Review article - commercial and government sector

Assignment Help Software Engineering
Reference no: EM132082076

You need to review this article with references.

Being compromised and not knowing it is a large threat that everyone in the commercial and government sector needs to understand. The question is no longer if we are going to be compromised but when are we going to be compromised?

No matter how many devices you place on your network to stop incoming threats there is always a way on through the user. This is because the user is the weakest link in information systems security. Through social engineering an attacker can simply ask the user for their password or physical access to the building in areas they do not belong. A more common social engineering attack is phishing.

With phishing an attacker carefully creates an email that looks legitimate to the user. However, the links embedded within them would lead to a fake site where the attacker gathers the username and password of the individual. Also, the phishing email can contain malware that would allow the attacker to gain access to the system or the network.

If an attacker wanted to go after a target within the company the attack is then called spear-phishing. Further, a disgruntled employee or a trusted insider could purposely cause an attack. These attacks bypass all the perimeter defenses within the organization allowing the attacker to work unnoticed for months or years. This type of attack is known as an advanced persistent threat (Walker, 2017).

Combating advanced persistent threats (APT) is now the forefront of security personal. The first step to secure the network would be to educate the users of the network.

Teaching your employees, the security polices of the company as well as educating them on what is social networking and what a phishing email is will go a long way to helping secure the network. With the end user being the weakest link, anything you can teach them will make them stronger (Johnson, 2015).

The information security professional can do several things themselves that can also combat APT. Looking at big data is necessary. Collecting and analyzing data from different sources and over a sustained period of time will help find compromise. Compromises are no longer at a single point but spread out over several areas within the network.

Using data from different sources and analyzing it together will help spot a compromise in the systems. Looking for indicators of compromise is a big step. Anything from unique DNS queries, looking for custom tools, finding remote desktop connections, proxies, or encrypted tunnels can all be a sign of a compromise.

It is best to know what the network does under normal circumstances so that any anomaly can be detected quickly. Finally, a test of your network can help find APTs. Hacking your own network or allowing someone on the outside ethically hack your network will help you find vulnerabilities. This information can be used to further secure your network defenses. Ultimately, it will take a combination of several different approaches to secure the system from APTs (Armerding, 2014). In Ephesians 6:10-18 talks about putting on the entire armor of God. Each piece of the armor is needed for protection while there is one piece used for attacking.

It is the combination of each of these pieces of armor that brings about protection for us in our spiritual walks. Likewise, it is a combination of defensive tools that will bring protection to the information system networks we are to protect. While the shield represents a firewall, the helmet, breastplate, shoes, and belt represent the internal protections such as user education, analyzing big data, looking for indicators of compromise and hacking your own system. Each part plays a role in protecting the system.

If one piece of armor is missing, then there is a weakness for the enemy to exploit like if one part of system defense is missing it is an area for an attacker to enter and go about unnoticed. A complete defense will assist you in protecting the network from attackers.

Attachment:- References.rar

Verified Expert

The report is about APT, preparedness to combat the same.Further there is also information about general profiling of the security threat. Significance of comprehensive immunization of the system to threats is also discussed in the article.

Reference no: EM132082076

Questions Cloud

Walt disney world resort may just be the most impressive : One of the newest thrill rides to open in the Walt Disney World Resort may just be the most impressive.
Define what changes are occurring in the economy : Determine what changes are occurring in the economy or concerning labor and regulatory factors that must be considered in the future.
What is the amount of contribution margin per unit : Shadow Lake Bottling Company produces a soft drink that is sold for a dollar, what is the amount of contribution margin per unit
Valid diversification argument : If you invest your entire capital in a financial sector mutual fund or exchange traded fund (ETF) with 50 financial stocks in each fund, then you would
Review article - commercial and government sector : You need to review article - commercial and government sector needs to understand - It is the combination of each of these pieces of armor that brings
Which project is better from cash flow standpoint : The company is very concerned about their cash flow. Using the payback period, which project is better from a cash flow standpoint? Why?
What is its margin of safety in units : Berkut Company would break even at $600,000 in total sales. what is its margin of safety in units if budgeted sales total $800,000
Balance sheet and an income statement : What is the difference between the balance sheet and an income statement?
Little law application : Little’s law application. How many new mothers are staying in Children’s Hospital (at any time point)?

Reviews

inf2082076

11/1/2018 1:48:55 AM

Good quick response to any of the my query. Looks good quality and the expert reads the case and provided a proper response instead of rushing despite needed it after 5 hours of asking for help. Instructions were followed correctly, the assignment is prepared correctly too! Cool.

Write a Review

Software Engineering Questions & Answers

  Make changes to the format class

Be sure to notice that the supplied program already handles compound statements, which are delimited by braces, so the code that you add should not treat compound statements as a special case.

  Describe purpose of the three primitive control structures

List, and briefly describe the purpose of, the three primitive control or logic structures. (Hint: These structures are given in the Programming Methodologies section of this module's reading, titled programming and sdlc.pdf.)

  What are the critical responsibilities for the manager

Define information technology and information systems in APA style

  Web authoring application

Compare the drawbacks and benefits of using a Web authoring application, an HTML editor and a text editor for developing websites.

  Describe challenge of cost estimation for software projects

Describe the challenges of cost estimation for software development projects where requirements are usually not clear in early stages of the project.

  What decimal value does the 8-bit binary number

What Decimal value does the 8-bit binary number 10011110.

  Performing the algorithm for insertafter

Draw a picture illustrating the final state of a doubly linked list after performing the algorithm for insertAfter(p, e), but with the order

  How practices defined in process area project planning

Describe how Specific Practices defined in Process Area Project Planning (PP) support the Specific Practices defined in Process Area Project Monitoring and Control (PMC). That is, elaborate why PP serves as the basis for PMC as defined in CMMI.

  Project scenario on customer request for pc

Develop a project scenario on Customer request for PC.

  Develop use case diagram to summarize functional requirement

Develop a use case diagram to summarize the functional requirements of the system through the use of Microsoft Visio or its open source alternative, Dia. Note: The graphically depicted solution is not included in the required page length.

  Design and develop a small java console application

ITECH7201 - Analysis and design techniques, including development of use cases and UML diagrams - specifically, use case diagrams.

  What is the trend in languages used to develop today''s s/w

Programming languages: What is the trend in the languages used to develop today's software?

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd