Objectives

Students will be able to:

  • show understanding of the role of the browser
  • show understanding of the role of an ISP (Internet Service Provider
  • show understanding of what is meant by HTTP and HTML
  • distinguish between HTML structure and presentation
  • show understanding of what is meant by MAC address, IP address, URL and cookies

DDoS Mitigation

Specialized services or software will be required to detect the storm of malicious traffic attempting to overwhelm the server.

MITM Mitigation

Use secure protocols such as HTTPS that encrypt data sent between a client and a server. This will prevent eavesdropping.

A padlock on your browser's address bar will tell you that the website you are connecting to has a valid SSL Digital Security Certificate.

Black Lists

When an IT Administrator sets up a firewall to protect a network from malicious network traffic, (s)he creates rules to help the firewall decide what traffic to let into the network and out of the network.

As well as rules, an administrator can create a blacklist, which is list of known entities that will not be blocked from entering the network.

These entities might include Domain Names, IP Addresses, Geographic locations, amongst others.

So, when a packet of data tries to enter the network, the firewall will check what the packet contains against its blacklist.

White Lists

When an IT Administrator sets up a firewall to protect a network from malicious network traffic, (s)he creates rules to help the firewall decide what traffic to let into the network and out of the network.

As well as rules, an administrator can create a whitelist, which is list of known entities that will be guaranteed access to the network, even if it breaks any of the rules.

These entities might include Domain Names, IP Addresses, Geographic locations, amongst others.

In some situations, anything that is not listed on the white list will be denied access to the network.

Unpatched software Mitigation

Regular patching/updating of software fixes known vulnerabilities.

Insecure Protocols Mitigation

Update to a secure protocol such as HTTPS. It may cost money, but it is worth buying that SSL Certificate.

Malware Mitigation

Implement a firewall to monitor (and block) incoming and outgoing suspicious network traffic.

Malware Mitigation

Carefully check any email addresses or URLs. Do they look legitimate? If in doubt, do some research and double check.

XSS Mitigation

Employ techniques to ensure that user-submitted data is in the correct format and does not include malicious code. This is often refered to as input sanitization.

SQL Injection Mitigation

Similar to XSS, employ techniques to ensure that user-submitted data is in the correct format and does not include malicious code. This is often refered to as input sanitization.

Weak authentication Mitigation

Rules are required to enforce the use of strong passwords eg using a miz of letters, numbers and special characters.

This makes passwords harder to crack.

Network Security

Firewalls

As soon as we connect a private network like a LAN to a public network like the Internet, we are asking for trouble!

Suddenly, devices on the network can potentially be accessed by millions of other computers around the world, including

  • malicious users attempting to
  • malicious users attempting to spread malware
  • malicious users attempting to gain unauthorized access

Because of these risks, networks need a way to monitor and control the traffic entering and leaving the system - this is where a firewall becomes important.

Watch the video and complete the worksheet.

HL Extension

Let's try and hack into an of a popular website.

Your username is admin

You have forgotten your password but you do remember it is 2 characters long in the range a-z!

You have 3 chances to log in!

Other Threats [HL]

Here is a list of common threats/vulneribilities to network security:

Vulnerability Description Countermeasure
DDoS Aims to overwhelm a network service such as a web server with excessive traffic from multiple sources, making the service unavailable to legitimate users.
Insecure Network Protocols These days most networks use Secure Socket Layer (SSL) protocols which provide a layer of security by using strategies such as encryption. However, not all networks use these protocols leaving them open to threats such as eavesdropping.
Malware Malicious software aiming to damage, disrupt or gain unauthorised accessed to a network. Ransomware is an example of this.
MiTM Attacks An attacker intercepts communication between two parties, without them realising it. For example, a cafe using insecure network protocols is a haven for attackers stealing personal information such as credit card info when someone is making an online purchase.
Phishing attacks A fraudulent attempt to obtain sensitive information such as usernames and passwords by pretending to be a trustworthy entity such as a bank.
SQL Injection An attack that involves inserting malicious SQL statements into an input field eg a login field to exploit an SQL database.
XSS Cross site scripting is when malicious scripts are injected into content viewed by other users eg in a blog, to steal content on those users'machines eg cookies which may store usernames and passwords.
Unpatched software Unpatched/unfixed software is a network vulnerability because attackers can exploit known security flaws in outdated software to gain unauthorized access, spread malware, steal data, or disrupt services. A patch is the fix.
Zero-day exploits A zero-day exploit involves a vulnerability that is unknown to the software developer or for which no patch yet exists. Attackers exploit the flaw and defenders have zero days to prepare a fix - too late!

There are a variety of strategies that are commonly used to improve network security.

Task

Complete the worksheet and attempt the sample exam questions at the end of the document.