Monday, October 14, 2019

Network Security

TYPES OF HACKERS:
  • Gray Hat Hacker
    • A cracker who exploits a security weakness in a computer system or product in order to bring the weakness of the owners.
    • Gray hackers are breaking down laws and violating ethics, but their intent isn't malicious.
    • They hack without permission but the don't do harm. They Fix it.
  • Hobby Hacker
    • Focuses on making the traffic, the generated leads, the clients and the branding grow with the minimum investment.
    • E.g. Jordi Robert - Hobby to hack since he was 15 years old to make money.
  • Phreakers
    • Phone + Freaks
    • People who studies, equipment and explores telecommunication system on how it work.
    • Use different audio frequencies to manipulate a phone system.
    • Not as common nowadays as people rarely use telephone.
    • E.g. Public telephone, Elevator phone.
  • Script Kiddy
    • Also known as kiddie.
    • The hacker will use the existing script or any well-known script to hack any computer.
    • the hackers normally comes from the low education of programming.
  • Academic Hacker
    • An action of hacking the academic or any institution. This is mostly done by either by student or anyone in order to get what they want.
    • E.g. To change their grades or to know what is on the exam paper.
  • Black Hat Hacker
    • A person who attempts to find computer security vulnerabilities and exploit them for personal financial gain or other malicious reasons.
    • Can inflict major damage on both individual computer users and large organizations by stealing financial information, compromising the security of major systems, or shutting down or altering the function of websites and networks.
    • A person who hack with harm, who spread viruses, malicious and threats to destroy or damage the system/software.
  • Computer Security Hacker
    • Someone who explores methods for breaching defenses and exploiting weaknesses in computer system or network.
  • Hacktivist
    • They hack to protest.
  • White Hat Hacker
    • Known as Ethical Hacker.
    • Hacking with permission to fix the faults of the system.
Image result for what is white hat hacker
Image result for what is white hat hacker

Sunday, October 13, 2019

Business Intelligence

Produce an I/O for the following scenario:
  • Enrolling HND in Micronet
    • Data Input:
      • Full name
      • Home address
      • Phone number
    • Data Capture:
      • Gender
      • Course
      • Date of birth
    • Data Processing Activities:
      • Form submission (Collecting)
      • Admin stored the applicant information (Storage)
      • Giving an Invitation to parent for parents meeting (Communication)
    • Information Output:
      • List the student name with their parent's name and provide a notice letter for parent meeting.

  • Creating an Email
    • Data Input:
      • Username
      • Password
      • Backup Email
      • Backup Phone number
      • Password confirmation
    • Data Capture:
      • Gender
      • Date of birth
      • Country
    • Data Processing Activities
      • Recording applicant information (Collecting)
      • Verifying username and email address (Conversion)
      • Retrieving information (Storage)
    • Information Output:
      • A notification of successfully creating a new Email (Approved Email).

  • Registering on Facebook
    • Data Input:
      • Full name
      • Email
      • Username
      • Alternative Email
      • Backup Phone number
      • Insert Image 
    • Data Capture:
      • Date of birth (month, day and year)
      • Gender (male or female)
      • Country 
    • Data Processing Activities
      • Verifying the username and password (Conversion)
      • Store the information (Storage)
    • Data Output:
      • A notification of successfully creating a Facebook account.


Business Intelligence


FLOWCHART
  • Registration HND course in Micronet

  • Renting or owning a car in Brunei
  • Opening a bank account





Monday, October 7, 2019

Network Security

1. What are Network Security breaches?
  • A network security breach is also known as a security violation.
  • It is any incident that results in unauthorized access to data, applications, services, networks or devices through their underlying security mechanisms.
  • This occurs when illegally user or application can access a private, confidential or unauthorized IT perimeter. Once they can access the network, they can steal data, compromise software or install viruses. 
2. Two examples of Network Security breach
  • Phishing 
    • Phishing attacks attempt to gain sensitive, confidential information such as usernames, passwords, credit card information, network credentials and more.
    • It is fraudulent use of electronic communications to deceive and take advantage of users.
    • By posing as a legitimate individual or institution via phone or email, cyber attackers use social engineering to manipulate victims into performing specific actions - like clicking on a malicious link or attachment - or willfully divulging confidential information.
    • Types of Phishing Attacks:
      • Spear Phishing
      • Clone Phishing
      • Whaling Phishing
    • Prevention Steps:
      • To prevent Phishing attacks, organizations should educate employees on how to recognize suspicious emails, links and attachments.
      • Never entertain unsolicited emails, calls or SMSs.
      • Your bank will never ask you for confidential information via emails, calls or texts. If you do receive any such communication, report it to your bank.
      • Avoid accessing websites via links in email messages, especially those asking for personal information. It is always safe to type the URL manually into the web browser.
      • Do not fill any kind of form that comes along with an email. 

  • Denial of service (DDoS attacks).
    • It is occur when a website is overwhelmed with requests, which blocks other users from the site.
    • E.g. GITHUB: 1.35 TBPS on 28th February 2018.
      • They have doubled their transit capacity to withstand certain number of attacks.
    • Prevention Steps:
      • Buy more bandwidth (not an actual solution).
      • Configure your network hardware (e.g. firewall and router).
      • Protect the DNS server by building redundancy in the system (spread the data center far away and connected to different networks).
References:

  • Forcepoint. (2018). What is Phishing?. [online] Available at: https://www.forcepoint.com/cyber-edu/phishing-attack [Accessed 9 Oct. 2019].
  • Google.com. (2019). how to prevent phishing attack - Google Search. [online] Available at: https://www.google.com/search?q=how+to+prevent++phishing+attack&rlz=1C1LENP_enBN725BN726&sxsrf=ACYBGNQeAixozqKMuIFkpfTLIj1e-cxSmA:1570665414083&source=lnms&tbm=isch&sa=X&ved=0ahUKEwiR18TQsJDlAhXBLI8KHVq2ArEQ_AUIEigB&biw=712&bih=772#imgrc=ayYsxVVvlieFqM: [Accessed 9 Oct. 2019].
  • profile, V. (2017). Tips to Identify and Avoid Phishing Scams. [online] I-techgeeks.com. Available at: https://www.i-techgeeks.com/2017/10/tips-to-identify-and-avoid-phishing-scams.html [Accessed 9 Oct. 2019].



Network Security


1. What is Network Security?
  • Network security is a set of rules and configurations designed to protect the usability, integrity, confidentiality, and accessibility of your data or computer network which includes both hardware and software technologies.
  • It is to avoid and keep track of unauthorized access, exploitation, modification or denial of the network and network resources. In addition, network security blocks threats, viruses, malware hackers, etc. and stops them from accessing or spreading on your network.
2. The advantages of Network Security
  • Protect data
  • Prevent cyber attack
  • Levels of access
  • Centrally controlled
  • Centralized updates
3. The disadvantages of Network Security
  • Costly setup
  • Time-consuming 
  • Requires skilled staff
  • Careless admin
4. Importance of Network Security
  • To prevent serious consequences from the theft of information or loss of privacy.
  • To protect the network from threats attack or being hack. 
  • Act as an extra security layer to keep the data and information as secured as possible. 
  • It can prevent the traffic in the network from being congested (lagging).
5. Example of Network Security Breach
Related image
  • Facebook
  • In September 2018, Facebook announced that an attack on its computer network exposed the personal data of over 50 million users. According to Facebook, the hacker able to gain access to the system by exploiting a vulnerability in the code used for the 'View as' feature.
  • Once this feature was exploited, the attackers were able to steal 'access token' which used to take over user's account and gain access to other services. The breach also affected to the third part apps connected to the Facebook (E.g. Applications that connected with Facebook Account - PUBG).
  • As a Precautionary measure, the company logged 90 million users out of their accounts and reset the access tokens.

References
  • Advantages-disadvantages.co. (2019). Advantages and Disadvantages of Network Security. [online] Available at: https://www.advantages-disadvantages.co/network-security-advantages-and-disadvantages/ [Accessed 8 Oct. 2019].
  • http://www.metacompliance.com/, M. (2019). 5 Examples of Security Breaches in 2018. [online] Available at: https://www.metacompliance.com/blog/5-examples-of-security-breaches-in-2018/ [Accessed 15 Oct. 2019].





Sunday, October 6, 2019

Business Intelligence

L.O. 1 Exercise : Business Process


Explain Business Intelligence and its purpose.
  • General term that refers to the collection, analysis and use of data in business to make operational and strategic decisions. 
  • Enables the business to make intelligent, fact- based decisions.
  • The purpose of BI is to support  better business decision making where the systems provide historical, current and predictive views of business operations which most often using data that has been gathered into a data warehouse or a data mart and occasionally working from operational data.
  • The purpose of  BI in business is to help corporate executives, business managers and other operational workers make better and more informed business decisions. Companies also use BI to cut costs, identify new business opportunities and spot inefficient business processes.
  • NOTES: The only higher rank person can decide the decision making (e.g. manager or boss).
Discuss "Business Process" with example.
  • It is an activity or set of activities that can accomplish a specific organizational goal. 
  • It should have purposeful goals, be as specific as possible and have consistent outcomes.
  • It is an activities or tasks that conducted by people or equipment to produce a specific service or product for a particular user or consumer.
  • For example: Online Banking - BIBD which is a user friendly; Using BIBD mobile application, the user can perform online banking, money transfer and top-up as long as it has an internet connection connected to that devices.
Identify and describe the business process model.

  • Business process  modeling also known as process modeling.
  • It is the analytical representation or put simply an illustration of an organization's business process. 
  • It is a critical component for effective business process management.
  • E.g. FLOWCHART
Foe example: Expense Claim Process

references:
  • Google.com. (2019). the purpose business intelligence - Google Search. [online] Available at: https://www.google.com/search?rlz=1C1LENP_enBN725BN726&biw=1440&bih=789&tbm=isch&sxsrf=ACYBGNRujBzKC_1hH_1uL4msidwTnu2jCg%3A1570428969974&sa=1&ei=KdiaXfeSO4iHvQTBgLfYBw&q=the+purpose+business+intelligence&oq=the+purpose+business+intelligence&gs_l=img.3...69467.71897..72186...0.0..0.167.1546.3j9......0....1..gws-wiz-img.......0i7i30j0i7i5i30j0i8i7i30j0i24.bcrOWxn2Z8U&ved=0ahUKEwi3y5nnv4nlAhWIQ48KHUHADXsQ4dUDCAc&uact=5#imgrc=24Ft25ZuTgtvPM: [Accessed 7 Oct. 2019].
  • Google.com. (2019). what is business intelligence - Google Search. [online] Available at: https://www.google.com/search?q=what+is+business+intelligence&rlz=1C1LENP_enBN725BN726&sxsrf=ACYBGNTC7Uz4UZh-6zlQeJbhIjOXR_r9uA:1570428630433&source=lnms&tbm=isch&sa=X&ved=0ahUKEwiozaXFvonlAhVO62EKHYdLB5QQ_AUIEigB&biw=1600&bih=876#imgrc=0PRUyObUAwRg7M: [Accessed 7 Oct. 2019].
  • Google.com. (2019). the purpose business intelligence - Google Search. [online] Available at: https://www.google.com/search?rlz=1C1LENP_enBN725BN726&biw=1440&bih=789&tbm=isch&sxsrf=ACYBGNRujBzKC_1hH_1uL4msidwTnu2jCg%3A1570428969974&sa=1&ei=KdiaXfeSO4iHvQTBgLfYBw&q=the+purpose+business+intelligence&oq=the+purpose+business+intelligence&gs_l=img.3...69467.71897..72186...0.0..0.167.1546.3j9......0....1..gws-wiz-img.......0i7i30j0i7i5i30j0i8i7i30j0i24.bcrOWxn2Z8U&ved=0ahUKEwi3y5nnv4nlAhWIQ48KHUHADXsQ4dUDCAc&uact=5#imgdii=OQZFJWGDylLW8M:&imgrc=O_hZFVNRwxjzpM: [Accessed 7 Oct. 2019].
  • Financesonline.com. (2017). What Is the Purpose of Business Intelligence in a Business? - Financesonline.com. [online] Available at: https://financesonline.com/purpose-business-intelligence-business/ [Accessed 7 Oct. 2019].

Monday, May 6, 2019

Security

MICRONET SECURITY AUDIT

1) Define your audit
·         9 Labs
·         2 Classroom
·         Admin (15pc)
·         Theater Room (1pc)
·         Library (3pc)
·         Wireless Access Point (9)
·         Information – Student & Lecturer
·         Internal – School Payment, Employee Salary & Policy

Ø  To be audited:
o   Salary.
o   Information.
o   Admin.
o   Lecturer Room.
o   Wireless Access Point.
o   Internal.
Ø  Not important:
o   Library.
o   Classroom.
o   Theater.
o   Lab.
2) Define your threats
·         Natural Disaster.
·         Malware.
·         Hacker.
·         Physical Breach.
·         Negligence employees.
·         Malicious Insiders.
3) Security Performance
·         Network Scanning.
·         Virus Detection.
·         Password Cracking.
·         Vulnerability Scanning.
·         Interview employees.
4) Prioritize (Risk Scoring)
·         Natural Disaster
-       Damage (3)
-       It can occur (2)

·         Malware
-       Damage (3)
-       It can occur (3)

·         Hacker
-       Damage (4)
-       It can occur (2)

·         Physical Breach
-       Damage (2)
-       It can occur (4)

·         Negligence employees
-       Damage (2)
-       It can occur (1)

·         Malicious Insider
-       Damage (4)
-       It can occur (3)


·         Higher – lower risk :
o   Physical Breach.
o   Malware.
o   Malicious Insider.
o   Hacker.
o   Natural Disaster.
o   Negligence employee.

5) Formulate Security Solutions
·         Physical Breach
-       Limit access to hardware (Solution)
-       Tracking device (How to improve)
·         Malware
-       Install and update anti-virus (Solution)
-       Add Firewall (How to improve)
·         Malicious Insider
-       Apply one-time password (Solution)
-       Give access to trusted specific employee (How to improve)
·         Hacker
-       Create strong password (Solution)
-       Filter suspicious links and emails (How to improve)
·         Natural Disaster
-       Back-up data (Solution)
·         Negligence employee
-       Employee educations