Free Essay

Strategies for Protecting Our Systems from Internal or External Attacks

In:

Submitted By davidfada
Words 1763
Pages 8
Table of Contents Introduction 2 System Description 2 System Strengths and Weaknesses 4 System Protection Options 5 Antivirus Protection 5 Firewall 6 Comprehensive system configuration management 6 Application Whitelisting 6 Disk and filesystem-level Encryption 7 Tiered level authentication and Biometric level access 7 Risk Mitigation Strategies 7 Conclusion 10 Bibliography 11

Introduction The purpose of this white paper is to demonstrate the strength and potential weaknesses of the firms’ computer systems, and also to address the upper managements concerns over a possible threat of an internal or external attack to our systems. In this paper we will also be discussing the steps that have been taken to secure our systems against both forms of attacks; we will also be exploring risk mitigation strategies that serve as a means to help prevent such attacks from ever occurring. As with ever system, there is always the possibility of a sophisticated attack being invented that is capable of breaching our systems, so we will be addressing the strategies and steps that will be taken in the event that our systems are ever breached by an internal or external attack.

System Description

The system in question that is being used by the organization is the Dell Precision R5500 Rack Workstation. We currently have a total of 20 such workstations and our systems are equipped with the latest technological components and software to offer protection, flexibility and peak performance at all times. The table below highlights the different configurations for the system, ours being of the highest available specification.
Figure 1: Dell Precision R55001

Figure 2: Dell Precision R5500 Rack Workstation Technical Specifications1
System Strengths and Weaknesses As a top leading manufacturer of workstations worldwide, Dell has outfitted the R5500 with the best industry specifications to keep up with the ever demanding performance requirements of the Information technology industry. The R5500 offers real workstation class performance while being small enough to accommodate for space constrained environments. * For organizations where security is top priority, you need more than a lock and key. The Dell Precision R5500 can help safely house your intellectual property by keeping it contained in the data center1. * For end users who work in space-constrained areas or temperature- or noise-sensitive environments, the FX100 Remote Access Device is small, cool and quiet1. * By providing remote 1:1 access to your Dell PrecisionR5500 from virtually anywhere, the FX100 Remote Access Device can also help to boost productivity among offsite contractors, rotating workforces and geographically diverseemployees1. * PC-over-IP hardware-based compression transfers only the rendered graphics pixel data over the network, ensuring a fast and responsive user experience1.
As with all things technologically advanced there are bound to be components that can be exploited by hackers and other people trying to gain access to information stored within the system. Such weaknesses include but aren’t limited to: * The ability to access the system from an offsite location. * The many array of ports which make the options of retrieving information and data easier * The Operating system, as it is not made by the company or maintained may have some bugs that allow access to files and information * Various Third party software that are important to the day to day functionality of the company may also possess bugs and security flaws in them that could potentially allow an outsider to hack into the mainframe of the system.

System Protection Options

Here at the firm, we have adopted a layered protection approach towards the security of our systems. This layered defense system includes both host-based controls, such as firewalls and access control systems, in addition to network-based controls2. The importance of such an approach is that in the event that an outsider is able to bypass one of the layers of security, such an individual would still be required to bypass all additional layers in order to achieve their aim which would prove a more difficult thing to accomplish. The layers used by the firm are as followed: Antivirus Protection This is seen as the most fundamental and first line of dense of all security approaches. It is responsible for cleaning up the malware problem that usually plagues most third party applications3. Such malwares include Trojans, spyware, rootkits and viruses, these malwares continue to grow in sophistication at an alarming rate which usually makes them hard to contain once a system has been breached. The use of malware is usually prominent in attacks to the third party application vulnerabilities in a system and is also prominent with insider attacks where the perpetrator is trying to cripple the mainframe system. Firewall The next line of defense is the systems firewall. Its primary objective is to control the incoming and outgoing network traffic by analyzing the data packets and determining whether it should be allowed through or not, based on a predetermined rule set4. This is often expressed in the philosophy, “block anything that is not explicitly allowed2.” This simple function serves as a very capable means of preventing many simple attacks from occurring such as scanning ports and IP addresses for malicious information of addresses trying to pass through the network. The only detriment of a firewall is that it isn’t capable of protecting a system from an internal attack2. Comprehensive system configuration management The main means of hackers getting access to a systems mainframe is through the exploitation of systems third party software vulnerabilities. The function of a system management such as the Dell KACE K1000 is to reduce the need for a manual way of updating the third party applications installed on the firm systems as updates are being pushed out for the software to patch such vulnerabilities and bugs. Application Whitelisting This is just a means of protecting the system from allowing any form of unauthorized third party applications from being installed into the system. Any application that isn’t on the whitelist would be blocked from being allowed onto the system. This whitelist can only be modified by the head of the IT department and is only limited to third party applications used by the organization. Disk and filesystem-level Encryption Disk encryption is a technology which protects information by converting it into unreadable code that cannot be deciphered easily by unauthorized people. Disk encryption uses disk encryption software or hardware to encrypt every bit of data that goes on a disk or disk volume5. This prevents unauthorized persons from accessing the proprietary information and files on the system and also prevents the copying of data of the system to external drives or separate locations. Tiered level authentication and Biometric level access The function of this is to basically separate access to different levels of company sensitive information to separate individuals based on their level of authorization at the firm. This would help ensure that the wrong people don’t have access to information stored in sensitive locations of the organization.
Risk Mitigation Strategies In this section we would address the many ways attacks can be avoided to the computer systems in the company. We would also develop a Risk mitigation assessment plan in the event that our systems are ever successfully breached. As the saying goes “Prevention is better than cure” the best form of protecting a system against attack is to develop a means of making sure that the risk of being attacked is greatly minimized by internal or external forces. The following steps would help minimize the risk: * Train managers to interact and socialize with employees so as to understand their problems at the company and help tackle them * Create a system whereby every employee is required to change their system password every 3-6 months so as to avoid it getting into the wrong hands * Restrict remote access from offsite location to only authorized and cleared users. * Implement ISMS and follow the standards as described in ISO/IEC 27001 and ISO/IEC 27002 and related standards published jointly by ISO and IEC6. * Perform a daily system log check of all computers to scan for irregular user activity. * Perform a yearly assessment check of all security systems put into place and ensure all systems are up to date with the latest technological advancements.
As we have rightly said before, even with all the above steps followed, it is still possible for the systems to be breached by a highly sophisticated attack. In the event such a thing happens a plan is put in place to ensure the risk is managed efficiently.

* Risk Factors | * Low | * Medium | * High | * Mitigation Ideas | * 1)Scope of the attack | * Defined and Not Large or Complex | * Somewhat Defined/or Large/ Complex | * Not Defined && Large/Complex | * Decomposition of attack elements * Detailed specifications of attack | * 2) Overall state of the Network and its services | * Stable | * Moderately Unstable, restorable with backup services | * Highly Unstable, Shut down, Volatile, unable to utilize backup resources | * Additional testing * Deployment of backup resources * Inform users of a breach and implore them to take specific action, such as password changes | * 3) Impact on other Company services | * None or Very Little | * Some Change | * Extensive Changes | * Phased cutover * On-site assistance for cutover period * Fix core functionality first (decomposition) * Expose key stakeholders to prototype early | * 4)Time required to fix breach | * < 12 hours | * 12-24 hours | * >24 hours | * Split work required into smaller phases * Phased implementation of solution | * 5) Cost to Firm | * < $100,000 | * $100,000-$500,000 | > $500,000 | * Inform upper management and shareholders of breach and its cost to the company |
Figure3: Risk Assessment and Mitigation Plan7

Conclusion
As with all systems, the systems at Panther industries are breach-able but the procedures put in place to avoid such attacks, or to minimize the impact of a successful attack are second to none and would do greatly to help protect the companies intellectual property against hackers or people who are interested in obtaining such information for illegal or unsanctioned use.

Bibliography
1. Dell Co-operation. (n.d.). Dell Precison R5500. Retrieved Nov 2, 2012, from Dell.com: Dell.com/precison
2. SearchSecurity. (n.d.). Search Security. Retrieved Nov. 23, 2012, from Search Security Website.
3. Dell KACE & Lumension. (n.d.). 3 Strategies to protect Endpoints from Risky Application. Retrieved Nov. 24, 2012, from DELL KACE Website.
4. Wikipedia. (n.d.). Wikipedia: Firewalls. Retrieved Nov. 25, 2012, from http://en.wikipedia.org/wiki/Firewall_(computing)
5. Wikipedia. (n.d.). Wikipedia: Disk encryption. Retrieved Nov. 25, 2012, from http://en.wikipedia.org/wiki/Disk_encryption
6. Wikipedia. (n.d.). Wikipedia: Information security management system. Retrieved Nov 26., 2012, from http://en.wikipedia.org/wiki/Information_security_management_system

Similar Documents

Premium Essay

Critical Infrastructure Analysis

...1: About (inter)national critical infrastructures 1.1 Defining critical infrastructures A country’s critical infrastructures are the specific facilities, services and informational systems that are vital to its national security, economy, public health, and for the security and well functioning of the Government itself. The failure or destruction of such critical infrastructures could heavily weaken or threaten the latter. As such, both the management and protection of critical infrastructures go hand in hand. Each country is responsible for identifying the national infrastructures that are critical for its security and stability. However, there are certain infrastructures deemed critical by most states. Which are Romania’s critical...

Words: 2254 - Pages: 10

Free Essay

Hostel Management System

...Define user documentation Written or other visual information about an application system, how it works, and how to use it. (17) . User documentation refers to the documentation for a product or service provided to the end users. The user documentation is designed to assist end users to use the product or service. This is often referred to as user assistance. The user documentation is a part of the overall product delivered to the customer. The sections of a user manual often include: * A cover page * A title page and copyright page * A preface, containing details of related documents and information on how to navigate the user guide * A contents page * A guide on how to use at least the main functions of the system * A troubleshooting section detailing possible errors or problems that may occur, along with how to fix them * A FAQ (Frequently Asked Questions) * Where to find further help, and contact details * A glossary and, for larger documents, an index realized the importance of documentation many years ago when I joined an organization to head its IT function. The previous IT head had left the organization a couple of months ago. The managing director called me over and voiced his expectation. He told me that all ground work had been done for ordering new set of servers and application packages and that I should act upon it soon. I promised to take a look at the situation and revert with plans. However, when I sat in my department...

Words: 2026 - Pages: 9

Premium Essay

Autonomic Computing

...Manish Parashar1 and Salim Hariri2 The Applied Software Systems Laboratory, Rutgers University, Piscataway NJ, USA 2 High Performance Distributed Computing Laboratory, University of Arizona, Tucson, AZ, USA parashar@caip.rutgers.edu, hariri@ece.arizona.edu 1 Abstract. The increasing scale complexity, heterogeneity and dynamism of networks, systems and applications have made our computational and information infrastructure brittle, unmanageable and insecure. This has necessitated the investigation of an alternate paradigm for system and application design, which is based on strategies used by biological systems to deal with similar challenges – a vision that has been referred to as autonomic computing. The overarching goal of autonomic computing is to realize computer and software systems and applications that can manage themselves in accordance with high-level guidance from humans. Meeting the grand challenges of autonomic computing requires scientific and technological advances in a wide variety of fields, as well as new software and system architectures that support the effective integration of the constituent technologies. This paper presents an introduction to autonomic computing, its challenges, and opportunities. 1 Introduction Advances in networking and computing technology and software tools have resulted in an explosive growth in networked applications and information services that cover all aspects of our life. These sophisticated applications and services are...

Words: 5552 - Pages: 23

Premium Essay

Upgrade Internet Edge

...Technical Writing Project Cover Sheet Capstone Proposal Project Name: Upgrading ABC Inc. Internet Edge Student Name: Michael Wakefield Degree Program: Bachelor of Science IT-Security Mentor Name: Signature Block Student’s Signature Mentor’s Signature Table of Contents Capstone Proposal Summary 1 Review of Other Work 8 Rationale and Systems Analysis 16 Goals and Objectives 22 Project Deliverables 26 Project Plan and Timelines 27 References 28 Appendix 1: Competency Matrix 4 Capstone Proposal Summary Internet of Everything (IoE) and “Big Data” equates to competitive advantages to the modern business landscape. Numerous white papers are circulating on the Internet highlighting the business case supporting the IoE initiative. For instance, in a white paper conducted by Cisco Inc. on the Value Index of IoE in 2013 reported the following: In February 2013, Cisco released a study predicting that $14.4 trillion of value (net profit) will be at stake globally over the next decade, driven by connecting the unconnected –people-to-people (P2P), machine-to-people (M2P), and machine-to-machine (M2M) - via the Internet of Everything (IoE). Cisco defines the Internet of Everything as the networked connection of people, process, data, and things. The IoE creates new “capabilities, richer experiences, and unprecedented economic opportunity for businesses, individuals, and countries” (The Internet of Everything, Cisco, Inc. 2014). With such a...

Words: 5523 - Pages: 23

Premium Essay

Copq

...The reasons to estimate the cost of poor quality are multifold, including quantifying the cost of money generated by quality problems, identifying major opportunities for cost reduction, and verifying probabilities of reducing customer dissatisfaction and product salability threats. Additionally, measuring COPQ provides a means of evaluating the progress of quality improvement activities and knowing the cost of poor quality leads to the development of strategic quality plan that is consistent with overall organization of goals. 2.3 Categories of Quality Costs There are four general categories of costs concerning products’ quality. The Internal failure costs are the cost due to the deficiencies discovered before delivery, which are associated with the failure to meet explicit requirements or implicit needs of customers. External failure costs are because of afterwards deficiencies discovered. In the case of FDA, this cost might be associated with food and drug safety problems, and re-inspection of problematic products that have already been publicized. Appraisal costs are the cost generated by ensuring the degree of...

Words: 1042 - Pages: 5

Free Essay

Wfwrf

...Cloud Usage Risk Report November 2014 1 Executive summary The Adallom Cloud Risk Report is published annually, detailing actionable insights and information mined from the Adallom subscriber base. This specific report incorporates analysis of cloud application usage for over one million enterprise SaaS enabled users traversing four dominant SaaS platforms: Salesforce, Box, Google Apps, and Office 365 between October 2013 and October 2014. This report is the first of its kind to detail application usage patterns and risky behaviors for the top SaaS applications used by businesses. The key findings in this report reaffirm the need for a new approach to data governance, risk management, and security in the context of cloud adoption. Perimeter and endpoint security solutions provide minimal protection against new, emerging, and largely unknown risks. Therefore, enterprises need to proactively invest in new controls like Identity and Access Management (IAM) solutions and Cloud Access Security Brokers. Key findings include: • In the cloud zombies are real: 11% of all enterprise SaaS accounts are “zombies,” inactive assigned users that are at best eating up the cost of a license, and at worst increase the attack surface of the organization. • More admins, more problems: Every administrative account represents a real and present risk to the enterprise. In some SaaS applications Adallom recorded an average of 7 administrators out of every 100 users. •...

Words: 4076 - Pages: 17

Free Essay

Trends of Cybercrimes

...Digital equipment that were unheard of just five years ago now inundates both professional and personal arenas. As a result, organizations, as well as their employees, have begun to feel the pressure placed on them to address current and potential threats to the security of their systems and clients (CloudTweaks, 2013). Cybercriminals can retrieve and analyze information gained through technological access from a single business or entity and use such confidential data to give competitive advantages to other organizations, to satisfy the requests of influential individuals, or to benefit national security. The World Wide Web permits immediate and boundless communication and the ability to interface on a global level, which can have its downfalls just as much as its benefits. Unapproved access to, and abuse of, information, technology and fundamental systems can irreparably damage a person or organization’s character, financial status, sense of stability and, in specific instances, physical well-being. Cyber attacks are becoming more frequent, more complex and more effective as hackers develop new ways to reach a greater number of victims. Due to the anonymous nature of crimes related to cyber attacks, every person, organization and nation are potential victims. It is unavoidable. What would we be able to do to secure ourselves? What can...

Words: 1962 - Pages: 8

Premium Essay

Information Security Policy

...1 4.1.2. Security offices, rooms and facilities 1 4.1.3. Isolated delivery and loading areas 2 4.2. Security of the information systems 2 4.2.1. Workplace protection 2 4.2.2. Unused ports and cabling 2 4.2.3. Network/server equipment 2 4.2.4. Equipment maintenance 2 4.2.5. Security of laptops/roaming equipment 2 5. Access Control Policy 2 6. Network Security Policy 3 7. References 3 Executive Summary Due in Week Nine: Write 3 to 4 paragraphs giving a bottom-line summary of the specific measureable goals and objectives of the security plan, which can be implemented to define optimal security architecture for the selected business scenario. With advancements in technology there is a need to constantly protect one’s investments and assets. This is true for any aspect of life. Bloom Design is growing and with that growth we must always be sure to stay on top of protecting ourselves with proper security. For Bloom Design the measurable goals and objectives are website traffic and building security throughout our various buildings. This means we’ll have to implement certain security features to protect Bloom Design and our customers. What we’re trying to protect is both data and material. By this I mean we’re protecting our own data as well as our designers’ data....

Words: 4226 - Pages: 17

Premium Essay

Tjx Corporation

...course of action they must take. They will adhere to a secure network, protect their stored data, prevent future intrusion of their system, restrict access to unauthorized users and frequently test for the implementation of their security measures. TJX will focus on establishing IT governance, mitigate risk, and develop a management strategy through the following alternatives. They will focus on hardware and software upgrades to prevent future attacks of their communication lines and their network through enhanced software and data encryptions. A Payment Card industry Data Security standard has been established and must be maintained by TJX, an implementation from the IT security team will be completed on a regular basis ensuring that all files and file transfers are appropriately encrypted. Internal and external security and network audits will need to be performed on a regular basis to comply with the PCIDSS. This will allow for testing of their system access and identify concerns within the security system. In addition, process logs will be added to detect access to accounts. This will identify unauthorized use and theft of data. It is recommended that TJX upgrade their current network and security protocols, ensure terminals at kiosks are properly secured and firewalls will be installed. TJX will use the following 8 Keys to Sane Security Strategy and implement the...

Words: 3688 - Pages: 15

Premium Essay

Security Policies

...IT Security and Compliance Policy | IS3350/Security Issues; Roger Neveau; 3/12/2013; Mike Taylor, Instructor | This document is the Final Project for IS3350 Security Issues, creating and improving security policies for LenderLive Network | | Table of Contents Introduction2 Risk Analysis2 SWOT Analysis2 Physical Security5 Data Classification6 Regulatory Compliance8 Intellectual Property…………………………………………………………………………………………………………………………….10 Training……………………………………………………………………………………………………………………………………..............11 Security Breach……………………………………………………………………………………………………………………………………..12 Appendix A SWOT Analysis…………………………………………………………………………………………………………………..14 Appendix B Definitions………………………………………………………………………………………………………………………….17 Appendix C Roles…………………………………………………………………………………………………………………………………..18 Works Cited…………………………………………………………………………………………………………………………………………..19 Introduction An effective IT Security policy protects the organization against possible threats to the infrastructure and data that the organization has. It will provide and maintain its ability to provide confidentiality, integrity, availability, and security of the client’s data within the organization’s environment. Overview The IT Security and Compliance policy for LenderLive Network Inc. will detail the policies, procedures, and guidelines that the organization will adhere to, to ensure compliance of the Graham-Leach-Bliley Act (GLBA) and Federal Trade Commission’s Safeguards Rule. It describes...

Words: 4550 - Pages: 19

Free Essay

Social Networks

...receive, store, and process information in the real time. The nation’s state and non-state adversaries are equally aware of the significance of new technology, and will use information-related capabilities (IRCs) to gain advantages in the information environment, just as they would use more traditional military technologies to gain advantages in other operational environments. As the strategic environment continues to change, so does Information Operations (IO). Based on these changes, the present world now characterizes IO as the integrated employment, during military operations, of IRCs in concert with other lines of operation to influence, disrupt, corrupt, or take over the decision making of adversaries and potential adversaries while protecting our own. 0702. Background Information Operations are an evolving construct with roots back to olden times, thus it is both an old and a new concept. The late 1970 world saw the materialization of Information Warfare (IW) and Command and Control Warfare (C2W) as war-fighting constructs integrating several diverse capabilities. These further evolved into Information Operations, recognizing the role of information as an element of power across the spectrum of peace, conflict, and war. 0703. IO Definitions a. Information: Facts, data or instructions in any medium or form is known as information. b. Information Operations (IO):...

Words: 2128 - Pages: 9

Premium Essay

Why Hackers Turned Blackmail

...When Hackers turn to Blackmail How to deal with that attack? Abstract Information technology has become an integral part of any organization in the modern era of globalization. The organizations who have failed to use IT properly for their benefit either have declined or is in a very unproductive stage. Implementation of IT also brings in some dangers which are required to be dealt efficiently with responsibility. This efficiency comes with adequate knowledge of the nuances of the IT industry and the main drawbacks or problems regarding the system. In this case study, Sunnylake’s hospital has been attacked by intruders and Sunnylake’s electronic medical records (EMR), which used to help a lot to Sunnylake to improve its performance in dealing with patients’ information, have got hackers’ attack. The CEO of Sunnylake hospital Paul received the blackmail continuously and is facing a mind-boggling and annoying situation. With respect to this issue in the case, this report will discuss the suggestions to deal with the attack and offer some recommendations to Sunnylake in addition to the three pieces of advice given by the experts in the case. The Case Sunnylake Hospital started as a community center with a vision to help people to cure their disease. Paul Layman, the CEO of the Sunnylake Hospital had joined the organization five years back with a vistion of implementing cutting edge technology to the community center to build it into a hospital which is sought after by...

Words: 3458 - Pages: 14

Free Essay

Network Security

...Network security Network Security Installing firewall or anti-virus software on enterprise workstations can help prevent some of the security problems the Internet can cause; but not everything. By understanding the different Open Systems Interconnect (OSI) levels and security threats involved with each one of them, it is easier to plan a strategy to combat security problems. Purpose and Scope To cover all areas I have listed the network security measures that are associated with each level of the Open Systems Interconnect (OSI). Physical layer This layer is responsible for moving raw bits from one node to another: electrical impulse, light or radio signals. This layer represents the physical application security. It includes access control, power, fire, water, and backups. Many of the threats to security at the Physical layer cause a Denial of Service (DoS) of the enterprise application, making the application unavailable to enterprise users. To ensure this does not occur, the electrical and mechanical parts of the network are not only tested periodically but are kept safe from external damages like tampering or other physical destruction. The backups are in a secured room only few people have access to this room. One method used to manage security in this layer is through Physical Layer Automation. By use of tools such as the Apcon's IntellaPatch™ line of copper and fiber Physical Layer switches, the network administrators have control and security at the foundation...

Words: 995 - Pages: 4

Premium Essay

It Security

...governments are protecting against computer intrusions and attack to prevent loss of data, information and provided services. Everything is now on computers, peoples whole lives are documented on computers. Big business and the government rely on technologies that use computers, whether it is used for storage, a medium between the customers and themselves or actual work. With all this information and data being stored, transferred and used it needs to be secured. A bank is open to the public; you would not have this bank unsecured would you? There would be security guards, cameras, and a vault. The same mentality to secure your data should be implied if you have a network that is connected to the Internet. You should have software, hardware, and/or personnel monitoring your networks operations and security. All computers and systems that connect to the internet or networks run off software of some type. People called hackers or crackers, manipulate programs, create worms, and viruses to make systems do thing there not supposed to, access places they aren’t allowed, and shutdown or hinder a system from working properly (Dasgupta). Then there are attacks, phishing attacks which come in the form of email that try to lead you to fraudulent sites, Denial-of-service attacks overload servers causing no one to get on or shuts them down. Then there are SQL injection attacks which are used in security vulnerable web apps, it’s a code that pulls information from the database and...

Words: 1949 - Pages: 8

Premium Essay

Security Threats

...on the system. Before we can protect the information on a system we need to know what to protect and how to protect them. First must decide what a threat to our system is. A Security threat is anything or anyone that comprise data integrity, confidentiality, and availability of a system. Another security issue for systems is Vulnerabilities in software that can be exploited by people that want to do harm to a system. It’s up to the personnel or team that’s in charge of protecting the system from threats and vulnerabilities. The personnel that secure information technology systems are known as (ISO) Information Security Officer, (IASO) Information Assurance Security Officer, (ISM) Information Security Manager ect. No matter what name the personnel there job is the same to protect information systems. Security Officers will have to set policies that govern the system and create plan on how to handle security threat and vulnerabilities. Security threats can consist of any number issues ranging from physical attack, spoofing, password attacks, identity theft, virus attacks, and Denial of Service attacks, Social Threats, Espionage, malware, spyware, Careless Employees, and hackers. We will disuse all of these threats and ways to prevent them later in the report. In 2010 Kevin Prince, CTO, Perimeter E-Security "As these security threats are becoming more serious and difficult to detect, it is vital for companies to understand what they can do to best protect their systems and information”...

Words: 2408 - Pages: 10