Problem Definition - Why Security?


Problem Definition - Why Security?

Today organizations are increasingly getting networked, as information is exchanged at the speed of thought. Routine tasks rely on the use of computers for accessing, providing or just storing information. However, as information assets differentiate the competitive organization from others of its kind, so do they register an increase in their contribution to the corporate capital? There is a sense of urgency on behalf of the organization to secure these assets from likely threats and vulnerabilities.
The subject of addressing information security is vast and it is the endeavor of this course to give the student a comprehensive body of knowledge required to secure the information assets under his consideration.
This course assumes that there exist organizational policies that are endorsed from the top -level management and that business objective and goals related to security have been incorporated as part of the corporate strategy. A security policy is the specification of how objects in a security domain are allowed to interact.
As a prelude to the course we shall briefly highlight the need to address the security concerns in the contemporary scenario.
The importance of security in the contemporary information and telecommunications scenario cannot be overemphasized. There are myriad reasons for securing ICT infrastructure. For our discussion here, we shall take a macro-level view as detailing each and every aspect can be another course in itself.
The evolution of computers have transcended from the annals of universities to laptops and PDAs. Initially computers were designed to facilitate research and this did not place much emphasis on security as such resources being scarce, were meant for sharing. The permeation of computers into the routine workspace and daily life see more of control being transferred to computers and a higher dependency on them for facilitating important routine tasks. Any disruption meant loss of time, money and sometimes even loss of life.
Technology is evolving at an unprecedented rate and as a result, the products that reach the market are engineered more for ease of use than for secure computing. Technology originally developed for 'honest' research work and campu s related work has not evolved entirely at the pace with which the user profile and span has. However, increasing built -in default security mechanisms meant users had to be more competent. Moreover, vulnerabilities were often overlooked by system designers and would remain unnoticed through the intended deployment of the system.
As computers gain greater control over routine activities, it is becoming increasingly difficult for system administrators and other system professionals to allocate resources exclusively for securing systems. This includes time needed to check log files, detect vulnerabilities and sometimes even to apply security update patches.
The time available with system administrators are consumed by routine activities with less time available towards vigilant administration. There is too little time at hand to deploy measure and secure computing resources on a regular and innovative basis. This has increased the demand for dedicated security professionals who will constantly monitor and defend the ICT resources.
Originally, to 'hack' meant to possess extraordinary computer skills used to extend the limits of computer systems. It required great proficiency on part of the individual. However, today there are automated tools and codes available on the Internet that makes it possible for anyone with a will and desire to hack, to succeed in their effort.
Here, success need not denote the accomplishment of the objective. Mere compromise of the security of a system can denote success in this context. There are websites that insist on 'taking back the net' as well as those that believe that they are doing all a favor by hosting exploit details. These can act in a detrimental manner as well, bringing down the skill level required.
The ease with which system vulnerabilities can be exploited has increased while the knowledge curve required to perform such exploits is shortening. The concept of elite / super hacker is as abstract as before. However, the fast evolving genre of 'script kiddies' are largely comprised of lesser skilled individuals acquiring second hand knowledge and use them to perform exploits.
One of the main impediments to the growth of security infrastructure lies in the unwillingness of exploited or compromised victims to report the incident for fear of losing the goodwill and faith of their employees, customers, partners and market stand. The trend of market valuation being influenced by information assets have seen more enterprises think twice before reporting to law enforcement for fear of bad press and negative publicity.
The increased networked environment with organizations often having their website as a single point of contact across geographical boundaries makes it critical to take countermeasures to ward off any exploits that can result in loss. This is all the more reason why corporate should invest in security measures and protect their information assets.
The figure below illustrates the evolution in attacks and the relative skill profile of the attackers over the years.

Breach of security reflects not only on the information assets compromised, but also on the image of the corporation, which can have an adverse effect on partnerships and also customer base. The 2002 CSI/FBI computer crime and security survey noted that 90% of the respondents had detected security breaches and while only 44% were able to quantify the losses occurred; this alone amounted to a staggering $455,848,000.
This is a sharp increase from previous year's figures of $170,827,000 (theft of proprietary information) and $115,753,000 (financial fraud). It is evident therefore, that the current e-business scenario warrants extreme caution while administering security con figurations to the computing infrastructure.
While the above-mentioned aspects are not exhaustive, they can be cited as the predominant reasons why organizations and system administrators have to equip themselves with tools and methods to circumvent vulnerable scenarios towards achieving organizational objectives.
The primary objective of this course is to equip system administrators, network professionals and security professionals with the competency to defend their system. It must be noted that there are several tools available to provide counter measures and it is not within the scope of this course to detail each and every tool. However, the course will discuss the different genre of tools and examine popular, rich featured tools to give the students an in-depth understanding into the working of the tools belonging to that particular genre.
Another significant difference in approach is the holistic view being adopted throughout this course. We do not restrict our focus to the penetration, but try to explore the activity of the perpetrator in a phased manner. It is therefore assumed that the readers are familiar with technical domains. At the end of this course, students are trained to view adopting defensive tactics as a part of everyday work.

COMMENTS

Name

©2012 Oceninfo.co.cc,2,10:29 IST,1,2012,1,Adfly Bot,2,AFCEH,1,Ajax security,1,all posts for education purpose only...www.facebook.com/princebhalani,1,Android,1,android developer,1,android phone,1,android phone-1,1,anonymous email,1,Anti-Trojan software,8,Antivirus,1,Apple,1,article marketing,1,at risk,1,attacks,1,australian federal police,1,Auto Clicker,1,Auto surfer,1,backtrack link,2,Bank Hacking,2,BCMSN,2,BIOS Update,1,Blockchain,1,Blog and tagged Ransomware,1,boot fast...,1,boot xp faster,1,Business Deals,1,Bypass Antivirus and Hack Window Systems,1,CCIE,2,CCNA,2,CCNP,2,CEH,2,challenge-response system,1,Changing Root Bridge Election Results,2,code,2,commands,1,company deals,1,Computer Hacking,3,Connect,1,cookie stealing,3,Country,1,Crack,1,Credit Card Fraud,2,credit cards,1,Cryptography,1,cyber cell updated,1,cyber security,1,DATA CARD TRICK,1,delhi,1,Digital Marketing,1,direct admission in any colleges,2,Direct Link,3,Directory Traversal Attacks,1,Dos and Ddos,1,DotNetNuke Remote File Upload Vulnerability,1,Earn Lots of money,3,EARN MONEY PART2,1,earnings in$,1,email hacking,4,email spoofing,2,Er Prince Bhalani jobs,1,Ethical Hacker job,1,ethical hacking,8,exploit,1,facebook autoliker,1,Facebook tricks,3,Fake Mail,1,fake sms,1,FB hackz,1,FBI,1,FBI HACKERS,2,FBI Jobs,2,featured,6,Finger scan,1,fingerprint Hacking,1,format without pain,1,Free Download,1,Free Flash Templates,1,free hacking book,5,Free Recharge,1,free sms,2,Freebeacon,1,friendship day,2,friendship day image,2,friendship image,1,Future Computer,2,future of hacking,1,Gadgets,1,good clean fun,1,google,3,Google Ads,1,google adsense account,1,Google hacking,3,google hacks,1,google search,1,hack,2,hack the world,2,HACK WEBSITES USING SQL INJECTION,2,hacker,1,hacker uni,1,hacker/LPT/etc,1,hackers,2,Hackerz info,1,hacking,4,hacking games,1,hacking matterial,1,HACKING OFER,1,hacking softwares,1,hacking tools,2,Hacking with Mobile phones,1,HackingTeacher Security Solutions,1,hacks,1,hijack,1,history of hacking,1,How to,8,How to Hack,37,how to play,1,How to sniff,1,html,1,HTTPS/SSL secured sites,1,I LOVE YOU VIRUS,1,i-phone hacking,1,ICITAM 2012,1,iCloud Era,1,In Flow,1,indian cyber cell,4,information security,1,interesting,1,inurl:fcklinkgallery.as,1,IP hacks,1,iphone,1,IT Act,1,IT Decision Maker,1,IT Implem_App/LOB Spec,1,IT Implem_Desktop/EndUser Spec,1,IT Implem_Infrastructure Spec,1,IT Implem_IT Generalist and IT Manager.,1,it security,1,java,1,jobs for ethical hacker,3,jobs in hacking,5,Joe job,1,Just for education purpose only,1,Kaspersky,1,kaspersky crack 2013,1,keyboard hacking,1,keyloggers,1,keywords,1,Laptop Tracking,1,Laws of computer crime,1,Learn Cracking,1,Learn Website Hacking,7,Linkbucks Bot,1,Macromedia Flash,1,make some rules...|||_|||,1,malicious code,1,Malware,1,malware analysis,1,man in the middle attack (LAN),1,master,1,master list,1,metasploit,3,Microsoft scams,1,mobile,1,mobile recharge,1,moblie phone hacking,1,munging,1,network hack,1,Network Sniffers,1,new command set,1,new projects,1,nmap,1,No Survey,1,not infrequent,1,online scanners,1,paisa live hack,1,panetration for educational purpose only,1,Parental Controls,1,password hacking,4,Password sniffing with arp poisoning,1,PC TIPS,1,PE_PARITE (Trend Micro),1,penetration testing,1,pharming,1,phishing,1,phone hacking charged,1,PHP,1,pin ball,1,Play WMV Files,1,Press Trust of India / New Delhi Aug 15,1,Prime minister,1,prince bhalani,1,princebhalani,1,Professional job in FBI,1,Professional Penetration Testing,1,Programming,1,Programming of virus,2,protect my pc against hackin,1,proxy list by http,1,Proxy SOCKS Port,1,R-Admin With Key,1,Radmin,1,RAW Jobs,1,Real Hackers vs fake ethical hackers. ..:),1,Register of Known Spam Operations (ROKSO),1,repair corrupt hard disk,1,RFT,1,Robbery,1,Rupert Murdoch,1,SAMPLE,1,Sample dynamic flash template from TM website,1,Scams,2,Scanned Vulnerabilities,1,SEA,2,search engine hacking,1,Search Operators,1,Security,2,Security breach,1,security code brack,1,SEM,4,SEO,112,SEO Mistakes,1,SEO TOOLS,1,SEO Tricks,3,SERM,1,SERP,1,Session Hijacking,4,SET,1,shell commands...,1,shell list with download,1,SITES,1,Smart Home,1,Smartphones,1,SMM,1,SMO,2,sms spoofing,1,SMTP Servers,1,Sniffing passwords,1,Sothink SWF Decompiler,1,spam cocktail (or anti-spam cocktail),1,spam trap,1,spear phishing,2,SQL hacking,2,SQL Injection Attacks by Example,2,SSL,1,SSL Analysis,1,starting of help,1,System Information,1,System Restore,1,Tablet in 1000,1,Tablets,1,Temporary Email Service,1,time need,1,timer,1,tracing,1,Traffic,3,tricks,5,Tricks and Tips,1,Trojan,1,Trojan tools,1,Trojans and Backdoors,2,trojon,7,Turbo C++,1,UK phone hacking,1,UK phone hacking arrest,1,USA JOBS,4,Virus,2,virus writing,2,VPN,1,vulnerabilities,1,vulnerability assessment,1,W32/Pate (McAfee),1,W32/Pinfi (Symantec),1,Washington,2,web hacking,6,web security,1,Website Development,1,Website Hacking,3,White House,1,wifi hacking,3,Win32 : parite (Avast),1,Win32.Parite (Kaspersky),1,Win32/Parite,1,windows,2,Windows 8 event for IT Professionals,1,wirless hack,1,WordPress,1,WordPress hacking,1,working with Virus and worm,9,XP Hacking,1,xp hacking-1,1,XP part 3,1,xss hacking,1,
ltr
item
Group Of Oceninfo: Problem Definition - Why Security?
Problem Definition - Why Security?
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwAotiLeGnu3bornZk6hH58kIQVMwouQ_KVAyaGbvloZrXFND63aH-j6UPt1utLbzKVXKpggLORtIj-LN81TpqNMU53n7f2XCc3i_gKuPeIDVfJPS7F8IzrCioEKSh2LczRV3h_tTZVsSy/s320/graph.JPG
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwAotiLeGnu3bornZk6hH58kIQVMwouQ_KVAyaGbvloZrXFND63aH-j6UPt1utLbzKVXKpggLORtIj-LN81TpqNMU53n7f2XCc3i_gKuPeIDVfJPS7F8IzrCioEKSh2LczRV3h_tTZVsSy/s72-c/graph.JPG
Group Of Oceninfo
https://oceninfo.blogspot.com/2011/09/problem-definition-why-security.html
https://oceninfo.blogspot.com/
https://oceninfo.blogspot.com/
https://oceninfo.blogspot.com/2011/09/problem-definition-why-security.html
true
6415817773321450103
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS CONTENT IS PREMIUM Please share to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy