Sunday, 18 May 2014

. Explain the four classifications of crime issues

Ethical issues can be classified into:
1. Privacy issues: The privacy issues deal with the collection, storage, and dissemination of information about individuals. For example:

  • What information about oneself should an employer reveal to others?
  • What kind of surveillance can an employer use on its employees?
  • What things can people keep to themselves and not be forced to reveal to others?
  • What information about individuals should be kept in databases, and how secure is the information there?
2. Accuracy issues: The accuracy issues deal with authenticity, fidelity, and accuracy of information collected and procured. The questions that need to be addressed in accuracy issues include:
Who is responsible for the accuracy, fidelity, and accuracy of information collected?


  • How can we ensure that information will be processed properly and presented accurately to the users?
  • How can we ensure that errors in databases, data transmissions, and data processing are accidental and not intentional?
    • Who is to be held responsible for errors in information, and how should the injured party be compensated?
    3. Property issues: The property issues deal with ownership and value of information (intellectual property). Examples of issues that need to be addressed as property issues are:

    • Who owns the information?
    • What are the just and fair prices for its exchange?
    • How should one handle software piracy?
    • Under what circumstances can one use proprietary databases?
    • Can corporate computers be used for private purposes?
    • How should experts who contribute their knowledge to create expert systems be compensated?
    • How should access to information channels be allocated?
    4. Accessibility issues: The accessibility issues concern with the right to access information and payment towards the same. These issues include:

    • Who is allowed to access information?
    • How much should be charged for permitting accessibility to information?
    • How can accessibility be provided for employees with disability?
    • Who will be provided with the necessary equipments for accessing information?
    There is a need to address these four types of issues so that the computer and information technology business operates in an ethical domain. We must ensure that information
      
    Question=3.Discuss the distinct features of the Internet.

    Answer- 
                      The Internet has three distinct features:

    Global Scope: The Internet has a global reach. Internet technology has much broader scope and access than conventional modes of communications and data retrieval. With little effort, a user can reach hundreds and thousands of individuals around the globe. The ability to reach many people quickly and easily is not exactly new or unique compared to radio or television communication. But the significant difference between the Internet and television and radio is that in the case of radio and television, communication is in most cases one way whereas in the case of Internet it is interactive. It is this interactivity, which is the unique
    • characteristic of the Internet. Not just interactivity, customizability, easy usability, and accessibility are also distinct features of Internet.
    • Anonymity: The second important feature of the Internet is that it provides a certain kind of anonymity. On the Internet, individuals have the possibility of creating a different profile, ensuring that information about them cannot be traced while in communication with others on the Internet. It is a silent feature of Internet communication and people can deliberately avoid seeing or hearing one another directly. Anonymity makes accountability for one’s action difficult to achieve and tends to diminish trust in the information that is being exchanged. The feature of anonymity has also facilitated the development of “virtual information”.
    The open and anonymous nature of communications on the web, has led to the development of software with stealth to gather information intelligently. An inference is made from information gathered without our knowledge or consent, which is termed as “virtual information”. This type of information adds information to a person’s profile and tends to redefine a person’s digital persona. This is an invasion of one’s “virtual privacy”. 
    Reproducibility: The third feature is not just a feature of the Internet, but of information technology in general. Electronic information exists in the form that makes it easy to copy without any loss of originality or value in the process of reproduction. Copied data or software is perfectly usable. Copied data or software leaves no evidence behind and the creator/owner of the data or software could remain unaware of their work being copied. Reproducibility facilitates anonymity 

Define computer crime

The term computer ethics was coined in the mid 1970s by Walter Manor to refer to that field of applied professional ethics dealing with ethical problems aggravated, transformed, or created by human technology. Computer ethics is the analysis of the nature and social impact of computer technology, and the formulation and justification of the policies for the ethical use of such technology. Computer ethics examine the ethical issues surrounding computer usage and the connection between ethics and technology. It includes consideration of both personal and social policies for ethical use of computer technology. The goal is to understand the impact of computing technology upon human values, minimize the damage that technology can do to human values, and to identify ways to use computer technology to advance human values

Friday, 16 May 2014

How we use cookies

Cookies do not contain any information that personally identifies you, but personal information that we store about you may be linked, by us, to the information stored in and obtained from cookies. The cookies used on the website include those which are strictly necessary cookies for access and navigation, cookies that track usage (performance cookies), remember your choices (functionality cookies), and cookies that provide you with targeted content or advertising
We may use the information we obtain from your use of our cookies for the following purposes:
  1. to recognise your computer when you visit the website
  2. to track you as you navigate the website, and to enable the use of any e-commerce facilities
  3. to improve the website’s usability
  4. to analyse the use of the website
  5. in the administration of the website
  6. to personalise the website for you, including targeting advertisements which may be of particular interest to you.

Thursday, 15 May 2014

full form of tcp and ip

Transmission Control Protocol-Internet Protocol

what is active attack

In computer and computer networks an attack is any attempt to destroy, expose, alter, disable, steal or gain unauthorized access to or make unauthorized use of an asset.
                                                     An active attack, in computing security, is an attack characterized by the attacker attempting to break into the system. During an active attack, the intruder will introduce data into the system as well as potentially change data within the system.

The Importance of IT Security

The Importance of IT Security

 Due to advances in technology, communication and the university's decentralized nature, it is increasingly difficult to ensure that this information is provided in such a way that its integrity is ensured.
 To protect University integrity
To protect University assets Assets are not just physical computing hardware, but include the information stored on computers and networks. Years of critical research data, personal information and sensitive documents can be lost or destroyed without a plan for securing them and a good backup and recovery plan.
How many research grants would be awarded to the university if data were compromised on a routine basis? How many distinguished professors would seek University employment if the computing environment was unreliable? Developing and maintaining effective security measures enables trust and stability of a great university.
To comply with regulatory requirements and fiduciary responsibility
University leadership has responsibility to ensure the safety and soundness of its organizations. The protection and management of of non-public personal information (NP PI) must comply with a variety of state, federal and university laws. Accurate and reliable reporting according to these laws has an impact on the academic and financial health of the university. Failure to comply with these guidelines can have direct effects on the University’s ability to do business and continue its mission.
To improve efficiency
Good security practices can be a force multiplier. By integrating security tasks into job descriptions; installing and updating anti-virus software to local desktops and servers; backing-up important files and storing them in a secure offsite location; insuring processes and procedures are in place; and educating the user population about responsibilities pit falls and time lost by system compromises can be avoided. Although no system connected to the network is 100% secure, your ability to rapidly recover from a compromise can make the difference in the department’s productivity.
Information technology and computing pervades every aspect of daily life. Collectively, we use technology to teach and learn, to communicate and collaborate, to manage operations and finances, to access and deliver information and services. However, in this age of dynamic technological change, universities are prime targets for compromise. Information security experts acknowledge the importance of policies in helping to mitigate liability, reduce costs, cope with regulations and assure proper audit and control procedures for securing our critical infrastructure and assets. Confidentiality, integrity and availability are the three predominant principles of information protection. Compromising these principles leaves systems in jeopardy.
Expected Standards
Rutgers University’s organizational structure is decentralized and departments are responsible for many administrative operations. Expectations:
  • Be responsible and accountable.
  • Be good stewards of university assets, revenues, and resources.
  • Conduct their work with integrity and high ethical values.
  • Exercise sound judgment (Standards for University Operations)
Best Practices
A department security posture and plan should be established and policies created to address security concerns and other IT issues such as:
  • Remote access
  • Equipment/software removal
  • Acceptable software
  • File-sharing
  • System/file access
  • Document and log retention
  • Back-up of critical information/systems
  • Virus protection
  • Competent primary and backup personnel
  • Clear and complete job descriptions
  • Proper operating procedures
  • Training
  • Segregation of duties
  • Proper design of controls
  • Disaster planning and recovery
IT planning should include roles & responsibilities which will support the use of information technology.
Provide staff access to only necessary accounts and non-public personal information (NPPI) discuss roles and responsibilities. Appoint staff to back-up these individuals.
Identify a departmental Systems Administrator and/or Unit Computing Specialist to accept responsibility (under your direction) for the care and maintenance of your systems. Discuss your department's security posture, policies, roles and responsibilities. Work with through the Security Q & A Project with your technical staff to understand and direct the basics of IT security.

Types of attack:

Types of attack:

Classes of attack might include passive monitoring of communications, active network attacks, close-in attacks, exploitation by insiders, and attacks through the service provider. Information systems and networks offer attractive targets and should be resistant to attack from the full range of threat agents, from hackers to nation-states. A system must be able to limit damage and recover rapidly when attacks occur. 
There are five types of attack:

Passive Attack

A passive attack monitors unencrypted traffic and looks for clear-text passwords and sensitive information that can be used in other types of attacks. Passive attacks include traffic analysis, monitoring of unprotected communications, decrypting weakly encrypted traffic, and capturing authentication information such as passwords. Passive interception of network operations enables adversaries to see upcoming actions. Passive attacks result in the disclosure of information or data files to an attacker without the consent or knowledge of the user.

Active Attack

In an active attack, the attacker tries to bypass or break into secured systems. This can be done through stealth, viruses, worms, or Trojan horses. Active attacks include attempts to circumvent or break protection features, to introduce malicious code, and to steal or modify information. These attacks are mounted against a network backbone, exploit information in transit, electronically penetrate an enclave, or attack an authorized remote user during an attempt to connect to an enclave. Active attacks result in the disclosure or dissemination of data files, DoS, or modification of data.

Distributed Attack

A distributed attack requires that the adversary introduce code, such as a Trojan horse or back-door program, to a “trusted” component or software that will later be distributed to many other companies and users Distribution attacks focus on the malicious modification of hardware or software at the factory or during distribution. These attacks introduce malicious code such as a back door to a product to gain unauthorized access to information or to a system function at a later date.

Insider Attack

An insider attack involves someone from the inside, such as a disgruntled employee, attacking the network Insider attacks can be malicious or no malicious. Malicious insiders intentionally eavesdrop, steal, or damage information; use information in a fraudulent manner; or deny access to other authorized users. No malicious attacks typically result from carelessness, lack of knowledge, or intentional circumvention of security for such reasons as performing a task

Classes of attack might include passive monitoring of communications, active network attacks, close-in attacks, exploitation by insiders, and attacks through the service provider. Information systems and networks offer attractive targets and should be resistant to attack from the full range of threat agents, from hackers to nation-states. A system must be able to limit damage and recover rapidly when attacks occur. 
There are five types of attack:

Passive Attack

A passive attack monitors unencrypted traffic and looks for clear-text passwords and sensitive information that can be used in other types of attacks. Passive attacks include traffic analysis, monitoring of unprotected communications, decrypting weakly encrypted traffic, and capturing authentication information such as passwords. Passive interception of network operations enables adversaries to see upcoming actions. Passive attacks result in the disclosure of information or data files to an attacker without the consent or knowledge of the user.

Active Attack

In an active attack, the attacker tries to bypass or break into secured systems. This can be done through stealth, viruses, worms, or Trojan horses. Active attacks include attempts to circumvent or break protection features, to introduce malicious code, and to steal or modify information. These attacks are mounted against a network backbone, exploit information in transit, electronically penetrate an enclave, or attack an authorized remote user during an attempt to connect to an enclave. Active attacks result in the disclosure or dissemination of data files, DoS, or modification of data.

Distributed Attack

A distributed attack requires that the adversary introduce code, such as a Trojan horse or back-door program, to a “trusted” component or software that will later be distributed to many other companies and users Distribution attacks focus on the malicious modification of hardware or software at the factory or during distribution. These attacks introduce malicious code such as a back door to a product to gain unauthorized access to information or to a system function at a later date.

Insider Attack

An insider attack involves someone from the inside, such as a disgruntled employee, attacking the network Insider attacks can be malicious or no malicious. Malicious insiders intentionally eavesdrop, steal, or damage information; use information in a fraudulent manner; or deny access to other authorized users. No malicious attacks typically result from carelessness, lack of knowledge, or intentional circumvention of security for such reasons as performing a task