顯示具有 IVE 標籤的文章。 顯示所有文章
顯示具有 IVE 標籤的文章。 顯示所有文章

星期日, 6月 03, 2007

Network Security - Advanced Security and Beyond

  1. ______Computer Forensic___________ can attempt to retrieve information that can be used in the pursuit of the criminal.
  2. The reasons to make computer forensics more important are: ___High amount of digital evidence; increased scrutiny by legal profession; higher lever of computer skill by criminals.
  3. List the ways that computer forensics is different from standard investigations: __Volume of electronic evidence; Distribution of evidence; Dynamic content; False leads; Encrypted evidence; Hidden evidence.
  4. Taking photographs of the crime scene is a step to ___secure the crime scene________.
  5. The computer forensic team first captures _______volatile____________ data to preserve the data; this includes any data in _______content of RAM; Current network connections; Logon sessions; network configurations; open files.
  6. _____Mirror image (bit-stream)____________ backups create exact replicas of the computer contents at the crime scene.
  7. The ____chain of custody___________ documents that the evidence was under strict control all times and no unauthorized person was given the opportunity to corrupt the evidence.
  8. __RAM slack______________ are data from RAM that is used to fill up the last sector on a disk.








Forensic Team Step
Action
Secure the crime scene
Instruct users to call response team at first hint of security issue.
Document surroundings
Label and photograph equipment
Take custody of computer, peripherals, and media.
Preserve the data
Capture volatile data
Perform mirror image backup
Establish chain of custody
Document in detail location of evidence
Examine for evidence
Search files, document, e-mail etc.
Examine Windows page files.
Explore RAM slack
Look at file slack

  1. ___Trusted Platform Model (TPM)___________ is to make a cryptographic coprocessor standard equipment on every microprocessor.
  2. ____Behavior blocking_________ protects computers by recognizing when they are not acting normally.
  3. ______Host intrusion prevention (HIP)_ restricts the availability of functions such as read, write and execute and protects system resources such as ports, files, and registry keys.

星期三, 5月 23, 2007

Network Security - Security Basics

  1. State the advantages and disadvantages of using bottom-up and top-down approaches.

Approach
Advantages
Disadvantages
Bottom-up

The bottom-level employees have the technical expertise to understand what to do to secure information and how to do it.



The bottom-level employees do not have the resource and authority to enforce the security policy for all employees
Top-down

A security plan initiated by top-level managers has the backing to make the plan work. Additional resources such as funding, equipment, and personnel have the highest level of support.
The top management may not know the technical details of implementing the security plan.









  1. Why is Human Firewall necessary in a company to ensure the implementation of security policy successful? (Note: a human firewall is an employee who tries to prevent security attacks from passing through him or her.)

___Human Firewall involves the commitment of each employee and therefore each employee tends to follow the security policy of the company closely, hence making the policy successful.
_____________________________________________________________________

  1. Why is it difficult for an attacker to break through a layered security system?

___An attacker is unlikely possesses the tools and skills to break through all the layers of defenses.________________________________________________________________

  1. The company has a security policy which does not allow employees of other departments to access the human resource system. This is an example of using the ____limiting__ policy.

  1. Guards do not change shifts at the same time each night is using the ___obscurity_ policy.

  1. Using firewalls produced by different vendors is an example of using the ___diversity_ policy.


  1. Describe why simplicity principle is using in security policy. If the security system is simple, then how can it prevent the crackers from breaking in?

____Simple security systems can be easily understood and maintained. The challenge is to make the system simple from inside but complex from outside.




  1. There are three main categories of authentication, list down one example for each.

Authentication by what you know. Examples:____password_kerberos and CHAP

Authentication by what you have. Examples:_____tokens, digital certificate
Authentication by what you are. Examples: ______iris, finger print__

  1. Information security rests on ___authentication, access control, and ___auditing_____, or we can also say it rests on AAA, i.e. _____authentication, authorization and accounting.

  1. A __digital certificate_____________ is issued by a certification authority (CA) and it links or binds a specific person to a __public_key___________.

  1. Kerberos is an authentication system which issues a ___ticket______ which contains specific user information, restrict what a user can do and expire after a few hours or a day.

  1. There are three models of access control:

Access control Model
Level of Restriction
Characteristics
Discretionary Access Control
Least
One subject can adjust the permissions for other subjects over objects
Role Based Access Control
Medium
The users and objects inherit all of the permissions for the role.
Mandatory Access Control
Most
One subject is not allowed to grant right to another subject to use an object


  1. You can audit a security system in two ways:___logging ________________ and _____system scanning____________.

推薦此文