CYBER SECURITY
FOUNDATION
Module 1.1 : Cyber Landscape
Module 1.2 : Cyber Threats
Module 1.3 : Cyber Attacks types and
Techniques
Module 1.4 : Cyber Security Models &
Design Principles
Module 1.5 : Security Operating Platform
MODULE – 1.1
CYBER LANDSCAPE
Modern computing trends
New application threat vectors
Turbulence in the cloud
SaaS application risks
Compliance and security are not the same
Recent high-profile cyber-attack examples
MODERN COMPUTING TRENDS
Web 2.0
o Cloud computing
o Consumerization and BYOD/BYOA
o Mobile computing and 5G
o Content delivery networks
CLOUD COMPUTING
The three types of cloud computing:
Public cloud
Private cloud
Hybrid cloud.
CONSUMERIZATION AND
BYOD/BYOA
BYOD (Bring Your Own Device)
BYOA (Bring Your Own Application)
CONSUMERIZATION AND
BYOD/BYOA
It is the adoption of consumer technologies
in the workplace.
Adoption of Personal Devices
Familiarity and Usability
Cloud-Based Services
MOBILE COMPUTING AND
5G
It is an ability to access and use computing
resources and services
It refers to the use of portable computing
devices
It involves the integration of hardware,
software, and communication technologies
MOBILE COMPUTING AND 5G
5G, short for "fifth generation
It is the latest generation of wireless
technology for cellular networks
It aims to provide faster data speeds
It designed to meet the growing demand
for high-speed and reliable wireless
communication
CONTENT DELIVERY
NETWORKS
It is a network of distributed servers that
work together to deliver web content
The primary purpose of a CDN is to
improve the performance, reliability, and
scalability of content delivery
MODERN COMPUTING
TRENDS
Artificial intelligence and machine learning
Artificial Intelligence (AI) refers to the simulation
of human-like intelligence in machines
AI systems use data, algorithms, and
computational power to learn, reason, and make
decisions.
The goal of AI is to create machines that can
mimic human cognitive functions and solve
complex problems.
MODERN COMPUTING
TRENDS
Blockchain
It is a distributed and decentralized digital
ledger technology
Originally developed as the underlying
technology for the cryptocurrency Bitcoin.
MODERN COMPUTING
TRENDS
Data mining
Data mining is the process of discovering
patterns, trends, correlations, or meaningful
insights from large datasets.
Data mining aims to uncover hidden
relationships within the data, which can be
used for decision-making
MODERN COMPUTING
TRENDS
Mixed reality
It combines elements of both virtual reality
(VR) and augmented reality (AR)
Virtual objects are integrated into the real
environment.
It enables users to engage with a merged
reality, where physical and digital elements
coexist and interact.
MODERN COMPUTING
TRENDS
Virtual Assistants
It allows users to interact with a computer or
search engine using everyday language
The goal of natural language search is to
understand the user's intent and provide
relevant results that best match that intent
Natural language search is particularly useful
for complex queries
APPLICATION THREAT
VECTORS
Port Hopping
Port hopping, also known as "port hopping
attack”
It is a network security term that refers to a
technique used by attackers to evade
detection
APPLICATION THREAT
VECTORS
Use of non-standard ports
o Port Obfuscation
o Evasion of Port-based Filters
o Preventing Detection of Well-Known
Exploits
o Hiding in Plain Sight
o Persistence and Backdoor Access
APPLICATION THREAT
VECTORS
Tunneling with commonly used services
It is the practice of encapsulating one
network protocol within another
Tunneling is commonly used to bypass
network restrictions
Attackers can also leverage tunneling to
hide malicious activities and evade security
measures
APPLICATION THREAT
VECTORS
Hiding within SSL encryption
It is a technique used by attackers to
obfuscate their malicious activities and
evade detection by security systems.
TURBULENCE IN THE CLOUD
Network Issues
Server Downtime
Resource Allocation
Security Incidents
Software Bugs or Incompatibility
Sudden Traffic Spikes
SAAS APPLICATION RISKS
Data Security and Privacy
Data Loss
Service Reliability and Downtime
Vendor Lock-in
Compliance and Regulatory Concerns
Integration Challenges
Service Level Agreements (SLAs)
Dependency on Internet Connectivity
Hidden Costs
End of Service Life
COMPLIANCE AND
SECURITY
ARE NOT THE SAME
An organization might be compliant but not
secure, or secure but not compliant
Regulatory requirements are generally based on
security best practices
Regulatory environment is complex and
confusing; some regulations may overlap or
contradict others
Security and compliance are typically separate,
but closely related, functions within an
organization
IMPORTANT SECURITY AND
PRIVACY
REGULATIONS/STANDARDS
California Consumer Privacy Act (CCPA)
EU General Data Protection Regulation (GDPR)
North American Reliability Corporation (NERC) Critical
Infrastructure Protection (CIP)
Payment Card Industry Data Security Standards (PCI
DSS)
U.S. Federal Information Security Modernization Act
(FISMA)
U.S. Health Insurance Portability and Accountability Act
(HIPAA)
U.S. Sarbanes-Oxley (SOX) Act
RECENT HIGH-PROFILE
CYBER-ATTACK EXAMPLES
Target and Home Depot
Anthem
Yahoo!
Equifax
Marriott
Quest Diagnostics
City of Baltimore
Capital One