Saturday, July 22, 2023

Week 7 Posting - The Importance of Proactive Threat Hunting

Attack vectors

A feared and respected general does not necessarily rush into the battlefield with no plans in their arsenal. In order for a successful attack against their enemies, they need to plan ahead, optimize their current resources and understand the playground. Likewise, most attackers usually have an attack vector in their bag. This is a method of obtaining access to a network or system illegally. These attackers have different ways to approach them, whether it’s through malware, vulnerability exploitation, social engineering or insiders (Chapman & Maymi, p.339, 2020). Malware now days are becoming more polymorphic, meaning they adapt to their environments while on the move to infecting the system. Regarding vulnerability exploitation, zero-day attacks prove to be a massive blow to defenders and threat hunters since no one will be aware or notice any breach that occurs. Social engineering is tricking users and targets into revealing their personal and sensitive information. Because of this manipulative act, attackers will plant their malware into the network. Lastly, an insider can be anyone, which is one of the trickiest assignments for a threat hunter to exploit. This could be a former or current employee. They are literally in the network and it’s hard to figure out whether they’re doing suspicious activities or not.

 

References:

Chapman, B., & Maymi, F. (2020). CompTIA CySA+ Cybersecurity Analyst Certification All-in-One Exam Guide, Second Edition (Exam CS0-002). McGraw Hill Professional.

Saturday, July 15, 2023

Week 6 Posting - Data Analysis in Security Monitoring Activities and Implement Configuration Changes to Existing Controls to Improve Security

            You can learn a lot from experimenting different subjects to further enhance the knowledge of the scholar. In other words, you gain a lot of data from proving or disproving hypotheses or ideas by providing evidence or lack of. Sandboxing is one of the many examples of experimentation. It’s an effective cyber security practice that allows security specialists to operate codes by observing / analyzing them in an isolated, virtual environment on a network that mirrors regular user’s OS environments. Basically, it’s a practice that inspect unknown and untested code. It’s a helpful area to test out malware without worrying about it attacking neighboring networks since nothing is directly attach to the isolated environment. Often times, security specialists execute software in the sandboxes and report / examine the effects that occurs. With enough data, counter measurements will take place that would benefit the company (Chapman & Maymi, p322, 2020). Some drawbacks with sandboxing are that it is heavily resources reliant, meaning that it can be costly. On top of that, the infrastructure of the sandboxes can be complex and consist of a steep learning curve.

 

References:

Chapman, B., & Maymi, F. (2020). CompTIA CySA+ Cybersecurity Analyst Certification All-in-One Exam Guide, Second Edition (Exam CS0-002). McGraw Hill Professional.

Saturday, July 8, 2023

Week 5 Posting - Software and Hardware Assurance Best Practices

 

          Most businesses have their software development department, quality assurance, cyber security team, and IT operations team. Somewhere down the line, there would be hiccups that would negatively affect one department that was created by its neighboring department. For example, assignments from QA could indirectly affect the IT operation team’s incentive and productivity. According to Chapman and Maymi, a solution to solve the friction between teams and department is collaborating them into one multifunctional team called DevOps or DevSecOps. This practice will align all department’s incentives and goals to ultimately enable more efficient and consistent performance (Chapman & Maymi, p.225, 2020).

Personally, communication is key. By having everyone collaborate to further prevent anymore hiccups and speed bumps on the way will definitely improve the company’s production. The only flaw I can think of in this multifunctional team that it’ll get more complicated and more complex. It’ll be hard to manage and monitor multiple resources and programs within the team. On top of that, it might be required for all team players to learn new programs which could be timely.

References:

Chapman, B., & Maymi, F. (2020). CompTIA CySA+ Cybersecurity Analyst Certification All-in-One Exam Guide, Second Edition (Exam CS0-002). McGraw Hill Professional.

Online, O. E. (2023). 10 Advantages and Disadvantages of DevOps. Open Education Onlinehttps://openeducationonline.com/magazine/advantages-and-disadvantages-of-devops/

Week 4 Posting - Security Solutions for Infrastructure Management

 

Honeypots and Honeynets are every cyber security worker’s best friends. These tools are ultimately designed to attract cyber attackers by intentionally exposing a vulnerable hardware or system. One of my favorite features about these tools is that it’s being monitored and will send out alters and messages to any suspicious activities.

 Honeypots target attackers that are attempting to sabotage a hardware whereas honeynet target attackers that are attempting to sabotage an entire network. One of the flaws with utilizing these tools are experienced attackers will bypass them and will attack other areas. The thing is, these tools are isolated away from other networks, which makes it obvious to experienced attackers. Another flaw is that they can only collect a limited amount of data.

 

References:

Chapman, B., & Maymi, F. (2020). CompTIA CySA+ Cybersecurity Analyst Certification All-in-One Exam Guide, Second Edition (Exam CS0-002). McGraw Hill Professional.

Lutkevich, B., Clark, C., & Cobb, M. (2021). honeypot (computing). Securityhttps://www.techtarget.com/searchsecurity/definition/honey-pot

Sunday, June 25, 2023

Week 3 Posting - Threats and Vulnerabilities Associated with Specialized Technology and Operating in the Cloud; Mitigating Controls for Attacks and Software Vulnerabilities

 

Vulnerabilities

            According to Fortinet, four IoT threats to devices include limited hardware, a mix of transmission technology, vulnerable components, and user security awareness (Fortinet, 2023). In most cases, consumers of any IoT products have limited amount of security and security awareness since some of these devices lack built-in security to combat cyber threats. For example, Chapman and Maymi explains the functionality of the Mirai botnet, a malware that attacks IoT devices (Chapman & Maymi, p.130, 2020). To put things into perspective, the attacker attacks the control server which initially attacks the compromised hosts and ultimately affects the victim by attacking traffic. Another vulnerability to consider are weak or defaulted passwords or passcodes. Users settle for easy and fast passwords to access their devices and ignoring the risks of implementing harder passwords, which should include special characters, numbers, and extended character requirement. For example, “R3ign0ver!37” a solid password should be around 12-15 characters added with special characters and capital or lower-case sensitivity. 


References:

Chapman, B., & Maymi, F. (2020). CompTIA CySA+ Cybersecurity Analyst Certification All-in-One Exam Guide, Second Edition (Exam CS0-002). McGraw Hill Professional.

Top IoT Device Vulnerabilities: How To Secure IoT Devices | Fortinet. (n.d.). Fortinet. https://www.fortinet.com/resources/cyberglossary/iot-device-vulnerabilities

Sunday, June 18, 2023

Week 2 Posting - Vulnerability Management Activities and Vulnerability Assessment Tools

 Active scanning and passive scanning have their advantages and disadvantages. When it comes to active scanning, I will have an ongoing overview of the health and processes of my home network. In addition, this method of scanning collects basic and detailed profile and configuration information. However, due to fast data collection and active operation, the consequences of endpoint malfunction could be lethal in the long run. Although it’s great to be on top of my game and actively running tests and scans, overloading the signals and causing network traffic could be tedious. On the flip side, passive scanning operates in silence. Unlike its counterpart, passive scanning scans my systems and applications without any direct interaction with the network. The good thing about this is that it does not clog up the network traffic while identifying the traffic patterns and conditions of every endpoint. The downside of passive scanning is it takes forever to collect important data since it has to wait for each asset to finish its operation. Since I’m not running a business and this is more towards personal use, I’m leaning more towards passive scanning since it still gets the job done without excessive manual scanning (Sherry, 2020).


References:

Chapman, B., & Maymi, F. (2020). CompTIA CySA+ Cybersecurity Analyst Certification All-in-One Exam Guide, Second Edition (Exam CS0-002). McGraw Hill Professional.

Sherry, C. (2020, April 21). Advantages and Disadvantages of Active vs. Passive Scanning in IT and OT Environments. Infosecurity Magazine. https://www.infosecurity-magazine.com/opinions/active-passive-scanning/

Sunday, June 11, 2023

Week 1 Posting - Introduction

Hello IT World,

My name is Genesis Perez, and I am an Information Technology student attending Bellevue University. I've always found technology extremely fascinating and spectacular. I enjoy utilizing technology daily, whether it's at the comfort of my own home or working in my office at work. Technology is much more accessible and affordable now. New gadgets like the Apple Vision Pro and advanced artificial intelligence are on the rise and will continue to structure the future. That being said, with the rise of technology comes with the rise of threats and cyber-attacks. It is crucial to be well equipped and prepared for any threats that could potentially damage your device, documents, and reputation. I am a firm believer of cyber security and its role in the defense against hackers and malicious tools. I am excited to learn more about cyber security and proper procedures to handling security power and monitoring your respected network / systemic area.


Week 10 Posting - Cloud Automation

For the final week of class, we learned about cloud automation and using common terminology that are used in automation services and techniq...