Detailed Notes on Network and Internet Security Lecture

Learning Objectives

  • Explain the importance of network and Internet security for computer users.
  • List examples of unauthorized access and use.
  • Describe ways to protect against unauthorized access such as access control systems, firewalls, and encryption methods.
  • Provide examples of computer sabotage and how to protect against it.
  • Discuss online theft, identity theft, phishing schemes, and other online frauds, along with protective measures.
  • Identify personal safety risks when using the Internet and safeguarding measures individuals can take.
  • Discuss the current legislation governing network and Internet security.

Overview

  • Highlight security concerns stemming from the use of computer networks and the Internet.
  • Analyze safeguards and precautions against security threats.
  • Discuss personal safety issues, particularly related to Internet use.
  • Review relevant laws and regulations related to network and Internet security.

Importance of Network and Internet Security

  • Cybercrime defined as any illegal act involving a computer:
    • Theft of financial assets.
    • Data manipulation for personal gain.
    • Acts of sabotage (e.g., viruses, web server shutdown).
    • Phishing and scams.
  • All users must be aware of security concerns and precautions.

Unauthorized Access and Unauthorized Use

  • Unauthorized Access: Gaining access to a computer or network without permission.
  • Unauthorized Use: Utilizing resources for unapproved activities, committed by both insiders and outsiders.
  • Examples:
    • Hacking and its implications on national security.
    • War Driving: Using a car to find unsecured Wi-Fi networks.
    • Wi-Fi Piggybacking: Unauthorized access to unsecured networks.
    • Interception: Capturing unsecured communications and sensitive data like credit card information.

Protecting Against Unauthorized Access

  • Access Control Systems: Regulate access to networks, databases, and accounts.
    • Identification Systems: Verify authorized users.
    • Authentication Systems: Confirm user identities.
    • Possessed Knowledge Access Systems: Utilize strong passwords.
  • Strategies for strong passwords:
    • Minimum of 8 characters, include a mix of lowercase, uppercase, numbers, and symbols.
    • Avoid using easily obtainable personal information.
    • Change passwords regularly and avoid same passwords across multiple sites.
  • Cognitive Authentication Systems: Use personal trivia for recovery processes.
  • Two-Factor Authentication: A combination of two methods (password and biometric or token).
  • Possessed Object Access Systems: Require physical tokens like RFID cards, USB keys.
  • Biometric Access Systems: Unique biological characteristics for identification (e.g., fingerprints, face recognition).
  • Securing Wireless Networks:
    • Change default router passwords; enable encryption.
    • Hide SSID to limit unauthorized access.

Firewalls and Intrusion Prevention Systems

  • Firewalls: Hardware/software protecting a network by blocking unauthorized access.
    • Must monitor both incoming and outgoing traffic.
    • Configured to close unnecessary ports to enhance security.
  • Intrusion Prevention Systems (IPS): Active monitoring of traffic to block suspicious activities.

Computer Sabotage Definition

  • Computer Sabotage: Intentional destructive acts against a computer system.
    • Launching viruses, conducting DoS attacks, or using botnets.
  • Malware: Any software intentionally designed to cause harm (includes viruses, worms, trojans).
  • DDoS Attacks: Flooding servers with overwhelming traffic to cause crashes.

Protecting Against Computer Sabotage

  • Security Software: Suite of programs (antivirus) to guard against varied threats.
  • Best practices:
    • Keep software updated.
    • Use intrusion detection systems.
    • Control access to sensitive data and configurations.

Online Theft and Fraud

  • Definition of Dot Cons: Frauds executed through the internet, including:
    • Data theft: Gaining unauthorized data access.
    • Identity Theft: Misusing another’s identity for personal gain.
    • Phishing: Sending spoofed emails to acquire personal information.
    • Other scams: Auction frauds, illegal loans, pyramid scams.

Protecting Against Online Theft

  • Businesses to utilize robust security measures and monitor for unauthorized data access.
  • Preventing Identity Theft:
    • Shred sensitive documents, monitor credit reports, and control personal information distribution.

Personal Safety Issues Online

  • Cyberbullying and Cyberstalking: Emerging threats affecting users, especially teens.
  • Online pornography: Attempts to control it have faced challenges.

Safety Tips for Prevention

  • Online safety for adults and children:
    • Be cautious with personal details.
    • Monitor children’s online activities.
    • Use strong passwords, and modify privacy settings.

Network and Internet Security Legislation

  • Overview of significant laws:
    • Identity Theft Penalty Enhancement Act: Increased penalties for identity theft.
    • CAN-SPAM Act: Regulations against unsolicited emails.
    • HIPAA: Securing health information electronically.
    • Cybersecurity provisions in the Homeland Security Act.

Summary

  • Revise the importance of network security, unauthorized access prevention, protection against sabotage, online fraud, and personal safety. Discuss legislation that affects Internet security.