Jump to content

Internet security: Difference between revisions

From Wikipedia, the free encyclopedia
Content deleted Content added
External links: sigh - typo
Internet Protocol Security (IPsec): that is already covered in the above section
 
Line 1: Line 1:
{{Short description|Branch of computer security}}
{{article issues|cleanup=April 2009|copyedit=April 2009|refimprove=April 2009|tone=April 2009}}
{{more citations needed |date=April 2009}}
When a computer connects to a network and begins communicating with others, it is taking a risk. '''Internet security''' involves the protection of a computer's [[internet]] account and files from intrusion of an unknown user.<ref> ''Riding the Internet Highway.'' Fisher, S. 1993 </ref> Basic security measures involve protection by well selected [[passwords]], change of file permissions and back up of computer's data.
'''Internet security''' is a branch of [[computer security]]. It encompasses the [[Internet]], [[browser security]], web site security,<ref>{{Cite web|title=What Is Internet Security? {{!}} McAfee|url=https://www.mcafee.com/enterprise/en-us/security-awareness/cybersecurity/what-is-internet-security.html|access-date=2021-09-05|website=www.mcafee.com}}</ref> and [[network security]] as it applies to other [[Application software|applications]] or [[operating systems]] as a whole. Its objective is to establish rules and measures to use against attacks over the Internet.<ref>{{cite book|last=Gralla|first=Preston|title=How the Internet Works|year=2007|publisher=Que Pub|location=Indianapolis|isbn=978-0-7897-2132-7|url-access=registration|url=https://archive.org/details/howinternetworks00gral}}</ref> The Internet is an inherently [[insecure channel]] for information exchange, with high risk of [[Hacker (computer security)|intrusion]] or fraud, such as [[phishing]],<ref>{{cite book|last=Rhee|first= M. Y.|title= Internet Security: Cryptographic Principles, Algorithms and Protocols|year=2003|publisher=[[John Wiley & Sons|Wiley]]|location= Chichester|isbn= 0-470-85285-2}}</ref> online [[Computer virus|viruses]], [[Trojan horse (computing)|trojans]], [[ransomware]] and [[Computer worm|worms]].


Many methods are used to combat these threats, including [[encryption]] and ground-up engineering.<ref>{{Cite web|date=2019-12-16|title=101 Data Protection Tips: How to Keep Your Passwords, Financial & Personal Information Safe in 2020|url=https://digitalguardian.com/blog/101-data-protection-tips-how-keep-your-passwords-financial-personal-information-safe|access-date=2020-10-23|website=Digital Guardian}}</ref>{{toclimit|3}}
Security concerns are in some ways peripheral to normal business working, but serve to highlight just how important it is that business users feel confident when using IT systems. Security will probably always be high on the IT agenda simply because cyber criminals know that a successful attack is very profitable. This means they will always strive to find new ways to circumvent IT security, and users will consequently need to be continually vigilant. Whenever decisions need to be made about how to enhance a system, security will need to be held uppermost among its requirements.


==Threats==
Internet security professionals should be fluent in the four major aspects:
===Emerging Threats ===
* [[Penetration test]]ing
Emerging cyberthreats are a result of recent technological breakthroughs. For example, [[deepfakes]] use AI to produce audio and video that seems real but are actually fake, which increases the danger of fraud and false information. Furthermore, traditional risks can be automated and strengthened by AI-driven attacks, making them harder to identify and neutralize.
* Intrusion Detection
===Malicious software ===
* Incidence Response
* Legal / Audit [[Compliance (regulation)|Compliance]]


Malicious software comes in many forms, such as [[Computer virus|viruses]], [[Trojan horse (computing)|Trojan horses]], [[spyware]], and worms.
== Anti-virus ==
{{Details|Malware}}Some apparently useful programs also contain features with hidden malicious intent. Such programs are known as [[Malware]], [[Viruses]], [[Trojan horse (computing)|Trojans]], [[Computer worm|Worms]], [[Spyware]] and [[Bots]].


* [[Malware]], a portmanteau of malicious software, is any software used to disrupt computer operation, gather sensitive information, or gain access to private computer systems. Malware is defined by its malicious intent, acting against the requirements of the computer user, and does not include software that unintentionally causes harm due to some deficiency. The term badware applies to both malware and unintentionally harmful software.
* '''Malware''' is the most general name for any malicious software designed for example to infiltrate, spy on or damage a computer or other programmable device or system of sufficient complexity, such as a home or office computer system, network, mobile phone, PDA, automated device or robot.
* A [[botnet]] is a network of [[zombie computer|computer]]s that have been taken over by a robot or [[Internet bot|bot]] that performs large-scale malicious acts for its creator.
* '''Viruses''' are programs which are able to replicate their structure or effect by integrating themselves or references to themselves, etc into existing files or structures on a penetrated computer. They usually also have a malicious or humorous payload designed to threaten or modify the actions or data of the host device or system without consent. For example by deleting, corrupting or otherwise hiding information from its owner.
* '''Trojans''' ([[Trojan Horses]] are programs which may pretend to do one thing, but in reality steal information, alter it or cause other problems on a such as a computer or programmable device / system. Trojans can be hard to detect.
* [[Computer viruses]] are programs that can replicate their structures or effects by infecting other files or structures on a computer. The typical purpose of a virus is to take over a computer to steal data.
* [[Computer worms]] are programs that can replicate themselves throughout a computer network.
* '''Spyware''' includes programs that surreptitiously monitor keystrokes, or other activity on a computer system and report that information to others without consent.
* [[Ransomware (malware)|Ransomware]] is a type of malware that restricts access to the computer system that it infects, and demands a ransom in order for the restriction to be removed.
* '''Worms''' are programs which are able to replicate themselves over a (possibly extensive) computer network, and also perform malicious acts that may ultimately affect a whole society / economy.
* [[Scareware]] is a program of usually limited or no benefit, containing malicious payloads, that is sold via unethical marketing practices. The selling approach uses social engineering to cause shock, anxiety, or the perception of a threat, generally directed at an unsuspecting user.
* '''Bots''' are program which take over and use the resources of a computer system over a network without consent, and communicate those results to others who may control the [[Bots]].
* [[Spyware]] refers to programs that surreptitiously monitor activity on a computer system and report that information to others without the user's consent.
* One particular kind of spyware is [[Keystroke logging|key logging]] malware. Often referred to as keylogging or keyboard capturing, is the action of recording (logging) the keys struck on a [[Keyboard (computing)|keyboard]].
* A [[Trojan horse (computing)|Trojan horse]], commonly known as a ''Trojan'', is a general term for malware that pretends to be harmless, so that a user will be convinced to download it onto the computer.


=== Denial-of-service attacks ===
The above concepts overlap and they can obviously be combined. The terminology is evolving.
{{Main|Denial-of-service attack}}


A [[denial-of-service attack]] (DoS) or distributed denial-of-service attack (DDoS) is an attempt to make a computer resource unavailable to its intended users. It works by making so many service requests at once that the system is overwhelmed and becomes unable to process any of them. DoS may target [[cloud computing]] systems.<ref>{{cite journal|title=Software-Defined Networking (SDN) and Distributed Denial of Service (DDoS) Attacks in Cloud Computing Environments: A Survey, Some Research Issues, and Challenges|first1=Q.|last1=Yan|first2=F. R.|last2=Yu|first3=Q.|last3=Gong|first4=J.|last4=Li|journal=IEEE Communications Surveys and Tutorials|volume=18|issue=1|pages=602–622|doi=10.1109/COMST.2015.2487361|year=2016|s2cid=20786481}}</ref> According to business participants in an international security survey, 25% of respondents experienced a DoS attack in 2007 and another 16.8% in 2010.{{citation needed| reason=no link|date=January 2024}} DoS attacks often use bots (or a botnet) to carry out the attack.
[[Antivirus]] programs and Internet security programs are useful in protecting a computer or programmable device / system from malware.


===Phishing===
Such programs are used to detect and usually eliminate viruses. [[Anti-virus software]] can be purchased or downloaded via the internet. Care should be taken in selecting anti-virus software, as some programs are not as effective as others in finding and eliminating viruses or malware. Also, when downloading anti-virus software from the Internet, one should be cautious as some websites say they are providing protection from viruses with their software, but are really trying to install malware on your computer by disguising it as something else.
{{main|Phishing}}


Phishing targets online users in an attempt to extract sensitive information such as passwords and financial information.<ref>{{cite web|last1=Izak|first1=Belarua|title=Welke virusscanners zijn het beste voor macOS High Sierra|url=https://virusscannermac.nl/beste-virusscanner-voor-mac/|website=Virusscanner MAC|access-date=4 January 2018|language=nl-NL}}</ref> Phishing occurs when the attacker pretends to be a trustworthy entity, either via email or a web page. Victims are directed to web pages that appear to be legitimate, but instead route information to the attackers. Tactics such as [[email spoofing]] attempt to make emails appear to be from legitimate senders, or long complex [[URL]]s hide the actual website.<ref>{{cite book |author=Ramzan, Zulfikar |chapter=Phishing attacks and countermeasures |editor1=Stamp, Mark |editor2=Stavroulakis, Peter |title=Handbook of Information and Communication Security |publisher=Springer |year=2010 |isbn=978-3-642-04117-4 |chapter-url=https://books.google.com/books?id=I-9P1EkTkigC&pg=PA433}}</ref><ref>{{cite journal|last1=van der Merwe|first1=Alta|last2=Loock|first2=Marianne|last3=Dabrowski|first3=Marek|title=Characteristics and Responsibilities Involved in a Phishing Attack|journal=Proceedings of the 4th International Symposium on Information and Communication Technologies|date=2005|pages=249–254|url=https://dl.acm.org/citation.cfm?id=1071800|access-date=4 January 2018|publisher=Trinity College Dublin|isbn=978-1-59593-169-6 }}</ref> Insurance group [[RSA Insurance Group|RSA]] claimed that phishing accounted for worldwide losses of $10.8 billion in 2016.<ref name="First_Post">{{cite web|url=https://www.rsa.com/en-us/blog/2017-02/fraud-insights-integration|title=Fraud Insights Through Integration|last=Long|first=Mathew|date=February 22, 2017|publisher=RSA|access-date=October 20, 2018|archive-date=October 20, 2018|archive-url=https://web.archive.org/web/20181020140826/https://www.rsa.com/en-us/blog/2017-02/fraud-insights-integration}}</ref>
== Anti-spyware ==
{{details|Malware}}
There are two major kinds of threats in relation to spyware:


=== Man in the middle ===
[[Spyware]] collects and relays data from the compromised computer to a [[third-party]].
{{Main|Man-in-the-middle attack}}


A man-in-the-middle (MITM) attack is a type of cyber attack. Cybercriminals can intercept data sent between people to steal, eavesdrop or modify data for certain malicious purposes, such as extorting money and [[identity theft]]. Public WiFi is often insecure because monitoring or intercepting Web traffic is unknown.{{citation needed|date=August 2022}}
[[Adware]] automatically plays, displays, or downloads advertisements. Some types of adware are also spyware and can be classified as privacy-invasive software. Adware often are integrated with other software.


=== Application vulnerabilities ===
==Email Security==
{{main|Application security}}
A significant part of the Internet, [[E-mail encryption]] is an important subset of this topic.


Applications used to access Internet resources may contain security vulnerabilities such as [[memory safety]] bugs or flawed authentication checks. Such bugs can give network attackers full control over the computer.<ref>{{Cite web|url=https://msdn.microsoft.com/en-us/library/ms994920.aspx|title=Improving Web Application Security: Threats and Countermeasures|website=msdn.microsoft.com|date=14 July 2010 |access-date=2016-04-05}}</ref><ref>{{cite news|title=Justice Department charges Russian spies and criminal hackers in Yahoo intrusion|url=https://www.washingtonpost.com/world/national-security/justice-department-charging-russian-spies-and-criminal-hackers-for-yahoo-intrusion/2017/03/15/64b98e32-0911-11e7-93dc-00f9bdd74ed1_story.html?tid=ss_fb-bottom|newspaper=Washington Post|access-date=15 March 2017}}</ref>
== Browser choice ==
Almost 70% of the browser market is occupied by [[Internet Explorer]][http://www.pcworld.com/article/156306/ie_loses_market_share.html?tk=rss_news]. As a result, malware writers often exploit Internet Explorer. Often malware exploit [[ActiveX]] vulnerabilities. Internet Explorer market share is continuously dropping (as of 2009; see [[list of web browsers]] for statistics) as users switch to other browsers, most notably [[Firefox]], [[Opera (web browser)|Opera]] and [[Google Chrome]].


== Buffer overflow attacks ==
=== User Awareness ===
{{Details|Buffer overflow}}


As cyberthreats become more complex, user education is essential for improving internet security. Important areas of attention consist of:
A buffer overflow is an attack that could be used by a hacker to get full system access through various methods. It is similar to "Brute Forcing" a computer in that it sends an immense attack to the victim computer until it cracks.

Most internet security solutions today lack sufficient protection against these types of attacks.
* Users should have the ability to spot [[phishing]] emails by looking for odd sender addresses, cliched salutations, and language that seems urgent. Both simulated phishing exercises and real-world examples can be incorporated into training programs.
* Enabling [[two-factor authentication]] (2FA) and stressing the usage of strong, one-of-a-kind passwords are essential for protecting personal information. Additionally, users need to understand the dangers of oversharing on social media and how crucial it is to change their privacy settings.
* It's critical to educate people on how to spot secure websites (search for HTTPS), steer clear of dubious downloads, and use caution when clicking links. Also, users need to be aware of the dangers of utilizing open WiFi networks without a [[VPN]].

==Countermeasures==

===Network layer security===
[[TCP/IP]] protocols may be secured with [[Cryptography|cryptographic]] methods and [[Cryptographic protocol|security protocols]]. These protocols include [[Secure Sockets Layer]] (SSL), succeeded by [[Transport Layer Security]] (TLS) for [[web traffic]], [[Pretty Good Privacy]] (PGP) for email, and [[IPsec]] for network layer security.<ref>{{Cite web|url=https://www.tdktech.com/tech-talks/securing-the-network-layer-against-malicious-attacks/|title=Securing the Network Layer Against Malicious Attacks|date=October 27, 2020|website=TDK Technologies}}</ref>

===Threat modeling===
Threat Modeling tools helps you to proactively analyze the cyber security posture of a system or system of systems and in that way prevent security threats.

===Multi-factor authentication===
{{Main|Multi-factor authentication}}

[[Multi-factor authentication]] (MFA) is an [[access control]] method in which a [[User (computing)|user]] is granted access only after successfully presenting separate pieces of evidence to an [[authentication]] mechanism – two or more from the following categories: knowledge (something they know), possession (something they have), and inference (something they are).<ref>{{Cite web|title = Two-factor authentication: What you need to know (FAQ) – CNET|url = https://www.cnet.com/news/two-factor-authentication-what-you-need-to-know-faq/|website = CNET|access-date = 2015-10-31}}</ref><ref>{{Cite web|url=https://www.iphonebackupextractor.com/blog/extract-data-two-factor-authentication/|title=How to extract data from an iCloud account with two-factor authentication activated|website=iphonebackupextractor.com|access-date=2016-06-08}}</ref> Internet resources, such as websites and email, may be secured using this technique.

===Security token===
{{Main|Security token}}

Some online sites offer customers the ability to use a six-digit code which randomly changes every 30–60 seconds on a physical [[security token]]. The token has built-in computations and manipulates numbers based on the current time. This means that every thirty seconds only a certain array of numbers validate access. The website is made aware of that device's serial number and knows the computation and correct time to verify the number. After 30–60 seconds the device presents a new random six-digit number to log into the website.<ref>{{cite web|url=https://searchsecurity.techtarget.com/definition/security-token|title= What is a security token?|publisher=SearchSecurity.com|author=Margaret Rouse|date=September 2005|access-date=2014-02-14}}</ref>

===Electronic mail security===
====Background====
[[Email]] messages are composed, delivered, and stored in a multiple step process, which starts with the message's composition. When a message is sent, it is transformed into a standard format according to <nowiki>RFC 2822</nowiki>.<ref>{{Cite journal|last=Resnick|first=Peter W.|editor-first1=P |editor-last1=Resnick |title=Internet Message Format|url=https://tools.ietf.org/html/rfc2822.html|access-date=2021-05-01|website=tools.ietf.org|year=2001 |doi=10.17487/RFC2822 |language=en|doi-access=free}}</ref> Using a network connection, the mail client sends the sender's identity, the recipient list and the message content to the server. Once the server receives this information, it forwards the message to the recipients.

==== Pretty Good Privacy (PGP) ====
{{Main|Pretty Good Privacy}}

[[Pretty Good Privacy]] provides confidentiality by encrypting messages to be transmitted or data files to be stored using an encryption algorithm such as [[Triple DES]] or [[CAST-128]]. Email messages can be protected by using cryptography in various ways, such as the following:
*[[Digital signature|Digitally signing]] the message to ensure its integrity and confirm the sender's identity.
*Encrypting the message body of an email message to ensure its confidentiality.
*Encrypting the communications between mail servers to protect the confidentiality of both message body and message header.

The first two methods, message signing and message body encryption, are often used together; however, encrypting the transmissions between mail servers is typically used only when two organizations want to protect emails regularly sent between them. For example, the organizations could establish a [[virtual private network]] (VPN) to encrypt communications between their mail servers.<ref>{{cite web|url=http://itcd.hq.nasa.gov/networking-vpn.html|title=Virtual Private Network|publisher=NASA|access-date=2014-02-14|archive-url=https://web.archive.org/web/20130603122059/http://itcd.hq.nasa.gov/networking-vpn.html|archive-date=2013-06-03}}</ref> Unlike methods that only encrypt a message body, a VPN can encrypt all communication over the connection, including email header information such as senders, recipients, and subjects. However, a VPN does not provide a message signing mechanism, nor can it provide protection for email messages along the entire route from sender to recipient.

==== Message Authentication Code ====
{{Main|Message Authentication Code}}

A [[Message authentication code]] (MAC) is a cryptography method that uses a [[Key (cryptography)|secret key]] to digitally sign a message. This method outputs a MAC value that can be decrypted by the receiver, using the same secret key used by the sender. The Message Authentication Code protects both a message's [[data integrity]] as well as its [[Message authentication|authenticity]].<ref>{{cite web|url=http://www.wisegeek.com/what-is-a-message-authentication-code.htm |title=What Is a Message Authentication Code? |publisher=Wisegeek.com |access-date=2013-04-20}}</ref>

=== Firewalls ===
{{Main|Firewall (computing)}}

A [[firewall (computing)|computer firewall]] controls access to a single computer. A network firewall controls access to an entire network. A firewall is a security device — computer hardware or software — that filters traffic and blocks outsiders. It generally consists of gateways and filters. Firewalls can also screen network traffic and block traffic deemed unauthorized.

====Web security====
Firewalls restrict incoming and outgoing [[network packet]]s. Only authorized traffic is allowed to pass through it. Firewalls create checkpoints between networks and computers. Firewalls can block traffic based on IP source and TCP port number. They can also serve as the platform for IPsec. Using tunnel mode, firewalls can implement VPNs. Firewalls can also limit network exposure by hiding the internal network from the public Internet.

====Types of firewall====

===== Packet filter =====
A packet filter processes network traffic on a packet-by-packet basis. Its main job is to filter traffic from a remote IP host, so a router is needed to connect the internal network to the Internet. The router is known as a [[screening router]], which screens packets leaving and entering the network.

===== Stateful packet inspection=====
In a [[stateful firewall]] the [[circuit-level gateway]] is a [[proxy server]] that operates at the network level of an [[OSI model|Open Systems Interconnect (OSI) model]] and statically defines what traffic will be allowed. Circuit proxies forward [[network packet]]s (formatted data) containing a given port number, if the [[Port (computer networking)|port]] is permitted by the [[algorithm]]. The main advantage of a proxy server is its ability to provide [[Network Address Translation]] (NAT), which can hide the user's IP address from the Internet, effectively protecting internal information from the outside.

===== Application-level gateway =====
An [[application-level firewall]] is a third-generation firewall where a [[proxy server]] operates at the very top of the OSI model, the [[Internet protocol suite|IP suite]] application level. A network packet is forwarded only if a connection is established using a known protocol. Application-level gateways are notable for analyzing entire messages rather than individual packets.

=== Browser choice ===
{{main|Browser security}}

Web browser market share predicts the share of hacker attacks. For example, [[Internet Explorer]] 6, which used to lead the market,<ref name="browser stats">{{cite web|url=https://www.w3schools.com/browsers/default.asp|title= Browser Statistics|publisher=W3Schools.com|access-date=2011-08-10}}</ref> was heavily attacked.<ref name="time to drop IE6">{{cite web|url=https://www.pcworld.com/article/191356/its_time_to_finally_drop_internet_explorer_6.html|title=It's Time to Finally Drop Internet Explorer 6|author=Bradly, Tony|publisher=PCWorld.com|access-date= 2010-11-09}}</ref>

==Protections ==

===Antivirus===
{{Main|Antivirus software}}

[[Antivirus software]] can protect a programmable device by detecting and eliminating [[malware]].<ref name="Build free security suite">{{cite web|url=http://www.pcworld.com/article/150204/build_your_own_free_security_suite.html|title=Build Your Own Free Security Suite|author=Larkin, Eric|date=2008-08-26|access-date=2010-11-09|archive-date=2010-11-06|archive-url=https://web.archive.org/web/20101106132932/http://www.pcworld.com/article/150204/build_your_own_free_security_suite.html}}</ref> A variety of techniques are used, such as signature-based, heuristics, [[rootkit]], and real-time.

=== Password managers ===
{{Main|Password manager}}

A [[password manager]] is a software application that creates, stores and provides passwords to applications. Password managers encrypt passwords. The user only needs to remember a single master password to access the store.<ref name="PASSWORD MANAGER">{{cite web|url=http://www.scsccbkk.org/Use%20a%20Password%20Manager%20for%20Security.pdf|publisher=scsccbkk.org|title=USE A FREE PASSWORD MANAGER|access-date=2016-06-17|archive-url=https://web.archive.org/web/20160125015536/http://scsccbkk.org/Use%20a%20Password%20Manager%20for%20Security.pdf|archive-date=2016-01-25}}</ref>

===Security suites===
Security suites were first offered for sale in 2003 ([[McAfee]]) and contain [[Firewall (computing)|firewalls]], [[Antivirus software|anti-virus]], [[Anti spyware|anti-spyware]] and other components.<ref name="all-in-one security 2006">{{cite web|url=https://www.pcworld.com/article/125817/article.html |publisher=PC World.com |title=All-in-one Security |author=Rebbapragada, Narasu |access-date=2010-11-09 |archive-url=https://web.archive.org/web/20101027173353/http://www.pcworld.com/article/125817/allinone_security.html |archive-date=October 27, 2010 }}</ref> They also offer theft protection, portable storage device safety check, private Internet browsing, cloud [[Anti-spam techniques|anti-spam]], a file shredder or make security-related decisions (answering popup windows) and several were free of charge.<ref>{{cite web| url=https://www.comodo.com/products/free-products.php|title= Free products for PC security|date= 2015-10-08}}</ref>

=== Wireless Sensor Networks (WSNs) ===
A promising technology with low production and installation costs, unattended network operation, and autonomous longtime operation. According to research, building a secure Internet of Things (IoT) should start with securing WSNs ahead of other components.<ref>{{Cite journal |last=Butun |first=Ismail |date=2020 |title=Security of the Internet of Things: Vulnerabilities, Attacks, and Countermeasures |journal=IEEE Communications Surveys and Tutorials |volume=22 |issue=1 |pages=616–644 |doi=10.1109/COMST.2019.2953364 |arxiv=1910.13312 |s2cid=204950321 |via=PISCATAWAY: IEEE}}</ref>

==History==
At the National Association of Mutual Savings Banks (NAMSB) conference in January 1976, [[Atalla Corporation]] (founded by Mohamed Atalla) and [[Bunker Ramo Corporation]] (founded by George Bunker and [[Simon Ramo]]) introduced the earliest products designed for dealing with online security. Atalla later added its Identikey [[hardware security module]], and supported [[online transaction processing|processing]] [[online transactions]] and [[network security]]. Designed to process [[bank transactions]] [[online]], the Identikey system was extended to shared-facility operations. It was compatible with various [[Packet switching|switching]] [[Computer network|networks]], and was capable of resetting itself electronically to any one of 64,000 irreversible [[nonlinear]] [[algorithms]] as directed by [[Card Transaction Data|card data]] information.<ref name="Computerworld1976">{{cite journal |title=Four Products for On-Line Transactions Unveiled |journal=[[Computerworld]] |date=26 January 1976 |volume=10 |issue=4 |page=3 |url=https://books.google.com/books?id=3u9H-xL4sZAC&pg=PA3 |publisher=IDG Enterprise}}</ref> In 1979, Atalla introduced the first [[Network processor|network]] [[Secure cryptoprocessor|security processor]] (NSP).<ref>{{cite web |last1=Burkey |first1=Darren |title=Data Security Overview |url=http://www.gtug.de/HotSpot2018/download/Presentation/C108-Burkey.pdf |publisher=[[Micro Focus]] |date=May 2018 |access-date=21 August 2019}}</ref>


== See also ==
== See also ==
{{colbegin|colwidth=30em}}
* [http://www.oodhub.com OODHUB Internet Security News]
<!-- New links in alphabetical order please -->
* [http://www.obetg.com]
* [[Comparison of antivirus software]]
* [[AVG Anti-Virus]]
* [[Comodo Internet Security]]
* [[Comparison of firewalls]]
* [[Cybersecurity information technology list]]
* [[Computer security]]
* [[Cyberspace Electronic Security Act]] (in the US)
* [[Cyberspace Electronic Security Act]] (in the US)
* [[Identity driven networking]]
* ''[[Firewalls and Internet Security]]'' (book)
* [[Identity Driven Networking]]
* [[Internet Crime Complaint Center]]
* [[Internet safety]]
* [[Network security policy]]
* [[Network security policy]]
* [[Usability of web authentication systems]]
* [[Antivirus software]]
* [[Web literacy]] (Security)
* [[Viruslist.com]]
{{colend}}


==References==
==References==
{{Reflist|30em}}
*[http://www.springer.com/computer/communications/book/978-1-4419-0165-1 ''Network Infrastructure Security''], Angus Wong and Alan Yeung, Springer, 2009.
{{reflist}}


== External links ==
== External links ==
{{commons category}}
* [http://www.oodhub.com Internet Security and Safety News and tips] - Review of the most appropriate security solution for home users.
* [https://www.nist.gov/information-technology-portal.cfm National Institute of Standards and Technology (NIST.gov)] - Information Technology portal with links to computer- and cyber security
* [http://www.securitypresentations.com Internet Security Concepts] - Presentations showing everything from how to secure a home system, to multi-factor authentication, encryption, social engineering, and advanced topics like XSS, IDS and SSL Certificate Hijacking.
* [https://csrc.nist.gov/publications/detail/sp/800-45/version-2/final National Institute of Standards and Technology (NIST.gov)] -Computer Security Resource Center -Guidelines on Electronic Mail Security, version 2
* [http://www.anonyproz.com OpenVPN Based VPN for Internet Security] - Anonyproz OpenVPN obscures your IP address by sending your traffic through an encrypted tunnel using OpenVPN Clients and Servers. The 30-second Client Setup and excellent performance of OpenVPN makes Anonyproz.com an easy choice for OpenVpn based VPN.
* [https://crypto.stanford.edu/PwdHash/ PwdHash Stanford University] - Firefox & IE browser extensions that transparently convert a user's password into a domain-specific password.
* [http://www.wireless-safety.org Wireless Safety] - Up to date info on the latest security threats, top news stories, and step by step tutorials on how to best protect yourself and family or organization.
* [http://www.dslreports.com/ Broadband Reports] - FAQs and forums on internet security etc
* [https://www.cybertelecom.org/security/ Cybertelecom.org Security] - surveying federal Internet security work.
* [https://www.dslreports.com/ DSL Reports.com]- Broadband Reports, FAQs and forums on Internet security, est 1999
* [http://passwordmaker.org PasswordMaker] and [http://crypto.stanford.edu/PwdHash/ PwdHash] - Firefox & IE browser extensions that transparently converts a user's password into a domain-specific password.
* [http://foxyproxy.mozdev.org FoxyProxy] - Firefox proxy extension
* [http://www.internetinsecure.net Internet security] - by JC & Goio (security programs).
* [http://www.ruleworks.co.uk/Security/ The Internet and Data Security Guide] - A to Z Glossary of terms
* [http://www.cybertelecom.org/security/ Cybertelecom :: Security] - surveying federal Internet security work


[[Category:Computer network security]]
{{Computer security}}


{{DEFAULTSORT:Internet Security}}
[[ar:أمن الإنترنت]]
[[Category:Internet security| ]]
[[es:Seguridad en Internet]]
[[Category:Web security exploits| ]]
[[ko:인터넷 보안]]

Latest revision as of 14:33, 18 November 2024

Internet security is a branch of computer security. It encompasses the Internet, browser security, web site security,[1] and network security as it applies to other applications or operating systems as a whole. Its objective is to establish rules and measures to use against attacks over the Internet.[2] The Internet is an inherently insecure channel for information exchange, with high risk of intrusion or fraud, such as phishing,[3] online viruses, trojans, ransomware and worms.

Many methods are used to combat these threats, including encryption and ground-up engineering.[4]

Threats

[edit]

Emerging Threats

[edit]

Emerging cyberthreats are a result of recent technological breakthroughs. For example, deepfakes use AI to produce audio and video that seems real but are actually fake, which increases the danger of fraud and false information. Furthermore, traditional risks can be automated and strengthened by AI-driven attacks, making them harder to identify and neutralize.

Malicious software

[edit]

Malicious software comes in many forms, such as viruses, Trojan horses, spyware, and worms.

  • Malware, a portmanteau of malicious software, is any software used to disrupt computer operation, gather sensitive information, or gain access to private computer systems. Malware is defined by its malicious intent, acting against the requirements of the computer user, and does not include software that unintentionally causes harm due to some deficiency. The term badware applies to both malware and unintentionally harmful software.
  • A botnet is a network of computers that have been taken over by a robot or bot that performs large-scale malicious acts for its creator.
  • Computer viruses are programs that can replicate their structures or effects by infecting other files or structures on a computer. The typical purpose of a virus is to take over a computer to steal data.
  • Computer worms are programs that can replicate themselves throughout a computer network.
  • Ransomware is a type of malware that restricts access to the computer system that it infects, and demands a ransom in order for the restriction to be removed.
  • Scareware is a program of usually limited or no benefit, containing malicious payloads, that is sold via unethical marketing practices. The selling approach uses social engineering to cause shock, anxiety, or the perception of a threat, generally directed at an unsuspecting user.
  • Spyware refers to programs that surreptitiously monitor activity on a computer system and report that information to others without the user's consent.
  • One particular kind of spyware is key logging malware. Often referred to as keylogging or keyboard capturing, is the action of recording (logging) the keys struck on a keyboard.
  • A Trojan horse, commonly known as a Trojan, is a general term for malware that pretends to be harmless, so that a user will be convinced to download it onto the computer.

Denial-of-service attacks

[edit]

A denial-of-service attack (DoS) or distributed denial-of-service attack (DDoS) is an attempt to make a computer resource unavailable to its intended users. It works by making so many service requests at once that the system is overwhelmed and becomes unable to process any of them. DoS may target cloud computing systems.[5] According to business participants in an international security survey, 25% of respondents experienced a DoS attack in 2007 and another 16.8% in 2010.[citation needed] DoS attacks often use bots (or a botnet) to carry out the attack.

Phishing

[edit]

Phishing targets online users in an attempt to extract sensitive information such as passwords and financial information.[6] Phishing occurs when the attacker pretends to be a trustworthy entity, either via email or a web page. Victims are directed to web pages that appear to be legitimate, but instead route information to the attackers. Tactics such as email spoofing attempt to make emails appear to be from legitimate senders, or long complex URLs hide the actual website.[7][8] Insurance group RSA claimed that phishing accounted for worldwide losses of $10.8 billion in 2016.[9]

Man in the middle

[edit]

A man-in-the-middle (MITM) attack is a type of cyber attack. Cybercriminals can intercept data sent between people to steal, eavesdrop or modify data for certain malicious purposes, such as extorting money and identity theft. Public WiFi is often insecure because monitoring or intercepting Web traffic is unknown.[citation needed]

Application vulnerabilities

[edit]

Applications used to access Internet resources may contain security vulnerabilities such as memory safety bugs or flawed authentication checks. Such bugs can give network attackers full control over the computer.[10][11]

User Awareness

[edit]

As cyberthreats become more complex, user education is essential for improving internet security. Important areas of attention consist of:

  • Users should have the ability to spot phishing emails by looking for odd sender addresses, cliched salutations, and language that seems urgent. Both simulated phishing exercises and real-world examples can be incorporated into training programs.
  • Enabling two-factor authentication (2FA) and stressing the usage of strong, one-of-a-kind passwords are essential for protecting personal information. Additionally, users need to understand the dangers of oversharing on social media and how crucial it is to change their privacy settings.
  • It's critical to educate people on how to spot secure websites (search for HTTPS), steer clear of dubious downloads, and use caution when clicking links. Also, users need to be aware of the dangers of utilizing open WiFi networks without a VPN.

Countermeasures

[edit]

Network layer security

[edit]

TCP/IP protocols may be secured with cryptographic methods and security protocols. These protocols include Secure Sockets Layer (SSL), succeeded by Transport Layer Security (TLS) for web traffic, Pretty Good Privacy (PGP) for email, and IPsec for network layer security.[12]

Threat modeling

[edit]

Threat Modeling tools helps you to proactively analyze the cyber security posture of a system or system of systems and in that way prevent security threats.

Multi-factor authentication

[edit]

Multi-factor authentication (MFA) is an access control method in which a user is granted access only after successfully presenting separate pieces of evidence to an authentication mechanism – two or more from the following categories: knowledge (something they know), possession (something they have), and inference (something they are).[13][14] Internet resources, such as websites and email, may be secured using this technique.

Security token

[edit]

Some online sites offer customers the ability to use a six-digit code which randomly changes every 30–60 seconds on a physical security token. The token has built-in computations and manipulates numbers based on the current time. This means that every thirty seconds only a certain array of numbers validate access. The website is made aware of that device's serial number and knows the computation and correct time to verify the number. After 30–60 seconds the device presents a new random six-digit number to log into the website.[15]

Electronic mail security

[edit]

Background

[edit]

Email messages are composed, delivered, and stored in a multiple step process, which starts with the message's composition. When a message is sent, it is transformed into a standard format according to RFC 2822.[16] Using a network connection, the mail client sends the sender's identity, the recipient list and the message content to the server. Once the server receives this information, it forwards the message to the recipients.

Pretty Good Privacy (PGP)

[edit]

Pretty Good Privacy provides confidentiality by encrypting messages to be transmitted or data files to be stored using an encryption algorithm such as Triple DES or CAST-128. Email messages can be protected by using cryptography in various ways, such as the following:

  • Digitally signing the message to ensure its integrity and confirm the sender's identity.
  • Encrypting the message body of an email message to ensure its confidentiality.
  • Encrypting the communications between mail servers to protect the confidentiality of both message body and message header.

The first two methods, message signing and message body encryption, are often used together; however, encrypting the transmissions between mail servers is typically used only when two organizations want to protect emails regularly sent between them. For example, the organizations could establish a virtual private network (VPN) to encrypt communications between their mail servers.[17] Unlike methods that only encrypt a message body, a VPN can encrypt all communication over the connection, including email header information such as senders, recipients, and subjects. However, a VPN does not provide a message signing mechanism, nor can it provide protection for email messages along the entire route from sender to recipient.

Message Authentication Code

[edit]

A Message authentication code (MAC) is a cryptography method that uses a secret key to digitally sign a message. This method outputs a MAC value that can be decrypted by the receiver, using the same secret key used by the sender. The Message Authentication Code protects both a message's data integrity as well as its authenticity.[18]

Firewalls

[edit]

A computer firewall controls access to a single computer. A network firewall controls access to an entire network. A firewall is a security device — computer hardware or software — that filters traffic and blocks outsiders. It generally consists of gateways and filters. Firewalls can also screen network traffic and block traffic deemed unauthorized.

Web security

[edit]

Firewalls restrict incoming and outgoing network packets. Only authorized traffic is allowed to pass through it. Firewalls create checkpoints between networks and computers. Firewalls can block traffic based on IP source and TCP port number. They can also serve as the platform for IPsec. Using tunnel mode, firewalls can implement VPNs. Firewalls can also limit network exposure by hiding the internal network from the public Internet.

Types of firewall

[edit]
Packet filter
[edit]

A packet filter processes network traffic on a packet-by-packet basis. Its main job is to filter traffic from a remote IP host, so a router is needed to connect the internal network to the Internet. The router is known as a screening router, which screens packets leaving and entering the network.

Stateful packet inspection
[edit]

In a stateful firewall the circuit-level gateway is a proxy server that operates at the network level of an Open Systems Interconnect (OSI) model and statically defines what traffic will be allowed. Circuit proxies forward network packets (formatted data) containing a given port number, if the port is permitted by the algorithm. The main advantage of a proxy server is its ability to provide Network Address Translation (NAT), which can hide the user's IP address from the Internet, effectively protecting internal information from the outside.

Application-level gateway
[edit]

An application-level firewall is a third-generation firewall where a proxy server operates at the very top of the OSI model, the IP suite application level. A network packet is forwarded only if a connection is established using a known protocol. Application-level gateways are notable for analyzing entire messages rather than individual packets.

Browser choice

[edit]

Web browser market share predicts the share of hacker attacks. For example, Internet Explorer 6, which used to lead the market,[19] was heavily attacked.[20]

Protections

[edit]

Antivirus

[edit]

Antivirus software can protect a programmable device by detecting and eliminating malware.[21] A variety of techniques are used, such as signature-based, heuristics, rootkit, and real-time.

Password managers

[edit]

A password manager is a software application that creates, stores and provides passwords to applications. Password managers encrypt passwords. The user only needs to remember a single master password to access the store.[22]

Security suites

[edit]

Security suites were first offered for sale in 2003 (McAfee) and contain firewalls, anti-virus, anti-spyware and other components.[23] They also offer theft protection, portable storage device safety check, private Internet browsing, cloud anti-spam, a file shredder or make security-related decisions (answering popup windows) and several were free of charge.[24]

Wireless Sensor Networks (WSNs)

[edit]

A promising technology with low production and installation costs, unattended network operation, and autonomous longtime operation. According to research, building a secure Internet of Things (IoT) should start with securing WSNs ahead of other components.[25]

History

[edit]

At the National Association of Mutual Savings Banks (NAMSB) conference in January 1976, Atalla Corporation (founded by Mohamed Atalla) and Bunker Ramo Corporation (founded by George Bunker and Simon Ramo) introduced the earliest products designed for dealing with online security. Atalla later added its Identikey hardware security module, and supported processing online transactions and network security. Designed to process bank transactions online, the Identikey system was extended to shared-facility operations. It was compatible with various switching networks, and was capable of resetting itself electronically to any one of 64,000 irreversible nonlinear algorithms as directed by card data information.[26] In 1979, Atalla introduced the first network security processor (NSP).[27]

See also

[edit]

References

[edit]
  1. ^ "What Is Internet Security? | McAfee". www.mcafee.com. Retrieved 2021-09-05.
  2. ^ Gralla, Preston (2007). How the Internet Works. Indianapolis: Que Pub. ISBN 978-0-7897-2132-7.
  3. ^ Rhee, M. Y. (2003). Internet Security: Cryptographic Principles, Algorithms and Protocols. Chichester: Wiley. ISBN 0-470-85285-2.
  4. ^ "101 Data Protection Tips: How to Keep Your Passwords, Financial & Personal Information Safe in 2020". Digital Guardian. 2019-12-16. Retrieved 2020-10-23.
  5. ^ Yan, Q.; Yu, F. R.; Gong, Q.; Li, J. (2016). "Software-Defined Networking (SDN) and Distributed Denial of Service (DDoS) Attacks in Cloud Computing Environments: A Survey, Some Research Issues, and Challenges". IEEE Communications Surveys and Tutorials. 18 (1): 602–622. doi:10.1109/COMST.2015.2487361. S2CID 20786481.
  6. ^ Izak, Belarua. "Welke virusscanners zijn het beste voor macOS High Sierra". Virusscanner MAC (in Dutch). Retrieved 4 January 2018.
  7. ^ Ramzan, Zulfikar (2010). "Phishing attacks and countermeasures". In Stamp, Mark; Stavroulakis, Peter (eds.). Handbook of Information and Communication Security. Springer. ISBN 978-3-642-04117-4.
  8. ^ van der Merwe, Alta; Loock, Marianne; Dabrowski, Marek (2005). "Characteristics and Responsibilities Involved in a Phishing Attack". Proceedings of the 4th International Symposium on Information and Communication Technologies. Trinity College Dublin: 249–254. ISBN 978-1-59593-169-6. Retrieved 4 January 2018.
  9. ^ Long, Mathew (February 22, 2017). "Fraud Insights Through Integration". RSA. Archived from the original on October 20, 2018. Retrieved October 20, 2018.
  10. ^ "Improving Web Application Security: Threats and Countermeasures". msdn.microsoft.com. 14 July 2010. Retrieved 2016-04-05.
  11. ^ "Justice Department charges Russian spies and criminal hackers in Yahoo intrusion". Washington Post. Retrieved 15 March 2017.
  12. ^ "Securing the Network Layer Against Malicious Attacks". TDK Technologies. October 27, 2020.
  13. ^ "Two-factor authentication: What you need to know (FAQ) – CNET". CNET. Retrieved 2015-10-31.
  14. ^ "How to extract data from an iCloud account with two-factor authentication activated". iphonebackupextractor.com. Retrieved 2016-06-08.
  15. ^ Margaret Rouse (September 2005). "What is a security token?". SearchSecurity.com. Retrieved 2014-02-14.
  16. ^ Resnick, Peter W. (2001). Resnick, P (ed.). "Internet Message Format". tools.ietf.org. doi:10.17487/RFC2822. Retrieved 2021-05-01.
  17. ^ "Virtual Private Network". NASA. Archived from the original on 2013-06-03. Retrieved 2014-02-14.
  18. ^ "What Is a Message Authentication Code?". Wisegeek.com. Retrieved 2013-04-20.
  19. ^ "Browser Statistics". W3Schools.com. Retrieved 2011-08-10.
  20. ^ Bradly, Tony. "It's Time to Finally Drop Internet Explorer 6". PCWorld.com. Retrieved 2010-11-09.
  21. ^ Larkin, Eric (2008-08-26). "Build Your Own Free Security Suite". Archived from the original on 2010-11-06. Retrieved 2010-11-09.
  22. ^ "USE A FREE PASSWORD MANAGER" (PDF). scsccbkk.org. Archived from the original (PDF) on 2016-01-25. Retrieved 2016-06-17.
  23. ^ Rebbapragada, Narasu. "All-in-one Security". PC World.com. Archived from the original on October 27, 2010. Retrieved 2010-11-09.
  24. ^ "Free products for PC security". 2015-10-08.
  25. ^ Butun, Ismail (2020). "Security of the Internet of Things: Vulnerabilities, Attacks, and Countermeasures". IEEE Communications Surveys and Tutorials. 22 (1): 616–644. arXiv:1910.13312. doi:10.1109/COMST.2019.2953364. S2CID 204950321 – via PISCATAWAY: IEEE.
  26. ^ "Four Products for On-Line Transactions Unveiled". Computerworld. 10 (4). IDG Enterprise: 3. 26 January 1976.
  27. ^ Burkey, Darren (May 2018). "Data Security Overview" (PDF). Micro Focus. Retrieved 21 August 2019.
[edit]