Ethical M1
MODULE 1: Elements of Information Security
Overview
Information security involves protecting systems and hardware that use, store, and transmit information.
It aims to prevent unauthorized access, disclosure, destruction, or disruption of data.
Defined as a state where the possibility of theft, tampering, or disruption of information and services is kept low.
Five Major Elements of Information Security
Confidentiality
Ensures that sensitive data is only accessible to authorized individuals.
Breaches can occur from improper data handling or hacking.
Controls include data classification, encryption, and secure disposal of sensitive materials (e.g., DVDs, CDs).
Access to information should be restricted based on a classification system for risk and sensitivity.
Integrity
Focuses on keeping information intact, complete, and accurate.
Essential for maintaining trust in data and preventing unauthorized changes.
Threats to integrity can be mitigated through methods like checksums and access controls.
Integrity measures maintain consistency and trustworthiness throughout the data lifecycle.
Availability
Ensures that systems provide access to authorized users when needed.
Threats include Denial of Service (DoS) attacks aimed at compromising availability.
Measures to maintain availability include redundant systems, disk arrays, anti-virus software, and DDoS prevention systems.
Authenticity
Guarantees that the data or communication is genuine and unaltered.
Involves security policies that define data handling and access approval processes.
Authentication methods include biometrics, smart cards, and digital certificates.
Addresses the challenge of ensuring secure communications and transactions.
Non-Repudiation
Ensures that senders cannot deny sending messages and recipients cannot deny receiving them.
Digital signatures are commonly used to ensure non-repudiation.
Provides legal assurance regarding the integrity and origin of messages.
Security Challenges
Capability Challenges: Variability in skills and experience among ethical hacking teams.
Capacity Challenges: Limited skilled manpower for effective pen testing due to resource constraints.
Cost Challenges: High costs associated with identifying vulnerabilities and implementing solutions.
Legal Challenges: Ethical hackers require legal agreements (e.g., NDAs) to avoid criminal prosecution.
Heterogeneous Challenges: Differences in approaches and tools among various ethical hacking teams can lead to inconsistencies in vulnerability identification.
Knowledge Challenges: Ethical hackers may struggle against undetected or new attack vectors such as zero-day attacks.
Effects of Hacking
Impact on Communication and Society
Communication has evolved from letters to telephone and, subsequently, to computers and online platforms.
The rise of social media has transformed relationships but also introduced risks such as cyberbullying.
Hacking leads to identity theft, breach of privacy, and national security risks.
Definition of Hacking
Hacking is the act of modifying hardware or software to cause damage or steal sensitive data.
Can also refer to finding vulnerabilities for ethical purposes.
Types of Hackers
White Hat Hackers: Ethical hackers who improve cybersecurity for organizations.
Black Hat Hackers: Malicious hackers who exploit vulnerabilities for personal gain.
Gray Hat Hackers: Hackers who operate between ethical and unethical motives without explicit authorization.
Script Kiddies: Inexperienced hackers using scripts written by others to launch attacks for attention.
Green Hat Hackers: Novice hackers seeking to learn and gain experience.
Blue Hat Hackers: Hackers seeking revenge or popularity among peers through malicious acts.
Red Hat Hackers: Ethical hackers who aggressively target black hat hackers.
State/Nation Sponsored Hackers: Government-employed hackers for intelligence purposes.
Hacktivists: Hackers with a political or social agenda, targeting government websites.
Malicious Insiders: Whistleblowers or employees exposing sensitive data for personal gain.
Ethical Hackers
Ethical hackers, or white hat hackers, test security systems with authorization from the system owners.
They identify vulnerabilities to protect against potential cyber-attacks.
Require high technical expertise and may utilize industry certifications.
Security Testing Roles
Responsibilities of Security Test Engineers
Conduct security audits and identify gaps in various security types (web, application, network).
Communicate findings effectively to technical and non-technical audiences.
Deliver comprehensive security engagement results.
Penetration Testing
Good hacking practice to identify vulnerabilities in IT systems.
Involves planning, executing tests, and reporting on security findings.
Different types include internal, external, wireless, web application, and mobile application testing.
Vulnerability Assessments
Identify, document, and prioritize security vulnerabilities in systems.
Performed using automated tools and manual techniques for comprehensive coverage.
Categories include network-based, application-based, API-based, host-based, wireless, physical, social engineering, and cloud-based assessments.