Thursday, 21 February 2019

Hacking - Types of Hackers


        
Welcome back to yet another post on Cyber Security Hacking-Types of Hacking . In the last post we read about Cyber Security - Elements Overview. If you did not come across that post yet please https://creocyber.blogspot.com/2019/02/cyber-security-elements.html to read that.

          Hacking is an attempt of finding and exploiting a weakness in a system or in a network to gain unauthorized access to data and system resources. It can also refer to non-malicious activities or unauthorized intrusion into the information systems/networks by compromising the security. The person who engaged in hacking activities is known as a hacker.


Types of Hackers

          Hackers can be of different categories such as white hat, black hat and grey hat, based on their intent of hacking a system. These different terms come from old Spaghetti Westerns, where the bad guy wears a black cowboy hat and a good guy wears a white hat.


White Hat Hackers


          White Hat Hackers, also known as Ethical Hackers are the cyber security experts who helps the Government Organizations by performing penetration testing and identifying loopholes in a system or a network. They never intent to harm a system or a network, rather they try to find vulnerabilities in a computer or a network as a part of penetration testing and vulnerability assessments and help you to remove virus and malware from your system.
       Ethical Hacking is legal and it is one of the demanding jobs in the IT industry. There are numerous companies that hire ethical hackers for penetration testing and vulnerability assessments.


Black Hat Hackers


           Black Hat Hackers , also known as a cracker, are those who you should be worried off. They hack your computer in order to gain unauthorized access to a system and harm its operations or steal sensitive information. These hackers look for vulnerabilities in victim PCs, organizations or bank systems. Using some loopholes they may hack into your network and get access to your personal, business and financial information.
            Black Hat Hacking is illegal because of its bad intent which includes stealing corporate data, violating privacy, damaging the systems, blocking network communication, etc.


Grey Hat Hackers


            Grey Hat Hackers are a combination of both black hat and white hat hackers. They exploit a security weakness in a computer system or a network without the owner’s permission or knowledge for their fun, not for malicious intent.
        Their main intention is to bring the weakness to the attention of the owners and getting appreciation or a little bounty from  the owners.


Miscellaneous Hackers


         Apart from the above well-known classes of hackers, we have the following categories of hackers based on what they hack and how they do it –


Red Hat Hackers    

     

          Red Hat Hackers are again a combination of both black hat and white hat hackers. They are hacking Government agencies, top-secret information hubs, and generally anything that falls under the category of sensitive information. They launch a series of cyber attacks and malware to crash the whole system.


Script Kiddies                

        

           A Script Kiddie is a non-expert who breaks into computer or network by using automated tools developed by others, usually with little understanding of the underlying concept, hence the term Kiddie. They perform hacking to gain attention or to impress their friends. The attacks by script kiddies might result in DoS/DDoS attacks.


Blue Hat Hackers  


           A Blue Hat Hackers are a person outside computer security consulting firm. They used to bug-test a system prior to its launch. They look for loopholes that can be exploited and try to close these gaps. Microsoft also uses the term BlueHat to represent a series of security briefing events. Blue hat hackers are similar to script kiddie whose aim is to take revenge on someone who makes them angry. They may  use simple cyber attacks like flooding your IP with overloaded packets which will result in DoS.


Elite Hackers    


           Elite Hacker is the term utilized by the community in identifying those individuals who are deemed to be as experts in their line of work. These people are the “cutting edge” of both the computer and network industry. Newly discovered exploits will circulate among these hackers.
              Elites are commonly recognized as the “innovators” or those who took part in the primal years of hacking with utmost skillset.


Neophyte   


        A neophyte, is a person who is new to hacking or phreaking and with no knowledge or experience of the workings of technology and hacking. These hackers are also known as noob, or newbie or Green Hat Hackers. These Green Hat Hackers have a desire to become full-blown hackers and they are very curious to learn new things. They can be identified by their spark to grow and learn more about the hacking trade.


Hacktivist    

                         

          A hacker who utilizes technology to announce a social, ideological, religious, or political message is known as Hacktivist. In general, hacktivist is an online version of an activist which involves website defacement or denial of service attacks. They think that they can bring about social changes and often hack government and organizations to gain attention or share their displeasure over opposing their line of thought.


Monday, 11 February 2019

Cyber Security - Elements


Welcome back to yet another post on Cyber Security – Elements Overview. In the last post we read about Cyber Security History. If you did not come across that post yet please click to the link https://creocyber.blogspot.com/2019/02/cyber-security-history-explained.html to read that.

What are the Elements of Computer Security?
The computer security can able to detect and prevent attacks and it can recover. If the data or information is breached or any disruption occurs then there comes the concept of computer security.
The three main elements of computer security are
·         Confidentiality
·         Integrity
·         Availability

Confidentiality

Confidentiality is protecting your private information from being accessed by unauthorized users. It can be ensured by using role-based security techniques to ensure user or viewer authorization (data access levels may be assigned to a specific department) or access controls that ensure user actions which remains within their roles (for example, define user to read but not write data).

Example in real life: When two people are communicating with one another via an encrypted email. The two people should know their decryption keys of each other and they can read the email by entering decryption keys into the email program. Here, there is a chance for an intruder  to know decryption keys, by this confidentiality of that email reduces.

Integrity

       Integrity ensures that stored data are accurate and contain no unauthorized modifications. Generally, Integrity is composed of two sub-elements they are
·     Data-integrity: There should not be any modification to the content of the data.
·  Authentication: It is a security measure designed to establish the validity of a transmission or message for verifying an individual’s authorization to receive specific categories of information. Authenticity involves checking the credentials of the users who is going to transact with the system. A better form of authenticity is biometrics, because it depends on the user’s physical and biological features. The PKI (Public Key Infrastructure) authentication method uses digital certificates to prove user identity.

Example in real life: In an Online Banking, if it is possible to modify a fund transfer message passing between you and your banking website. The attacker may hijack the transfer and steal the  funds by altering the account number of the recipient of the funds and redirect it into attacker’s own bank account number. Ensuring the integrity of this type of messages is vital to any security system.

Availability

Availability refers to the ability to access information or resources whenever needed in a specified location and in the correct format. When a computer system cannot deliver information efficiently, then availability is compromised. Data availability can be ensured by its storage.Nowadays denying access to the data has become a common attack. Non-repudiation means that the parties involved in a transaction cannot deny their role with data transmission or reception.

Example in real life: When you want to send money through e-banking, but it is impossible to access it because the hacker has compromised a web server of a bank and put it down. 




Tuesday, 5 February 2019

Cyber Security - History Explained


Welcome to my new post on the Cyber Security - History Explained

What is Cyber Security?

            Computer Security is commonly known as Cyber Security. Cyber Security is a process of detecting and preventing any unauthorized use of your Internet connected systems, including hardware, software and your personal data. It can recover the device, network or a source code from any kind of Cyberattack. Cyberattacks are an evolving danger to the organization, employees, and customers. It may be designed to access or destroy sensitive data or to extort money. They can even destroy businesses and damage people’s lives. It is designed to maintain the confidentiality, integrity and availability of the data. Cybersecurity strategies may include identity management, risk management and incident management.


What is Cyberspace?

            Cyberspace is a worldwide network of computers and the equipment that helps to connect them through an electronic medium. It forms a global computer network to facilitate online communications. Its design is free and open to the public. Cyberspace is becoming a dangerous place for all organizations or an individual to protect their data. It allows users to share information, interact, swap ideas, play games, engage in discussions or social forums, conduct business and create intuitive media, among many other activities. In 1984, the term cyberspace was introduced by William Gibson in his book, “Neuromancer.” Cyberspace's core feature is an interactive and virtual environment for a broad range of participants.

History of Cyber Security

The history  of cyber security started with a research project. Bob Thomas is the one who realized that it is possible for a computer program to move across a network, leaving a small trial wherever it goes. Bob designed a program named Creeper, it can able to travel between Tenex terminals on the early ARPANET, printing the message “I’m The Creeper: Catch Me If You Can”. Later, Ray Tomlinson the one who invented email saw bob’s idea. He modified the program and made it self-replicating, which is the first worm. Again he came up with another program named Reaper, the first antivirus software which would chase Creeper and delete it.

In late 1988, Robert Morris came up with an idea that he wanted to gauge the size of the internet. To do this, he wrote a code designed to propagate across networks, infiltrate Unix terminals with a known bug, and then copy itself. Robert Morris became the first person successfully charged under the Computer Fraud and Abuse Act. This act leads to the formation of the Computer Emergency Response Team, which functions as a nonprofit research center for systemic issues that might affect the internet as a whole.

Morris worm is the start of everything. After the Morris worm, viruses started getting deadlier and deadlier, affecting more and more systems. Then there is a rise of Antivirus as a commodity. In 1989,   the first dedicated antivirus company was released. Later, the worm took advantage of the sendmail function in Unix, which was originally created by Ray Tomlinson. In other words, the world’s first famous virus took at advantage of the first virus author’s most famous creation.

It’s interesting to look back from where we are now, in an era of ransomware, fileless malware, and nation-state attacks.

Why Cyber Security is needed?

The use of Cyber Security can help prevent Cyberattacks, data breaches and identity theft and can aid in risk management. When an organization has a depth knowledge of network security and an effective incident response plan, it is better able to prevent and mitigate these attacks. For example, end user protection defends information, and it can guard against loss or theft while scanning computers for malicious code.

Nowadays advisory organizations are promoting a proactive and adaptive approach. The National Institute of Standards and Technology issued updated guidelines in its risk assessment framework  for continuous monitoring and real-time assessments. US president Donald Trump issued an executive order mandating that federal agencies adopt the NIST Cyber Security Framework (NIST CSF) in May 2017. Version 1.1 of the framework for Improving Critical Infrastructure was released in April 2018.

Cyber Security - Famous Hackers

Cyber Security - Famous Hackers Jonathan James           Jonathan James was an American hacker, known as the first juvenile sent to ...