Topic 18 Cybersecurity Study Notes

Intro to Cybersecurity Concepts

  • Overview of the Triple A Method

    • Application in social engineering

    • Concerns regarding policy creation related to security

Balance Between Security and Availability

  • Fundamental principle in cybersecurity

    • Complete security could lead to zero availability

    • Introduction of availability creates vulnerabilities

    • Essential to strike a balance between security and availability

CIA Triad

  • Explanation of CIA Triad

    • C: Confidentiality

    • Keeping data private and ensuring only authorized access

    • I: Integrity

    • Ensuring data has not been altered or manipulated

    • A: Availability

    • Ensuring data is accessible to authorized users when needed

  • Importance of CIA triad in creating security policies

  • Common knowledge in cybersecurity interviews and tests (e.g., Security+, Certified Ethical Hacker)

Access Controls and the Triple A Process

  • Access Controls: Method to uphold the CIA triad

  • Triple A Process: Authentication, Authorization, and Accounting

    1. Authentication: Proving identity before gaining access

    • Common methods: Username and password, PINs, RFID cards, biometrics (e.g., fingerprint, retinal scan, behavioral traits)

    1. Authorization: Granting access based on identity

    • Role-based access controls (RBAC) based on user employment or position

    1. Accounting: Tracking activity on the network

    • Tools include Windows Event Viewer for monitoring actions

Security Basics and Principles

  • Principle of Least Privilege

    • Granting only necessary access to users

Concerns Related to the CIA Triad

Confidentiality Concerns

  • Applicability in both digital and physical security

  • Common threats:

    • Snooping

    • Physical snooping: Example - shoulder surfing (observing someone entering data)

    • Digital snooping: Tools like Wireshark for analyzing data packets

    • Misaddressed Email

    • Example of unintentional data leak due to incorrect email addressing

    • Holds accountability even when unintended

    • Eavesdropping

    • Listening in on conversations or digital communications

    • Social Engineering

    • Exploiting human psychology to gain access to information without using code

    • Example: Frank Abagnale Jr.

    • Techniques include impersonation and interaction with unsuspecting individuals

    • Dumpster Diving

    • Physically searching garbage for sensitive documents or unshredded hard drives

    • Importance of properly disposing sensitive data

Integrity Concerns

  • Ensuring data integrity by preventing alteration

  • Threats include:

    • Man-in-the-middle attacks (intercepting and potentially altering data during transmission)

    • Impersonation (pretending to be someone else to alter data)

Availability Concerns

  • Importance of data accessibility to authorized users

  • Potential threats:

    • Denial of Service (DoS): Any action taking a service down, whether via cyber or physical means

    • Distributed Denial of Service (DDoS): Large-scale attack using botnets to overwhelm services

    • Hardware failures (e.g., bad power supplies or hard drives)

Implementation of Access Controls using the Triple A Process

  • Each user or resource has an identity and requires authentication to access resources

  • Detailed breakdown of authentication methods:

    • Username and password

    • Physical tokens like RFID cards

    • Biometrics (e.g., finger print, facial recognition)

    • Unique behavioral patterns (typing recognition)

Social Engineering Techniques

  • Definition and use of social engineering to extract confidential information

  • Types:

    • Phishing (deceptive email attempts)

    • Vishing (voice solicitation via phone calls)

    • Smishing (SMS solicitation)

    • Quishing (QR code scams)

  • Engagement tactics include creating urgency or fear

Current Trends in Cybersecurity Threats

  • Developing methods for human security and vulnerabilities

  • Utilization of social engineering for hacking without needing advanced coding skills

  • The importance of reinforcing physical security alongside cybersecurity practices

  • Risks associated with hacking critical infrastructure (e.g., power plants, GPS navigation)

Conclusion

  • Recap of key concepts and methodologies in cybersecurity

  • Importance of ongoing awareness and policy implementation to enhance security measures and protect data.