Unit 2: Security threats and vulnerabilities
Information Security notes · PTU syllabus (BSIT501)
On this page
Unit summary
Attackers exploit people, software and networks. This unit covers intruders, malicious software, viruses and related threats, desktop security, email security with PGP and S/MIME, web security — authentication, SSL and SET — database security, and firewall design principles and types.
After this unit you can
- Classify intruders and malicious software
- Explain desktop and email security
- Explain web and database security
- Explain firewall design principles and types
PTU syllabus topics
- Intruders
- malicious software
- viruses and related threats
- desktop security
- email security (PGP and S/MIME)
- web security (authentication, SSL, SET)
- database security
- firewall overview/design principles/types
Virus
Attaches to files and spreads
Worm
Spreads by itself over networks
Trojan
Hides inside useful-looking software
Ransomware
Encrypts data and demands payment
Phishing
Fake messages to steal credentials
Topic 1
Intruders
- Masquerader
- Outsider using a legitimate user's account
- Misfeasor
- Insider who misuses access or accesses data not authorised
- Clandestine user
- Seizes supervisory control to evade auditing
- Intrusion techniques: password guessing and cracking, phishing, exploiting unpatched software, sniffing, privilege escalation. Defences: strong password policies, salted password hashing, account lockout, MFA, monitoring.
Topic 2
Malicious software
Virus
Attaches to a host program and spreads when it runs
File infectors, macro viruses
Worm
Self-replicates across networks without a host
WannaCry (2017)
Trojan horse
Pretends to be useful but hides malicious code
Fake app installers
Ransomware
Encrypts data and demands payment
LockBit, WannaCry
Spyware and keyloggers
Secretly collect information
Banking credential stealers
Rootkit and backdoor
Hide presence; give hidden access
Kernel rootkits
Logic bomb
Triggers on a condition or date
Code deleting files on a set date
- 1Dormant
Idle, waiting
- 2Propagation
Copies itself into other programs
- 3Triggering
Activated by an event
- 4Execution
Performs its payload
- Virus types: boot sector, file infector, macro, polymorphic (changes code with each infection), stealth, metamorphic.
- Countermeasures: antivirus and EDR (signature, heuristic and behaviour-based detection), patching, least privilege, backups, user awareness.
Topic 3
Desktop security
- Keep the OS and applications updated; use antivirus and a personal firewall; standard (non-admin) user accounts; strong passwords and screen locks; full-disk encryption (BitLocker); disable autorun; download only from trusted sources; back up regularly.
Topic 4
Email security: PGP and S/MIME
- Threats: phishing, spoofing, malware attachments, interception. Email needs confidentiality, authentication, integrity and non-repudiation.
- 1Sign
Hash the message (SHA) and encrypt the hash with the sender's private key
- 2Compress
ZIP compression
- 3Encrypt
Encrypt with a one-time session key (symmetric)
- 4Protect the key
Encrypt the session key with the receiver's public key
- 5Encode
Radix-64 for email compatibility
Developed by
Phil Zimmermann (1991)
RSA Data Security; IETF standard
Trust model
Web of trust — users sign each other's keys
Hierarchical X.509 certificates from CAs
Use
Individuals, open-source community
Organisations, built into Outlook and Apple Mail
Services
Signature, encryption, compression, compatibility
Signed and enveloped data
- Domain protections: SPF, DKIM and DMARC records help receiving servers reject spoofed email.
Topic 5
Web security: authentication, SSL and SET
- Web authentication: passwords with hashing, MFA (OTP, authenticator apps), session tokens and cookies with secure flags, OAuth single sign-on.
Topic 6
SSL and TLS
- HTTP transfers web pages in plain text; HTTPS adds TLS (successor of SSL) to encrypt traffic and authenticate the server.
- 1Client hello
Supported versions and ciphers
- 2Server hello and certificate
- 3Client verifies certificate with a trusted CA
- 4Key exchange
Session key agreed
- 5Encrypted session
Symmetric encryption of data
- The browser padlock shows a valid certificate; TLS 1.2 and 1.3 are current versions.
- SSL protocol stack: SSL Record Protocol (fragment, compress, MAC, encrypt) with Handshake, Change Cipher Spec and Alert protocols above it. SSL is obsolete; TLS 1.2 and 1.3 are used today.
- SET (Secure Electronic Transaction): a protocol by Visa and MasterCard (1996) to secure card payments using certificates for cardholder, merchant and payment gateway. Its dual signature links the order information (seen by the merchant) and payment information (seen by the bank) so neither sees the other's details. SET was too complex and was replaced by TLS-based payment gateways and 3-D Secure.
- Web attacks: SQL injection, cross-site scripting (XSS), cross-site request forgery (CSRF); defended by input validation, prepared statements, output encoding and CSRF tokens.
Topic 7
Database security
- Threats: SQL injection, excessive privileges, weak authentication, unencrypted backups, inference attacks on statistical databases.
- Controls: authentication, GRANT and REVOKE privileges, views to hide sensitive columns, encryption (TDE), auditing, data masking, regular patching and backups.
Topic 8
Firewalls: overview and types
A firewall is a hardware or software system that monitors and controls incoming and outgoing network traffic based on security rules, separating trusted internal networks from untrusted ones.
Packet-filtering router
Checks IP addresses, ports, protocols
Stateful inspection
Tracks connection states
Application (proxy) gateway
Inspects application-level traffic
Circuit-level gateway
Validates TCP sessions
Next-generation firewall
Deep packet inspection, intrusion prevention, application awareness
DMZ (screened subnet)
Hosts public servers between two firewalls
- Functionality: access control, logging and auditing, NAT (hiding internal addresses), VPN support, content filtering, alerts.
- Design factors: security policy (default deny), network architecture (DMZ), performance and scalability, redundancy, ease of management, cost, regular updating and monitoring; firewalls do not stop insider threats or malware in permitted traffic — layered security is needed.
Topic 9
Firewall design principles
- Single choke point
- All traffic between inside and outside must pass through the firewall
- Authorised traffic only
- Only traffic allowed by the security policy passes
- Immune to penetration
- The firewall itself is hardened
- Default deny
- Block everything not explicitly allowed
- Defence in depth
- Combine with IDS, antivirus and host firewalls
Screened host
Packet-filtering router plus a bastion host
Moderate
Dual-homed bastion host
Bastion host with two network cards, no direct routing
Higher
Screened subnet (DMZ)
Two routers with public servers in between
Highest — common choice
Key terms
- Masquerader
- Outsider using a legitimate user's identity
- Worm
- Self-replicating malware spreading over networks
- PGP
- Email security program using a web of trust
- SET
- Card payment protocol using dual signatures
- Bastion host
- Hardened system exposed to the internet
Quick revision
- Masquerader, misfeasor, clandestine user.
- Virus, worm, trojan, ransomware, spyware, rootkit, logic bomb; virus phases and types.
- Desktop security practices.
- PGP operations; S/MIME; SPF, DKIM, DMARC.
- SSL/TLS, SET dual signature; web attacks; database security; firewall principles and configurations.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.Distinguish a virus and a worm.
- Q2.What is a polymorphic virus?
- Q3.State the services provided by PGP.
- Q4.What is a dual signature in SET?
- Q5.Name two database security controls.
- Q6.What is a DMZ?
Long-answer questions
- Q1.Explain intruders and types of malicious software.
- Q2.Explain email security with PGP and S/MIME.
- Q3.Explain web security with SSL and SET.
- Q4.Explain firewall design principles and types.
Stuck on this unit?
Message SBS on WhatsApp for help with Information Security, or to ask about studying B.Sc IT at Synetic.
