Posts

Showing posts with the label computer security

Computer Security book by Charles Chapter 1 Exercise Solutions

Image
1. Distinguish between vulnerability, threat, and control. In the above diagram, a man is standing near a wall with his finger placed inside a hole. There is water on left side of wall and a crack in a wall that you can see. For understanding the threat and vulnerability difference, we will understand it by the above diagram as a analogy.  By definition. Vulnerability is a weakness in the system ( loophole ) that might be exploited in the future to cause harm or loss.  Threat is a set of events, circumstances that may happen and potential to cause harm. Now, in the above diagram, If the water level rises, then the man may get wet, get harm either the water gets spilled out, overflows. So Water is the threat to Man. Now there is a weakness in the wall, i.e Crack is present, that some time it can diminish the entire wall, break the entire wall and thus it is a vulnerability.  To address this Harm, Threats, Vulnerabilities, We have Control or CounterMeasures.  Therefore...

Confidentiality - Integrity - Availability

Confidentiality Confidentiality means some things need protection against unauthorised access. It can be anything ranging from financial transactions to bank records to medical records, tax returns etc. But It varies from person to person. For example, A Student might scream out of the class saying "I got an A", so he is ok exposing his grades to all but other student might not choose to reveal. Other things like order of military food might not seem confidential, but an sudden increase in the order could be the sign of an military conflict or war.  Integrity Examples of Integrity failures are easy to find and too many. A number of years ago, Macro in a document added the word "not" after is in the statements after random instances. This might not appear integrity failure, but you can image the kind of havoc it can do if the word document consisted of Pentium computer chip details that produced an incorrect result due to the word "not" in a statement conta...

Threats in Computer Security

 In this Computer Security Article, we are going to discuss Threats, Assets, Value, Confidentiality, Integrity, Availability, Value, etc. In the previous articles, we had discussed all about computer security assets, value. We are not going to make this article boring, so lets discuss in a very general, easy to understand way. Harm or Attacks to the valuable assets can be seen in two perspectives or ways.  1. What bad things can happen to assets 2. Who or what can cause those bad things to happen. These two views enable us to determine how to protect assets, implement computer security. Let us think What bad things can happen, What makes your computer valuable to you. First, you use it for sending and receiving emails, searching web, writing and publishing papers, performing many other tasks like running business online, teaching online, you store and access private data, etc... and you expect the computer to be available for your use when you want. Without your computer, thes...

What is Computer Security

Image
In this blog, We are going to discuss  1. What is computer security in a basic sense 2. What are Assets 3. What are the goal of computer security 4. What are Threats Welcome back to another blog, in this blog i am going answer to basic questions related to Computer Security. What is Computer Security? Before answering this question, lets discuss about computers We encounter computers daily in countless situations where it is involved in moving money, controlling planes, radio, communication, monitoring health, Heating buildings, locking doors, playing music, regulate heart, tally votes, Health, finance,etc. Most of the time computers work well as they should but occasionally it does something horrible, weird that causes havoc everywhere because of an attack. Therefore Computer Security plays an very important role by not letting attackers compromise computers in any possible way. Computer Security is the protection of items that we value called Assets of computer system. There are ...

Early Days of Computer Security

As the Title suggests, Lets discuss the early days of Computer Security and by early days I mean from 1950's and 1960's. I have taken the reference from computer security book "Security in Computing " by "Charles Pfleeger" and two other authors. "Willis Ware" had written a brief overview about early days of computing which i am going to discuss it next. Lets go back in 1950's In 50's and 60's, there were mainly two conferences yearly in US named Joint Computer Conferences (JCC) later renamed to National Computer Conference (NCC) where Computer Technology Enthusiastic, Researchers, Scientists, Engineers visit Conference. Nowadays The Term "Computer Security" has got changed to "Information Systems Security". Due to wide spread of computers, Entire Computer Security Industry moved from Private Defence classified Interest to Public View. Three People namely "Robert Patrick, John Haverty, Willis Ware" observed ...