Showing posts with label IA2. Show all posts
Showing posts with label IA2. Show all posts

Wednesday, November 14, 2012

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking: Account Safety

Passwords are usually the only thing unknown about social networking site credentials and that makes them gold for those will malicious intent. In fact, according to Kim, site passwords along the the username have even been sold through illicit channels. Once the account’s credentials have been compromised, the new holder can harvest the owner’s posted information, any information that has been shared with the owner, and even impersonate the owner. Such impersonation can facilitate phishing attacks against the owner’s contacts with messages made plausible by accessing the private information which the victims have thought they only shared with friends. (Kim, 2012)

Account compromise can result in devastating damage to all three facets of cybersecurity. All confidentiality is stripped away from unencrypted data when an unauthorized user accesses the account. If there is modify access to posted data then the intruder has the ability to damage the integrity of such data. Through password modification the attacker can even lock the owner out of their account, impacting the availability, as was reported to have happened to the interviewed user Brian twice. (Debatin et al, 2009, pp. 98)

Account compromise is a high risk threat because of the extremely high amount of damage which can be inflicted upon a user, their social network, their data, their reputation, and other accounts that use the same credentials. Thankfully, the rate at which account credentials end up compromised is far less than the rate that private data is exposed. Policies prevent account compromise have to be broad to cover both prevention of malware as well as to prevent social engineering attacks. Users must be trained to avoid shady websites and not download unauthorized software. They must have it ingrained to never share or reveal their account details, even to persons that seem like legitimate support personnel. Systems administrators need to keep the machines patched to prevent automatic exploit access to the machine for malware.

Such policies and training can impose a significant burden on users. If the machines are not kept stocked with all authorized tools to address any needs they may have occur then the prohibition to download the requisite tools will impact their system use.


Debatin, B., Lovejoy, J. P., Horn, A. K., & Hughes, B. N. (2009). Facebook and online privacy: Attitudes, behaviors, and unintended consequences. Journal of Computer‐Mediated Communication, 15(1), 83-108.

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking
INTRODUCTION
PRIVACY
 UNREMOVABLE CONTENT
 PRIVACY RISK
 PRIVACY PROTECTION
SAFETY
 ACCOUNT SAFETY
 NETWORK SAFETY
 INTERACTION SAFETY
CONCLUSION

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking: Conclusion

Vulnerabilities abound when confronting cybersecurity issues with online social networking, but they are manageable. Careful user practices can protect both the privacy of their shared data and the safety of their account, system, and reputation. Assuming that all posted information will be broadcast publicly and minimizing trust granted to others will maximize the security of the user.

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking
INTRODUCTION
PRIVACY
 UNREMOVABLE CONTENT
 PRIVACY RISK
 PRIVACY PROTECTION
SAFETY
 ACCOUNT SAFETY
 NETWORK SAFETY
 INTERACTION SAFETY
CONCLUSION

Monday, November 12, 2012

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking: Interaction Safety

Interacting with contacts on an online social networking site has two dangerous scenarios which a user must protect themselves from. The first, and more readily apparent, is interacting with a new contact. This can be either someone whom the user thinks they know, but has not established a connection with through the site, or a stranger. In either situation, the person behind the persona may be a malicious actor attempting to gain access to the user’s private data. The second is that a user to communicating with a malicious actor impersonating a friend through compromised account credentials.

Both of these scenarios are cases which pose dangerous to the user’s confidentiality, as any private information divulged is being turned over to unauthorized recipients. Any files received from such an actor may very possibly be trojan horse malware which poses threats to all three cybersecurity facets.

Risks from tainted interactions are low when there is a reasonable belief that the other party is known and medium when the other party is unknown. Rarely will the friend you talk to actually be an imposter and even among strangers, most are not malicious. As the impact of a tainted interaction is potentially very high, the mitigation policies should still be followed.

Mitigation of these dangerous scenarios can be achieved through policies which instruct users to view all online interactions as potentially compromised, and as such not to ignore any suspicious indicators in a conversation. Before friending a ‘known’ contact, an out-of-band communication should be performed to verify that the account in question belongs to the expected person. Any conversation that only includes the other party referencing data available on the site should be questioned as well, because it may be an impostor.

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking
INTRODUCTION
PRIVACY
 UNREMOVABLE CONTENT
 PRIVACY RISK
 PRIVACY PROTECTION
SAFETY
 ACCOUNT SAFETY
 NETWORK SAFETY
 INTERACTION SAFETY
CONCLUSION

Sunday, November 11, 2012

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking: Network Safety

Utilization of social networking sites over untrusted network infrastructure can result in account compromise, privacy compromise, or even system compromise. Unsecured Wi-Fi, a LAN with a hostile workstation (such as a hotel or an intranet with a compromised host on it), and a malicious router can all create hostile network conditions. Once the traffic on the wire cannot be trusted, an attacker could change in transit the link that a friend posted and the user wants to follow. They could change the poster’s upload such that the executable they are attempting to share is actually a trojan horse. A user’s communications can be eavesdropped on to sniff out the private data that is being posted, or even sniff out credentials if they are sent unencrypted, as was the case for the first two years of Facebook. (Mensch & Wilkie, 2011)

With ISP and Internet backbone infrastructure typically being considered trusted, most network accesses will not be reasonably unsafe, leading to this vulnerability to be low risk. The damage at risk during an incident is extremely high, but the likelihood of an incident is small, averaged across all accesses to the social network. When only addressing reasonable unsafe networks, the risk escalates to high.

Untrusted network situations are severe risks for social networking users, especially as a lot of social networking sites still utilize HTTP. Confidentiality is stripped away when eavesdroppers can view and record your plaintext communications with the site. Integrity is lost if routers, legitimate or spoofed, can perform in-transit packet modification. Dropped packets, TCP-reset injections, and wireless jamming are all methods that the untrusted network can impact the availability of the social networking service.

Outside of the implausible command to only utilize trusted infrastructure, the policy recommendations which prevent some of the problem, loss of confidentiality, is to use a VPN to connect to a mostly trusted infrastructure and then still only use social networking sites that can use HTTPS. The damage to integrity can be changed to the less damaging loss of availability by a signed and encrypted protocol. It doesn't prevent a hostile router from modifying the packets, but it will keep the other end from accepting them as clean.


Mensch, S., & Wilkie, L. (2011). INFORMATION SECURITY ACTIVITIES OF COLLEGE STUDENTS: AN EXPLORATORY STUDY. Academy of Information and Management Sciences Journal, 14(2).

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking
INTRODUCTION
PRIVACY
 UNREMOVABLE CONTENT
 PRIVACY RISK
 PRIVACY PROTECTION
SAFETY
 ACCOUNT SAFETY
 NETWORK SAFETY
 INTERACTION SAFETY
CONCLUSION

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking: Safety Intro

Account safety, network safety, data safety, interaction safety, application safety, and monetary safety; there are a lot of ways to get something damaged through online social networking. Your traffic gets viewed, BAM! Compromised. A third party now knows more about your trip to Florida and you are being successfully phished because of it. Your account credentials get stolen and then the bank account which uses the same information is drained. Online social networking vulnerabilities directly threaten your safety with cyber attack and cyber exploitation. (Mensch & Wilkie, 2011)


Mensch, S., & Wilkie, L. (2011). INFORMATION SECURITY ACTIVITIES OF COLLEGE STUDENTS: AN EXPLORATORY STUDY. Academy of Information and Management Sciences Journal, 14(2).

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking
INTRODUCTION
PRIVACY
 UNREMOVABLE CONTENT
 PRIVACY RISK
 PRIVACY PROTECTION
SAFETY
 ACCOUNT SAFETY
 NETWORK SAFETY
 INTERACTION SAFETY
CONCLUSION

Saturday, November 10, 2012

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking: Privacy Protection

Privacy violations can be completely prevented through a single, strict policy: do not post content to online social networking sites. The complete lack of control over disseminated content means that any distribution is a potential redistribution. Damage mitigation can be achieved through one of three fairly disjoint policies. One option is to encrypt posted content and only distribute the key to the trusted recipients out-of-band. This way if either the first or second of the above privacy violations occur then the secondary recipients will be unable to view the content. The third violation is still possible, in that the authorized recipient can either forward/post the key or repost the received, but decrypted, content. Alternatively, a policy of treating all, even limited, distributions as full public postings. Anything, and everything, posted should be classified as approved for public dispersal, because each post has the potential to be released publicly. (UMUC, 2010) Lastly, any postings of non-publicly releasable content can be performed under careful scrutiny of the social networking site’s privacy settings and to be released to recipients under a legally binding and enforceable non-disclosure agreement. Such an agreement will still not physically prevent redistribution, but does permit a legal recourse in the event of redistribution.

Of the four policy suggestions to prevent or mitigate the damage from the discussed privacy violation, only one truly maintains the usability of the social networking site. Personal poster responsibility and operating under the assumption of full public disclosure allows the user to continue operating as is expected on the site. Not posting equates to not using the site. Posting only under encryption or a non-disclosure agreement runs significantly counter to the social, as opposed to business, nature and focus of most social networking sites.


UMUC (2010). Cybersecurity Policies in the Private and Public Sector. UMUC CSEC620 Module

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking
INTRODUCTION
PRIVACY
 UNREMOVABLE CONTENT
 PRIVACY RISK
 PRIVACY PROTECTION
SAFETY
 ACCOUNT SAFETY
 NETWORK SAFETY
 INTERACTION SAFETY
CONCLUSION

Friday, November 9, 2012

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking: Privacy Risk

The likelihood of such privacy violations is very high, especially when default settings result in a user’s data being exposed to everyone who is connected to their friends. A given user may practice safe social networking, but it is unlikely that every one of their friends do. It only takes one friend making one bad connection for a user’s data, with such protections, to become exposed to dangerous actors. In fact, in the time it took to write this paper, a fake account on Facebook that the author created and spammed random friend requests was able to become friends with 28 users, even with a public description that the account was a test to access their information. To most users, though, the risk is at the most medium, as they see a negligible value associated with such a breach, despite the extremely high occurrence rate. This is supported by a reported 30% acceptance rate to complete strangers. (Debatin et al, 2009, pp. 87)

The cybersecurity threat posed by the lack of content privacy severely damages the confidentiality of the messages intended for the originally limited audience. In the case of secondary uploading of a poster’s content, there is also a danger to the integrity of the message, because the secondary uploader can manipulate the content and repost it as if simply re-sharing it. The victim of the integrity damage is twofold: the recipient of the counterfeit message is damaged by collecting mis-information, the sender of the original message is damaged by the counterfeit by weakening the audience’s view of the sender (Counterfeit, 2012).


Counterfeiting (2012) Fact Sheets Protecting a Trademark. Global Trademark Research. Retrieved November 3, 2012 from http://www.inta.org/TrademarkBasics/FactSheets/Pages/Counterfeiting.aspx

Debatin, B., Lovejoy, J. P., Horn, A. K., & Hughes, B. N. (2009). Facebook and online privacy: Attitudes, behaviors, and unintended consequences. Journal of Computer‐Mediated Communication, 15(1), 83-108.

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking
INTRODUCTION
PRIVACY
 UNREMOVABLE CONTENT
 PRIVACY RISK
 PRIVACY PROTECTION
SAFETY
 ACCOUNT SAFETY
 NETWORK SAFETY
 INTERACTION SAFETY
CONCLUSION

Thursday, November 8, 2012

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking: Unremovable Content

All content posted onto a social networking site is released permanently, for the intents of a technically knowledgeable user. Whether that content is in the form of thoughts, images, videos, or otherwise, once it is made available to a second user it is out of the control of the poster. Often misunderstood, even by those that should know better as shown by the prohibition on downloading content in the YouTube terms of service (YouTube, 2010), is that all content displayed to the screen of another user has been downloaded by them. That content, technically rather than legally, is then the property of that other user to do with as they will. If it has been viewed, even if the poster tries to delete it, then it has been distributed.

Once distributed, the poster no longer controls where their content is sent, no longer controls how it is used. Social networking sites often provide visibility or access control options which limit the initial distribution, but these do very little to impact the vulnerability to privacy. First, the default settings tend to lean toward open, rather than closed, because “creation and preservation of this social capital is systematically built upon the voluntary disclosure of private information to a virtually unlimited audience” (Debatin et al, 2009, pp. 87) Thus, having users broadcast their content to the greatest audience in turn leads to the most people joining the audience. Secondly, the sites themselves tend to have controls built into them to allow those with viewing permission to directly share that content to an audience of their choosing. Posting content to only be accessed by a select group of people does not limit the audience at all if one of those recipients in turn just forward the content to the public. Thirdly and lastly, the recipient audience can claim the content as their own and directly post it themselves to the site, or even to a different social networking site. With such a sharing, the sharer may not even provide proper attribution to the content.


Debatin, B., Lovejoy, J. P., Horn, A. K., & Hughes, B. N. (2009). Facebook and online privacy: Attitudes, behaviors, and unintended consequences. Journal of Computer‐Mediated Communication, 15(1), 83-108.

YouTube (2010). Your Use of Content. Terms of Service. Retrieved November 3, 2012 from http://www.youtube.com/static?gl=US&template=terms

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking
INTRODUCTION
PRIVACY
 UNREMOVABLE CONTENT
 PRIVACY RISK
 PRIVACY PROTECTION
SAFETY
 ACCOUNT SAFETY
 NETWORK SAFETY
 INTERACTION SAFETY
CONCLUSION

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking: Privacy Intro

Privacy concerns, in online social networking as well as elsewhere, are primarily centered around data control. Before digital content, albums of family photos were accessible to the family and those that were given access to the images. Duplication was time consuming and costly, so surreptitiously doing so was impractical. A viewer keeping the image to view at a later time would be noticed by the owner, because their copy of the image would be physically taken from the album. Digital content has invalidated these assumptions. Data control no longer can be exercised by the owner keeping the original.

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking
INTRODUCTION
PRIVACY
 UNREMOVABLE CONTENT
 PRIVACY RISK
 PRIVACY PROTECTION
SAFETY
 ACCOUNT SAFETY
 NETWORK SAFETY
 INTERACTION SAFETY
CONCLUSION

Wednesday, November 7, 2012

Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking: Introduction

Online social networking is chock full of cybersecurity vulnerabilities and they are primarily disregarded by the users. For various reasons, users engage in behaviors related to social networking sites in ways that they would not normally perform in the physical realm. Trusting random people while knowing nothing about them. Exposing private data to perfect strangers. Providing intimate details of themselves to the public where the details can be viewed anonymously without the subject even knowing how many times it was viewed. These activities all expose the social networking users to cybersecurity vulnerabilities which pose true risks to them.

This paper will classify each presented vulnerability as a threat to one of the major principles of cybersecurity: confidentiality, integrity, availability. The risks associated with the threats of each vulnerability shall be discussed as well as prevention and mitigation possibilities as encapsulated in policies and procedures. Finally, the impact to customer satisfaction related to the prevention effort is covered.

The full paper in document form.
Vulnerabilities To Be Addressed To Safely Utilize Online Social Networking
INTRODUCTION
PRIVACY
 UNREMOVABLE CONTENT
 PRIVACY RISK
 PRIVACY PROTECTION
SAFETY
 ACCOUNT SAFETY
 NETWORK SAFETY
 INTERACTION SAFETY
CONCLUSION