. Krüptograafia on informatsiooni muutmine loetamatuks ilma eriteadmiste ja -vahenditeta. DDoS is an attempt to make a machine or network resource unavailable to its intended users. Ransomware is a type of malware which restricts access to the computer system that it infects, and demands a ransom paid to the creator(s) of the malware in order for the restriction to be removed Internet Bot is a software application that runs automated tasks over the Internet Honeypot is a trap set to detect, deflect, or, in some manner, counteract attempts at unauthorized use of information systems. Generally, a honeypot consists of a computer, data, or a network site that appears to be part of a network, but is actually isolated and monitored, and which seems to contain information or a resource of value to attackers. LÜHENDID CERT- Computer emergency response teams DNS- Domain Name System ISP- Internet service provider IKT- info- ja kommunikatsioonitehnoloogia
[21] For marketing and research, many of the businesses use big data, but may not have the fundamental assets particularly from a security perspective. If a security breach occurs to big data, it would result in even more serious legal repercussions and reputational damage than at present. [18] There is no way around it, but to increase security measures, such as putting extra layers around and encrypting the valuable data within its core, in addition to logging and honeypot detection. It can become quite a difficult task considering the evergrowing amounts of data, as we are talking of petabytes of data already. Data storage and retention is the most obvious risk associated with big data. When data gets accumulated at such a rapid pace and in such huge volumes, the first concern is its storage. Traditional data storage methods and technology are just not enough to store big data and retain it well
mingi teenuse saamiseks (näiteks veebilehe avamiseks) ei leia vastukaja või on meeletult aeglased. Turvamehhanismid Filtrid o Web filtering o E-mail filtering, Antispam, Antimalware, Messaging Security, Content Inspection Liikluse jälgimine töötlemine: o IDS = Intrusion Detection System o IPS = Intrusion Prevention System o Application Control, Traffic profiling o Honeypot Tulemüürid Ligipääsu kontroll -> lubamine või tõkestamine Väljastpoolt sissepoole Seestpoolt väljapoole Paketifilter (packet filter firewall) ~tulemüür o SRC IP o DST IP o Protocol, port (TCP, UDP, ICMP, ...) o ACTION: accept, drop, log Statefull firewall (olekuga tulemüür) o (TCP) sessiooni põhine Rakendustaseme tulemüür (application layer firewall)
· Näiteid: Tripwire, LIDS, AIDE IDS võrgu tasemel · Võrgus on seade, mis kuulab teistega toimuvat · Arhiveerib, analüüsib, saadab mujale edasi · Edasi saatmisel on konfidentsiaalsus oluline · Uute aktiivsete seadmete avastamine · Etherneti pealtkuulamine hub riistvaraline harund (tap) spetsiaalne switchi port (port mirror) IDS võrgu tasemel · IDS süsteemid tunnevad paljusid konkreetseid rünnakuid ja rünnakute tüüpe · Näide: snort · Meepott (honeypot) -- spetsiaalne masin ründaja eemale meelitamiseks ja tema meetodite uurimiseks · Meevõrk (honeynet) -- terve (virtuaalne) võrk ründaja püüdmiseks · IDS sarnased on ka turvaskännerid -- (oma) võrgust automaatselt aukude otsijad Snifferite avastamine · Teoreetiliselt pole 100% ulatuses võimalik · Vale MAC aadressiga IP tasemel pingimine · Muud vastuse välja meelitamised vale MAC aadressiga (ICMP vead jms) · Sama asi IP broadcastiga (255.255.255.255 või suunatud broadcast 192