Skip to main content

INTRODUCTION TO ETHICAL HACKING


 Technology Brief

Information Security Overview

Information security ensures the confidentiality, integrity, & availability.

An organization without security policies & appropriate security rules are at great risk, & the confidential information & data related to that organization are not secure in the absence of these security policies.

An organization along well-defined security policies & procedures helps in protecting the assets of that organization from unauthorized access & disclosures.

Essential Terminologies

HACK VALUE – This is a value that denotes attractiveness, interest or something that is worthy.

ZERO-DAY ATTACK – This refers to threats & vulnerabilities that can exploit the victim before the developer identify or address & release patch for that vulnerability.

VULNERABILITY – IT refers to a week point, loophole or a cause in any system, software, or network which can be helpful & utilized by the attackers to go through it.

DAISY CHAINING – This is a sequential (logical order) process of several hacking or attacking attempts to gain access to network or systems, one after another, using the same information & the information obtained from the previous attempt.

EXPLOIT – This is a breach of security of a system through vulnerability, zero-day attack or any other hacking techniques.

DOXING – This refers to publishing information or a set of information associated with an individual.

PAYLOAD – In information security, payload is a section or part of a malicious & exploited code that causes potentially harmful activities & actions such as exploit, opening back door, & hijacking.

BOT – These are software that is used to control the target remotely to execute predefined tasks.

Elements of Information Security

CONFIDENTIALITY

Confidentiality means that only authorized user ca work with & see our infrastructure’s digital resources.

It also means that unauthorized user should not have any access to the data.

They are 2 to 3 types of data:

  1. Data at rest which can be encrypted at the storage level.
  2. Data in motion which can also be encrypted before transmission.
  3.  Data in processing which can be protected with access control.

INTEGRITY

Integrity means only authorized parties can modify data, systems, or network.

AVAILABILITY

Data & systems must be available to the authorized users.

If authorized users cannot get the data due to general network failure or denial-of-service (DOS) attack, then that is a problem as long as the business is concerned.

AUTHENTICITY

Authenticity is the process which identifies the user or device to grant privileges, access, & certain rules & policies.

The process of authentication through the combined function of identities & passwords can achieve authenticity.

NON-REPUDIATION

Non-repudiation is one of the Information Assurance (AS) pillars which guarantee the information transmission & receiving between the sender & receiver via different techniques such as digital signature & encryption.

Comments

Popular posts from this blog

WHY BECOME A CISSP

  CISSP means Certified Information Systems Security Professional CISSP is an (ISC)2 Certification (ISC)2 means The International Information System Security Certification Consortium (ISC)2 said CISSP is  THE WORLD PREMIER CYBERSECURITY CERTIFICATION Jobs that Typically Use or Require CISSP are as follows: Chief Information Officer Chief Information Security Officer Director of Security IT Director/Manager Network Architect Security Analyst Security Architect Security Auditor Security Consultant Security Manager Security Systems Engineer  As the Internet continues to change the world, corporations and other organizations are desperate to identify and recruit talented and experienced security professionals. They do this to protect the resources on which they depend to run their businesses in other to remain competitive. Some of the main reasons for becoming a CISSP are as follows: You will b...

THE CISSP EXAM

The CISSP exam is described as being “AN INCH DEEP & A MILE WIDE” The CISSP exam covers 8 security domains making up the CISSP CBK (Common Body of Knowledge). The CISSP exam evaluate expertise across 8 security domains. Domain means topics you need to master based on your professional experience & education. Passing the exam proves you have the advanced knowledge & technical skills to effectively design, implement & manage a best-in-class cybersecurity program. The CISSP exam questions are not very detailed & do not require you to be an expert in every subject, but the questions require you to be familiar with many different security subjects. The CISSP exam comes in 2 versions depending on the language in which the test is written. As at 18th December 2017, the CISSP exam comes in 2 different versions. The English version is now Computer Adaptive Test (CAT). The number of questions you are asked ranges from 100 to 150. Do not forget that 25 question...

BEFORE TAKING THE CISSP EXAM

  WHO SHOULD BECOME A CISSP? CISSP candidates must have a minimum of 5 years of cumulative paid full-time professional security experience in 2 or more of the 8 CISSP domains. The 8 domains are as follows: Domain One: Security & Risk Management Domain Two: Asset Security Domain Three: Security Architecture & Engineering Domain Four: Communication & Network Security Domain Five: Identity & Access Management Domain Six: Security Assessment & Testing Domain Seven: Security Operations Domain Eight: Software Development Security Enable Ginger Cannot connect to Ginger Check your internet connection or reload the browser Disable in this text field Edit Edit in Ginger Edit in Ginger ×