Cyber Security: a Panoramic View
Total Page:16
File Type:pdf, Size:1020Kb
IITM Journal of Management and IT SOUVENIR National Conference on Emerging Trends in Information Technology- Cyber Security: A Panoramic View Volume 6 Issue 1 January-June, 2015 CONTENTS Research Papers & Articles Page No. ● FIRe: Firefox for Computer Society Incident Reporting and Coordination 3-11 - Ashutosh Bahuguna ● Nine Steps to Indian Security, Confidentiality Privacy & Technology in Cyber Space 12-16 - Rajiv Kumar Singh ● Security Vulnerabilities in ‘Future of the Web’ - IPv6 Protocol Suite 17-20 - Navneet Kaur Popli, Anup Girdhar ● A Study to Examine Cyber Forensic: Trends and Patterns in India 21-25 - Shruti Verma, Saurbh Mehta ● General View on the Aspects of Cryptography 26-32 - Amit Kumar, Sonia Kumari ● A Scalable Server Architecture for Mobile Presence Services in 33-39 Social Network Applications - A. Radha Krishna, K. Chandra Sekharaiah ● “Aadhar” Management System 40-43 - Ameer Ulla Siddiqui, Hare Krishna Singh ● A Survey on Honeypots Security 44-50 - Sonia Kumari, Amit Kumar ● Security Features of User’s Online Social Networks 51-58 - A. Radha Krishna, K. Chandra Sekharaiah ● Cyber Security in India: Problems and Prospects 59-68 - Sushma Devi, Mohd. Aarif Rather ● An Analysis on Improvement of Website Ranking Using Joomla 69-72 - Kirti Nigam, Satyam Saxena, Nargish Gupta ● Network Security - Authentication Methods and Firewall 73-79 - Minal Dhankar IITM Journal of Management and IT Page No. ● Cyber Security in Biometrics Using Fingerprints 80-85 - Priyanka Rattan, Ritika Kapoor ● The Online Murder: Death via Hacked Internet Connected Technologies 86-89 - Nishtha Girotra, Raghunatha Sethupathy ● Future Towards Danger:The Terror of Cyber Attacks 90-94 - Kanika Sharma, Tanvi Bhalla ● Method for Storing User Password Securely 95-99 - Gunjan Jha, Navneet Popli ● Security Issues in Bluetooth Technology - A Review 100-103 - Menal Dr., Sumeet Gill ● Detection of Terrorism Activities Using Face Recognition Technique 104-111 - Garima Bhatia, Mansi ● Cloud Security: A Concerning Issue 112-115 - Apurva Aggarwal, Shalini Sharma ● Hand Recognition System Design 116-119 - Harleen Kaur, Simranjeet Kaur ● Infrared Thermal Imaging 120-122 - Amit Sharma, Nidhi Jindal ● Cyber Forensic: Introducing A New Approach to Studying Cyber Forensic 123-128 and Various Tools to Prevent Cybercrimes - B. Vanlasiama, Nitesh Jha ● Cybercrime and Information Warfare - The New Arenas for WAR 129-134 - Anwesha Pathak, Rohit Sharma ● Legislation Vulnerabilities, Threats and Counter Measures in 135-139 Wireless Network Security - Kushagra Dhingra, Ankit Verma ● Cyber Ethics in Security Application in The Modern Era of Internet 140-143 - Megha Sharma, Sanchit Mittal, Ankit Verma ● Comparison of AES and DES 144-146 - Shruti Kumari, Gautam Kumar ● Social Networking Security Loopholes 147-151 - Shelly Taneja, Shalini Rawat ● Cloud Computing: Vulnerabilities, Privacy and Legislation 152-156 - Amit Kiran, Priyam Lizmay Cherian ● The Exigency in Accretion of Cyber Warfare Legislation 157-163 - Raman Solanki, Ankit Verma ● Cyber Terrorism - An International Phenomena and An Eminent Threat 164-168 - Binny Pal Singh, Ankit Verma 2 National Conference on Emerging Trends in Information Technology FIRe: Firefox for Computer Security Incident Reporting and Coordination Ashutosh Bahuguna* Abstract Information Security breaches are on the increase and adversaries are regularly coming up with new tools and techniques to compromise the information infrastructure. Effective incident information sharing and coordination during incident resolution is crucial for thwarting the cyber attack and protecting the critical assets of organization and nation. It is observed from the current means and methods employed by various national Computer Security Incident Response Teams (CSIRT) and Information Sharing and Analysis Centers (ISAC) that there is need for improvement in the incident reporting and coordination means & methods, relaying only few available means like unsecured email communication is insufficient in countering cyber attacks. FIRe (Firefox for Incident Reporting) is developed to provide reporting organization, a single window solution for incident reporting & coordination activities with CSIRTs (National & Sectoral) during incident resolution process. FIRe is a customized Firefox browser with extensions developed to enable the organizations to share the incident information in standardize format with the national and/or sectoral CSIRTs. FIRe provides the functionalities to communicate & coordinate during the incident resolution. FIRe also integrated tools for secure communication, sensitive information labeling, real time interaction with handler & analyst and database of stakeholder point of contacts. Operational testing of FIRe is planned in upcoming national cyber security exercise 2015 to be conducted by Indian Computer Emergency Response Team (CERT-In). Learning’s of exercise and feedback of participating organizations with respect to FIRe will be used for improving the tool. Keywords: Computer Emergency Response Team (CERT); Computer Security Incident Response Team (CSIRT); Incident Reporting; Incident Handling; Incident Coordination; Indicators of Compromise (IOC) Introduction national security. Rapid identification, incident A security incident is defined as an adverse event in an information exchange and coordinated response can information system and/or network that pose a threat mitigate the damage caused by malicious cyberspace to computer or network security. In other words, an activity. incident is any event that causes, or may cause a breach A significant cyber incident requires increased national of information security in respect of availability, and/or sectoral coordination. Study of different integrity and confidentiality. Examples of such incident reporting and coordination means & methods incidents could be unauthorized access to information adopted by CSIRTs worldwide reveals that there is lack system, disruption of data, denial of services/ of standardize formats, channels & methods, (to) availability, misuse of system resources, malwaresand report the incidents to CSIRT, (for) incident others. Large scale cyber incidents may overwhelm information exchange with CSIRTs & stakeholders government, public and private sector resources and and (for) coordination with CSIRT during incident services by disrupting functioning of critical resolution. It is also observed that there is only few information systems. Complications from disruptions instances where means for real time coordination for of the magnitude may threaten lives, economy and incident resolution is implemented. It comes finally Ashutosh Bahuguna* to regional coordination bodies or national CSIRT to Scientist, Department of Electronics & IT, enable sectoral CSIRTs and organizations under their Ministry of Communication & IT Electronics purview for improved incident reporting and Niketan, 6-CGO Complex, New Delhi-110003 coordination activities. IITM Journal of Management and IT FIRe (Firefox for Incident Reporting), an extended testing of FIRe in exercise scenarios. Study of Firefox browser is developed with objective to implemented means & mediums by various national standardize and enhance the incident reporting and CSIRTs for facilitating coordination & coordination activities, it provides features for secure communications between reporting entities and email communication, web-form based incident national CSIRT are also presented in this paper. The reporting, Instant messaging for coordination during rest of the paper is organized as follows. Section 2 is incident resolution, information sensitivity labeling, about need and challenges of Computer Security access to centralized point of contact database of Incidents Reporting. Section 3 discuss current relevant stakeholders and sharing of Indicators of computer security incident reporting practices and compromise (IoC). In summary, FIReis a tool to solutions at various national CERTs/CSIRT. In Section enable reporting party for better coordination & 4 FIRe functionality details are provided. Section 5 is communication with national or/and sectoral CSIRTs about operational testing of FIRe in upcoming cyber during incident resolution process. There is notable security exercise. Finally section 6 concludes the paper effort by European Union Agency for Network and with future roadmap for FIRe. Information Security (ENISA) [1] in standardization Computer Security Incidents Reporting of incident reporting across European union. ENISA also developed a tool Cyber Incident Reporting and National and sectoral CSIRTs also known as Computer Analysis System (CIRAS) [2][3], as per Article 13a: Emergency Response Teams (CERTs) are the national guidelines for incident reporting [2][3], for online or sectoral nodal agencies for responding to the cyber incident reporting to replaces the electronics forms security incidents [4]. National/Sectoral CSIRTs are email exchange in incident reporting. FIRe is not only using multiple channels for gathering the information a incident reporting system but a tool with purpose of related to the incidents impacting cyberspace under improving coordination & communication in their purview. By reporting computer security handling cyber attacks. incidents to CSIRTs, the organizations and users receive coordination with other entities & technical This paper discuss need for improvement in incident assistance in timely resolving of incidents. This also reporting & coordination means & methods, help national/sectoral