Ethical M1

MODULE 1: Elements of Information Security

Overview

  • Information security involves protecting systems and hardware that use, store, and transmit information.

  • It aims to prevent unauthorized access, disclosure, destruction, or disruption of data.

  • Defined as a state where the possibility of theft, tampering, or disruption of information and services is kept low.

Five Major Elements of Information Security

  1. Confidentiality

    • Ensures that sensitive data is only accessible to authorized individuals.

    • Breaches can occur from improper data handling or hacking.

    • Controls include data classification, encryption, and secure disposal of sensitive materials (e.g., DVDs, CDs).

    • Access to information should be restricted based on a classification system for risk and sensitivity.

  2. Integrity

    • Focuses on keeping information intact, complete, and accurate.

    • Essential for maintaining trust in data and preventing unauthorized changes.

    • Threats to integrity can be mitigated through methods like checksums and access controls.

    • Integrity measures maintain consistency and trustworthiness throughout the data lifecycle.

  3. Availability

    • Ensures that systems provide access to authorized users when needed.

    • Threats include Denial of Service (DoS) attacks aimed at compromising availability.

    • Measures to maintain availability include redundant systems, disk arrays, anti-virus software, and DDoS prevention systems.

  4. Authenticity

    • Guarantees that the data or communication is genuine and unaltered.

    • Involves security policies that define data handling and access approval processes.

    • Authentication methods include biometrics, smart cards, and digital certificates.

    • Addresses the challenge of ensuring secure communications and transactions.

  5. Non-Repudiation

    • Ensures that senders cannot deny sending messages and recipients cannot deny receiving them.

    • Digital signatures are commonly used to ensure non-repudiation.

    • Provides legal assurance regarding the integrity and origin of messages.

Security Challenges

  • Capability Challenges: Variability in skills and experience among ethical hacking teams.

  • Capacity Challenges: Limited skilled manpower for effective pen testing due to resource constraints.

  • Cost Challenges: High costs associated with identifying vulnerabilities and implementing solutions.

  • Legal Challenges: Ethical hackers require legal agreements (e.g., NDAs) to avoid criminal prosecution.

  • Heterogeneous Challenges: Differences in approaches and tools among various ethical hacking teams can lead to inconsistencies in vulnerability identification.

  • Knowledge Challenges: Ethical hackers may struggle against undetected or new attack vectors such as zero-day attacks.

Effects of Hacking

Impact on Communication and Society

  • Communication has evolved from letters to telephone and, subsequently, to computers and online platforms.

  • The rise of social media has transformed relationships but also introduced risks such as cyberbullying.

  • Hacking leads to identity theft, breach of privacy, and national security risks.

Definition of Hacking

  • Hacking is the act of modifying hardware or software to cause damage or steal sensitive data.

  • Can also refer to finding vulnerabilities for ethical purposes.

Types of Hackers

  1. White Hat Hackers: Ethical hackers who improve cybersecurity for organizations.

  2. Black Hat Hackers: Malicious hackers who exploit vulnerabilities for personal gain.

  3. Gray Hat Hackers: Hackers who operate between ethical and unethical motives without explicit authorization.

  4. Script Kiddies: Inexperienced hackers using scripts written by others to launch attacks for attention.

  5. Green Hat Hackers: Novice hackers seeking to learn and gain experience.

  6. Blue Hat Hackers: Hackers seeking revenge or popularity among peers through malicious acts.

  7. Red Hat Hackers: Ethical hackers who aggressively target black hat hackers.

  8. State/Nation Sponsored Hackers: Government-employed hackers for intelligence purposes.

  9. Hacktivists: Hackers with a political or social agenda, targeting government websites.

  10. Malicious Insiders: Whistleblowers or employees exposing sensitive data for personal gain.

Ethical Hackers

  • Ethical hackers, or white hat hackers, test security systems with authorization from the system owners.

  • They identify vulnerabilities to protect against potential cyber-attacks.

  • Require high technical expertise and may utilize industry certifications.

Security Testing Roles

Responsibilities of Security Test Engineers

  • Conduct security audits and identify gaps in various security types (web, application, network).

  • Communicate findings effectively to technical and non-technical audiences.

  • Deliver comprehensive security engagement results.

Penetration Testing

  • Good hacking practice to identify vulnerabilities in IT systems.

  • Involves planning, executing tests, and reporting on security findings.

  • Different types include internal, external, wireless, web application, and mobile application testing.

Vulnerability Assessments

  • Identify, document, and prioritize security vulnerabilities in systems.

  • Performed using automated tools and manual techniques for comprehensive coverage.

  • Categories include network-based, application-based, API-based, host-based, wireless, physical, social engineering, and cloud-based assessments.