File: /home/iestorre/Discovery1IntSpanish/courses/en0400000000/chapter08.xml
<chapter type="" id="en0408000000">
<title><content-text>Basic Security</content-text></title>
<section type="ChapterIntroduction" id="en0408000000">
<title><content-text>Chapter Introduction</content-text></title>
<topic type="" id="en0408000100">
<title><content-text>Introduction</content-text></title>
<page type="FullScreen" id="en0408000101">
<content-media type="AnimationFullScreen" id="cm9070933316"><title><content-text></content-text></title><media ref="en0408000000/en0408000000/en0408000100/en0408000101/cm9070933316.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408000000/en0408000100/en0408000101/cm9070933316text.xml"/></content-media>
<content-text></content-text>
</page>
</topic>
</section>
<section type="" id="en0408010000">
<title><content-text>Networking threats</content-text></title>
<topic type="" id="en0408010100">
<title><content-text>Risks of Network Intrusion</content-text></title>
<page type="OneColumn" id="en0408010101">
<content-media type="InteractiveGraphicRollovers" id="cm8079896147"><title><content-text>Roll over each threat to learn more.</content-text></title><media ref="en0408000000/en0408010000/en0408010100/en0408010101/cm8079896147.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408010000/en0408010100/en0408010101/cm8079896147text.xml"/></content-media>
<content-text><p>Whether wired or wireless, computer networks are quickly becoming essential to everyday activities. Individuals and organizations alike depend on their computers and networks for functions such as email, accounting, organization and file management. Intrusion by an unauthorized person can result in costly network outages and loss of work. Attacks to a network can be devastating and can result in a loss of time and money due to damage or theft of important information or assets. </p><p>Intruders can gain access to a network through software vulnerabilities, hardware attacks or even through less high-tech methods, such as guessing someone's username and password. Intruders who gain access by modifying software or exploiting software vulnerabilities are often called <b>hackers</b>. </p><p>Once the hacker gains access to the network, four types of threat may arise:</p><ul><li> Information theft</li><li> Identity theft</li><li> Data loss / manipulation</li><li> Disruption of service</li></ul></content-text>
</page>
<page type="FullScreen" id="en0408010102">
<content-media type="ActivityMCSA" id="cm9365186734"><title><content-text></content-text></title><media ref="en0408000000/en0408010000/en0408010100/en0408010102/cm9365186734.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408010000/en0408010100/en0408010102/cm9365186734text.xml"/></content-media>
<content-text><p><b>Lab Activity</b></p><p>Match the term to the security threat scenario description.</p><p><b>For each security threat scenario displayed, select the answer that most closely matches the scenario.</b></p></content-text>
</page>
</topic>
<topic type="" id="en0408010200">
<title><content-text>Sources of Network Intrusion</content-text></title>
<page type="OneColumn" id="en0408010201">
<content-media type="StaticGraphic" id="cm5646995462"><title><content-text></content-text></title><media ref="en0408000000/en0408010000/en0408010200/en0408010201/cm5646995462.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408010000/en0408010200/en0408010201/cm5646995462text.xml"/></content-media>
<content-text><p>Security threats from network intruders can come from both internal and external sources. </p><p><b>External Threats</b></p><p>External threats arise from individuals working outside of an organization. They do not have authorized access to the computer systems or network. External attackers work their way into a network mainly from the Internet, wireless links or dialup access servers.</p><p><b>Internal Threats</b></p><p>Internal threats occur when someone has authorized access to the network through a user account or have physical access to the network equipment. The internal attacker knows the internal politics and people. They often know what information is both valuable and vulnerable and how to get to it. </p><p>However, not all internal attacks are intentional. In some cases, an internal threat can come from a trustworthy employee who picks up a virus or security threat, while outside the company and unknowingly brings it into the internal network. </p><p>Most companies spend considerable resources defending against external attacks however most threats are from internal sources. According to the FBI, internal access and misuse of computers systems account for approximately 70% of reported incidents of security breaches.</p></content-text>
</page>
</topic>
<topic type="" id="en0408010300">
<title><content-text>Social Engineering and Phishing</content-text></title>
<page type="OneColumn" id="en0408010301">
<content-media type="StaticGraphic" id="cm2648812358"><title><content-text></content-text></title><media ref="en0408000000/en0408010000/en0408010300/en0408010301/cm2648812358.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408010000/en0408010300/en0408010301/cm2648812358text.xml"/></content-media>
<content-text><p>One of the easiest ways for an intruder to gain access, whether internal or external is by exploiting human behavior. One of the more common methods of exploiting human weaknesses is called Social Engineering. </p><p><b>Social Engineering</b></p><p>Social engineering is a term that refers to the ability of something or someone to influence the behavior of a group of people. In the context of computer and network security Social Engineering refers to a collection of techniques used to deceive internal users into performing specific actions or revealing confidential information. </p><p>With these techniques, the attacker takes advantage of unsuspecting legitimate users to gain access to internal resources and private information, such as bank account numbers or passwords. </p><p>Social engineering attacks exploit the fact that users are generally considered one of the weakest links in security. Social engineers can be internal or external to the organization, but most often do not come face-to-face with their victims. </p><p>Three of the most commonly used techniques in <content-link target="cg6081130562" type="glossary">social engineering</content-link> are: <content-link target="cg2562438962" type="glossary">pretexting</content-link>, <content-link target="cg3272392888" type="glossary">phishing</content-link>, and <content-link target="cg6922747317" type="glossary">vishing</content-link>.</p></content-text>
</page>
<page type="OneColumn" id="en0408010302">
<content-media type="StaticGraphic" id="cm2256925093"><title><content-text></content-text></title><media ref="en0408000000/en0408010000/en0408010300/en0408010302/cm2256925093.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408010000/en0408010300/en0408010302/cm2256925093text.xml"/></content-media>
<content-text><p><b>Pretexting</b></p><p>Pretexting is a form of social engineering where an invented scenario (the pretext) is used on a victim in order to get the victim to release information or perform an action. The target is typically contacted over the telephone. For pretexting to be effective, the attacker must be able to establish legitimacy with the intended target, or victim. This often requires some prior knowledge or research on the part of the attacker. For example, if an attacker knows the target's social security number, they may use that information to gain the trust of their target. The target is then more likely to release further information. </p><p><b>Phishing</b></p><p>Phishing is a form of social engineering where the phisher pretends to represent a legitimate outside organization. They typically contact the target individual (the phishee) via email. The phisher might ask for verification of information, such as passwords or usernames in order prevent some terrible consequence from occurring. </p><p><b>Vishing / Phone Phishing</b></p><p>A new form of social engineering that uses Voice over IP (VoIP) is known as vishing. With vishing, an unsuspecting user is sent a voice mail instructing them to call a number which appears to be a legitimate telephone-banking service. The call is then intercepted by a thief. Bank account numbers or passwords entered over the phone for verification are then stolen.</p></content-text>
</page>
</topic>
</section>
<section type="" id="en0408020000">
<title><content-text>Methods of attack</content-text></title>
<topic type="" id="en0408020100">
<title><content-text>Viruses, Worms, and Trojan Horses</content-text></title>
<page type="OneColumn" id="en0408020101">
<content-media type="StaticGraphic" id="cm4422007113"><title><content-text></content-text></title><media ref="en0408000000/en0408020000/en0408020100/en0408020101/cm4422007113.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408020000/en0408020100/en0408020101/cm4422007113text.xml"/></content-media>
<content-text><p>Social engineering is a common security threat which preys upon human weakness to obtain desired results. </p><p>In addition to social engineering, there are other types of attacks which exploit the vulnerabilities in computer software. Examples of these attack techniques include: viruses, worms and Trojan horses. All of these are types of malicious software introduced onto a host. They can damage a system, destroy data, as well as deny access to networks, systems, or services. They can also forward data and personal details from unsuspecting PC users to criminals. In many cases, they can replicate themselves and spread to other hosts connected to the network. </p><p>Sometimes these techniques are used in combination with social engineering to trick an unsuspecting user into executing the attack.</p></content-text>
</page>
<page type="OneColumn" id="en0408020102">
<content-media type="AnimationPartialScreen" id="cm4659809261"><title><content-text>Click the Play button to download space wars.</content-text></title><media ref="en0408000000/en0408020000/en0408020100/en0408020102/cm4659809261.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408020000/en0408020100/en0408020102/cm4659809261text.xml"/></content-media>
<content-text><p><b>Viruses</b></p><p>A virus is a program that runs and spreads by modifying other programs or files. A virus cannot start by itself; it needs to be activated. Once activated, a virus may do nothing more than replicate itself and spread. Though simple, even this type of virus is dangerous as it can quickly use all available memory and bring a system to a halt. A more serious virus may be programmed to delete or corrupt specific files before spreading. Viruses can be transmitted via email attachments, downloaded files, instant messages or via diskette, CD or USB devices.</p><p><b>Worms</b></p><p>A worm is similar to a virus, but unlike a virus does not need to attach itself to an existing program. A worm uses the network to send copies of itself to any connected hosts. Worms can run independently and spread quickly. They do not necessarily require activation or human intervention. Self-spreading network worms can have a much greater impact than a single virus and can infect large parts of the Internet quickly.</p><p><b>Trojan Horses</b></p><p>A <content-link target="cg9187516396" type="glossary">Trojan horse</content-link> is a non-self replicating program that is written to appear like a legitimate program, when in fact it is an attack tool. A Trojan horse relies upon its legitimate appearance to deceive the victim into initiating the program. It may be relatively harmless or can contain code that can damage the contents of the computer's hard drive. Trojans can also create a back door into a system allowing hackers to gain access.</p></content-text>
</page>
<page type="FullScreen" id="en0408020103">
<content-media type="ActivityMCSA" id="cm1840352125"><title><content-text></content-text></title><media ref="en0408000000/en0408020000/en0408020100/en0408020103/cm1840352125.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408020000/en0408020100/en0408020103/cm1840352125text.xml"/></content-media>
<content-text><p><b>Lab Activity</b></p><p>Determine if the user has been infected by a virus, worm or Trojan horse.</p><p><b>Select virus, worm or Trojan horse for each scenario.</b></p></content-text>
</page>
</topic>
<topic type="" id="en0408020200">
<title><content-text>Denial of Service and Brute Force Attacks</content-text></title>
<page type="OneColumn" id="en0408020201">
<content-media type="AnimationPartialScreen" id="cm8218536595"><title><content-text>Click Play to see a DoS attack.</content-text></title><media ref="en0408000000/en0408020000/en0408020200/en0408020201/cm8218536595.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408020000/en0408020200/en0408020201/cm8218536595text.xml"/></content-media>
<content-text><p>Sometimes the goal of an attacker is to shut down the normal operations of a network. This type of attack is usually carried out with the intent to disrupt the functions of an organization.</p><p><b>Denial of Service (<content-link target="cg3025994781" type="glossary">DoS</content-link>)</b></p><p>DoS attacks are aggressive attacks on an individual computer or groups of computers with the intent to deny services to intended users. DoS attacks can target end user systems, servers, routers, and network links.</p><p>In general, DoS attacks seek to:</p><ul><li> Flood a system or network with traffic to prevent legitimate network traffic from flowing </li><li> Disrupt connections between a client and server to prevent access to a service</li></ul><p>There are several types of DoS attacks. Security administrators need to be aware of the types of DoS attacks that can occur and ensure that their networks are protected. Two common DoS attacks are:</p><p>SYN (synchronous) Flooding - a flood of packets are sent to a server requesting a client connection. The packets contain invalid source IP addresses. The server becomes occupied trying to respond to these fake requests and therefore cannot respond to legitimate ones.</p><p>Ping of death: a packet that is greater in size than the maximum allowed by IP (65,535 bytes) is sent to a device. This can cause the receiving system to crash.</p></content-text>
</page>
<page type="OneColumn" id="en0408020202">
<content-media type="AnimationPartialScreen" id="cm5031414281"><title><content-text>Click Play to see a brute force attack.</content-text></title><media ref="en0408000000/en0408020000/en0408020200/en0408020202/cm5031414281.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408020000/en0408020200/en0408020202/cm5031414281text.xml"/></content-media>
<content-text><p><b>Distributed Denial of Service (<content-link target="cg3939467183" type="glossary">DDoS</content-link>)</b></p><p>DDoS is a more sophisticated and potentially damaging form of the DoS attack. It is designed to saturate and overwhelm network links with useless data. DDoS operates on a much larger scale than DoS attacks. Typically hundreds or thousands of attack points attempt to overwhelm a target simultaneously. The attack points may be unsuspecting computers that have been previously infected by the DDoS code. The systems that are infected with the DDoS code attack the target site when invoked. </p><p><b>Brute Force</b></p><p>Not all attacks that cause network outages are specifically DoS attacks. A Brute force attack is another type of attack that may result in denial of services. </p><p>With brute force attacks, a fast computer is used to try to guess passwords or to decipher an encryption code. The attacker tries a large number of possibilities in rapid succession to gain access or crack the code. Brute force attacks can cause a denial of service due to excessive traffic to a specific resource or by locking out user accounts.</p></content-text>
</page>
<page type="FullScreen" id="en0408020203">
<content-media type="ActivityMCSA" id="cm4125596598"><title><content-text></content-text></title><media ref="en0408000000/en0408020000/en0408020200/en0408020203/cm4125596598.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408020000/en0408020200/en0408020203/cm4125596598text.xml"/></content-media>
<content-text><p><b>Activity</b></p><p>Attempt to establish a TCP connection to the web server during a Denial of Service (DoS) attack.</p><p><b>Click one of the Inside User client PCs to obtain a TCP connection to the server.</b></p></content-text>
</page>
</topic>
<topic type="" id="en0408020300">
<title><content-text>Spyware, Tracking Cookies, Adware and Pop-ups</content-text></title>
<page type="OneColumn" id="en0408020301">
<content-media type="StaticGraphic" id="cm9777073343"><title><content-text></content-text></title><media ref="en0408000000/en0408020000/en0408020300/en0408020301/cm9777073343.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408020000/en0408020300/en0408020301/cm9777073343text.xml"/></content-media>
<content-text><p>Not all attacks do damage or prevent legitimate users from having access to resources. Many threats are designed to collect information about users which can be used for advertising, marketing and research purposes. These include Spyware, Tracking Cookies, Adware and Pop-ups. While these may not damage a computer, they invade privacy and can be annoying.</p><p><b>Spyware</b></p><p>Spyware is any program that gathers personal information from your computer without your permission or knowledge. This information is sent to advertisers or others on the Internet and can include passwords and account numbers. </p><p>Spyware is usually installed unknowingly when downloading a file, installing another program or clicking a <content-link target="cg8386495526" type="glossary">popup</content-link>. It can slow down a computer and make changes to internal settings creating more vulnerabilities for other threats. In addition, <content-link target="cg3568259296" type="glossary">spyware</content-link> can be very difficult to remove. </p><p><b>Tracking Cookies</b></p><p>Cookies are a form of spyware but are not always bad. They are used to record information about an Internet user when they visit websites. Cookies may be useful or desirable by allowing personalization and other time saving techniques. Many web sites require that cookies be enabled in order to allow the user to connect.</p></content-text>
</page>
<page type="OneColumn" id="en0408020302">
<content-media type="StaticGraphic" id="cm1670650768"><title><content-text></content-text></title><media ref="en0408000000/en0408020000/en0408020300/en0408020302/cm1670650768.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408020000/en0408020300/en0408020302/cm1670650768text.xml"/></content-media>
<content-text><p><b>Adware</b></p><p>Adware is a form of spyware used to collect information about a user based on websites the user visits. That information is then used for targeted advertising. Adware is commonly installed by a user in exchange for a "free" product. When a user opens a browser window, Adware can start new browser instances which attempt to advertize products or services based on a user's surfing practices. The unwanted browser windows can open repeatedly, and can make surfing the Internet very difficult, especially with slow Internet connections. Adware can be very difficult to uninstall.</p><p><b>Pop-ups and pop-unders</b></p><p>Pop-ups and pop-unders are additional advertising windows that display when visiting a web site. Unlike Adware, pop-ups and pop-unders are not intended to collect information about the user and are typically associated only with the web-site being visited. </p><ul><li> Pop-ups: open in front of the current browser window. </li><li> Pop-unders: open behind the current browser window.</li></ul><p>They can be annoying and usually advertise products or services that are undesirable.</p></content-text>
</page>
</topic>
<topic type="" id="en0408020400">
<title><content-text>Spam</content-text></title>
<page type="OneColumn" id="en0408020401">
<content-media type="AnimationPartialScreen" id="cm8744542040"><title><content-text>Click Play to see how spam is propagated.</content-text></title><media ref="en0408000000/en0408020000/en0408020400/en0408020401/cm8744542040.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408020000/en0408020400/en0408020401/cm8744542040text.xml"/></content-media>
<content-text><p>Another annoying by-product of our increasing reliance on electronic communications is unwanted bulk email. Sometimes merchants do not want to bother with targeted marketing. They want to send their email advertising to as many end users as possible hoping that someone is interested in their product or service. This widely distributed approach to marketing on the Internet is called <content-link target="cg6190673185" type="glossary">spam</content-link>.</p><p>Spam is a serious network threat that can overload ISPs, email servers and individual end-user systems. A person or organization responsible for sending spam is called a spammer. Spammers often make use of unsecured email servers to forward email. Spammers can use hacking techniques, such as viruses, worms and Trojan horses to take control of home computers. These computers are then used to send spam without the owner's knowledge. Spam can be sent via email or more recently via Instant messaging software. </p><p>It is estimated that every user on the Internet receives over 3,000 spam emails in a year. Spam consumes large amounts of Internet bandwidth and is a serious enough problem that many countries now have laws governing spam use.</p></content-text>
</page>
</topic>
</section>
<section type="" id="en0408030000">
<title><content-text>Security Policy</content-text></title>
<topic type="" id="en0408030100">
<title><content-text>Common Security Measures</content-text></title>
<page type="OneColumn" id="en0408030101">
<content-media type="InteractiveGraphicRollovers" id="cm1990849855"><title><content-text>Roll over the parts of the security policy for a description of each.</content-text></title><media ref="en0408000000/en0408030000/en0408030100/en0408030101/cm1990849855.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408030000/en0408030100/en0408030101/cm1990849855text.xml"/></content-media>
<content-text><p>Security risks cannot be eliminated or prevented completely. However, effective risk management and assessment can significantly minimize the existing security risks. To minimize the amount of risk, it is important to understand that no single product can make an organization secure. True network security comes from a combination of products and services, combined with a thorough <content-link target="cg1011274759" type="glossary">security policy</content-link> and a commitment to adhere to that policy. </p><p>A security policy is a formal statement of the rules that users must adhere to when accessing technology and information assets. It can be as simple as an acceptable use policy, or can be several hundred pages in length, and detail every aspect of user connectivity and network usage procedures. A security policy should be the central point for how a network is secured, monitored, tested and improved upon. While most home users do not have a formal written security policy, as a network grows in size and scope, the importance of a defined security policy for all users increases drastically. Some things to include in a security policy are: identification and authentication policies, password policies, acceptable use policies, remote access policies, and incident handling procedures. </p><p>When a security policy is developed, it is necessary that all users of the network support and follow the security policy in order for it to be effective. </p></content-text>
</page>
<page type="OneColumn" id="en0408030102">
<content-media type="InteractiveGraphicRollovers" id="cm5198568306"><title><content-text>Roll over the security applications and devices for a description of each.</content-text></title><media ref="en0408000000/en0408030000/en0408030100/en0408030102/cm5198568306.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408030000/en0408030100/en0408030102/cm5198568306text.xml"/></content-media>
<content-text><p>A security policy should be the central point for how a network is secured, monitored, tested and improved upon. Security procedures implement security policies. Procedures define configuration, login, audit, and maintenance processes for hosts and network devices. They include the use of both preventative measures to reduce risk, as well as active measure for how to handle known security threats. Security Procedures can range from simple, inexpensive tasks such as maintaining up-to-date software releases, to complex implementations of firewalls and intrusion detection systems. </p><p>Some of the security tools and applications used in securing a network include:</p><ul><li> Software patches and updates</li><li> Virus protection</li><li> Spyware protection</li><li> Spam blockers</li><li> Pop-up blockers</li><li> Firewalls</li></ul></content-text>
</page>
</topic>
<topic type="" id="en0408030200">
<title><content-text>Updates and Patches</content-text></title>
<page type="OneColumn" id="en0408030201">
<content-media type="StaticGraphic" id="cm5954333884"><title><content-text></content-text></title><media ref="en0408000000/en0408030000/en0408030200/en0408030201/cm5954333884.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408030000/en0408030200/en0408030201/cm5954333884text.xml"/></content-media>
<content-text><p><b>Patches and Updates</b></p><p>One of the most common methods that a <content-link target="cg4804354446" type="glossary">hacker</content-link> uses to gain access to hosts and/or networks is through software vulnerabilities. It is important to keep software applications up-to-date with the latest security patches and updates to help deter threats. A patch is a small piece of code that fixes a specific problem. An update, on the other hand, may include additional functionality to the software package as well as patches for specific issues. </p><p>OS (operating system, such as <content-link target="cg7898442205" type="glossary">Linux</content-link>, Windows, etc.) and application vendors continuously provide updates and security patches that can correct known vulnerabilities in the software. In addition, vendors often release collections of patches and updates called service packs. Fortunately, many operating systems offer an automatic update feature that allows OS and applications updates to be automatically downloaded and installed on a host.</p></content-text>
</page>
</topic>
<topic type="" id="en0408030300">
<title><content-text>Anti-virus Software</content-text></title>
<page type="OneColumn" id="en0408030301">
<content-media type="AnimationPartialScreen" id="cm5321356317"><title><content-text></content-text></title><media ref="en0408000000/en0408030000/en0408030300/en0408030301/cm5321356317.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408030000/en0408030300/en0408030301/cm5321356317text.xml"/></content-media>
<content-text><p><b>Antivirus Software (Detecting a virus)</b></p><p>Even when the OS and applications have all the current patches and updates, they may still be susceptible to attack. Any device that is connected to a network is susceptible to viruses, worms and Trojan horses. These may be used to corrupt OS code, affect computer performance, alter applications, and destroy data.</p><p>Some of the signs that a virus, worm or Trojan horse may be present include:</p><ul><li> Computer starts acting abnormally</li><li> Program does not respond to mouse and keystrokes</li><li> Programs starting or shutting down on their own</li><li> Email program begins sending out large quantities of email</li><li> CPU usage is very high </li><li> There are unidentifiable, or a large number of processes running </li><li> Computer slows down significantly or crashes</li></ul></content-text>
</page>
<page type="OneColumn" id="en0408030302">
<content-media type="StaticGraphic" id="cm8274178573"><title><content-text></content-text></title><media ref="en0408000000/en0408030000/en0408030300/en0408030302/cm8274178573.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408030000/en0408030300/en0408030302/cm8274178573text.xml"/></content-media>
<content-text><p><b>Anti-virus Software</b></p><p>Anti-virus software can be used as both a preventative tool and as a reactive tool. It prevents infection and detects, and removes, viruses, worms and Trojan horses. Anti-virus software should be installed on all computers connected to the network. There are many Anti-virus programs available. </p><p>Some of the features that can be included in Anti-virus programs are:</p><ul><li><b>Email checking</b> - Scans incoming and outgoing emails, and identifies suspicious attachments.</li><li><b>Resident dynamic scanning</b> - Checks executable files and documents when they are accessed.</li><li><b>Scheduled scans</b> - Virus scans can be scheduled to run at regular intervals and check specific drives or the entire computer. </li><li><b>Automatic Updates</b> - Checks for, and downloads, known virus characteristics and patterns. Can be scheduled to check for updates on a regular basis.</li></ul><p>Anti-virus software relies on knowledge of the virus to remove it. Therefore, when a virus is identified, it is important to report it or any virus-like behavior to the network administrator. This is normally done by submitting an incident report according to the company's network security policy. </p><p>Network administrators can also report new instances of threats to the local governmental agency that handle security problems. For example, an agency in the U.S. is: <content-link target="https://forms.us-cert.gov/report/" type="external">https://forms.us-cert.gov/report/</content-link>. This agency is responsible for developing counter measures to new virus threats as well as ensuring that those measures are available to the various anti-virus software developers.</p></content-text>
</page>
</topic>
<topic type="" id="en0408030400">
<title><content-text>Anti-spam</content-text></title>
<page type="OneColumn" id="en0408030401">
<content-media type="AnimationPartialScreen" id="cm6872148539"><title><content-text></content-text></title><media ref="en0408000000/en0408030000/en0408030400/en0408030401/cm6872148539.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408030000/en0408030400/en0408030401/cm6872148539text.xml"/></content-media>
<content-text><p>Spam is not only annoying; it can overload email servers and potentially carry viruses and other security threats. Additionally, Spammers take control of a host by planting code on it in the form of a virus or a Trojan horse. The host is then used to send spam mail without the user's knowledge. A computer infected this way is known as a Spam mill.</p><p>Anti-spam software protects hosts by identifying spam and performing an action, such as placing it into a junk folder or deleting it. It can be loaded on a machine locally, but can also be loaded on email servers. In addition, many ISPs offer spam filters. Anti-spam software does not recognize all spam, so it is important to open email carefully. It may also accidentally identify wanted email as spam and treat it as such. </p></content-text>
</page>
<page type="OneColumn" id="en0408030402">
<content-media type="StaticGraphic" id="cm2837622702"><title><content-text></content-text></title><media ref="en0408000000/en0408030000/en0408030400/en0408030402/cm2837622702.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408030000/en0408030400/en0408030402/cm2837622702text.xml"/></content-media>
<content-text><p>In addition to using spam blockers, other preventative actions to prevent the spread of spam include: </p><ul><li> Apply OS and application updates when available.</li><li> Run an Antivirus program regularly and keep it up to date.</li><li> Do not forward suspect emails.</li><li> Do not open email attachments, especially from people you do not know.</li><li> Set up rules in your email to delete spam that by-pass the anti-spam software.</li><li> Identify sources of spam and report it to a network administrator so it can be blocked.</li><li> Report incidents to the governmental agency that deals with abuse by spam.</li></ul><p>One of the most common types of spam forwarded is a virus warning. While some virus warnings sent via email are true, a large amount of them are hoaxes and do not really exist. This type of spam can create problems because people warn others of the impending disaster and so flood the email system. In addition, network administrators may overreact and waste time investigating a problem that does not exist. Finally, many of these emails can actually contribute to the spread of viruses, worms and Trojan horses. Before forwarding virus warning emails, check to see if the virus is a hoax at a trusted source such as: <content-link target="http://vil.mcafee.com/hoax.asp" type="external">http://vil.mcafee.com/hoax.asp</content-link> or <content-link target="http://hoaxbusters.ciac.org/" type="external">http://hoaxbusters.ciac.org/</content-link></p></content-text>
</page>
</topic>
<topic type="" id="en0408030500">
<title><content-text>Anti-spyware</content-text></title>
<page type="OneColumn" id="en0408030501">
<content-media type="StaticGraphic" id="cm4542883410"><title><content-text></content-text></title><media ref="en0408000000/en0408030000/en0408030500/en0408030501/cm4542883410.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408030000/en0408030500/en0408030501/cm4542883410text.xml"/></content-media>
<content-text><p><b>Anti-Spyware and Adware</b></p><p>Spyware and <content-link target="cg5830472275" type="glossary">adware</content-link> can also cause virus-like symptoms. In addition to collecting unauthorized information, they can use important computer resources and affect performance. Anti-spyware software detects and deletes spyware applications, as well as prevents future installations from occurring. Many Anti-Spyware applications also include detection and deletion of cookies and adware. Some Anti-virus packages include Anti-Spyware functionality. </p><p><b>Pop-up Blockers</b></p><p>Pop-up stopper software can be installed to prevent pop-ups and pop-unders. Many web browsers include a pop-up blocker feature by default. Note that some programs and web pages create necessary and desirable pop-ups. Most pop-up blockers offer an override feature for this purpose.</p></content-text>
</page>
<page type="FullScreen" id="en0408030502">
<content-media type="ActivityDnDSnapback" id="cm5455855032"><title><content-text></content-text></title><media ref="en0408000000/en0408030000/en0408030500/en0408030502/cm5455855032.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408030000/en0408030500/en0408030502/cm5455855032text.xml"/></content-media>
<content-text><p><b>Activity</b></p><p>Identify the purpose of each security tool.</p><p><b>Drag the security tool to the appropriate definition</b></p></content-text>
</page>
</topic>
</section>
<section type="" id="en0408040000">
<title><content-text>Using Firewalls</content-text></title>
<topic type="" id="en0408040100">
<title><content-text>What is a Firewall?</content-text></title>
<page type="OneColumn" id="en0408040101">
<content-media type="AnimationPartialScreen" id="cm8554183742"><title><content-text>NEEDS INSTRUCTION TEXT</content-text></title><media ref="en0408000000/en0408040000/en0408040100/en0408040101/cm8554183742.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408040000/en0408040100/en0408040101/cm8554183742text.xml"/></content-media>
<content-text><p>In addition to protecting individual computers and servers attached to the network, it is important to control traffic traveling to and from the network. </p><p>A Firewall is one of the most effective security tools available for protecting internal network users from external threats. A firewall resides between two or more networks and controls the traffic between them as well as helps prevent unauthorized access. Firewall products use various techniques for determining what is permitted or denied access to a network. </p><ul><li><b>Packet Filtering</b> - Prevents or allows access based on IP or MAC addresses.</li><li><b>Application / Web Site Filtering</b> - Prevents or allows access based on the application. Websites can be blocked by specifying a website <content-link target="cg6302482575" type="glossary">URL</content-link> address or keywords.</li><li><b>Stateful Packet Inspection (SPI)</b> - Incoming packets must be legitimate responses to requests from internal hosts. Unsolicited packets are blocked unless permitted specifically. SPI can also include the capability to recognize and filter out specific types of attacks such as DoS.</li></ul><p>Firewall products may support one or more of these filtering capabilities. Additionally, Firewalls often perform Network Address Translation (NAT). NAT translates an internal address or group of addresses into an outside, public address that is sent across the network. This allows internal IP addresses to be concealed from outside users.</p></content-text>
</page>
<page type="OneColumn" id="en0408040102">
<content-media type="InteractiveGraphicRollovers" id="cm1316593116"><title><content-text>Roll over each device for more information.</content-text></title><media ref="en0408000000/en0408040000/en0408040100/en0408040102/cm1316593116.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408040000/en0408040100/en0408040102/cm1316593116text.xml"/></content-media>
<content-text><p>Firewall products come packaged in various forms:</p><ul><li><b>Appliance-based firewalls</b> - An appliance-based firewall is a firewall that is built-in to a dedicated hardware device known as a security appliance. </li><li><b>Server-based firewalls</b> - A server-based firewall consists of a firewall application that runs on a network operating system (NOS) such as <content-link target="cg4151264568" type="glossary">UNIX</content-link>, Windows or Novell.</li><li><b>Integrated Firewalls</b> - An integrated firewall is implemented by adding firewall functionality to an existing device, such as a router.</li><li><b>Personal firewalls</b> - Personal firewalls reside on host computers and are not designed for LAN implementations. They may be available by default from the OS or may be installed from an outside vendor.</li></ul></content-text>
</page>
</topic>
<topic type="" id="en0408040200">
<title><content-text>Using a Firewall</content-text></title>
<page type="OneColumn" id="en0408040201">
<content-media type="AnimationPartialScreen" id="cm9349392279"><title><content-text>Click Play to see request flow from internal and external hosts.</content-text></title><media ref="en0408000000/en0408040000/en0408040200/en0408040201/cm9349392279.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408040000/en0408040200/en0408040201/cm9349392279text.xml"/></content-media>
<content-text><p>By placing the firewall between the internal network (<content-link target="cg4478389122" type="glossary">intranet</content-link>) and the Internet as a border device, all traffic to and from the Internet can be monitored and controlled. This creates a clear line of defense between the internal and external network. However, there may be some external customers that require access to internal resources. A <content-link target="cg5295761206" type="glossary">demilitarized zone (DMZ)</content-link> can be configured to accomplish this. </p><p>The term demilitarized zone is borrowed from the military, where a DMZ is a designated area between two powers where military activity is not permitted. In computer networking, a DMZ refers to an area of the network that is accessible to both internal and external users. It is more secure than the external network but not as secure as the internal network. It is created by one or more firewalls to separate the internal, DMZ and external networks. Web servers for public access are frequently placed in a DMZ.</p></content-text>
</page>
<page type="OneColumn" id="en0408040202">
<content-media type="StaticGraphic" id="cm6847269728"><title><content-text></content-text></title><media ref="en0408000000/en0408040000/en0408040200/en0408040202/cm6847269728.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408040000/en0408040200/en0408040202/cm6847269728text.xml"/></content-media>
<content-text><p><b>Single firewall configuration</b></p><p>A single firewall has three areas, one for the external network, the internal network, and the DMZ. All traffic is sent to the firewall from the external network. The firewall is then required to monitor the traffic and determine what traffic should be passed to the DMZ, what traffic should be passed internally, and what should be denied altogether.</p><p><b>Two firewall configuration</b></p><p>In a two firewall configuration, there is an internal and external firewall with the DMZ located between them. The external firewall is less restrictive and allows Internet user access to the services in the DMZ as well as allowing a traffic that any internal user requested to pass through. The internal firewall is more restrictive and protects the internal network from unauthorized access.</p><p>A single firewall configuration is appropriate for smaller, less congested networks. However, a single firewall configuration does have a single point of failure and can be overloaded. A two-firewall configuration is more appropriate for larger, more complex networks that handle a lot more traffic.</p></content-text>
</page>
<page type="OneColumn" id="en0408040203">
<content-media type="StaticGraphic" id="cm5087693796"><title><content-text></content-text></title><media ref="en0408000000/en0408040000/en0408040200/en0408040203/cm5087693796.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408040000/en0408040200/en0408040203/cm5087693796text.xml"/></content-media>
<content-text><p>Many home network devices, such as integrated routers, frequently include multi-function firewall software. This firewall typically provides Network Address Translation (NAT), Stateful Packet Inspection (SPI) and IP, Application and web site filtering capabilities. They also support DMZ capabilities.</p><p>With the integrated router, a simple DMZ can be set up that allows an internal server to be accessible by outside hosts. To accomplish this, the server requires a <content-link target="cg8768592958" type="glossary">static IP address</content-link> that must be specified in the DMZ configuration. The integrated router isolates traffic destined to the IP address specified. This traffic is then forwarded only to the switch port where the server is connected. All other hosts are still protected by the firewall. </p><p>When the DMZ is enabled, in its simplest form, outside hosts can access all ports on the server, such as 80 (HTTP), 21 (FTP), and 110 (Email POP3), etc. </p><p>A more restrictive DMZ can be set up using the port forwarding capability. With port forwarding, ports that should be accessible on the server are specified. In this case, only traffic destined for those port(s) is allowed, all other traffic is excluded. </p><p>The wireless access point within the integrated router is considered part of the internal network. It is important to realize that if the wireless access point is unsecured, anyone who connects to it is within the protected part of the internal network and is behind the firewall. Hackers can use this to gain access to the internal network and completely bypass any security.</p></content-text>
</page>
<page type="OneColumn" id="en0408040204">
<content-media type="ActivityLab" id="cm9970093638"><title><content-text></content-text></title><media ref="en0408000000/en0408040000/en0408040200/en0408040204/cm9970093638/" mime="application/pdf" scale="false" type="directory" width="0" height="0" external="en0408000000/en0408040000/en0408040200/en0408040204/cm9970093638/icontext.xml"/></content-media>
<content-text><p><b>Lab Activity</b></p><p>Configure firewall settings using the Linksys GUI interface and use it to create a DMZ.</p><p><b>Click on the lab icon to begin.</b></p></content-text>
</page>
</topic>
<topic type="" id="en0408040300">
<title><content-text>Vulnerability Analysis</content-text></title>
<page type="OneColumn" id="en0408040301">
<content-media type="StaticGraphic" id="cm6311768545"><title><content-text></content-text></title><media ref="en0408000000/en0408040000/en0408040300/en0408040301/cm6311768545.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408040000/en0408040300/en0408040301/cm6311768545text.xml"/></content-media>
<content-text><p>There are many vulnerability analysis tools for testing host and network security. These are known as security scanners, and can help identify areas where attacks might occur and offer guidance on steps that can be taken. While the capabilities of the vulnerability analysis tools can vary based on manufacturer, some of the more common features include determining:</p><ul><li> Number of hosts available on a network</li><li> The services hosts are offering</li><li> The operating system and versions on the hosts</li><li> Packet filters and firewalls in use</li></ul></content-text>
</page>
<page type="OneColumn" id="en0408040302">
<content-media type="ActivityLab" id="cm9320877926"><title><content-text></content-text></title><media ref="en0408000000/en0408040000/en0408040300/en0408040302/cm9320877926/" mime="application/pdf" scale="false" type="directory" width="0" height="0" external="en0408000000/en0408040000/en0408040300/en0408040302/cm9320877926/icontext.xml"/></content-media>
<content-text><p><b>Lab Activity</b></p><p>Research, download and install a Security Vulnerability tester and use it to determine weaknesses in a host and the network.</p><p><b>Click the lab icon to begin.</b></p></content-text>
</page>
</topic>
<topic type="" id="en0408040400">
<title><content-text>Best Practices</content-text></title>
<page type="OneColumn" id="en0408040401">
<content-media type="StaticGraphic" id="cm7424591870"><title><content-text></content-text></title><media ref="en0408000000/en0408040000/en0408040400/en0408040401/cm7424591870.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408040000/en0408040400/en0408040401/cm7424591870text.xml"/></content-media>
<content-text><p>There are several recommended practices to help mitigate the risks they pose, including:</p><ul><li> Define security policies</li><li> Physically secure servers and network equipment</li><li> Set login and file access permissions</li><li> Update OS and applications</li><li> Change permissive default settings</li><li> Run anti-virus and anti-spyware</li><li> Update antivirus software files</li><li> Activate browser tools - Popup stoppers, anti-phishing, plug-in monitors </li><li> Use a firewall</li></ul><p>The first step towards securing a network is to understand how traffic moves across the network and the different threats and vulnerabilities that exist. Once security measures are implemented, a truly secure network needs to be monitored constantly. Security procedures and tools need to be reviewed in order to stay ahead of evolving threats.</p></content-text>
</page>
</topic>
</section>
<section type="ChapterSummary" id="en0408050000">
<title><content-text>Chapter Summary</content-text></title>
<topic type="" id="en0408050100">
<title><content-text>Summary</content-text></title>
<page type="FullScreen" id="en0408050101">
<content-media type="InteractiveGraphicHotspots" id="cm5016823259"><title><content-text></content-text></title><media ref="en0408000000/en0408050000/en0408050100/en0408050101/cm5016823259.swf" mime="shockwave/flash" scale="true" type="file" width="400" height="200" external="en0408000000/en0408050000/en0408050100/en0408050101/cm5016823259text.xml"/></content-media>
<content-text></content-text>
</page>
</topic>
</section>
<section type="ChapterQuiz" id="en0408060000">
<title><content-text>Chapter Quiz</content-text></title>
<topic type="" id="en0408060100">
<title><content-text>Quiz</content-text></title>
<page type="OneColumn" id="en0408060101">
<content-media type="ChapterQuiz" id="cm8291354030"><title><content-text></content-text></title><media ref="en0408000000/en0408060000/en0408060100/en0408060101/cm8291354030/" mime="" scale="true" type="directory" width="800" height="450" external="en0408000000/en0408060000/en0408060100/en0408060101/cm8291354030/icontext.xml"/></content-media>
<content-text><p>Take the chapter quiz to check your knowledge.</p><p><b>Click the quiz icon to begin.</b></p></content-text>
</page>
</topic>
</section>
</chapter>