Thursday, 15 May 2014

The Importance of IT Security

The Importance of IT Security

 Due to advances in technology, communication and the university's decentralized nature, it is increasingly difficult to ensure that this information is provided in such a way that its integrity is ensured.
 To protect University integrity
To protect University assets Assets are not just physical computing hardware, but include the information stored on computers and networks. Years of critical research data, personal information and sensitive documents can be lost or destroyed without a plan for securing them and a good backup and recovery plan.
How many research grants would be awarded to the university if data were compromised on a routine basis? How many distinguished professors would seek University employment if the computing environment was unreliable? Developing and maintaining effective security measures enables trust and stability of a great university.
To comply with regulatory requirements and fiduciary responsibility
University leadership has responsibility to ensure the safety and soundness of its organizations. The protection and management of of non-public personal information (NP PI) must comply with a variety of state, federal and university laws. Accurate and reliable reporting according to these laws has an impact on the academic and financial health of the university. Failure to comply with these guidelines can have direct effects on the University’s ability to do business and continue its mission.
To improve efficiency
Good security practices can be a force multiplier. By integrating security tasks into job descriptions; installing and updating anti-virus software to local desktops and servers; backing-up important files and storing them in a secure offsite location; insuring processes and procedures are in place; and educating the user population about responsibilities pit falls and time lost by system compromises can be avoided. Although no system connected to the network is 100% secure, your ability to rapidly recover from a compromise can make the difference in the department’s productivity.
Information technology and computing pervades every aspect of daily life. Collectively, we use technology to teach and learn, to communicate and collaborate, to manage operations and finances, to access and deliver information and services. However, in this age of dynamic technological change, universities are prime targets for compromise. Information security experts acknowledge the importance of policies in helping to mitigate liability, reduce costs, cope with regulations and assure proper audit and control procedures for securing our critical infrastructure and assets. Confidentiality, integrity and availability are the three predominant principles of information protection. Compromising these principles leaves systems in jeopardy.
Expected Standards
Rutgers University’s organizational structure is decentralized and departments are responsible for many administrative operations. Expectations:
  • Be responsible and accountable.
  • Be good stewards of university assets, revenues, and resources.
  • Conduct their work with integrity and high ethical values.
  • Exercise sound judgment (Standards for University Operations)
Best Practices
A department security posture and plan should be established and policies created to address security concerns and other IT issues such as:
  • Remote access
  • Equipment/software removal
  • Acceptable software
  • File-sharing
  • System/file access
  • Document and log retention
  • Back-up of critical information/systems
  • Virus protection
  • Competent primary and backup personnel
  • Clear and complete job descriptions
  • Proper operating procedures
  • Training
  • Segregation of duties
  • Proper design of controls
  • Disaster planning and recovery
IT planning should include roles & responsibilities which will support the use of information technology.
Provide staff access to only necessary accounts and non-public personal information (NPPI) discuss roles and responsibilities. Appoint staff to back-up these individuals.
Identify a departmental Systems Administrator and/or Unit Computing Specialist to accept responsibility (under your direction) for the care and maintenance of your systems. Discuss your department's security posture, policies, roles and responsibilities. Work with through the Security Q & A Project with your technical staff to understand and direct the basics of IT security.

Types of attack:

Types of attack:

Classes of attack might include passive monitoring of communications, active network attacks, close-in attacks, exploitation by insiders, and attacks through the service provider. Information systems and networks offer attractive targets and should be resistant to attack from the full range of threat agents, from hackers to nation-states. A system must be able to limit damage and recover rapidly when attacks occur. 
There are five types of attack:

Passive Attack

passive attack monitors unencrypted traffic and looks for clear-text passwords and sensitive information that can be used in other types of attacks. Passive attacks include traffic analysis, monitoring of unprotected communications, decrypting weakly encrypted traffic, and capturing authentication information such as passwords. Passive interception of network operations enables adversaries to see upcoming actions. Passive attacks result in the disclosure of information or data files to an attacker without the consent or knowledge of the user.

Active Attack

In an active attack, the attacker tries to bypass or break into secured systems. This can be done through stealth, viruses, worms, or Trojan horses. Active attacks include attempts to circumvent or break protection features, to introduce malicious code, and to steal or modify information. These attacks are mounted against a network backbone, exploit information in transit, electronically penetrate an enclave, or attack an authorized remote user during an attempt to connect to an enclave. Active attacks result in the disclosure or dissemination of data files, DoS, or modification of data.

Distributed Attack

distributed attack requires that the adversary introduce code, such as a Trojan horse or back-door program, to a “trusted” component or software that will later be distributed to many other companies and users Distribution attacks focus on the malicious modification of hardware or software at the factory or during distribution. These attacks introduce malicious code such as a back door to a product to gain unauthorized access to information or to a system function at a later date.

Insider Attack

An insider attack involves someone from the inside, such as a disgruntled employee, attacking the network Insider attacks can be malicious or no malicious. Malicious insiders intentionally eavesdrop, steal, or damage information; use information in a fraudulent manner; or deny access to other authorized users. No malicious attacks typically result from carelessness, lack of knowledge, or intentional circumvention of security for such reasons as performing a task

Classes of attack might include passive monitoring of communications, active network attacks, close-in attacks, exploitation by insiders, and attacks through the service provider. Information systems and networks offer attractive targets and should be resistant to attack from the full range of threat agents, from hackers to nation-states. A system must be able to limit damage and recover rapidly when attacks occur. 
There are five types of attack:

Passive Attack

passive attack monitors unencrypted traffic and looks for clear-text passwords and sensitive information that can be used in other types of attacks. Passive attacks include traffic analysis, monitoring of unprotected communications, decrypting weakly encrypted traffic, and capturing authentication information such as passwords. Passive interception of network operations enables adversaries to see upcoming actions. Passive attacks result in the disclosure of information or data files to an attacker without the consent or knowledge of the user.

Active Attack

In an active attack, the attacker tries to bypass or break into secured systems. This can be done through stealth, viruses, worms, or Trojan horses. Active attacks include attempts to circumvent or break protection features, to introduce malicious code, and to steal or modify information. These attacks are mounted against a network backbone, exploit information in transit, electronically penetrate an enclave, or attack an authorized remote user during an attempt to connect to an enclave. Active attacks result in the disclosure or dissemination of data files, DoS, or modification of data.

Distributed Attack

distributed attack requires that the adversary introduce code, such as a Trojan horse or back-door program, to a “trusted” component or software that will later be distributed to many other companies and users Distribution attacks focus on the malicious modification of hardware or software at the factory or during distribution. These attacks introduce malicious code such as a back door to a product to gain unauthorized access to information or to a system function at a later date.

Insider Attack

An insider attack involves someone from the inside, such as a disgruntled employee, attacking the network Insider attacks can be malicious or no malicious. Malicious insiders intentionally eavesdrop, steal, or damage information; use information in a fraudulent manner; or deny access to other authorized users. No malicious attacks typically result from carelessness, lack of knowledge, or intentional circumvention of security for such reasons as performing a task

what is passive attack

passive attack on a cryptosystem is one in which the cryptanalyst cannot interact with any of the parties involved, attempting to break the system solely based upon observed data (i.e. the ciphertext). This can also include known plaintext attacks where both the plaintext and its corresponding ciphertext are known.While most classical ciphers are vulnerable to this form of attack, most modern ciphers are designed to prevent this type of attack above all others.


                                                                          A passive attack, in computing security, is an attack characterized by the attacker listening in on communication. In such an attack, the intruder/hacker does not attempt to break into the system or otherwise change data.

Techopedia explains Passive Attack

Passive attacks basically mean that the attacker is eavesdropping. This is in comparison to an active attack, where the intruder attemps to break into the system. Even though a passive attack sounds less harmful, the damage in the end can be just as severe if the right type of information is obtained.

what is Cryptography

*  the art of writing or solving codes.

  1. *The art of protecting information by transforming it (encrypting it) into an unreadable format, called cipher text. Only those who possess a secret key can decipher (or decrypt) the message intoplain text. Encrypted messages can sometimes be broken by cryptanalysis, also called codebreaking, although modern cryptography techniques are virtually unbreakable.
  2.  More generally, it is about constructing and analyzingprotocols that overcome the influence of adversaries[3]and which are related to various aspects in information security such as data confidentialitydata integrity,authentication, and non-repudiation.[4] Modern cryptography intersects the disciplines of mathematics,computer science, and electrical engineering. Applications of cryptography include ATM cards,computer passwords, and electronic commerce.

Wednesday, 14 May 2014

what is Sessions

*    A PHP session variable is used to store information about, or change settings for a user session. Session variables hold information about one single user, and are available to all pages in one application.
*  In computer science, in particular networking, a session is a semi-permanent interactive information interchange, also known as a dialogue, a conversation or a meeting, between two or more communicating devices, or between a computer and user (see Login session). A session is set up or established at a certain point in time, and then torn down at some later point. An established communication session may involve more than one message in each direction. A session is typically, but not always, stateful, meaning that at least one of the communicating parts needs to save information about the session history in order to be able to communicate, as opposed to statelesscommunication, where the communication consists of independent requests with responses.

Communication sessions may be implemented as part of protocols and services at the application layer, at thesession layer or at the transport layer in the OSI model.
  • Application layer examples:
    • HTTP sessions, which allow associating information with individual visitors
    • telnet remote login session
  • Session layer example:
  • Transport layer example:
    • TCP session, which is synonymous to a TCP virtual circuit, a TCP connection, or an established TCPsocket.
    • Session management

    • In human–computer interactionsession management is the process of keeping track of a user's activity across sessions of interaction with the computer system.
      Typical session management tasks in a desktop environment include keeping track of which applications are open and which documents each application has opened, so that the same state can be restored when the user logs out and logs in later. For a website, session management might involve requiring the user to re-login if the session has expired (i.e., a certain time limit has passed without user activity). It is also used to store information on the server-side between HTTP requests.

      Desktop session management

      A desktop session manager is a program that can save and restore desktop sessions. A desktop session is all the windows currently running and their current content. Session management on Linux-based systems is provided by X session manager. On Microsoft Windows systems, no session manager is included in the system, but session management can be provided by third-party applications like twinsplay.

      Browser session management

      Session management is particularly useful in a web browser where a user can save all open pages and settings and restore them at a later date. To help recover from a system or application crash, pages and settings can also be restored on next run. Google ChromeMozilla FirefoxInternet ExplorerOmniWeb and Opera are examples of web browsers that support session management. Session management is often managed through the application ofcookies.
    • PHP Session VariablesWhen you are working with an application, you open it, do some changes and then you close it. This is much like a Session. The computer knows who you are. It knows when you start the application and when you end. But on the internet there is one problem: the web server does not know who you are and what you do because the HTTP address doesn't maintain state.

      A PHP session solves this problem by allowing you to store user information on the server for later use (i.e. username, shopping items, etc). However, session information is temporary and will be deleted after the user has left the website. If you need a permanent storage you may want to store the data in a database.
      Sessions work by creating a unique id (UID) for each visitor and store variables based on this UID. The UID is either stored in a cookie or is propagated in the URL.
    • <?php session_start(); ?>

      <html>
      <body>

      </body>
      </html>
    • Storing a Session Variable

      The correct way to store and retrieve session variables is to use the PHP $_SESSION variable:
      <?php
      session_start();
      // store session data
      $_SESSION['views']=1;
      ?>

      <html>
      <body>

      <?php
      //retrieve session data
      echo "Pageviews=". $_SESSION['views'];
      ?>

      </body></html>

Multidimensional Arrays

Earlier in this tutorial, we have described arrays that are a single list of key/value pairs.
However, sometimes you want to store values with more than one key.
This can be stored in multidimensional arrays.
Now the two-dimensional $cars array contains four arrays, and it has two indices: row and column.
To get access to the elements of the $cars array we must point to the two indices (row and colum
We can store the data from the table above in a two-dimensional array, like this:
$cars = array
  (
  array("Volvo",22,18),
  array("BMW",15,13),
  array("Saab",5,2),
  array("Land Rover",17,15)
  );


We can also put a For loop inside another For loop to get the elements of the $cars array (we still have to point to the two indices):

Example

<?php
for ($row = 0; $row < 4; $row++) {
  echo "<p><b>Row number $row</b></p>";
  echo "<ul>";
  for ($col = 0; $col < 3; $col++) {
    echo "<li>".$cars[$row][$col]."</li>";
  }
  echo "</ul>";
}
?>

Friday, 14 February 2014

What is a Cookie?

A cookie is often used to identify a user. A cookie is a small file that the server embeds on the user's computer. Each time the same computer requests a page with a browser, it will send the cookie too. With PHP, you can both create and retrieve cookie values.

How to Create a Cookie?

The setcookie() function is used to set a cookie.
Note: The setcookie() function must appear BEFORE the <html> tag.

Syntax

setcookie(name, value, expire, path, domain);

Example

<?php
setcookie("user", "Alex Porter", time()+3600);
?>

How to Retrieve a Cookie Value?

The PHP $_COOKIE variable is used to retrieve a cookie value.

In the example below, we retrieve the value of the cookie named "user" and display it on a page:
<?php
// Print a cookie
echo $_COOKIE["user"];

// A way to view all cookies
print_r($_COOKIE);
?>

How to Delete a Cookie?

When deleting a cookie you should assure that the expiration date is in the past.
Delete example:
<?php
// set the expiration date to one hour ago
setcookie("user", "", time()-3600);
?>                                                        
by sanseep