Securities Issues in a company, Computer Network Security

Assignment Help:

'Near Field Communication' (NFC) technologies are expected to become commonplace in the near future. Some relevant features are these:

  • A suitable device (such as a mobile phone) may interact with another device (another phone, or a simple tag, or some other fixed reader), provided the two devices are held in close proximity, or 'tapped' together. In order to communicate, simple tags can derive their power from the nearby device.
  • Moderate amounts of data may be exchanged (one-way or two-way) in such interactions - a few kBytes, typically.
  • Management of data relevant to such interactions might be stored in the ordinary memory of the phone, or might be undertaken by a secure element such as the SIM card. In a payment application, for example, the 'cash balance' might be recorded by the card, that card running a protocol with the remote card, intended to ensure that a rogue application could not corrupt its legitimate operation. Such secure storage is characterized by high qualities of security, and very limited storage capacity.

One topic of debate among security experts is whether the 'near field' property can be subverted - for example, whether special antennae could eavesdrop from a distance: this is likely to be the case, in the right circumstances.

Suppose a supermarket has decided to use NFC to enhance shoppers' experience, and to attempt to induce its customers (or potential customers) to buy more items.

Crucially, this will involve giving the shoppers a special app to run on their smartphones, and will involve placing relevant tags on shelves and/or individual products. Three phases of app roll-out are envisaged:

1. The app allows shoppers to look up information about products - such as their nutritional content - before buying them. The shopper's phone is tapped onto the relevant shelf label to receive such information.

2. the app receives vouchers and special offers, pushed by the supermarket (perhaps on a schedule, perhaps based on the shopper's habits, perhaps when tapped on a shelf to activate a particular offer, or perhaps when the phone's location service indicates proximity to this supermarket or a competitor's shop).

3. The app allows shoppers to scan each item they place in their trollies (much as some supermarkets currently allow with hand-held barcode scanners); 3 stored vouchers are automatically applied; upon leaving the shop, the app automatically triggers an online payment for the full cost of the contents of the cart

Your task is to identify the threats inherent in this scenario (or, these scenarios, regarding each phase separately). Describe each threat, making clear the anticipated motive(s) of the attacker(s). There may be significant high-level design decisions to be made which will impact the security of the solution: explain what these are, and what their implications are.

Which threats would you expect to give rise to the biggest risks? Explain your answer. Your answer will necessarily be incomplete without an assessment of vulnerabilities, which is out of scope. Is there any other information you would need in order to complete a risk assessment?


Related Discussions:- Securities Issues in a company

Nessus vulnerability, You see two IP addresses. The IP address 192.168.58.1...

You see two IP addresses. The IP address 192.168.58.130 is the one of Bt4. The IP address 192.168.58.133 has ports 135 and 445 open; which indicates that it is a Windows machine. S

Deploying host-based idss, Deploying Host-Based IDSs -Proper implementat...

Deploying Host-Based IDSs -Proper implementation of HIDSs can be painstaking and time-consuming task .The process of deployment begins with implementing most critical systems fi

Explain how the framework will align to the model, MB Enterprise Systems Lt...

MB Enterprise Systems Ltd based in Mauritius is a company specialized in application development with Europe as the main customer base. The company has implemented CMMI and has rec

Explain how the diffie-hellman key agreement protocol works, (a) Using Fer...

(a) Using Fermat's theorem, find 3 201 mod 11. (b) Explain how the Diffie-Hellman key agreement protocol works and what its purpose and main properties are. Consider a Dif

How to create a security policy, Five years ago, Calgary Kids' Cloth Ltd wa...

Five years ago, Calgary Kids' Cloth Ltd was just a small retail store in downtown Calgary. The company started their own factory in SE Calgary to produce outdoor clothes for kids.

Calculate the dynamic range of the 16-bit scanner, You are hired as a consu...

You are hired as a consultant to help design a digital library in which books are scanned and stored digitally and made available to users of the World Wide Web. Assume that the li

Direct sequence modulation, Question 1 a) Provide three advantages of ...

Question 1 a) Provide three advantages of using optical fiber. b) Distinguish between "Direct Sequence Modulation" and "Frequency Hopping" c) Decribe the purpose of using "

CS, Discuss how developers should apply the following countermeasures to im...

Discuss how developers should apply the following countermeasures to improve the security of their code:

Systems development life cycle security-information security, The Role of t...

The Role of the Investigation The first phase, investigation is the most significant. What problem is the system being developed to solve? During investigation phase, objectives

Http protocol, Question (a) Name 3 popular electronic mail access prot...

Question (a) Name 3 popular electronic mail access protocols? (b) i. What is DNS? ii. Briefly, describe what it does and how it works? iii. Why does DNS use a dist

Write Your Message!

Captcha
Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd