IT Security

Running Head: IT SECURITY

IT Security

IT Security
1. When virus attacks a computer it tends to replicate itself by storing a copy of itself in its code. The virus is similarly able to affect several files. Other viruses are programmed to create destruction to the computer by damaging it, while others just simply replicate themselves and are easily detected by presenting a text, video or even audio messages. These computer viruses are able to acquire some portion of the memory of the computer that is used by genuine programs or operating system files (Cleancomputerhelp, 2010). They more often than not create an erratic behaviour and impact the system by crashing it. Moreover, most of the computer viruses are composed of bugs which may similarly lead to system crashes and loss of data.
They are found by scanning the ordinary programs using antivirus programs. Such antivirus programs try to get virus patterns in the genuine programs or operating system files by looking for the virus signature. A signature is a feature byte-pattern from a certain virus of collection of viruses. If the virus scanner gets this pattern in an operating system file or program, it informs the user that the file is infected.
2. Rootkit are used by attackers to conceal malicious software that are involved in acquiring sensitive information from the client’s computer (World, 2009). They allow intruders to monitor, record, alter, steal and transfer information kept on a computer leading to the disabling of computer’s firewalls and avoiding security products. It is hard to detect but are found by the effect it has caused in a system. Though quite difficult, it is repaired by removing it.
3. Phishing scams are cases where websites are copied and steal the site’s digital certificate to pull a prank on clients to issuing their personal details. It involves taking the client to the actual site for authentication then returning him or her to the clone site (Geeks, 2011). There are other instances of phishing scams that involve the application of self-signed digital certificates that do away with the trusted third party or otherwise Certificate Authority. The one allocating the digital certificate and the one signing it is the same person.
4. A brute force attack involves the attacker trying all the possible key combination until it works. The length of the key combination is considered necessary for a strong key combination. In our case, the thief has narrowed it down to four keys, making it easier for him to break it (Allexperts, 2006). Brute force attacks starts from the basic number 0000 then continues to adding one till the number is gotten. Since the thief does not know which number to start with he will have to start with all the numbers. In our case the worst number combination is 4 × 4 × 4 × 4 = 256.
5. The two-dimensional enables a secure and automated cash transaction for paying clients which eliminates the need to hire cashiers that manage cash (Atlantic, 2008). The system is different and better than the traditional ATM system as it eliminates the need to issue plastics to clients for onsite payment. It otherwise issues a printed receipt to clients composing of the encrypted barcode which can be read from the ATM composed of a scanner. The new technology is difficult to copy and can hold a larger size of information.
6. A person on the no-fly list is able to fly provided the passes are printed online by using a stolen credit card to buy a ticket on a fake name. One can then printing it with your real name and then going to the airport (Atlantic, 2008). Issuing your documents for security check is done by checking the documents against each other. In this case, they are not checking your name alongside the no-fly list as it was done on the computers. Once past security, you may dispose of the fake boarding pass and employ the use of the real documents containing names from the stolen credit card. On the airplane no one checks your name against your ID. To solve this problem additional security measures should be applied; there should be a transfer of the passenger watch list to the aircraft operators as well as transferring responsibilities to flights that come in and go out as well as over certain country. There may as well be presence of physical security on the airplane that compares the passengers’ lists against another list containing the no-fly list names.
7. The picture-based password system, is it more secure than a standard password system? The electronic representation of a series of the pictures is to be stored somewhere which is not hard for someone to break it using a Lopht crack-style utility to break the code. When compared to the standard password system, the picture-based or otherwise image-based password system has a complex implementation process that creates a wide range for poor coders to create a hash about it (Leyden, 2002). It is therefore easier and better to use the standard or text-based password system over the picture-based password system.
8. The issuance of privileges to the owner of the file other than the users creates an aspect of least privileges which is quite difficult or expensive to implement as it is complex to tailor access based on the varied forms of constraints.
Another of the owner having access is that it does not provide for flexibility (Weber, 2008). The owner having sole access to the files binds him or her to the file in cases of urgency it would be hard to access the file especially in big organizations.
When it comes to security it opens a lee way for loose security, it needs an experienced and knowledgeable staff failure to which may lead to incompetent staff insecurity arises.
Bibliography
All experts. (2006). Basic Math/combination/permutation charts. All Experts.
Atlantic, T. (2008, November). Transact Payment Systems uses NCR’s new 2D barcode tech at ATM.
Cleancomputerhelp. (2010). what is a Computer Virus? Computer Cleanup.
Geeks, W. (2011). What are Digital Certificates? Clear Answers for Common Questions.
Hu, V. C., Ferraiolo, D. F., & Kuhn, D. R. (2006). Assessment of Access Control Systems. National Institute of Standard and Technology.
Leyden, J. (2002). Picture this: image-based passwords. The Register.
Srinath Akula. (n.d.). Image Based Registration and Authentication System. Retrieved August 11, 2011, from http://www.micsymposium.org/mics_2004/Akula.pdf
Technology, U. I. (2011, August 11). Checking Virus Pattern Files. Retrieved August 11, 2011, from http://uit.tufts.edu/?pid=462
Tranact. (2011). Transact Payment Systems uses NCR’s new 2D barcode tech at ATM. News.
Weber, H. A. (2008). Role-Based Access Control: The NIST Solution. SANS Institute InfroSec Reading Room.
World, A. (2009). What is a rootkit? Retrieved August 11, 2011, from http://antivirusworld.com/articles/rootkit.php

Latest Assignments