{"id":147,"date":"2018-07-02T11:25:52","date_gmt":"2018-07-02T11:25:52","guid":{"rendered":"http:\/\/lisp1.epgpbooks.inflibnet.ac.in\/?post_type=chapter&#038;p=147"},"modified":"2018-12-04T10:21:24","modified_gmt":"2018-12-04T10:21:24","slug":"informationprincipal-securityinvestigatorissues-in-the-networked-environment","status":"publish","type":"chapter","link":"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/chapter\/informationprincipal-securityinvestigatorissues-in-the-networked-environment\/","title":{"rendered":"Information Principal Security Investigator issues in the Networked environment"},"content":{"raw":"<div><span style=\"float: right\"><a href=\"https:\/\/youtu.be\/SbAsJ-kehQU\" target=\"_blank\" rel=\"noopener\"><img src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a>\r\n<\/span><\/div>\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n<strong style=\"text-align: initial;font-size: 1em\">I.\u00a0<\/strong><strong style=\"text-align: initial;font-size: 1em\">Objectives<\/strong>\r\n<p style=\"text-align: justify\"><span style=\"text-align: justify;font-size: 1em\">The objective of this unit is to provide the students with an overview of the major security issues involved in a networked environment. On completing this unit, the student should be in a position to understand the risks involved as also get an idea of the mechanisms that need to be put in place by way of solutions to secure the information.<\/span><\/p>\r\n<p style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">II.\u00a0\u00a0\u00a0 <\/strong><strong style=\"text-align: initial;font-size: 1em\">Learning Outcome<\/strong><\/p>\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">On completing this module you should have an understanding of the different kinds of threats to information security. You should also have a clear understanding of the terminology in this regard. It is also expected that you have an idea of the measures that are widely employed to ensure information security, especially in the network environment<\/span><\/p>\r\n<p style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">III.\u00a0\u00a0 <\/strong><strong style=\"text-align: initial;font-size: 1em\">Structure of the Module<\/strong><\/p>\r\n\r\n<div>\r\n\r\n1.\u00a0 Information and Networked Environment \u2013 an introduction\r\n\r\n2.\u00a0 \u00a0Information security aspects\r\n<p style=\"padding-left: 30px\">2.1.\u00a0\u00a0\u00a0\u00a0\u00a0 The challenges to provide information security<\/p>\r\n<p style=\"padding-left: 30px\">2.2.\u00a0\u00a0 Why should be information secured?<\/p>\r\n<p style=\"padding-left: 30px\">2.3.\u00a0\u00a0 Three elements of Information Security<\/p>\r\n<p style=\"padding-left: 30px\">2.3.1. Confidentiality<\/p>\r\n<p style=\"padding-left: 30px\">2.3.2. Integrity<\/p>\r\n<p style=\"padding-left: 30px\">2.3.3. Availability<\/p>\r\n3.\u00a0\u00a0\u00a0\u00a0 Main controls aimed at protecting the C-I-A triad.\r\n<p style=\"padding-left: 30px\">3.1. Identification<\/p>\r\n<p style=\"padding-left: 30px\">3.2. Authentication<\/p>\r\n<p style=\"padding-left: 30px\">3.3. Authorization<\/p>\r\n<p style=\"padding-left: 30px\">3.4. Accountability<\/p>\r\n<p style=\"padding-left: 30px\">3.5. Privacy<\/p>\r\n4.\u00a0 Threats to Information Security\r\n<p style=\"padding-left: 30px\">4.1. Information security policy \u2013 a mandate for the organizations.<\/p>\r\n<p style=\"padding-left: 30px\">4.2. Best Practices to Protect Digital Assets.<\/p>\r\n<p style=\"padding-left: 30px\">4.3. Other simple best practices<\/p>\r\n5.\u00a0 Wireless World creating serious security vulnerabilities\r\n\r\n6.\u00a0 The security and privacy issues associated with social networking sites\r\n<p style=\"padding-left: 30px\">6.1. Precautions to be taken<\/p>\r\n7.\u00a0 Summary\r\n\r\n<span style=\"font-size: 1em;text-align: initial\">8. References<\/span>\r\n\r\n&nbsp;\r\n\r\n<strong style=\"text-align: justify;font-size: 1em\">1. Information and Networked Environment \u2013 An Introduction<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"text-align: justify;font-size: 1em\">In the present society, it is a proven fact that information is \u2018power\u2019, information is \u2018wealth\u2019. Information is almost like air that continuously flows. Information flows from human to human, human to machine, machine to machine. Information takes different forms namely handwritten documents, printed documents, voice, text, image, video, etc. The Internet is the core of the Information Society.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">The Internet is not a single network, but a worldwide collection of loosely connected networks that are accessible by individual computer hosts, in a variety of ways, to anyone with a computer and a network connection. Thus, individuals and organizations can reach any point on the internet without regard to national or geographic boundaries or time of day. However, along with the convenience and ease of access to information come risks. Among them are the risks that valuable information may be lost, stolen, altered, or misused. If information is recorded electronically and is available on networked computers, it is more vulnerable than if the same information is printed on paper and locked in a file cabinet. Intruders do not need to enter an office or home; they may not even be in the same country. They can steal or tamper with information without touching a piece of paper or a photocopier. They can also create new electronic files, run their own programs, and hide evidence of their unauthorized activity.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Computers have become an inevitable and essential component of information society today. One cannot imagine a professional life or personal life without computers. Once upon a time, computer used to be an expensive, bulky machine that was used only for number crunching purposes and for handling complicated mathematical operations. Computers were the property of only big and rich organizations. They were available in the form of mainframe computers and mini computers wherein terminals (input\/output devices) had to be connected to get the work done. But today computers are available in different forms like desktop, laptop, tablets, smart phones, and \u2018Google glass\u2019, etc. It\u2019s amazing to note that there has been a paradigm shift in the functionality of computer. Present day computer does:<\/span><\/p>\r\n\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Number crunching;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Information (content) generation;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Information processing;\r\n\r\n<span style=\"font-size: 1em;text-align: initial\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Communication;<\/span>\r\n\r\n<span style=\"text-align: initial;font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Provide entertainment;<\/span>\r\n\r\n<span style=\"text-align: initial;font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Monitoring and many more.<\/span>\r\n\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Out of these functions, the \u2018magic role\u2019 played by computers is to create Information Networked Society. The largest engineered system ever created by mankind, namely Internet, binds or connects or networks millions of such computers to create Information Networked Society. Internet has converted the whole world in to what is known as \u2018global village\u2019. Let us look at the basic elements of internet.<\/p>\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 User end machines \/ Hosts\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Network\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Protocols\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">User end machine could be a desktop, laptop, a smart phone that creates and exchanges information in the form voice, text, image, video or a combination of these. In other words, information is also called \u2018content\u2019. Network deals with how the machines \/ gadgets creating and exchanging information are connected using a set of hardware and software. The process of exchanging information is popularly known as protocol. Figure below presents a macro-view of the building blocks of the internet.<\/p>\r\n<img class=\"alignnone size-full wp-image-294\" src=\"http:\/\/lisp1.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/7\/2018\/07\/1-88.png\" alt=\"\" width=\"425\" height=\"220\" \/>\r\n\r\n&nbsp;\r\n\r\n<strong>2. Information security aspects<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\"><em>\u201cInformation security is the practice of defending information from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording or destruction. It is a general term that can be used regardless of the form the data may take (electronic, physical, etc...)\u201d <\/em>(Wikipedia)<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Many organizations realize that one of their most valuable assets is their data, because without data, an organization loses its record of transactions and\/or its ability to deliver value to its customers. Protecting data in motion and data at rest are both critical aspects of information security. An effective information security program is essential to the protection of the integrity and value of the organization\u2019s data.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Two major aspects of information security are:<\/span><\/p>\r\n\r\n<ul>\r\n \t<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">IT Security: <\/strong><span style=\"font-size: 1em\">Information Technology Security is information security applied to technology (most often some form of computer system). IT security specialists are almost always found in any major enterprise\/establishment due to the nature and value of the data within large businesses. They are responsible for keeping all of the technology within the organization secure from malicious cyber attacks that often attempt to breach into the critical private information or gain control of the internal systems.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Information Assurance: <\/strong><span style=\"font-size: 1em\">The process to assure that data is not lost when\u00a0<\/span>critical issues arise. These issues include but are not limited to: natural disasters, computer\/server malfunction, physical theft, or any other instance where data has the potential of being lost. Since most information is stored on computers in the modern era, information assurance is typically dealt with by IT security specialists.<\/li>\r\n<\/ul>\r\n&nbsp;\r\n<p style=\"text-align: justify\">2.1 <strong style=\"font-size: 1em\">The challenges to provide Information Security:<\/strong><span style=\"font-size: 1em\"> Let us look at simple day-to-day example of browsing the Internet. End user, typically called as client, invokes a browser like internet explorer, google chrome, enters the address of the web site (the address of the server computer) to be browsed and presses enter key. After a few seconds, the first page of the web site, typically called as home page, is displayed on the monitor. In this process, there is a complex sequence of actions that takes place in the background. The request for the page travels through a complex Internet infrastructure that makes use of private and public infrastructure and reaches the server at the other end. The home page is returned to the client.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">An important point to be noted from this simple example is that securing the information has to be done a 4 levels, end-to-end namely:<\/span><\/p>\r\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Data<\/span><\/p>\r\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Application<\/span><\/p>\r\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Host<\/span><\/p>\r\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Network<\/span><\/p>\r\n\r\n<\/div>\r\n<img class=\"size-full wp-image-152 aligncenter\" src=\"http:\/\/lisp1.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/7\/2018\/07\/1-37.png\" alt=\"\" width=\"615\" height=\"326\" \/>\r\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">2.2. <\/span><strong style=\"text-align: initial;font-size: 1em\">Why should information be secured?: <\/strong><span style=\"text-align: initial;font-size: 1em\">The answer is simple: a mentioned earlier, information is wealth. It\u2019s obvious to secure the wealth if an organization has to survive and grow. Broadly information security:<\/span><\/p>\r\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">1.\u00a0\u00a0\u00a0\u00a0 Prevents data theft<\/span><\/p>\r\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">2.\u00a0\u00a0\u00a0\u00a0 Avoids legal consequences of not securing information<\/span><\/p>\r\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">3.\u00a0\u00a0\u00a0\u00a0 Maintains productivity<\/span><\/p>\r\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">4.\u00a0\u00a0\u00a0\u00a0 Foils cyber terrorism<\/span><\/p>\r\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">5.\u00a0\u00a0\u00a0\u00a0 Prevents identity theft<\/span><\/p>\r\n\r\n<div>\r\n\r\n&nbsp;\r\n\r\n2.3. <strong>Three Elements of Information Security: <\/strong>The three key elements of information security are:\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <strong>C<\/strong>onfidentiality,\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <strong>I<\/strong>ntegrity\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <strong>A<\/strong>vailability\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Referred to as the C-I-A triad or information security triad<strong>.<\/strong> Let\u2019s look at the meaning of each of these elements.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">2.3.1. <strong>Confidentiality:<\/strong> Confidentiality means that information that is not in public domain should stay secret and be accessible to only those persons authorized to access it. Unauthorized access to confidential information may have devastating consequences, not only in national security applications, but also in commerce and industry. Main mechanisms of protection of confidentiality in information systems are cryptography and access controls. Examples of threats to confidentiality are malware, intruders, social engineering, insecure networks, and poorly administered systems.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">2.3.2. <strong>Integrity:Integrity<\/strong> is concerned with the trustworthiness, origin, completeness, and correctness of information as well as the prevention of improper or unauthorized modification of information. Integrity in the information security context refers not only to integrity of information itself but also to the origin integrity\u2014that is, integrity of the source of information.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">Integrity protection mechanisms may be grouped into two broad types: <strong>Preventive mechanisms <\/strong>such as access controls that prevent unauthorized modification of information,<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">Detective <\/strong><span style=\"font-size: 1em\">mechanisms<\/span><strong style=\"font-size: 1em\">, <\/strong><span style=\"font-size: 1em\">which are intended to detect unauthorized modifications when preventive mechanisms have failed. Controls that protect integrity include principles of least privilege, separation, and rotation of duties.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">2.3.3. <\/span><strong style=\"font-size: 1em\">Availability:<\/strong><span style=\"font-size: 1em\">Availability of information, although usually mentioned last, is not the least important pillar of information security. Who needs confidentiality and integrity if the authorized users of information cannot access and use it? Who needs sophisticated encryption and access controls if the information being protected is not accessible to authorized users when they need it? Therefore, despite being mentioned last in the C-I-A triad, availability is just as important and as necessary a component of information security as confidentiality and integrity.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Attacks against availability are known as denial of service (DoS) attacks, Natural and man made disasters obviously may also affect availability as well as confidentiality and integrity of information, though their frequency and severity greatly differ\u2014natural disasters are infrequent but severe, whereas human errors are frequent but usually not as severe as natural disasters. In both cases, business continuity and disaster recovery planning (which at the very least includes regular and reliable backups) is intended to minimize losses.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">3.\u00a0\u00a0\u00a0\u00a0 <\/span><strong style=\"font-size: 1em\">Main controls aimed at protecting the C-I-A triad.<\/strong><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Central to information security is the concept of controls, which is categorized as physical, administrative, technical and functional.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Physical <\/span><strong style=\"font-size: 1em\">controls<\/strong><span style=\"font-size: 1em\"> include doors, secure facilities, fire extinguishers, flood protection, and air conditioning.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">Administrative <\/strong><span style=\"font-size: 1em\">controls are the organization\u2019s policies, procedures, and guidelines intended to facilitate information security.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">Technical control <\/strong><span style=\"font-size: 1em\">includes measures such as firewalls, authentication systems, intrusion detection systems, and file encryption, among others.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">Functional control <\/strong><span style=\"font-size: 1em\">is again classified in to:<\/span><\/p>\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><strong style=\"font-size: 1em\">Preventive<\/strong><\/p>\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><strong style=\"font-size: 1em\">Detective<\/strong><\/p>\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><strong style=\"font-size: 1em\">Corrective<\/strong><\/p>\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><strong style=\"font-size: 1em\">Deterrent<\/strong><\/p>\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><strong style=\"font-size: 1em\">Recovery<\/strong><\/p>\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><strong style=\"font-size: 1em\">Compensating<\/strong><\/p>\r\n&nbsp;\r\n<ul>\r\n \t<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Preventive Controls: <\/strong><span style=\"font-size: 1em\">Preventive controls are the first controls met by the adversary. Preventive controls try to prevent security violations and enforce access control. Like other controls, preventive controls may be physical, administrative, or technical: doors, security procedures, and\u00a0<\/span><span style=\"font-size: 1em\">authentication requirements are examples of physical, administrative, and technical preventive controls, respectively.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Detective Controls<\/strong><span style=\"font-size: 1em\">: are in place to detect security violations and alert the defenders. They come into play when preventive controls have failed or have been circumvented and are no less crucial than detective controls. Detective cont rols include cryptographic checksums, file integrity checkers, audit trails and logs, and similar mechanisms.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Corrective control: <\/strong><span style=\"font-size: 1em\">try to correct the situation after a security violation has occurred. Although a violation occurred, not all is lost, so it makes sen se to try and fix the situation. Corrective controls vary widely, depending on the area being targeted, and they may be technical or administrative in nature.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Deterrent <\/strong><span style=\"font-size: 1em\">Controls are intended to discourage potential attackers and send the message that it is better not to attack, but even if you decide to attack we are able to defend ourselves. Examples of deterrent controls include notices of monitoring and logging as well as the visible practice of sound information security management.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Recovery <\/strong><span style=\"font-size: 1em\">Controls are somewhat like corrective controls, but they are applied in more serious situations to recover from security violations and restore information and information processing resources. Recovery controls may include disaster recovery and business continuity mechanisms, backup systems and data, emergency key management arrangements, and similar controls.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Compensating: These <\/strong><span style=\"font-size: 1em\">are intended to be alternative arrangements for other controls when the original controls have failed or cannot be used.<\/span>When a second set of controls addresses the same threats that are addressed by another set of controls, the second set of controls are compensating controls.<\/li>\r\n<\/ul>\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Let us now look at the typical process followed to ensure information security.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Identification<\/p>\r\n<p style=\"text-align: justify\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Authentication<\/p>\r\n<p style=\"text-align: justify\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Authorization Processes<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>3.1. Identification: <\/strong>Identification is the first step in the identify-authenticate-authorize sequence that is performed every day countless times by humans and computers. While particulars of identification systems differ depending on who or what is being identified, some intrinsic properties of identification apply regardless of these particulars. Just three of these properties are the:<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">i. Scope<\/p>\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em;text-align: initial\">ii.\u00a0\u00a0\u00a0\u00a0\u00a0 Locality<\/span><\/p>\r\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">iii.\u00a0\u00a0\u00a0\u00a0\u00a0 Uniqueness of IDs<\/span><\/p>\r\n\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Identification name spaces can be local or global in scope. To illustrate this concept, let\u2019s refer to the familiar notation of Internet e-mail addresses. while many e-mail accounts named <strong>john<\/strong> may exist around the world, an e -mail address john@company.com unambiguously refers exactly to one such user in the company .com locality. Provided that the company in question is a small one, and that only one employee is named John, inside the company everyone may refer to that particular person by simply using his first name. That would work because they are in the same locality and only one John works there. However, if John were someone on the other side of the world or even across town, to refer to john@company.com as simply john would make no sense, because user name john is not globally unique and refers to different persons in different localities. This is one of the reasons why two user accounts should never use the same name on the same system\u2014not only because you would not be able to enforce access controls based on non-unique and ambiguous user names, but also because you would not be able to establish accountability for user actions. What it means is that, for information security purposes, unique names are required and, depending on their scope, they must be locally unique and possibly globally unique so that access control may be enforced and accountability established.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>3.2. Authentication: <\/strong>Authentication, which happens just after identification and before authorization, verifies the authenticity of the identity declared at the identification stage. In other words, it is at the authentication stage that you prove that you are indeed the person or the system you claim to be. The three methods of authentication are:<\/p>\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 What you know\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 What you have\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 What you are.\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">The aim is to obtain reasonable assurance that the identity declared at the identification stage belongs to the party in communication. It is important to note that reasonable assurance may mean different degrees of assurance, depending on the particular environment and application, and therefore may require different approaches to authentication: authentication requirements of a national security\u2013 critical system naturally differ from authentication requirements of a small company. Because different authentication methods have different costs and properties as well as different returns on investment, the choice of authentication method for a particular system or organization should be made after these factors have been carefully considered.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">What You Know<\/strong><span style=\"font-size: 1em\">: Among what you know authentication methods are passwords, passphrases, secret codes, and personal identification numbers (PINs). When using what you know authentication methods, it is implied that if you know something that is supposed to be known only by X, then you must be X (although in real life that is not always the case). What you know authentication is the most commonly used authentication method thanks to its low cost and easy implementation in information systems. <\/span><em style=\"font-size: 1em\">However, what you know authentication alone may not be<\/em> <em style=\"font-size: 1em\">considered strong authentication and is not adequate for systems requiring high security.<\/em><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">What You Have<\/strong><strong style=\"font-size: 1em\">: <\/strong><span style=\"font-size: 1em\">Perhaps the most widely used and familiar what you have authentication methods are keys\u2014keys we use to lock and unlock doors, cars, and drawers; just as with doors, what you have authentication in information systems implies that if you possess some kind of token, such as a smart card or a USB token, you are the individual you are claiming to be. Of course, the same risks that apply to keys also apply to smart cards and USB tokens\u2014they may be stolen, lost, or damaged. What you have authentication methods include an additional inherent per-user cost. Compare these methods with passwords: it costs nothing to issue a new password, whereas per-user what you have authentication costs may be considerable.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">What You Are<\/strong><strong style=\"font-size: 1em\">: <\/strong><span style=\"font-size: 1em\">What you are authentication refers to biometric authentication methods. A biometric is a physiological or behavioral characteristic of a human being that can distinguish one person from another and that theoretically can be used for identification or verification of identity. Biometric authentication methods include<\/span><\/p>\r\n\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Fingerprint\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Iris, and Retina Recognition\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Voice and Signature Recognition\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Biometric authentication methods when used correctly, in addition to what you have or what you know authentication, may significantly contribute to the strength of authentication. Biometrics is a complex subject and is much more cumbersome to deploy than what you know or what you have authentication. Unlike what you know or what you have authentication methods, whether or not you know the password or have the token, biometric authentication systems say how much you are like the subject you are claiming to be; naturally this method requires much more installation-dependent tuning and configuration.<\/p>\r\n&nbsp;\r\n\r\n<strong>3.3. Authorization<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">After declaring identity at the identification stage and proving it at the authentication stage, users are assigned a set of authorizations referred to as rights, privileges, or permissions that define what they can do on the system. These\u00a0<span style=\"font-size: 1em\">authorizations are most commonly defined by the system\u2019s security policy and are set by the security or system administrator. These privileges may range from the extremes of \u201cpermit nothing\u201d to \u201cpermit everything\u201d and include anything in between. As you can see, the second and third stages of the identify-authenticate-authorize process depend on the first stage, and the final goal of the whole process is to enforce access control and accountability.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">3.4. Accountability<\/strong><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Accountability is another vital principle of information security that refers to the possibility of tracing actions and events back in time to the users, systems, or processes that performed them, to establish responsibility for actions or omissions. A system may not be considered secure if it does not provide accountability, because it would be impossible to ascertain who is responsible and what did or did not happen on the system without that safeguard. Accountability in the context of information systems is mainly provided by logs and the audit trail.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">Logs<\/strong><span style=\"font-size: 1em\">: System and application logs are ordered lists of events and actions and are the primary means of establishing accountability in most systems. However, logs (as well as the audit trail, which is described next) may be considered trustworthy only if their integrity is reasonably assured. In other words, if anyone can write to and\/or erase logs or the audit trail, they would not be considered dependable enough to serve as the basis for accountability. In case of networked or communication systems, logs should be correctly <\/span><strong style=\"font-size: 1em\">timestamped<\/strong><span style=\"font-size: 1em\"> and time should be synchronized across the network so events that affect more than one system may be correctly correlated and attributed.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">Audit Trail <\/strong><span style=\"font-size: 1em\">: Logs usually show high-level actions, such as an e -mail message delivered or a web page served, whereas audit trails usually refer to lower-level operations such as opening a file, writing to a file, or sending a packet across a network. Another aspect by which logs and audit trails differ is their source: logs are usually and mostly generated by particular system software or applications, and an audit trail is usually kept by the operating system or its auditing module.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">3.5. Privacy<\/strong><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Privacy normally refers to the expectation and rights of individuals to privacy of their personal information and adequate, secure handling of this information by its users. Personal information here usually refers to information that directly identifies a human being, such as a name and address, although the details may differ in different countries. In many countries, privacy of personal information is protected by laws that impose requirements on organizations processing personal data and set penalties for noncompliance. The European Union (EU) in particular has strict personal data protection legislation in place, which limits how organizations may process personal information and what they can do with it. The\u00a0<\/span><span style=\"font-size: 1em;text-align: initial\">U.S. Constitution also guarantees certain privacy rights, although the approach to privacy issues differs between the United States and Europe.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">IV. Threats to Information Security<\/strong><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Threat is nothing but an object, person, or other entity that represents a constant danger to an asset. Management must be informed of the different threats facing the organization. By examining each threat category, management effectively protects information through policy, education, training, and technology controls.<\/span><\/p>\r\n\r\n<\/div>\r\n<div>\r\n\r\n<img class=\"alignnone wp-image-153\" src=\"http:\/\/lisp1.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/7\/2018\/07\/1-38.png\" alt=\"\" width=\"721\" height=\"485\" \/>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>Malicious code: <\/strong>includes execution of viruses, worms, Trojan horses, and active Web scripts with intent to destroy or steal information<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>Back door: <\/strong>gaining access to system or network using known or previously unknown\/newly discovered access mechanism<\/p>\r\n&nbsp;\r\n\r\n<strong>Password crack<\/strong>: attempting to reverse calculate a password\r\n\r\n&nbsp;\r\n\r\n<strong>Brute force<\/strong>: trying every possible combination of options of a password\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>Dictionary<\/strong>: selects specific accounts to attack and uses commonly used passwords (i.e., the dictionary) to guide guesses<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>Denial-of-Service<\/strong> <strong>(DoS<\/strong>): attacker sends large number of connection or information requests to a target<\/p>\r\n\r\n<ul>\r\n \t<li style=\"text-align: justify\">Target system cannot handle successfully along with other, legitimate service requests<\/li>\r\n \t<li style=\"text-align: justify\">May result in system crash or inability to perform ordinary functions <strong style=\"text-align: initial;font-size: 1em\">Distributed Denial-of-Service (DDoS): <\/strong><span style=\"text-align: initial;font-size: 1em\">coordinated stream of requests is launched against target from many locations simultaneously<\/span><\/li>\r\n \t<li style=\"text-align: justify\">Spoofing: technique used to gain unauthorized access; intruder assumes a trusted IP address<\/li>\r\n \t<li style=\"text-align: justify\">Man-in-the-middle: attacker monitors network packets, modifies them, and inserts them back into network<\/li>\r\n \t<li style=\"text-align: justify\">Spam: unsolicited commercial e-mail; more a nuisance than an attack, though is emerging as a vector for some attacks<\/li>\r\n \t<li style=\"text-align: justify\">Mail bombing: also a DoS; attacker routes large quantities of e-mail to target<\/li>\r\n \t<li style=\"text-align: justify\">Sniffers: program or device that monitors data traveling over network; can be used both for legitimate purposes and for stealing information from a network<\/li>\r\n \t<li style=\"text-align: justify\">Social engineering: using social skills to convince people to reveal access credentials or other valuable information to attacker<\/li>\r\n \t<li style=\"text-align: justify\">Buffer overflow: application error occurring when more data is sent to a buffer than can be handled<\/li>\r\n \t<li style=\"text-align: justify\">Timing attack: relatively new; works by exploring contents of a Web browser\u2019s cache to create malicious cookie<\/li>\r\n<\/ul>\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>4.1. Information Security Policy \u2013 a mandate for the organizations. <\/strong>Information security is not an 'IT problem', it is a business issue. Obviously compliance with legal and regulatory requirements is important. It provides a very good reason for reviewing your information security practices, but it should not in itself be the sole or even the main driver. If a business wishes to survive, let alone prosper, it must grasp the importance of information security and put in place appropriate measures and processes.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">An information security policy is a set of rules and practices that define how the sensitive information of a company should be managed, protected, and distributed within the organization. The different aspects of an information security policy include labeling the information, modification of the information, accountability, and information ownership.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">Each organization has an organization structure and the staff members at different levels needs to access different types of data. The information classification and the data distribution policies are therefore important for a company, so that the staff members at lower level should not be allowed to access data stored for higher level staff.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">The main objectives of information security policy are:<\/p>\r\n\r\n<ul>\r\n \t<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Integrity<\/strong><span style=\"text-align: initial;font-size: 1em\">: The data is not tempered and modified undetectably.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Availability<\/strong><span style=\"font-size: 1em\">: Data is available when it is required. This means that all the systems that are involved in data security, data access or processing or data distribution function properly.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Disclosure<\/strong><span style=\"font-size: 1em\">: The disclosure of data should be as much, as it is important for the user to perform his task.<\/span><\/li>\r\n<\/ul>\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n\r\n<strong>4.2. Best Practices to Help Protect Digital Assets.<\/strong>\r\n\r\n&nbsp;\r\n\r\nIt is essential to install:\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Anti-Virus Software\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Anti-Spyware Software\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Applications Updates\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Security Bundles\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Personal Firewalls\r\n\r\n&nbsp;\r\n\r\n<strong>4.3. Other simple best practices<\/strong>\r\n\r\n&nbsp;\r\n\r\nIt is very important to follow simple best practices as part of creating information security:\r\n<ul>\r\n \t<li>When not using your PC, turn it off<\/li>\r\n \t<li>View your E-mail as text only; disable the function that automatically views E-mail as HTML<\/li>\r\n \t<li>Do not automatically open attachments<\/li>\r\n \t<li>Do not run software programs of unknown origin<\/li>\r\n \t<li>Delete chain E-mails and junk mail. Do not forward or reply to any of them<\/li>\r\n \t<li style=\"text-align: justify\">Never reply back to an E-mail to \"unsubscribe\" or to remove yourself from an unknown list. This lets the spammers know that they have reached a live E-mail address and your spam mail will increase<\/li>\r\n \t<li>Back up your critical data and documents regularly \u2013 thumb drives and CDs are cheap<\/li>\r\n<\/ul>\r\n&nbsp;\r\n\r\n<strong style=\"text-align: initial;font-size: 1em\">5.\u00a0 <\/strong><strong style=\"text-align: initial;font-size: 1em\">Wireless World Creating Serious Security Vulnerabilities<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Wireless technologies have empowered IT users to access information anytime, anywhere. At the same time, creating serious security vulnerabilities like:<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Unauthorized users can access the wireless signal from outside a building and connect to the network<\/p>\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Attackers can capture and view transmitted data (including encrypted data)\r\n<p style=\"text-align: justify\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Employees in the office can install personal wireless equipment and defeat perimeter security measures<\/p>\r\n\r\n<\/div>\r\n&nbsp;\r\n\r\n<strong style=\"text-align: initial;font-size: 1em\">6. The security and privacy issues associated with social networking sites<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"text-align: justify;font-size: 1em\">Social networking sites have become very popular avenues for people to communicate with family, friends and colleagues from around the corner or across the globe. While there can be benefits from the collaborative, distributed approaches promoted by responsible use of social networking sites, there are information security and privacy concerns. The volume and accessibility of personal information available on social networking sites have attracted malicious people who seek to exploit this information. The same technologies that invite user participation also make the sites easier to infect with malware that can shut down an organization's networks, or keystroke loggers that can steal credentials.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">Common social networking risks such as spear phishing, social engineering, spoofing, and web application attacks attempt to steal a person's identity<\/span><strong style=\"text-align: initial;font-size: 1em\">.<\/strong><span style=\"text-align: initial;font-size: 1em\"> Such attacks are often successful due to the assumption of being in a trusting environment social networks create.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Security and privacy related to social networking sites are fundamentally behavioral issues, not technology issues. The more information a person posts, the more information becomes available for a potential compromise by those with malicious intentions. People who provide private, sensitive or confidential information about themselves or other people, whether wittingly or unwittingly, pose a higher risk to themselves and others. Information such as a person's social security number, street address, phone number, financial information, or confidential business information should not be published online. Similarly, posting photos, videos or audio files could lead to an organization's breach of confidentiality or an individual's breach of privacy.<\/span><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">6.1. Precautions to be taken<\/strong><\/p>\r\n\r\n<ul>\r\n \t<li style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">Below are some helpful tips regarding security and privacy while using social networking sites:<\/span><\/li>\r\n \t<li style=\"text-align: justify\">Ensure that any computer you use to connect to a social media site has <strong style=\"font-size: 1em\">proper<\/strong> <strong style=\"font-size: 1em\">security measures <\/strong><span style=\"font-size: 1em\">in place. Use and maintain anti-virus software and keep your application and operating system patches up-to-date.<\/span><\/li>\r\n \t<li style=\"text-align: justify\">Use caution when clicking a link to another page or running an online application, even if it is from someone you know. Many applications embedded within social networking sites require you to share your information when you use them. Attackers use these sites to distribute their malware.<\/li>\r\n \t<li style=\"text-align: justify\">Use <strong style=\"font-size: 1em\">strong and unique passwords<\/strong><span style=\"font-size: 1em\">. Using the same password on all accounts increases the vulnerability of these accounts if one becomes compromised.<\/span><\/li>\r\n \t<li style=\"text-align: justify\">If screen names are allowed, do not choose one that gives away <strong style=\"font-size: 1em\">too much<\/strong> <strong style=\"font-size: 1em\">personal information.<\/strong><\/li>\r\n \t<li style=\"text-align: justify\">Be careful who you add as a \"friend,\" or what groups or pages you join. The more \"friends\" you have or groups\/pages you join, the more people who have access to your information.<\/li>\r\n \t<li style=\"text-align: justify\">Do not assume <strong style=\"font-size: 1em\">privacy on a social networking<\/strong><span style=\"font-size: 1em\"> site. For both business and personal use, confidential information should not be shared. You should only post information you are comfortable disclosing to a complete stranger.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Use discretion before posting <\/strong><span style=\"font-size: 1em\">information or commenting about anything. Once information is posted online, it can potentially be viewed by anyone and may not be retracted afterwards. Keep in mind that content or communications on government-related social networking pages may be considered public records.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Configure privacy settings <\/strong><span style=\"font-size: 1em\">to allow only those people you trust to have access to the information you post. Also, restrict the ability for others to post information to your page. The default settings for some sites may allow anyone to see your information or post information to your page; these settings should be changed.<\/span><\/li>\r\n \t<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Review a site's privacy policy. <\/strong><span style=\"text-align: initial;font-size: 1em\">Some sites may share information such as email addresses or user preferences with other parties. If a site's privacy policy is vague or does not properly protect your information, do not use the site.<\/span><\/li>\r\n<\/ul>\r\n<div>\r\n\r\n&nbsp;\r\n\r\n<strong>7. Summary<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Modern society is completely dependent on information and information technology. Internet is the part and parcel of both professional and personal life. Anywhere, anytime access, with the advent of wireless technology, is really a boon. Variety of security threats may convert the boon to bane. It is extremely important to protect the information through variety of solutions. It should be the right blend of technologies, policies, education and culture.<\/p>\r\n<table>\r\n<tbody>\r\n<tr>\r\n<td><strong>you can view video on Information Principal Security Investigator issues in the Networked environment<\/strong><\/td>\r\n<td><a href=\"https:\/\/youtu.be\/SbAsJ-kehQU\" target=\"_blank\" rel=\"noopener\"><img class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n\r\n<strong>8.\u00a0 References<\/strong>\r\n\r\n&nbsp;\r\n<ul>\r\n \t<li style=\"text-align: justify\">Mcclure, scambray and kurtz - mcclure, s., j. Scambray, et al. (2005). Hacking exposed : network security secrets &amp; solutions. Emeryville, calif.,mcgraw-hill\/osborne. Wikipedia-http:\/\/en.wikipedia.org\/wiki\/information_security<\/li>\r\n \t<li style=\"text-align: justify\">Issue update on information security and privacy in network environments <span style=\"font-size: 1em\">september 1995 <\/span><span style=\"font-size: 1em\">Ota-bp-itc-147, gpo stock #052-003-01416-5<\/span><\/li>\r\n \t<li style=\"text-align: justify\">Computer networking, 6e, james f. Kurose , keith w. Ross, pearson publiction <span style=\"text-align: initial;font-size: 1em\">Tutorial- <\/span><a style=\"text-align: initial;font-size: 1em\" href=\"http:\/\/learnthat.com\/2010\/11\/introduction-to-network-security\/\">http:\/\/learnthat.com\/2010\/11\/introduction-to-network-security\/<\/a><\/li>\r\n \t<li style=\"text-align: justify\">Information security forum : web: www.securityforum.org<\/li>\r\n \t<li style=\"text-align: justify\">Information security policies and controls for a trusted environment by s. Srinivasan, i n f o r m at i o n s y s t e m s c o n t r o l j o u r n a l , vol. 2 , 2 0 0 8<\/li>\r\n \t<li style=\"text-align: justify\"><em style=\"font-size: 1em\">Cyber security tips, newsletter march 2010,volume 5, issue 3, from the desk of william f. Pelgrin, chair\u00a0<\/em><\/li>\r\n \t<li style=\"text-align: justify\">Internet and network security fundamentals, presentation by champika wijayatunga, training manager, apnic<\/li>\r\n<\/ul>\r\n<\/div>","rendered":"<div><span style=\"float: right\"><a href=\"https:\/\/youtu.be\/SbAsJ-kehQU\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a><br \/>\n<\/span><\/div>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong style=\"text-align: initial;font-size: 1em\">I.\u00a0<\/strong><strong style=\"text-align: initial;font-size: 1em\">Objectives<\/strong><\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: justify;font-size: 1em\">The objective of this unit is to provide the students with an overview of the major security issues involved in a networked environment. On completing this unit, the student should be in a position to understand the risks involved as also get an idea of the mechanisms that need to be put in place by way of solutions to secure the information.<\/span><\/p>\n<p style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">II.\u00a0\u00a0\u00a0 <\/strong><strong style=\"text-align: initial;font-size: 1em\">Learning Outcome<\/strong><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">On completing this module you should have an understanding of the different kinds of threats to information security. You should also have a clear understanding of the terminology in this regard. It is also expected that you have an idea of the measures that are widely employed to ensure information security, especially in the network environment<\/span><\/p>\n<p style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">III.\u00a0\u00a0 <\/strong><strong style=\"text-align: initial;font-size: 1em\">Structure of the Module<\/strong><\/p>\n<div>\n<p>1.\u00a0 Information and Networked Environment \u2013 an introduction<\/p>\n<p>2.\u00a0 \u00a0Information security aspects<\/p>\n<p style=\"padding-left: 30px\">2.1.\u00a0\u00a0\u00a0\u00a0\u00a0 The challenges to provide information security<\/p>\n<p style=\"padding-left: 30px\">2.2.\u00a0\u00a0 Why should be information secured?<\/p>\n<p style=\"padding-left: 30px\">2.3.\u00a0\u00a0 Three elements of Information Security<\/p>\n<p style=\"padding-left: 30px\">2.3.1. Confidentiality<\/p>\n<p style=\"padding-left: 30px\">2.3.2. Integrity<\/p>\n<p style=\"padding-left: 30px\">2.3.3. Availability<\/p>\n<p>3.\u00a0\u00a0\u00a0\u00a0 Main controls aimed at protecting the C-I-A triad.<\/p>\n<p style=\"padding-left: 30px\">3.1. Identification<\/p>\n<p style=\"padding-left: 30px\">3.2. Authentication<\/p>\n<p style=\"padding-left: 30px\">3.3. Authorization<\/p>\n<p style=\"padding-left: 30px\">3.4. Accountability<\/p>\n<p style=\"padding-left: 30px\">3.5. Privacy<\/p>\n<p>4.\u00a0 Threats to Information Security<\/p>\n<p style=\"padding-left: 30px\">4.1. Information security policy \u2013 a mandate for the organizations.<\/p>\n<p style=\"padding-left: 30px\">4.2. Best Practices to Protect Digital Assets.<\/p>\n<p style=\"padding-left: 30px\">4.3. Other simple best practices<\/p>\n<p>5.\u00a0 Wireless World creating serious security vulnerabilities<\/p>\n<p>6.\u00a0 The security and privacy issues associated with social networking sites<\/p>\n<p style=\"padding-left: 30px\">6.1. Precautions to be taken<\/p>\n<p>7.\u00a0 Summary<\/p>\n<p><span style=\"font-size: 1em;text-align: initial\">8. References<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><strong style=\"text-align: justify;font-size: 1em\">1. Information and Networked Environment \u2013 An Introduction<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: justify;font-size: 1em\">In the present society, it is a proven fact that information is \u2018power\u2019, information is \u2018wealth\u2019. Information is almost like air that continuously flows. Information flows from human to human, human to machine, machine to machine. Information takes different forms namely handwritten documents, printed documents, voice, text, image, video, etc. The Internet is the core of the Information Society.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">The Internet is not a single network, but a worldwide collection of loosely connected networks that are accessible by individual computer hosts, in a variety of ways, to anyone with a computer and a network connection. Thus, individuals and organizations can reach any point on the internet without regard to national or geographic boundaries or time of day. However, along with the convenience and ease of access to information come risks. Among them are the risks that valuable information may be lost, stolen, altered, or misused. If information is recorded electronically and is available on networked computers, it is more vulnerable than if the same information is printed on paper and locked in a file cabinet. Intruders do not need to enter an office or home; they may not even be in the same country. They can steal or tamper with information without touching a piece of paper or a photocopier. They can also create new electronic files, run their own programs, and hide evidence of their unauthorized activity.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Computers have become an inevitable and essential component of information society today. One cannot imagine a professional life or personal life without computers. Once upon a time, computer used to be an expensive, bulky machine that was used only for number crunching purposes and for handling complicated mathematical operations. Computers were the property of only big and rich organizations. They were available in the form of mainframe computers and mini computers wherein terminals (input\/output devices) had to be connected to get the work done. But today computers are available in different forms like desktop, laptop, tablets, smart phones, and \u2018Google glass\u2019, etc. It\u2019s amazing to note that there has been a paradigm shift in the functionality of computer. Present day computer does:<\/span><\/p>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Number crunching;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Information (content) generation;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Information processing;<\/p>\n<p><span style=\"font-size: 1em;text-align: initial\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Communication;<\/span><\/p>\n<p><span style=\"text-align: initial;font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Provide entertainment;<\/span><\/p>\n<p><span style=\"text-align: initial;font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Monitoring and many more.<\/span><\/p>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Out of these functions, the \u2018magic role\u2019 played by computers is to create Information Networked Society. The largest engineered system ever created by mankind, namely Internet, binds or connects or networks millions of such computers to create Information Networked Society. Internet has converted the whole world in to what is known as \u2018global village\u2019. Let us look at the basic elements of internet.<\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 User end machines \/ Hosts<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Network<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Protocols<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">User end machine could be a desktop, laptop, a smart phone that creates and exchanges information in the form voice, text, image, video or a combination of these. In other words, information is also called \u2018content\u2019. Network deals with how the machines \/ gadgets creating and exchanging information are connected using a set of hardware and software. The process of exchanging information is popularly known as protocol. Figure below presents a macro-view of the building blocks of the internet.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-294\" src=\"http:\/\/lisp1.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/7\/2018\/07\/1-88.png\" alt=\"\" width=\"425\" height=\"220\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-88.png 425w, https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-88-300x155.png 300w, https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-88-65x34.png 65w, https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-88-225x116.png 225w, https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-88-350x181.png 350w\" sizes=\"auto, (max-width: 425px) 100vw, 425px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><strong>2. Information security aspects<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><em>\u201cInformation security is the practice of defending information from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording or destruction. It is a general term that can be used regardless of the form the data may take (electronic, physical, etc&#8230;)\u201d <\/em>(Wikipedia)<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Many organizations realize that one of their most valuable assets is their data, because without data, an organization loses its record of transactions and\/or its ability to deliver value to its customers. Protecting data in motion and data at rest are both critical aspects of information security. An effective information security program is essential to the protection of the integrity and value of the organization\u2019s data.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Two major aspects of information security are:<\/span><\/p>\n<ul>\n<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">IT Security: <\/strong><span style=\"font-size: 1em\">Information Technology Security is information security applied to technology (most often some form of computer system). IT security specialists are almost always found in any major enterprise\/establishment due to the nature and value of the data within large businesses. They are responsible for keeping all of the technology within the organization secure from malicious cyber attacks that often attempt to breach into the critical private information or gain control of the internal systems.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Information Assurance: <\/strong><span style=\"font-size: 1em\">The process to assure that data is not lost when\u00a0<\/span>critical issues arise. These issues include but are not limited to: natural disasters, computer\/server malfunction, physical theft, or any other instance where data has the potential of being lost. Since most information is stored on computers in the modern era, information assurance is typically dealt with by IT security specialists.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">2.1 <strong style=\"font-size: 1em\">The challenges to provide Information Security:<\/strong><span style=\"font-size: 1em\"> Let us look at simple day-to-day example of browsing the Internet. End user, typically called as client, invokes a browser like internet explorer, google chrome, enters the address of the web site (the address of the server computer) to be browsed and presses enter key. After a few seconds, the first page of the web site, typically called as home page, is displayed on the monitor. In this process, there is a complex sequence of actions that takes place in the background. The request for the page travels through a complex Internet infrastructure that makes use of private and public infrastructure and reaches the server at the other end. The home page is returned to the client.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">An important point to be noted from this simple example is that securing the information has to be done a 4 levels, end-to-end namely:<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Data<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Application<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Host<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Network<\/span><\/p>\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-152 aligncenter\" src=\"http:\/\/lisp1.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/7\/2018\/07\/1-37.png\" alt=\"\" width=\"615\" height=\"326\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-37.png 615w, https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-37-300x159.png 300w, https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-37-65x34.png 65w, https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-37-225x119.png 225w, https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-37-350x186.png 350w\" sizes=\"auto, (max-width: 615px) 100vw, 615px\" \/><\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">2.2. <\/span><strong style=\"text-align: initial;font-size: 1em\">Why should information be secured?: <\/strong><span style=\"text-align: initial;font-size: 1em\">The answer is simple: a mentioned earlier, information is wealth. It\u2019s obvious to secure the wealth if an organization has to survive and grow. Broadly information security:<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">1.\u00a0\u00a0\u00a0\u00a0 Prevents data theft<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">2.\u00a0\u00a0\u00a0\u00a0 Avoids legal consequences of not securing information<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">3.\u00a0\u00a0\u00a0\u00a0 Maintains productivity<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">4.\u00a0\u00a0\u00a0\u00a0 Foils cyber terrorism<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">5.\u00a0\u00a0\u00a0\u00a0 Prevents identity theft<\/span><\/p>\n<div>\n<p>&nbsp;<\/p>\n<p>2.3. <strong>Three Elements of Information Security: <\/strong>The three key elements of information security are:<\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <strong>C<\/strong>onfidentiality,<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <strong>I<\/strong>ntegrity<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <strong>A<\/strong>vailability<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Referred to as the C-I-A triad or information security triad<strong>.<\/strong> Let\u2019s look at the meaning of each of these elements.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">2.3.1. <strong>Confidentiality:<\/strong> Confidentiality means that information that is not in public domain should stay secret and be accessible to only those persons authorized to access it. Unauthorized access to confidential information may have devastating consequences, not only in national security applications, but also in commerce and industry. Main mechanisms of protection of confidentiality in information systems are cryptography and access controls. Examples of threats to confidentiality are malware, intruders, social engineering, insecure networks, and poorly administered systems.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">2.3.2. <strong>Integrity:Integrity<\/strong> is concerned with the trustworthiness, origin, completeness, and correctness of information as well as the prevention of improper or unauthorized modification of information. Integrity in the information security context refers not only to integrity of information itself but also to the origin integrity\u2014that is, integrity of the source of information.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Integrity protection mechanisms may be grouped into two broad types: <strong>Preventive mechanisms <\/strong>such as access controls that prevent unauthorized modification of information,<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">Detective <\/strong><span style=\"font-size: 1em\">mechanisms<\/span><strong style=\"font-size: 1em\">, <\/strong><span style=\"font-size: 1em\">which are intended to detect unauthorized modifications when preventive mechanisms have failed. Controls that protect integrity include principles of least privilege, separation, and rotation of duties.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">2.3.3. <\/span><strong style=\"font-size: 1em\">Availability:<\/strong><span style=\"font-size: 1em\">Availability of information, although usually mentioned last, is not the least important pillar of information security. Who needs confidentiality and integrity if the authorized users of information cannot access and use it? Who needs sophisticated encryption and access controls if the information being protected is not accessible to authorized users when they need it? Therefore, despite being mentioned last in the C-I-A triad, availability is just as important and as necessary a component of information security as confidentiality and integrity.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Attacks against availability are known as denial of service (DoS) attacks, Natural and man made disasters obviously may also affect availability as well as confidentiality and integrity of information, though their frequency and severity greatly differ\u2014natural disasters are infrequent but severe, whereas human errors are frequent but usually not as severe as natural disasters. In both cases, business continuity and disaster recovery planning (which at the very least includes regular and reliable backups) is intended to minimize losses.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">3.\u00a0\u00a0\u00a0\u00a0 <\/span><strong style=\"font-size: 1em\">Main controls aimed at protecting the C-I-A triad.<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Central to information security is the concept of controls, which is categorized as physical, administrative, technical and functional.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Physical <\/span><strong style=\"font-size: 1em\">controls<\/strong><span style=\"font-size: 1em\"> include doors, secure facilities, fire extinguishers, flood protection, and air conditioning.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">Administrative <\/strong><span style=\"font-size: 1em\">controls are the organization\u2019s policies, procedures, and guidelines intended to facilitate information security.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">Technical control <\/strong><span style=\"font-size: 1em\">includes measures such as firewalls, authentication systems, intrusion detection systems, and file encryption, among others.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">Functional control <\/strong><span style=\"font-size: 1em\">is again classified in to:<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><strong style=\"font-size: 1em\">Preventive<\/strong><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><strong style=\"font-size: 1em\">Detective<\/strong><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><strong style=\"font-size: 1em\">Corrective<\/strong><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><strong style=\"font-size: 1em\">Deterrent<\/strong><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><strong style=\"font-size: 1em\">Recovery<\/strong><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><strong style=\"font-size: 1em\">Compensating<\/strong><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Preventive Controls: <\/strong><span style=\"font-size: 1em\">Preventive controls are the first controls met by the adversary. Preventive controls try to prevent security violations and enforce access control. Like other controls, preventive controls may be physical, administrative, or technical: doors, security procedures, and\u00a0<\/span><span style=\"font-size: 1em\">authentication requirements are examples of physical, administrative, and technical preventive controls, respectively.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Detective Controls<\/strong><span style=\"font-size: 1em\">: are in place to detect security violations and alert the defenders. They come into play when preventive controls have failed or have been circumvented and are no less crucial than detective controls. Detective cont rols include cryptographic checksums, file integrity checkers, audit trails and logs, and similar mechanisms.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Corrective control: <\/strong><span style=\"font-size: 1em\">try to correct the situation after a security violation has occurred. Although a violation occurred, not all is lost, so it makes sen se to try and fix the situation. Corrective controls vary widely, depending on the area being targeted, and they may be technical or administrative in nature.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Deterrent <\/strong><span style=\"font-size: 1em\">Controls are intended to discourage potential attackers and send the message that it is better not to attack, but even if you decide to attack we are able to defend ourselves. Examples of deterrent controls include notices of monitoring and logging as well as the visible practice of sound information security management.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Recovery <\/strong><span style=\"font-size: 1em\">Controls are somewhat like corrective controls, but they are applied in more serious situations to recover from security violations and restore information and information processing resources. Recovery controls may include disaster recovery and business continuity mechanisms, backup systems and data, emergency key management arrangements, and similar controls.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Compensating: These <\/strong><span style=\"font-size: 1em\">are intended to be alternative arrangements for other controls when the original controls have failed or cannot be used.<\/span>When a second set of controls addresses the same threats that are addressed by another set of controls, the second set of controls are compensating controls.<\/li>\n<\/ul>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Let us now look at the typical process followed to ensure information security.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Identification<\/p>\n<p style=\"text-align: justify\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Authentication<\/p>\n<p style=\"text-align: justify\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Authorization Processes<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>3.1. Identification: <\/strong>Identification is the first step in the identify-authenticate-authorize sequence that is performed every day countless times by humans and computers. While particulars of identification systems differ depending on who or what is being identified, some intrinsic properties of identification apply regardless of these particulars. Just three of these properties are the:<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">i. Scope<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em;text-align: initial\">ii.\u00a0\u00a0\u00a0\u00a0\u00a0 Locality<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">iii.\u00a0\u00a0\u00a0\u00a0\u00a0 Uniqueness of IDs<\/span><\/p>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Identification name spaces can be local or global in scope. To illustrate this concept, let\u2019s refer to the familiar notation of Internet e-mail addresses. while many e-mail accounts named <strong>john<\/strong> may exist around the world, an e -mail address john@company.com unambiguously refers exactly to one such user in the company .com locality. Provided that the company in question is a small one, and that only one employee is named John, inside the company everyone may refer to that particular person by simply using his first name. That would work because they are in the same locality and only one John works there. However, if John were someone on the other side of the world or even across town, to refer to john@company.com as simply john would make no sense, because user name john is not globally unique and refers to different persons in different localities. This is one of the reasons why two user accounts should never use the same name on the same system\u2014not only because you would not be able to enforce access controls based on non-unique and ambiguous user names, but also because you would not be able to establish accountability for user actions. What it means is that, for information security purposes, unique names are required and, depending on their scope, they must be locally unique and possibly globally unique so that access control may be enforced and accountability established.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>3.2. Authentication: <\/strong>Authentication, which happens just after identification and before authorization, verifies the authenticity of the identity declared at the identification stage. In other words, it is at the authentication stage that you prove that you are indeed the person or the system you claim to be. The three methods of authentication are:<\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 What you know<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 What you have<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 What you are.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The aim is to obtain reasonable assurance that the identity declared at the identification stage belongs to the party in communication. It is important to note that reasonable assurance may mean different degrees of assurance, depending on the particular environment and application, and therefore may require different approaches to authentication: authentication requirements of a national security\u2013 critical system naturally differ from authentication requirements of a small company. Because different authentication methods have different costs and properties as well as different returns on investment, the choice of authentication method for a particular system or organization should be made after these factors have been carefully considered.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">What You Know<\/strong><span style=\"font-size: 1em\">: Among what you know authentication methods are passwords, passphrases, secret codes, and personal identification numbers (PINs). When using what you know authentication methods, it is implied that if you know something that is supposed to be known only by X, then you must be X (although in real life that is not always the case). What you know authentication is the most commonly used authentication method thanks to its low cost and easy implementation in information systems. <\/span><em style=\"font-size: 1em\">However, what you know authentication alone may not be<\/em> <em style=\"font-size: 1em\">considered strong authentication and is not adequate for systems requiring high security.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">What You Have<\/strong><strong style=\"font-size: 1em\">: <\/strong><span style=\"font-size: 1em\">Perhaps the most widely used and familiar what you have authentication methods are keys\u2014keys we use to lock and unlock doors, cars, and drawers; just as with doors, what you have authentication in information systems implies that if you possess some kind of token, such as a smart card or a USB token, you are the individual you are claiming to be. Of course, the same risks that apply to keys also apply to smart cards and USB tokens\u2014they may be stolen, lost, or damaged. What you have authentication methods include an additional inherent per-user cost. Compare these methods with passwords: it costs nothing to issue a new password, whereas per-user what you have authentication costs may be considerable.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">What You Are<\/strong><strong style=\"font-size: 1em\">: <\/strong><span style=\"font-size: 1em\">What you are authentication refers to biometric authentication methods. A biometric is a physiological or behavioral characteristic of a human being that can distinguish one person from another and that theoretically can be used for identification or verification of identity. Biometric authentication methods include<\/span><\/p>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Fingerprint<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Iris, and Retina Recognition<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Voice and Signature Recognition<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Biometric authentication methods when used correctly, in addition to what you have or what you know authentication, may significantly contribute to the strength of authentication. Biometrics is a complex subject and is much more cumbersome to deploy than what you know or what you have authentication. Unlike what you know or what you have authentication methods, whether or not you know the password or have the token, biometric authentication systems say how much you are like the subject you are claiming to be; naturally this method requires much more installation-dependent tuning and configuration.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>3.3. Authorization<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">After declaring identity at the identification stage and proving it at the authentication stage, users are assigned a set of authorizations referred to as rights, privileges, or permissions that define what they can do on the system. These\u00a0<span style=\"font-size: 1em\">authorizations are most commonly defined by the system\u2019s security policy and are set by the security or system administrator. These privileges may range from the extremes of \u201cpermit nothing\u201d to \u201cpermit everything\u201d and include anything in between. As you can see, the second and third stages of the identify-authenticate-authorize process depend on the first stage, and the final goal of the whole process is to enforce access control and accountability.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">3.4. Accountability<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Accountability is another vital principle of information security that refers to the possibility of tracing actions and events back in time to the users, systems, or processes that performed them, to establish responsibility for actions or omissions. A system may not be considered secure if it does not provide accountability, because it would be impossible to ascertain who is responsible and what did or did not happen on the system without that safeguard. Accountability in the context of information systems is mainly provided by logs and the audit trail.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">Logs<\/strong><span style=\"font-size: 1em\">: System and application logs are ordered lists of events and actions and are the primary means of establishing accountability in most systems. However, logs (as well as the audit trail, which is described next) may be considered trustworthy only if their integrity is reasonably assured. In other words, if anyone can write to and\/or erase logs or the audit trail, they would not be considered dependable enough to serve as the basis for accountability. In case of networked or communication systems, logs should be correctly <\/span><strong style=\"font-size: 1em\">timestamped<\/strong><span style=\"font-size: 1em\"> and time should be synchronized across the network so events that affect more than one system may be correctly correlated and attributed.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong style=\"font-size: 1em\">Audit Trail <\/strong><span style=\"font-size: 1em\">: Logs usually show high-level actions, such as an e -mail message delivered or a web page served, whereas audit trails usually refer to lower-level operations such as opening a file, writing to a file, or sending a packet across a network. Another aspect by which logs and audit trails differ is their source: logs are usually and mostly generated by particular system software or applications, and an audit trail is usually kept by the operating system or its auditing module.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">3.5. Privacy<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Privacy normally refers to the expectation and rights of individuals to privacy of their personal information and adequate, secure handling of this information by its users. Personal information here usually refers to information that directly identifies a human being, such as a name and address, although the details may differ in different countries. In many countries, privacy of personal information is protected by laws that impose requirements on organizations processing personal data and set penalties for noncompliance. The European Union (EU) in particular has strict personal data protection legislation in place, which limits how organizations may process personal information and what they can do with it. The\u00a0<\/span><span style=\"font-size: 1em;text-align: initial\">U.S. Constitution also guarantees certain privacy rights, although the approach to privacy issues differs between the United States and Europe.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">IV. Threats to Information Security<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Threat is nothing but an object, person, or other entity that represents a constant danger to an asset. Management must be informed of the different threats facing the organization. By examining each threat category, management effectively protects information through policy, education, training, and technology controls.<\/span><\/p>\n<\/div>\n<div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-153\" src=\"http:\/\/lisp1.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/7\/2018\/07\/1-38.png\" alt=\"\" width=\"721\" height=\"485\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-38.png 653w, https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-38-300x202.png 300w, https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-38-65x44.png 65w, https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-38-225x151.png 225w, https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-content\/uploads\/sites\/7\/2018\/07\/1-38-350x235.png 350w\" sizes=\"auto, (max-width: 721px) 100vw, 721px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>Malicious code: <\/strong>includes execution of viruses, worms, Trojan horses, and active Web scripts with intent to destroy or steal information<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>Back door: <\/strong>gaining access to system or network using known or previously unknown\/newly discovered access mechanism<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Password crack<\/strong>: attempting to reverse calculate a password<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Brute force<\/strong>: trying every possible combination of options of a password<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>Dictionary<\/strong>: selects specific accounts to attack and uses commonly used passwords (i.e., the dictionary) to guide guesses<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>Denial-of-Service<\/strong> <strong>(DoS<\/strong>): attacker sends large number of connection or information requests to a target<\/p>\n<ul>\n<li style=\"text-align: justify\">Target system cannot handle successfully along with other, legitimate service requests<\/li>\n<li style=\"text-align: justify\">May result in system crash or inability to perform ordinary functions <strong style=\"text-align: initial;font-size: 1em\">Distributed Denial-of-Service (DDoS): <\/strong><span style=\"text-align: initial;font-size: 1em\">coordinated stream of requests is launched against target from many locations simultaneously<\/span><\/li>\n<li style=\"text-align: justify\">Spoofing: technique used to gain unauthorized access; intruder assumes a trusted IP address<\/li>\n<li style=\"text-align: justify\">Man-in-the-middle: attacker monitors network packets, modifies them, and inserts them back into network<\/li>\n<li style=\"text-align: justify\">Spam: unsolicited commercial e-mail; more a nuisance than an attack, though is emerging as a vector for some attacks<\/li>\n<li style=\"text-align: justify\">Mail bombing: also a DoS; attacker routes large quantities of e-mail to target<\/li>\n<li style=\"text-align: justify\">Sniffers: program or device that monitors data traveling over network; can be used both for legitimate purposes and for stealing information from a network<\/li>\n<li style=\"text-align: justify\">Social engineering: using social skills to convince people to reveal access credentials or other valuable information to attacker<\/li>\n<li style=\"text-align: justify\">Buffer overflow: application error occurring when more data is sent to a buffer than can be handled<\/li>\n<li style=\"text-align: justify\">Timing attack: relatively new; works by exploring contents of a Web browser\u2019s cache to create malicious cookie<\/li>\n<\/ul>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>4.1. Information Security Policy \u2013 a mandate for the organizations. <\/strong>Information security is not an &#8216;IT problem&#8217;, it is a business issue. Obviously compliance with legal and regulatory requirements is important. It provides a very good reason for reviewing your information security practices, but it should not in itself be the sole or even the main driver. If a business wishes to survive, let alone prosper, it must grasp the importance of information security and put in place appropriate measures and processes.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">An information security policy is a set of rules and practices that define how the sensitive information of a company should be managed, protected, and distributed within the organization. The different aspects of an information security policy include labeling the information, modification of the information, accountability, and information ownership.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Each organization has an organization structure and the staff members at different levels needs to access different types of data. The information classification and the data distribution policies are therefore important for a company, so that the staff members at lower level should not be allowed to access data stored for higher level staff.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The main objectives of information security policy are:<\/p>\n<ul>\n<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Integrity<\/strong><span style=\"text-align: initial;font-size: 1em\">: The data is not tempered and modified undetectably.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Availability<\/strong><span style=\"font-size: 1em\">: Data is available when it is required. This means that all the systems that are involved in data security, data access or processing or data distribution function properly.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Disclosure<\/strong><span style=\"font-size: 1em\">: The disclosure of data should be as much, as it is important for the user to perform his task.<\/span><\/li>\n<\/ul>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p><strong>4.2. Best Practices to Help Protect Digital Assets.<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>It is essential to install:<\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Anti-Virus Software<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Anti-Spyware Software<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Applications Updates<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Security Bundles<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Personal Firewalls<\/p>\n<p>&nbsp;<\/p>\n<p><strong>4.3. Other simple best practices<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>It is very important to follow simple best practices as part of creating information security:<\/p>\n<ul>\n<li>When not using your PC, turn it off<\/li>\n<li>View your E-mail as text only; disable the function that automatically views E-mail as HTML<\/li>\n<li>Do not automatically open attachments<\/li>\n<li>Do not run software programs of unknown origin<\/li>\n<li>Delete chain E-mails and junk mail. Do not forward or reply to any of them<\/li>\n<li style=\"text-align: justify\">Never reply back to an E-mail to &#8220;unsubscribe&#8221; or to remove yourself from an unknown list. This lets the spammers know that they have reached a live E-mail address and your spam mail will increase<\/li>\n<li>Back up your critical data and documents regularly \u2013 thumb drives and CDs are cheap<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong style=\"text-align: initial;font-size: 1em\">5.\u00a0 <\/strong><strong style=\"text-align: initial;font-size: 1em\">Wireless World Creating Serious Security Vulnerabilities<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Wireless technologies have empowered IT users to access information anytime, anywhere. At the same time, creating serious security vulnerabilities like:<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Unauthorized users can access the wireless signal from outside a building and connect to the network<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Attackers can capture and view transmitted data (including encrypted data)<\/p>\n<p style=\"text-align: justify\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Employees in the office can install personal wireless equipment and defeat perimeter security measures<\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p><strong style=\"text-align: initial;font-size: 1em\">6. The security and privacy issues associated with social networking sites<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: justify;font-size: 1em\">Social networking sites have become very popular avenues for people to communicate with family, friends and colleagues from around the corner or across the globe. While there can be benefits from the collaborative, distributed approaches promoted by responsible use of social networking sites, there are information security and privacy concerns. The volume and accessibility of personal information available on social networking sites have attracted malicious people who seek to exploit this information. The same technologies that invite user participation also make the sites easier to infect with malware that can shut down an organization&#8217;s networks, or keystroke loggers that can steal credentials.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">Common social networking risks such as spear phishing, social engineering, spoofing, and web application attacks attempt to steal a person&#8217;s identity<\/span><strong style=\"text-align: initial;font-size: 1em\">.<\/strong><span style=\"text-align: initial;font-size: 1em\"> Such attacks are often successful due to the assumption of being in a trusting environment social networks create.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 1em\">Security and privacy related to social networking sites are fundamentally behavioral issues, not technology issues. The more information a person posts, the more information becomes available for a potential compromise by those with malicious intentions. People who provide private, sensitive or confidential information about themselves or other people, whether wittingly or unwittingly, pose a higher risk to themselves and others. Information such as a person&#8217;s social security number, street address, phone number, financial information, or confidential business information should not be published online. Similarly, posting photos, videos or audio files could lead to an organization&#8217;s breach of confidentiality or an individual&#8217;s breach of privacy.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">6.1. Precautions to be taken<\/strong><\/p>\n<ul>\n<li style=\"text-align: justify\"><span style=\"text-align: initial;font-size: 1em\">Below are some helpful tips regarding security and privacy while using social networking sites:<\/span><\/li>\n<li style=\"text-align: justify\">Ensure that any computer you use to connect to a social media site has <strong style=\"font-size: 1em\">proper<\/strong> <strong style=\"font-size: 1em\">security measures <\/strong><span style=\"font-size: 1em\">in place. Use and maintain anti-virus software and keep your application and operating system patches up-to-date.<\/span><\/li>\n<li style=\"text-align: justify\">Use caution when clicking a link to another page or running an online application, even if it is from someone you know. Many applications embedded within social networking sites require you to share your information when you use them. Attackers use these sites to distribute their malware.<\/li>\n<li style=\"text-align: justify\">Use <strong style=\"font-size: 1em\">strong and unique passwords<\/strong><span style=\"font-size: 1em\">. Using the same password on all accounts increases the vulnerability of these accounts if one becomes compromised.<\/span><\/li>\n<li style=\"text-align: justify\">If screen names are allowed, do not choose one that gives away <strong style=\"font-size: 1em\">too much<\/strong> <strong style=\"font-size: 1em\">personal information.<\/strong><\/li>\n<li style=\"text-align: justify\">Be careful who you add as a &#8220;friend,&#8221; or what groups or pages you join. The more &#8220;friends&#8221; you have or groups\/pages you join, the more people who have access to your information.<\/li>\n<li style=\"text-align: justify\">Do not assume <strong style=\"font-size: 1em\">privacy on a social networking<\/strong><span style=\"font-size: 1em\"> site. For both business and personal use, confidential information should not be shared. You should only post information you are comfortable disclosing to a complete stranger.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Use discretion before posting <\/strong><span style=\"font-size: 1em\">information or commenting about anything. Once information is posted online, it can potentially be viewed by anyone and may not be retracted afterwards. Keep in mind that content or communications on government-related social networking pages may be considered public records.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"font-size: 1em\">Configure privacy settings <\/strong><span style=\"font-size: 1em\">to allow only those people you trust to have access to the information you post. Also, restrict the ability for others to post information to your page. The default settings for some sites may allow anyone to see your information or post information to your page; these settings should be changed.<\/span><\/li>\n<li style=\"text-align: justify\"><strong style=\"text-align: initial;font-size: 1em\">Review a site&#8217;s privacy policy. <\/strong><span style=\"text-align: initial;font-size: 1em\">Some sites may share information such as email addresses or user preferences with other parties. If a site&#8217;s privacy policy is vague or does not properly protect your information, do not use the site.<\/span><\/li>\n<\/ul>\n<div>\n<p>&nbsp;<\/p>\n<p><strong>7. Summary<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Modern society is completely dependent on information and information technology. Internet is the part and parcel of both professional and personal life. Anywhere, anytime access, with the advent of wireless technology, is really a boon. Variety of security threats may convert the boon to bane. It is extremely important to protect the information through variety of solutions. It should be the right blend of technologies, policies, education and culture.<\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>you can view video on Information Principal Security Investigator issues in the Networked environment<\/strong><\/td>\n<td><a href=\"https:\/\/youtu.be\/SbAsJ-kehQU\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>8.\u00a0 References<\/strong><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li style=\"text-align: justify\">Mcclure, scambray and kurtz &#8211; mcclure, s., j. Scambray, et al. (2005). Hacking exposed : network security secrets &amp; solutions. Emeryville, calif.,mcgraw-hill\/osborne. Wikipedia-http:\/\/en.wikipedia.org\/wiki\/information_security<\/li>\n<li style=\"text-align: justify\">Issue update on information security and privacy in network environments <span style=\"font-size: 1em\">september 1995 <\/span><span style=\"font-size: 1em\">Ota-bp-itc-147, gpo stock #052-003-01416-5<\/span><\/li>\n<li style=\"text-align: justify\">Computer networking, 6e, james f. Kurose , keith w. Ross, pearson publiction <span style=\"text-align: initial;font-size: 1em\">Tutorial- <\/span><a style=\"text-align: initial;font-size: 1em\" href=\"http:\/\/learnthat.com\/2010\/11\/introduction-to-network-security\/\">http:\/\/learnthat.com\/2010\/11\/introduction-to-network-security\/<\/a><\/li>\n<li style=\"text-align: justify\">Information security forum : web: www.securityforum.org<\/li>\n<li style=\"text-align: justify\">Information security policies and controls for a trusted environment by s. Srinivasan, i n f o r m at i o n s y s t e m s c o n t r o l j o u r n a l , vol. 2 , 2 0 0 8<\/li>\n<li style=\"text-align: justify\"><em style=\"font-size: 1em\">Cyber security tips, newsletter march 2010,volume 5, issue 3, from the desk of william f. Pelgrin, chair\u00a0<\/em><\/li>\n<li style=\"text-align: justify\">Internet and network security fundamentals, presentation by champika wijayatunga, training manager, apnic<\/li>\n<\/ul>\n<\/div>\n","protected":false},"author":3,"menu_order":16,"template":"","meta":{"_acf_changed":false,"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":["dr-chidambara"],"pb_section_license":""},"chapter-type":[],"contributor":[69],"license":[],"class_list":["post-147","chapter","type-chapter","status-publish","hentry","contributor-dr-chidambara"],"part":3,"_links":{"self":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-json\/pressbooks\/v2\/chapters\/147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-json\/wp\/v2\/users\/3"}],"version-history":[{"count":17,"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-json\/pressbooks\/v2\/chapters\/147\/revisions"}],"predecessor-version":[{"id":379,"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-json\/pressbooks\/v2\/chapters\/147\/revisions\/379"}],"part":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-json\/pressbooks\/v2\/parts\/3"}],"metadata":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-json\/pressbooks\/v2\/chapters\/147\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-json\/wp\/v2\/media?parent=147"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-json\/pressbooks\/v2\/chapter-type?post=147"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-json\/wp\/v2\/contributor?post=147"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp1\/wp-json\/wp\/v2\/license?post=147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}