Take Assessment: Test 7 Topic 7
Name Test 7 Topic 7
Instructions Instructions:
1. You have 30 minutes to complete this test
2. You only have one attempt and must finish it once started
3. Answer all 6 questions
Timed Assessment This Test has a 30 minute timer.The elapsed time appears at the top right of the window.
A 1 minute warning will be displayed.
Multiple Attempts Not allowed. This Test can only be taken once.
Force Completion This Test must be completed now.
Question 1
Which below are elements of a security audit and alarms model? (15.2)
A. System logs, email logs and apache logs
B. Operating system updates / patches, application updates / patches and anti virus updates
C. Audit analyzer, security reports, archives and security audit trail
D. None of the above
From the text, Stallings & Brown (2008), page 477 and 478, the elements of a security audit and alarms model are described as follows;
• Event discriminator: The is logic embedded into the software of the system that
monitors system activity and detects security-related events that it has been
configured to detect.
• Audit recorder: For each detected event, the event discriminator transmits the
information to an audit recorder. The model depicts this transmission as being in
the form of a message. The audit could also be done by recording the event in a
shared memory area.
• Alarm processor: Some of the events detected by the event discriminator are
defined to be alarm events. For such events an alarm is issued to an alarm
processor. The alarm processor takes some action based on the alarm. This action
is itself an auditable event and so is transmitted to the audit recorder.
• Security audit trail: The audit recorder creates a formatted record of each event
and stores it in the security audit trail.
• Audit analyzer: The security audit trail is available to the audit analyzer, which,
based on a pattern of activity, may define a new auditable event that is sent to the
audit recorder and may generate an alarm.
• Audit archiver: This is a software module that periodically extracts records from
the audit trail to create a permanent archive of auditable events.
• Archives: The audit archives are a permanent store of security-related events on
this system.
• Audit provider: The audit provider is an application and/or user interface to the
audit trail.
• Audit trail examiner: The audit trail examiner is an application or user who
examines the audit trail and the audit archives for historical trends, for computer
forensic purposes, and for other analysis.
• Security reports: The audit trail examiner prepares human-readable security
reports.
Question 2
Which of the following *are* supported by the Cisco Systems' "Monitoring, Analysis and Response System (MARS)"?
A. Network devices: Cisco software
B. Firewall / VPN devices
C. Intrusion detection software
D. Anti virus
E. Applications: Apache IIS web servers
F. All of the above G. None of the above
Refer to your text, page 503, Computer Security Principles and Practice, Stalling & Brown, 2008.
Question 3
Which of the following statements best describes "system-level audit trail"? (15.5)
A. traces the activity of individual users over time
B. captures data such as login attempts, both successful and unsuccessful, devices used, and OS functions performed
C. generated by equipment that controls physical access and then transmitted to a central host for subsequent storage and analysis
D. may be used to detect security violations within an application or to detect flaws in the application's interaction with the system
Four different categories of audit trails are;
System-level audit trails: captures data such as login attempts, both successful and unsuccessful, devices used, and OS functions performed
Application-level audit trails: may be used to detect security violations within an application or to detect flaws in the application's interaction with the system.
User-level audit trails: traces the activity of individual users over time.
Physical access audit trails: generated by equipment that controls physical access and then transmitted to a central host for subsequent storage and analysis.
Question 4
Which of the following areas (categories of data) should audit data be collecting? (15.4)
A. deletion of objects
B. identification and authentication functions
C. printout of data
D. use of access rights to bypass a policy check
E. All of the above F. Only A, B and D above
All actions that may effect access to data are to be collected by audit data.
The following are all categories of data that audit data should collect;
• Introduction of objects within the security-related portion of the software into a
subject’s address space
• Deletion of objects
• Distribution or revocation of access rights or capabilities
• Changes to subject or object security attributes
• Policy checks performed by the security software as a result of a request by a
subject
• The use of access rights to bypass a policy check
• Use of identification and authentication functions
• Security-related actions taken by an operator and/or authorized user (e.g.,
suppression of a protection mechanism)
• Import/export of data from/to removable media (e.g., printed output, tapes,
disks)
Question 5
Which of the follow need to be understood to perform effective reviews and analysis of an organisation's systems audit logs?
A. characteristics of common attack techniques
B. organisations policies regarding acceptable use
C. the operating systems and major applications
D. security software used on hosts
E. brand computers purchased by each department of the organisation
F. All of the above
G. Only A, B, C and D above
The brand of computers purchased is not relevant, but all other points listed are needed to be understood to review and analyse an organisation's systems audit logs.
Refer to your text, page 498, Computer Security Principles and Practise, Stalling & Brown, 2008.
Question 6
Audit logs that track user activity on an information system provide __________.
A. identification
B. authorization
C. accountability D. authentication
星期二, 9月 20, 2011
星期四, 8月 11, 2011
Mor-Christian General Soccer Ability Skill Test Battery
Introduction
Soccer is one of the popular sports in the world, as there is a very large number of people that play football at different levels. According to a survey conducted by FIFA published in 2008, over 300 million people from more than 200 countries regularly play football. As a result, we can see that effective skill tests are vitally important for placement, grading, diagnosis in various levels, since sport skill test is an instrument that elicits an observable respone which provides information about motor skill used in a sport.
Mor-Christian General Soccer Ability Skill Test Battery(Mor & Christian, 1979) is one of the soccer tests that evauate passing, dribbling and shooting ability in soccer. Here, the content of the tests will be discussed and evaluated in the following part. On the contrary, there are the suggestions on improving the quality of the test that instructors not only administer the tests smoothly, but also test the subjects’ ability widely.
a) Mor-Christian Soccer Dribbling Test
( Validity-0.73 , Reability-0.80 )
There are many good criteria in this test, including short period of time for administering, equipments, human resource, availability of venue and objectives. In this test, there is a short period of time, around 2 minutes for each subjects. Besides, few human resources and equipment are required, so that the test is easy for setting and administer. But large area is oocupied by the circular path in this test, some testing area may not provide sufficient area to carry out various tests at the same time. Actually, it is good for students that three trials are allowed in this dribbling test, as the learning effect is a key factor to reduce the relibility, so trials can help the subjects to familiarize the testing procedures. Moreover, clockwise and conterclockwise direction are required to finish that the test is suitable for real situation, soccer need to dribble in all direction continually in the match, not only in their dominant direction. However, there are some suggestions in this test. The first one is the distance between cones. In the outline of setting, there is 5 yds among the cones within the path, but too long distance may cause the reduction of validity and reliability. Dribbling refers to the maneuvering of a ball around a defender through short skillful taps or kicks with either the legs, excess time is allowed for dribblers to co-ordinate their body and it is easy to dribble all the cones if there are too long distance among the cones. In fact, players in the competition often execute dribbling in the short distance from the defenders, so the distance is suggested to reduce from 5 yds to 3.5 or 4 yds, and it can let the subjects in dribbling test as well as real situation. The second suggestion is that subjects’ liner-dribbling ability can be tested, not only in circulat direction. Since players also face the challenges face to face in the match, so the liner-dribbling part is suggested to follow the circular dribbling, this combination can fit in real situation and increase the validity of the test.
b) Mor-Christian Soccer Shooting Test
( Validity-0.78 , Reability-0.96 )
This shooting test can verify the shooting ability exactly, especially for the soccer attackers, as it can test the object shooting accuracy. However, shooting power is not tested and scoring scheme has a contridiction. Shooting ability is mainly consist of accuracy, power and speed, and the speed is a key factor to determine the quality and the chance of scoring, but this test just test subject’s shooting accuracy only. Also, the scoring scheme has conflict that the score is counted even subjects shoot at the other corner which is not they claimed, since there is a large difference in shooting two opposite concer, so the instruction of scoring scheme is not clear and unintelligible.
Actually, there are many reasons that it is quite difficult to administer this shootiing test. First of all, time consuming is factor that every subject consume much time to finish all of the trials, around five to six minutes, so an inconvenience may be caused. Second is about the availability of venue, because not all of the testing area contain a standard goal or sufficient area for setting, so this test is limited by small venue. Thirdly, many equipments are required for setting this test when it compares with another two tests, so it increases the difficulty in setting.
c) Mor-Christian Soccer Passing Test
( Validity-0.91 , Reability-0.98 )
This passing test has the highest validity and reability in these three tests, it prove that it has good criteria for a sport skill test, however, it also has some drawbacks.
There are few equipments in this test like the dribbling test metioned before, so instructors can prepare the test easily. Nevertheless, subjects consume a lot of time to finish all of the passing tests in different positions when it compares with other two soccer tests , around 4 minutes for each subject. Furthermore, it requires many human resources to keep the fluency of the test. For the objectives, the test is good for subjects’ passing abiliy, since the proper distance and several passing direction in the test are essential for a soccer match and it can explain why there are the high validity and reability. On the other hand, the test result may not reflect actual ability. It is because players will not pass the ball on the fixed points like this passing test if they play in the match. Players need to run and then pass the ball continually, so this passing test is not fit to test subjects’ actual passing ability. Moreover, ability of long pass is not involved in the test, so long pass testing is suggested to administer, as long pass is an important part in soccer, it is used in defenders and side attackers normally.
Conclusion
are the basic skills in soccer, it is necessary to test players’ ability of these aspect. Mor-Christian General Soccer Ability Skill Test Battery is one the the good tests to evaluate although there are some suggestions for improvement. In fact, not only these three aspect, many skills are also required for a good soccer player. For instance, agility and header are two of the important skills in soccer, perhaps it is better that various parts are included beside dribbling, passing and shooting and test the subject comprehensively.
星期日, 7月 24, 2011
星期日, 7月 17, 2011
REVIEW ASSESSMENT: TEST 3 TOPIC 3
REVIEW ASSESSMENT: TEST 3 TOPIC 3
Question 1
Which of the following best describes a relational database? (5.2)
Question 1 answers
A. A relational database uses a single file to store data sequentially.
D. None of the above.
E. A and B and C.
Question 2
How many primary keys and how many foreign keys are required in a relational database? (5.3)
Question 2 answers
C. None, as primary keys and foreign keys are not always required.
D. None of the above.
Question 3
Which statement below best describes a Decentralized Administration Policy? (5.4)
Question 3 answers
A. A small number of Administration users may grant and revoke access rights.
B. The owner (creator) of any table reserves all rights to grant and revoke access rights to each table that he or she has created.
E. All of the above
Question 4
Which statement below best describes an inference threat to a RDBMS? (5.6)
Question 4 answers
A. An inference threat arises when an unathorised person has gained access to a database.
Question 5
Which statement below best describes perturbation? (5.8)
Question 5 answers
A. Provides answers to all queries, but only to authorised users.
D. Only provides answers to queries that are not classified as secret.
Question 6
Which statement below best identifies the disadvantages of database encryption? (5.9)
Question 6 answers
A. Key management
B. Insecurity
C. Inflexibility
D. Vulnerabilities
E. Both A and B
H. Both C and D
Question 1
Which of the following best describes a relational database? (5.2)
Question 1 answers
A. A relational database uses a single file to store data sequentially.
B. A relational database is a collection of tables (also called relations).
C. A relational database organises its data in a tree-like structure.D. None of the above.
E. A and B and C.
Question 2
How many primary keys and how many foreign keys are required in a relational database? (5.3)
Question 2 answers
A. One primary key and zero or more foreign keys.
B. Every table must have one primary key and one foreign key.C. None, as primary keys and foreign keys are not always required.
D. None of the above.
Question 3
Which statement below best describes a Decentralized Administration Policy? (5.4)
Question 3 answers
A. A small number of Administration users may grant and revoke access rights.
B. The owner (creator) of any table reserves all rights to grant and revoke access rights to each table that he or she has created.
C. In addition to granting and revoking access rights to a table, the owner of a table may also grant and revoke authorisation to other users, allowing them to grant and revoke access rights to the table.
D. There needs to be at least one Administration person in each organisational unit of a company who can grant and revoke access rights to any specified table.E. All of the above
Question 4
Which statement below best describes an inference threat to a RDBMS? (5.6)
Question 4 answers
A. An inference threat arises when an unathorised person has gained access to a database.
B. An inference threat arises when the database administrator allows remote connections to the database server.
C. An inference threat arises when the database table structure is known to be poorly designed.D. An inference threat arises when the combination of a number of data items can be used to infer data of a higher sensitivity.
Question 5
Which statement below best describes perturbation? (5.8)
Question 5 answers
A. Provides answers to all queries, but only to authorised users.
B. Provides answers to all queries, but the answers may be approximate.
C. Provides answers to all queries, but the user identification of the querry is logged.D. Only provides answers to queries that are not classified as secret.
Question 6
Which statement below best identifies the disadvantages of database encryption? (5.9)
Question 6 answers
A. Key management
B. Insecurity
C. Inflexibility
D. Vulnerabilities
E. Both A and B
F. Both A and C
G. Both B and CH. Both C and D
星期日, 7月 10, 2011
Essay - Let's put a halt to capital punishment
Capital punishment, also known as death penalty or execution, is the most extreme sentence which can be devised in about 59 countries including China , Japan and the United States of America nowadays, according to Amnesty International’s figures in 2008. While more and more people actually come to realize problems of practicing capital punishment, yet, supporters insist on claiming that it is the most effective way to deter people from committing crimes. They continue to think that capital punishment is the only proportionate compensation for the victims whereas life imprisonment will solely cause a high cost which is ultimately paid by our hard-working and observant taxpayers unfairly. At first glance, their claims may seem reasonable and unassailable. However, you will probably find the flaws when you examine closer.
First and foremost, capital punishment may actually be practiced to kill people who have not committed any crimes mistakenly or deliberately. For instance, with the help of advanced technology such as DNA investigation, 23 people executed in the United States of America in the 20th century have actually been found guiltless. Doubtless, there is absolutely no way that can compensate these innocent people who were killed only because of wrong judgment. Yet, this kind of tragedies actually happens in most, if not all, of the other countries across the globe exercising capital punishment. In China , for example, a man called Tan Hang Sin was convicted to have killed his own wife and executed 16 years ago. Surprisingly, his wife was found to be still alive later. How ridiculous it is! Capital punishment is initially established to help uphold justice, protect people and penalize criminals. Ironically, it is now practiced to kill sinless people and just let criminals go free! How many harmless people should actually sacrifice before countries exercising capital punishment finally wake up? Worse still, capital punishment is sometimes utilized by dictators or dictatorial governments to extinguish their opponents deliberately. North Korean former president, Kam Tai Chung, was once accused of betraying North Korea and sentenced to capital punishment. However, the underlying reason why he was sentenced to capital punishment was that he was the leader of an opposition party at that time. It is undeniable that such kind of abuse of capital punishment still really exists in some countries around the world. Capital punishment actually becomes a form of witch hunt.
Aside from the tragedies which may be caused by capital punishment, legal sanctions should also in no way be regarded as a means for victims or their family members to take revenge on criminals. Honestly, when people get offended, it is common and normal for people to firstly think of taking revenge. “An eye for an eye and a tooth for a tooth” seems likely to be the first sentence springs up in our mind. Nevertheless, it is also true that we should all know and be reminded that taking revenge is useless and meaningless. Victims can never be brought back to life even when the criminals are killed. However, if the criminals are executed, they will surely lose a precious chance to turn a new leaf and more families will lose their family members forever and ever. There is a Chinese saying that “Do unto others as you would be done by”. When you have lost your beloved family members and you know the pain of this, you should never support capital punishment to cause others to suffer. After all, “an eye for an eye only ends up making the whole world blind”.
Apart from uselessness and meaninglessness of capital punishment, ethical problems should also be considered thoroughly. As a matter of fact, no-one in the world should be allowed to end any others’ lives for any reasons. Isn’t it nonsensical that we claim that we respect human life but we do not respect criminals’ lives at all? Isn’t it absurd that we claim that killing is wrong but we keep on killing criminals at the same time? I am sure that no-one will deny that life is precious. I find it especially preposterous to say that we should support capital punishment because many prisons are over-crowded and under-funded now and life sentence will cause a huge burden for our taxpayers. Not to say that prisoners can actually carry out some kinds of social services in jail to keep themselves productive, should a human life be anyway weighted like this? No way! How can we support to kill someone because he or she will become a burden of our society? It is really totally non-sense. Besides, Studies in the United States of America show that capital cases actually cost between $1 million and $7 million from arrest to execution. Nevertheless, life sentence cases only costs about $500,000, which is only half of the cost of capital cases. There is actually no more ridiculous excuse for us to support capital punishment.
In conclusion, capital punishment is actually a bane in disguise. Although it may seems that capital punishment can deter people from committing crimes, it is also capital punishment that causes more and more tragedies to make more and more people killed “legally”. Besides, acceptance of capital punishment definitely implies that taking revenge is a decent thing to do whereas it is definitely not. We should, thus, immediately stop this kind of wrong message from being passed on to the public and to our next generation. Another thing that we should immediately make clear is that life is doubtlessly invaluable and that criminals’ lives are also doubtlessly invaluable. No-one should be allowed to take away any others’ lives and high costs should not be a reason to support capital punishment. Therefore, it is my firm belief that capital punishment should be abolished at once under all circumstances and it is high time for all countries in the world to wake up to figure out what capital punishment really brings us. As the old saying goes, “to err is human”. We all have made some mistakes in our life and we all hope that others can forgive us and give us a second chance. So, why can’t we just also give all criminals a second chance?
星期二, 6月 14, 2011
Take Assessment: Test 4 Topic 4
Question 1
Which of the following is NOT identified as a intruder "class"? (6.1)
| | A. | |
| | B. | |
| | C. | |
| | D. | |
The following are identified by the text (page 177) as intruder classes;
1. Masquerader: An individual who is not authorized to use the computer and who
penetrates a system's access controls to exploit a legitimate user's account.
2. Misfeasor: A legitimate user who accesses data, programs, or resources for which
such access is not authorized, or who is authorized for such access but misuses his
or her privileges.
3. Clandestine user: An individual who seizes supervisory control
of the system and uses this control to evade auditing and access controls or to
suppress audit collection.
1. Masquerader: An individual who is not authorized to use the computer and who
penetrates a system's access controls to exploit a legitimate user's account.
2. Misfeasor: A legitimate user who accesses data, programs, or resources for which
such access is not authorized, or who is authorized for such access but misuses his
or her privileges.
3. Clandestine user: An individual who seizes supervisory control
of the system and uses this control to evade auditing and access controls or to
suppress audit collection.
Question 2
Which of the following is NOT a desirable characteristics of an IDS? (6.5)
| | A. | |
| | B. | |
| | C. | |
| | D. | |
| | E. | |
| | F. | |
These are desirable characteristics (specified in textbook, p 183) of an IDS;
•Run continually with minimal human supervision.
•Be fault tolerant in the sense that it must be able to recover from system crashes
and reinitializations.
•Resist subversion. The IDS must be able to monitor itself and detect if it has been
modified by an attacker.
•Impose a minimal overhead on the system where it is running.
•Be able to be configured according to the security policies of the system that is
being monitored.
•Be able to adapt to changes in system and user behavior over time.
•Be able to scale to monitor a large number of hosts.
•Provide graceful degradation of service in the sense that if some components of
the IDS stop working for any reason, the rest of them should be affected as little as
possible.
•Allow dynamic reconfiguration; that is, the ability to reconfigure the IDS without
having to restart it.
•Run continually with minimal human supervision.
•Be fault tolerant in the sense that it must be able to recover from system crashes
and reinitializations.
•Resist subversion. The IDS must be able to monitor itself and detect if it has been
modified by an attacker.
•Impose a minimal overhead on the system where it is running.
•Be able to be configured according to the security policies of the system that is
being monitored.
•Be able to adapt to changes in system and user behavior over time.
•Be able to scale to monitor a large number of hosts.
•Provide graceful degradation of service in the sense that if some components of
the IDS stop working for any reason, the rest of them should be affected as little as
possible.
•Allow dynamic reconfiguration; that is, the ability to reconfigure the IDS without
having to restart it.
Question 3
Which of the following ARE useful for profile-based intrusion detection? (6.7)
| | A. | |
| | B. | |
| | C. | |
| | D. | |
| | E. | |
| | F. | |
All the following ARE useful for profile-based intrusion detection (see textbook page 186);
Counter: A nonnegative integer that may be incremented but not decremented until it is reset by management action. Typically, a count of certain event types is kept over a particular period of time.
Gauge: A nonnegative integer that may be incremented or decremented. Typically, a gauge is used to measure the current value of some entity.
Interval timer: The length of time between two related events.
Resource utilization: Quantity of resources consumed during a specified period.
Counter: A nonnegative integer that may be incremented but not decremented until it is reset by management action. Typically, a count of certain event types is kept over a particular period of time.
Gauge: A nonnegative integer that may be incremented or decremented. Typically, a gauge is used to measure the current value of some entity.
Interval timer: The length of time between two related events.
Resource utilization: Quantity of resources consumed during a specified period.
Question 4
Which of the following best describes the "operation" of a virus or worm? (7.3)
| | A. | |
| | B. | |
| | C. | |
| | D. | |
| | E. | |
| | F. | |
Typical phases (as described by the textbook on page 220) of operation are; a dormant phase, a propagation phase, a triggering phase, and an execution phase.
Question 5
Which of the following is NOT an effective worm countermeasure? (7.7)
| | A. | |
| | B. | |
| | C. | |
| | D. | |
| | E. | |
| | F. | |
| | G. | |
A "DNS base scanning worm detector" would likely fail to detect an IM worm outbreak, because an IM worm’s attack payload will most likely be forwarded through the IM server, using the target’s user ID instead of a target IP address (Yan, Xiao,& Eidenbenz, 2008 pg 2).
See page 236 of textbook for details on the following.
See page 236 of textbook for details on the following.
Signature-based worm scan filtering: This type of approach generates a worm
signature, which is then used to prevent worm scans from entering/leaving a
network/host. Typically, this approach involves identifying suspicious flows and
generating a worm signature. This approach is vulnerable to the use of
polymorphic worms: Either the detection software misses the worm or, if it is
sufficiently sophisticated to deal with polymorphic worms, the scheme may take a
long time to react. [NEWS05] is an example of this approach.
Filter-based worm containment: This approach is similar to class A but focuses on
worm content rather than a scan signature. The filter checks a message to
determine if it contains worm code. An example is Vigilante [COST05], which
relies on collaborative worm detection at end hosts. This approach can be quite
effective but requires efficient detection algorithms and rapid alert dissemination.
Payload-classification-based worm containment: These network-based
techniques examine packets to see if they contain a worm. Various anomaly
detection techniques can be used, but care is needed to avoid high levels of false
positives or negatives. An example of this approach is reported in [CHIN05],
which looks for exploit code in network flows. This approach does not generate
signatures based on byte patterns but rather looks for control and data flow
structures that suggest an exploit.
Threshold random walk (TRW) scan detection: TRW exploits randomness in
picking destinations to connect to as a way of detecting if a scanner is in operation
[JUNG04]. TRW is suitable for deployment in high-speed, low-cost network
devices. It is effective against the common behavior seen in worm scans.
Rate limiting: This class limits the rate of scanlike traffic from an infected host.
Various strategies can be used, including limiting the number of new machines a
host can connect to in a window of time, detecting a high connection failure rate,
and limiting the number of unique IP addresses a host can scan in a window of
time. [CHEN04] is an example. This class of countermeasures may introduce
longer delays for normal traffic. This class is also not suited for slow, stealthy
worms that spread slowly to avoid detection based on activity level.
Rate halting: This approach immediately blocks outgoing traffic when a threshold
is exceeded either in outgoing connection rate or diversity of connection attempts
[JHI07]. The approach must include measures to quickly unblock mistakenly
blocked hosts in a transparent way. Rate halting can integrate with a signature- or
filter-based approach so that once a signature or filter is generated, every blocked
host can be unblocked. Rate halting appears to offer a very effective
countermeasure. As with rate limiting, rate-halting techniques are not suitable for
slow, stealthy worms.
Yan, G., Xiao, Z. & Eidenbenz, S., 2008. Catching instant messaging worms with change-point detection techniques. In Proceedings of the 1st Usenix Workshop on Large-Scale Exploits and Emergent Threats. San Francisco, California: USENIX Association, pp. 1-10. Available at: http://portal.acm.org/citation.cfm?id=1387715 [Accessed March 14, 2010].
signature, which is then used to prevent worm scans from entering/leaving a
network/host. Typically, this approach involves identifying suspicious flows and
generating a worm signature. This approach is vulnerable to the use of
polymorphic worms: Either the detection software misses the worm or, if it is
sufficiently sophisticated to deal with polymorphic worms, the scheme may take a
long time to react. [NEWS05] is an example of this approach.
Filter-based worm containment: This approach is similar to class A but focuses on
worm content rather than a scan signature. The filter checks a message to
determine if it contains worm code. An example is Vigilante [COST05], which
relies on collaborative worm detection at end hosts. This approach can be quite
effective but requires efficient detection algorithms and rapid alert dissemination.
Payload-classification-based worm containment: These network-based
techniques examine packets to see if they contain a worm. Various anomaly
detection techniques can be used, but care is needed to avoid high levels of false
positives or negatives. An example of this approach is reported in [CHIN05],
which looks for exploit code in network flows. This approach does not generate
signatures based on byte patterns but rather looks for control and data flow
structures that suggest an exploit.
Threshold random walk (TRW) scan detection: TRW exploits randomness in
picking destinations to connect to as a way of detecting if a scanner is in operation
[JUNG04]. TRW is suitable for deployment in high-speed, low-cost network
devices. It is effective against the common behavior seen in worm scans.
Rate limiting: This class limits the rate of scanlike traffic from an infected host.
Various strategies can be used, including limiting the number of new machines a
host can connect to in a window of time, detecting a high connection failure rate,
and limiting the number of unique IP addresses a host can scan in a window of
time. [CHEN04] is an example. This class of countermeasures may introduce
longer delays for normal traffic. This class is also not suited for slow, stealthy
worms that spread slowly to avoid detection based on activity level.
Rate halting: This approach immediately blocks outgoing traffic when a threshold
is exceeded either in outgoing connection rate or diversity of connection attempts
[JHI07]. The approach must include measures to quickly unblock mistakenly
blocked hosts in a transparent way. Rate halting can integrate with a signature- or
filter-based approach so that once a signature or filter is generated, every blocked
host can be unblocked. Rate halting appears to offer a very effective
countermeasure. As with rate limiting, rate-halting techniques are not suitable for
slow, stealthy worms.
Yan, G., Xiao, Z. & Eidenbenz, S., 2008. Catching instant messaging worms with change-point detection techniques. In Proceedings of the 1st Usenix Workshop on Large-Scale Exploits and Emergent Threats. San Francisco, California: USENIX Association, pp. 1-10. Available at: http://portal.acm.org/citation.cfm?id=1387715 [Accessed March 14, 2010].
Question 6
Which of the following is NOT a typical USE of a BOT? (7.8)
| | A. | |
| | B. | |
| | C. | |
| | D. | |
| | E. | |
| | F. | |
| | G. | |
| | H. | |
See page 240 of the textbook for details.The following are uses for bots; Distributed Denial of Service (DDoS) attack, Spamming, an attacker is able to send massive amounts of bulk e-mail (spam), Keylogging, captures keystrokes on the infected machine, Spreading new malware, Botnets are used to spread new bots, Installing advertisement add-ons and browser helper objects (BHOs), Botnets are used to gain finanical advantages, Attacking IRC chat networks, Botnets are also used for attacks against internet relay channel (IRC) networks, and Manipulating online pols / games, since every bot will have a unique ip address, every vote will have the same crediability as a vote by a realp person.
星期六, 6月 11, 2011
COMPUTER CONTROL AUDITING AND SECURITY > TAKE ASSESSMENT: TEST 6 TOPIC 6
| ||||||||||||||||||||||
The direct threat is the damage caused by the fire itself. The indirect threats are from heat, release of toxic fumes, water damage from fire suppression, and smoke damage.
Prevention and mitigation measures for water threats must encompass the range of such threats. For plumbing leaks, the cost of relocating threatening lines is generally difficult to justify. With knowledge of the exact layout of water supply lines, measures can be taken to locate equipment sensibly. The location of all shutoff valves should be clearly visible or at least clearly documented, and responsible personnel should know the procedures to follow in case of emergency. To deal with both plumbing leaks and other sources of water, sensors are vital. Water sensors should be located on the floor of computer rooms, as well as under raised floors, and should cut off power automatically in the event of a flood.
| |||||||||||||
To deal with brief power interruptions, an uninterruptible power supply (UPS) should be employed for each piece of critical equipment. The UPS is a battery backup unit that can maintain power to processors, monitors, and other equipment for a period of minutes. UPS units can also function as surge protectors, power noise filters, and automatic shutdown devices when the battery runs low. For longer blackouts or brownouts, critical equipment should be connected to an emergency power source, such as a generator. For reliable service, a range of issues need to be addressed by management, including product selection, generator placement, personnel training, testing and maintenance schedules, and so forth.
| ||||||||||||||||
1. Improving employee behavior
2. Increasing the ability to hold employees accountable for their actions
3. Mitigating liability of the organization for an employee's behavior
4. Complying with regulations and contractual obligations
2. Increasing the ability to hold employees accountable for their actions
3. Mitigating liability of the organization for an employee's behavior
4. Complying with regulations and contractual obligations
| |||||||||||||
An organizational security policy is a formal statement of the rules by which people that are given access to an organization's technology and information assets must abide.
| |||||||||||||
1. Significant employee work time may be consumed in non-work-related activities, such as surfing the Web, playing games on the Web, shopping on the Web, chatting on the Web, and sending and reading personal e-mail.
2. Significant computer and communications resources may be consumed by such non-work-related activity, compromising the mission that the IS resources are designed to support.
3. Excessive and casual use of the Internet and e-mail unnecessarily increases the risk of introduction of malicious software into the organization's IS environment.
4. The non-work-related employee activity could result in harm to other organizations or individuals outside the organization, thus creating a liability for the organization.
5. E-mail and the Internet may be used as tools of harassment by one employee against another.
6. Inappropriate online conduct by an employee may damage the reputation of the organization.
訂閱:
文章 (Atom)