During the week 3
Assignment where we picked different websites and pinged them using the URL as
the destination this command also reveals the IP address / addresses linked to
the servers behind the DNS which in turn allows network attacks which are
called Denial of Service attacks or DoS and DDoS attacks on those websites. So
why are DDoS attacks so effective, "DDoS attacks achieve effectiveness by
utilizing multiple compromised computer systems as sources of attack traffic.
Exploited machines can include computers and other networked resources such as
IoT devices." What is a DDoS Attack? Retrieved from https://www.cloudflare.com/learning/ddos/what-is-a-ddos-attack/
Phishing and Social
Engineering
I have chosen
to speak more about both Phishing and Social Engineering as in both my current
and past positions I have been in a place that requires yearly training on both
of these subjects in order to educate its employees of the harms and safe
guards against them. Phishing as described in the book "is an Internet scam that baits a user to share sensitive
information like a password or credit card number."
Social Engineering is when someone or a group of people can target individuals
from within a company or organization in which they might want to gain outside
access to or cause malicious harm to. This could include trying to gain
physical access to a location where equipment might being housed. This could
also be just getting enough information from someone in order to get more
information about them or someone else within that company or
organization.
Examples and Potential
Damage
For example getting to know
someone who might work at a local bank and pretending to be interested in them
or a product and getting their e-mail address they use for business, after
gaining this information they might send an e-mail that looks like it is
legitimate but actually is a phishing e-mail in order to gain the actual
information they were wanting to get in the first place all without the person
who was targeted even really understanding what was going on. This could
include gaining access to user accounts which would have most likely all the
personal information on those affected including SSN, bank account records,
Addresses, phone numbers etc.
Ways to Defend
In the time I have worked
for both Government agencies and Financial institutions I have seen personal
information within Databases which in some cases was fully available upon
gaining access to the DB, going a step further and not only encrypting personal
information that is being transmitted outside but also the information as it
sits in the DB is a very good practice. Also educating employees on how you
might be caught being social engineered without your knowing unless you
understand the signs to look for and how to avoid being targeted in some cases
the most simple things can stop those from happening, for example if you work somewhere
that requires a badge and has restricted access, do not keep your badge in
plain sight ever and remove it from your person as soon as you leave work, if
you vehicle has a parking pass remove it when leaving the location, don’t post
anywhere online where you actually work and be vague perhaps just mentioning
the type of work you do. Having educated staff is extremely important as most
times a data breach can be tied back to a human error of some kind.
No comments:
Post a Comment