3. Grey hat hacker.
1. WHITE HAT HACKER
First up, we have the perfect type of hacker to break the stereotype.
 The white hat hacker is a good guy, as ironic as it may sound. White Hackers,
white hat hackers or ethical hackers are the people who test existing internet
infrastructures to research loopholes in the system. They create algorithms and
perform multiple methodologies to break into systems, only to strengthen them.

LECTURER: KHALID GABBAL


BLACK HAT HACKER & 3. GREY HAT HACKER

 A Black hat hackers are responsible for all that is wrong with hacking. These
guys break into systems purely with negative intentions. From stealing credit
card information, to altering public databases, a black hat hacker looks to gain
fame or monetary benefits from exploiting the loopholes in internet frameworks.
Famous black hat hackers have notoriously robbed banks and financial
institutions of millions of dollars, and invaluable private data.
A grey hat hacker usually has mixed intentions. As the color code implies, this
hacker type does not have the good intentions of a white hat hacker, nor does he
have the ill intentions of a black hacker. A grey hat would break into systems but
never for his own benefit. Famous grey hat hackers have exploited systems only
to make the information public, and to bring to limelight vast datasets of
information that contains wrongdoings.

LECTURER: KHALID GABBAL


Script Kiddies & Insiders
 Script kiddies are individuals who want to break into computers to create
damage yet lack the advanced knowledge of computers and networks needed to do
so. Instead, script kiddies do their work by downloading automated attack
software (scripts) from Web sites and using it to perform malicious acts.
 This makes creating attacks even easier for these unskilled users. Figure 1-5
shows that over 40 percent of attacks are conducted by script kiddies with low or
no skills.
 Insiders: Another serious threat to an organization actually comes from an
unlikely source—its employees, contractors and business partners—often called
insiders. In one study of 900 cases of business “data leakage,” over 48 percent of
the breaches were attributed to insiders who abused their right to access corporate
information.
LECTURER: KHALID GABBAL
 One study revealed that most cases of
damage come from employees who have
announced their resignation or who have
been formally fired.
 When theft is involved, the criminals
are usually salespeople, engineers,
computer programmers, or scientists who
actually believe that the collected data is
owned by them and not the organization
 (most of these thefts occur within 30
days of the employee resigning).

LECTURER: KHALID GABBAL


A Model for Network Security
 When we send our data from source side to destination side we have to
use some transfer method like the internet or any other communication
channel by which we are able to send our message. The two parties, who
are the principals in this transaction, must cooperate for the exchange to
take place.
 When the transfer of data happened from one source to another source
some logical information channel is established between them by
defining a route through the internet from source to destination and by the
cooperative use of communication protocols (e.g., TCP/IP) by the two
principals.

LECTURER: KHALID GABBAL


Chapter One:
Introduction to Network Security

End
Q&A
LECTURER: KHALID GABBAL

You might also like