Skip to main content

Week 12

 Data security means protecting digital data, such as those in a database, from destructive forces and from the unwanted actions of unauthorized users, such as a cyberattack or a data breach. 

 

Software-based security solutions encrypt the data to protect it from theft. However, a malicious program or a hacker could corrupt the data to make it unrecoverable, making the system unusable. Hardware-based security solutions prevent reading and writing access to data, which provides strong protection against tampering and unauthorized access. 

Hardware-based security or assisted computer security offers an alternative to software-only computer security. Security tokens such as those using PKCS#11, or a mobile phone may be more secure due to the physical access required to be compromised. Access is enabled only when the token is connected, and the correct PIN is entered (two-factor authentication). However, dongles can be used by anyone who can gain physical access to them. Newer technologies in hardware-based security solve this problem by offering full proof of security for data. 

Working off hardware-based security: A hardware device allows a user to log in and log out through manual actions. The device uses biometric technology to prevent malicious users from logging in, logging out, and changing privilege levels. The current state of a user of the device is read by controllers in peripheral devices such as hard disks. Illegal access by a malicious user or a malicious program is interrupted based on the current state of a user by hard disk and DVD controllers making illegal access to data impossible. Hardware-based access control is more secure than the protection provided by the operating systems as operating systems are vulnerable to malicious attacks by viruses and hackers. The data on hard disks can be corrupted after malicious access is obtained. With hardware-based protection, the software cannot manipulate the user privilege levels. A hacker or a malicious program cannot gain access to secure data protected by hardware or perform unauthorized privileged operations. This assumption is broken only if the hardware itself is malicious or contains a backdoor. The hardware protects the operating system image and file system privileges from being tampered with. Therefore, a completely secure system can be created using a combination of hardware-based security and secure system administration policies. 


 Wrap-up


I enjoyed the experience of writing a blog and doing research about the topic and the body of the blog, it enabled me to read and learn more about the weekly chapter I needed to read. Writing a blog is helpful because it pushes me to study and read materials from my textbook to design a blog. 

I think I do see myself blogging in the future if it is not required for an assignment and if I have the time to do so. I am not sure blogging is desirable to most employers because I have yet to see it in a job description, but I hope it is the case. 

Comments

Popular posts from this blog

System Hardening and network week1

  The CompTIA Cybersecurity Analyst (CySA+) certification is a globally recognized certification that validates the skills required to perform cybersecurity analysis and response. The certificate is valid for three years from the exam date, after which it can be renewed through the   continuing education (CE) program.   ISO/ANSI accredits the CySA+ certification and meets the U.S. Department of Defense requirements. The certificate is designed to equip cybersecurity professionals with the necessary skills to identify and respond to security threats and vulnerabilities in real-world scenarios. Professionals must stay updated with the latest technologies and trends as the cybersecurity industry evolves . The CySA+ certification is a great way to demonstrate your knowledge and expertise in the field of cybersecurity and stay ahead of the curve.  

System Hardening Week 12.

  Network automation offers several compelling benefits, and its impact on IT professionals is significant. Below are some advantages.   Benefits of Network Automation: It eliminates manual tasks by automating network processes. This boosts IT productivity, allowing professionals to focus on strategic initiatives that drive business growth. Network automation enables faster provisioning of critical data services, optimizes network performance, and speeds up the rollout of new services and applications. Previously infrequent network changes have become more frequent due to automation, reducing manual adjustments' time-consuming and resource-intensive nature. It helps build a reliable network for an infrastructure-as-code approach that consistently maintains network state and configuration, enhancing reliability from data centers to edge location...

System Hardening week 10

  A Virtual Private Network (VPN) enables secure remote access to corporate resources. Critical aspects of VPN policies include: Connection Procedures: Employees with VPN privileges must ensure unauthorized users are not allowed access. VPNs should enforce robust authentication methods and secure data transmission. Security Measures: VPN users must comply with information security policies, use up-to-date anti-virus software, and configure their equipment correctly. Impact Assessment: Microsoft recently faced DDoS attacks that disrupted services like Outlook and OneDrive. While DDoS attacks mainly cause inconvenience, they can disturb global commerce if they affect critical services.