Topic 18 Cybersecurity Study Notes
Intro to Cybersecurity Concepts
Overview of the Triple A Method
Application in social engineering
Concerns regarding policy creation related to security
Balance Between Security and Availability
Fundamental principle in cybersecurity
Complete security could lead to zero availability
Introduction of availability creates vulnerabilities
Essential to strike a balance between security and availability
CIA Triad
Explanation of CIA Triad
C: Confidentiality
Keeping data private and ensuring only authorized access
I: Integrity
Ensuring data has not been altered or manipulated
A: Availability
Ensuring data is accessible to authorized users when needed
Importance of CIA triad in creating security policies
Common knowledge in cybersecurity interviews and tests (e.g., Security+, Certified Ethical Hacker)
Access Controls and the Triple A Process
Access Controls: Method to uphold the CIA triad
Triple A Process: Authentication, Authorization, and Accounting
Authentication: Proving identity before gaining access
Common methods: Username and password, PINs, RFID cards, biometrics (e.g., fingerprint, retinal scan, behavioral traits)
Authorization: Granting access based on identity
Role-based access controls (RBAC) based on user employment or position
Accounting: Tracking activity on the network
Tools include Windows Event Viewer for monitoring actions
Security Basics and Principles
Principle of Least Privilege
Granting only necessary access to users
Concerns Related to the CIA Triad
Confidentiality Concerns
Applicability in both digital and physical security
Common threats:
Snooping
Physical snooping: Example - shoulder surfing (observing someone entering data)
Digital snooping: Tools like Wireshark for analyzing data packets
Misaddressed Email
Example of unintentional data leak due to incorrect email addressing
Holds accountability even when unintended
Eavesdropping
Listening in on conversations or digital communications
Social Engineering
Exploiting human psychology to gain access to information without using code
Example: Frank Abagnale Jr.
Techniques include impersonation and interaction with unsuspecting individuals
Dumpster Diving
Physically searching garbage for sensitive documents or unshredded hard drives
Importance of properly disposing sensitive data
Integrity Concerns
Ensuring data integrity by preventing alteration
Threats include:
Man-in-the-middle attacks (intercepting and potentially altering data during transmission)
Impersonation (pretending to be someone else to alter data)
Availability Concerns
Importance of data accessibility to authorized users
Potential threats:
Denial of Service (DoS): Any action taking a service down, whether via cyber or physical means
Distributed Denial of Service (DDoS): Large-scale attack using botnets to overwhelm services
Hardware failures (e.g., bad power supplies or hard drives)
Implementation of Access Controls using the Triple A Process
Each user or resource has an identity and requires authentication to access resources
Detailed breakdown of authentication methods:
Username and password
Physical tokens like RFID cards
Biometrics (e.g., finger print, facial recognition)
Unique behavioral patterns (typing recognition)
Social Engineering Techniques
Definition and use of social engineering to extract confidential information
Types:
Phishing (deceptive email attempts)
Vishing (voice solicitation via phone calls)
Smishing (SMS solicitation)
Quishing (QR code scams)
Engagement tactics include creating urgency or fear
Current Trends in Cybersecurity Threats
Developing methods for human security and vulnerabilities
Utilization of social engineering for hacking without needing advanced coding skills
The importance of reinforcing physical security alongside cybersecurity practices
Risks associated with hacking critical infrastructure (e.g., power plants, GPS navigation)
Conclusion
Recap of key concepts and methodologies in cybersecurity
Importance of ongoing awareness and policy implementation to enhance security measures and protect data.