Computer Security Fundamentals, 4th edition

  • William Chuck Easttom

Your access includes:

  • Search, highlight, notes, and more
  • Easily create flashcards
  • Use the app for access anywhere
  • 14-day refund guarantee

$10.99per month

Minimum 4-month term, pay monthly or pay $43.96 upfront

Learn more, spend less

  • Listen on the go

    Learn how you like with full eTextbook audio

  • Find it fast

    Quickly navigate your eTextbook with search

  • Stay organized

    Access all your eTextbooks in one place

  • Easily continue access

    Keep learning with auto-renew

Overview

    Introduction xxvi
Chapter 1: Introduction to Computer Security 2
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2
    How Seriously Should You Take Threats to Network Security? . . . . . . . . . 4
    Identifying Types of Threats . . . . . . . . . . . . . . . . . . . . . . . . 7
    Assessing the Likelihood of an Attack on Your Network . . . . . . . . . . . . 16
    Basic Security Terminology . . . . . . . . . . . . . . . . . . . . . . . 16
    Concepts and Approaches . . . . . . . . . . . . . . . . . . . . . . . . 19
    How Do Legal Issues Impact Network Security? . . . . . . . . . . . . . . . 22
    Online Security Resources . . . . . . . . . . . . . . . . . . . . . . . . 23
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
Chapter 2: Networks and the Internet 32
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
    Network Basics . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
    How the Internet Works . . . . . . . . . . . . . . . . . . . . . . . . . 40
    History of the Internet . . . . . . . . . . . . . . . . . . . . . . . . . . 47
    Basic Network Utilities . . . . . . . . . . . . . . . . . . . . . . . . . 49
    Other Network Devices . . . . . . . . . . . . . . . . . . . . . . . . . 55
    Advanced Network Communications Topics . . . . . . . . . . . . . . . . 56
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58
Chapter 3: Cyber Stalking, Fraud, and Abuse 66
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
    How Internet Fraud Works . . . . . . . . . . . . . . . . . . . . . . . . 67
    Identity Theft . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72
    Cyber Stalking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 89
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 89
Chapter 4: Denial of Service Attacks 96
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96
    DoS Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 97
    Illustrating an Attack . . . . . . . . . . . . . . . . . . . . . . . . . . 97
    Common Tools Used for DoS Attacks . . . . . . . . . . . . . . . . . . . 99
    DoS Weaknesses . . . . . . . . . . . . . . . . . . . . . . . . . . . 102
    Specific DoS Attacks . . . . . . . . . . . . . . . . . . . . . . . . . 102
    Real-World Examples of DoS Attacks . . . . . . . . . . . . . . . . . . . 109
    How to Defend Against DoS Attacks . . . . . . . . . . . . . . . . . . . 111
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113
Chapter 5: Malware 120
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 120
    Viruses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 121
    Trojan Horses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 129
    The Buffer-Overflow Attack . . . . . . . . . . . . . . . . . . . . . . . 132
    Spyware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 134
    Other Forms of Malware . . . . . . . . . . . . . . . . . . . . . . . . 137
    Detecting and Eliminating Viruses and Spyware . . . . . . . . . . . . . . 140
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 145
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . 145
Chapter 6: Techniques Used by Hackers 152
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 152
    Basic Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . 153
    The Reconnaissance Phase . . . . . . . . . . . . . . . . . . . . . . . 153
    Actual Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . 162
    Malware Creation . . . . . . . . . . . . . . . . . . . . . . . . . . . 168
    Penetration Testing . . . . . . . . . . . . . . . . . . . . . . . . . . 171
    The Dark Web . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176
Chapter 7: Industrial Espionage in Cyberspace 182
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 182
    What Is Industrial Espionage? . . . . . . . . . . . . . . . . . . . . . . 183
    Information as an Asset . . . . . . . . . . . . . . . . . . . . . . . . 184
    Real-World Examples of Industrial Espionage . . . . . . . . . . . . . . . 187
    How Does Espionage Occur? . . . . . . . . . . . . . . . . . . . . . . 189
    Low-Tech Industrial Espionage . . . . . . . . . . . . . . . . 189
    Spyware Used in Industrial Espionage . . . . . . . . . . . . . 193
    Steganography Used in Industrial Espionage . . . . . . . . . . . 193
    Phone Taps and Bugs . . . . . . . . . . . . . . . . . . . . 194
    Protecting Against Industrial Espionage . . . . . . . . . . . . . . . . . . 194
    The Industrial Espionage Act . . . . . . . . . . . . . . . . . . . . . . 197
    Spear Phishing . . . . . . . . . . . . . . . . . . . . . . . . . . . . 198
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 199
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . 199
Chapter 8: Encryption 206
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 206
    Cryptography Basics . . . . . . . . . . . . . . . . . . . . . . . . . . 207
    History of Encryption . . . . . . . . . . . . . . . . . . . . . . . . . . 207
    Modern Cryptography Methods . . . . . . . . . . . . . . . . . . . . . 216
    Public Key (Asymmetric) Encryption . . . . . . . . . . . . . . . . . . . 223
    PGP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 228
    Legitimate Versus Fraudulent Encryption Methods . . . . . . . . . . . . . 229
    Digital Signatures . . . . . . . . . . . . . . . . . . . . . . . . . . . 230
    Hashing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 230
    MAC and HMAC . . . . . . . . . . . . . . . . . . . . . . . . . . . 231
    Steganography . . . . . . . . . . . . . . . . . . . . . . . . . . . . 233
    Cryptanalysis . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 235
    Cryptography Used on the Internet . . . . . . . . . . . . . . . . . . . . 236
    Quantum Computing Cryptography . . . . . . . . . . . . . . . . . . . 237
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 238
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . 238
Chapter 9: Computer Security Technology 244
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 244
    Virus Scanners . . . . . . . . . . . . . . . . . . . . . . . . . . . . 245
    Firewalls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 248
    Antispyware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 253
    Digital Certificates . . . . . . . . . . . . . . . . . . . . . . . . . . . 265
    SSL/TLS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 266
    Virtual Private Networks . . . . . . . . . . . . . . . . . . . . . . . . 268
    Wi-Fi Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . 270
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 272
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . 272
Chapter 10: Security Policies 278
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 278
    What Is a Policy? . . . . . . . . . . . . . . . . . . . . . . . . . . . 279
    Defining User Policies . . . . . . . . . . . . . . . . . . . . . . . . . 280
    Defining System Administration Policies . . . . . . . . . . . . . . . . . . 287
    New Employees . . . . . . . . . . . . . . . . . . . . . . . 287
    Departing Employees . . . . . . . . . . . . . . . . . . . . 287
    Change Requests . . . . . . . . . . . . . . . . . . . . . . 288
    Security Breaches . . . . . . . . . . . . . . . . . . . . . . 290
    Virus Infection . . . . . . . . . . . . . . . . . . . . . . . 290
    DoS Attacks . . . . . . . . . . . . . . . . . . . . . . . . 291
    Intrusion by a Hacker . . . . . . . . . . . . . . . . . . . . 291
    Defining Access Control . . . . . . . . . . . . . . . . . . . . . . . . 292
    Development Policies . . . . . . . . . . . . . . . . . . . . . . . . . 293
    Standards, Guidelines, and Procedures . . . . . . . . . . . . . . . . . . 294
    Disaster Recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . 295
    Important Laws . . . . . . . . . . . . . . . . . . . . . . . . . . . . 298
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 300
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . 300
Chapter 11: Network Scanning and Vulnerability Scanning 306
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 306
    Basics of Assessing a System . . . . . . . . . . . . . . . . . . . . . . 307
    Securing Computer Systems . . . . . . . . . . . . . . . . . . . . . . 315
    Scanning Your Network . . . . . . . . . . . . . . . . . . . . . . . . 321
    Getting Professional Help . . . . . . . . . . . . . . . . . . . . . . . . 330
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 333
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . 333
Chapter 12: Cyber Terrorism and Information Warfare 342
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 342
    Actual Cases of Cyber Terrorism . . . . . . . . . . . . . . . . . . . . . 343
    Weapons of Cyber Warfare . . . . . . . . . . . . . . . . . . . . . . . 345
    Economic Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . 347
    Military Operations Attacks . . . . . . . . . . . . . . . . . . . . . . . 350
    General Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . 350
    Supervisory Control and Data Acquisitions (SCADA) . . . . . . . . . . . . . 351
    Information Warfare . . . . . . . . . . . . . . . . . . . . . . . . . . 352
    Actual Cases . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 355
    Future Trends . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 359
    Defense Against Cyber Terrorism . . . . . . . . . . . . . . . . . . . . . 362
    Terrorist Recruiting and Communication . . . . . . . . . . . . . . . . . . 362
    TOR and the Dark Web . . . . . . . . . . . . . . . . . . . . . . . . . 363
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 365
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . 365
Chapter 13: Cyber Detective 370
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 370
    General Searches . . . . . . . . . . . . . . . . . . . . . . . . . . . 371
    Court Records and Criminal Checks . . . . . . . . . . . . . . . . . . . 375
    Usenet . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 379
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 380
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . 380
Chapter 14: Introduction to Forensics 386
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 386
    General Guidelines . . . . . . . . . . . . . . . . . . . . . . . . . . 387
    Finding Evidence on the PC . . . . . . . . . . . . . . . . . . . . . . . 397
    Finding Evidence in System Logs . . . . . . . . . . . . . . . . . . . . 398
    Getting Back Deleted Files . . . . . . . . . . . . . . . . . . . . . . . 399
    Operating System Utilities . . . . . . . . . . . . . . . . . . . . . . . 402
    The Windows Registry . . . . . . . . . . . . . . . . . . . . . . . . . 404
    Mobile Forensics: Cell Phone Concepts . . . . . . . . . . . . . . . . . . 408
    The Need for Forensic Certification . . . . . . . . . . . . . . . . . . . . 413
    Expert Witnesses . . . . . . . . . . . . . . . . . . . . . . . . . . . 414
    Additional Types of Forensics . . . . . . . . . . . . . . . . . . . . . . 415
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 418
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . 418
Chapter 15: Cybersecurity Engineering 422
    Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 422
    Defining Cybersecurity Engineering . . . . . . . . . . . . . . . . . . . . 423
    Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 440
    Test Your Skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . 440
Glossary 442
Appendix A: Resources 448
Appendix B: Answers to the Multiple Choice Questions 450
9780135774779, TOC, 8/15/19

Published by Pearson IT Certification (July 14th 2021) - Copyright © 2020

ISBN-13: 9780137459674

Subject: Networking & Security

Category: Computer Security

Your questions answered

Pearson+ is your one-stop shop, with eTextbooks and study videos designed to help students get better grades in college.

A Pearson eTextbook is an easy‑to‑use digital version of the book. You'll get upgraded study tools, including enhanced search, highlights and notes, flashcards and audio. Plus learn on the go with the Pearson+ app.

Your eTextbook subscription gives you access for 4 months. You can make a one‑time payment for the initial 4‑month term or pay monthly. If you opt for monthly payments, we will charge your payment method each month until your 4‑month term ends. You can turn on auto‑renew in My account at any time to continue your subscription before your 4‑month term ends.

When you purchase an eTextbook subscription, it will last 4 months. You can renew your subscription by selecting Extend subscription on the Manage subscription page in My account before your initial term ends.

If you extend your subscription, we'll automatically charge you every month. If you made a one‑time payment for your initial 4‑month term, you'll now pay monthly. To make sure your learning is uninterrupted, please check your card details.

To avoid the next payment charge, select Cancel subscription on the Manage subscription page in My account before the renewal date. You can subscribe again in the future by purchasing another eTextbook subscription.

Channels is a video platform with thousands of explanations, solutions and practice problems to help you do homework and prep for exams. Videos are personalized to your course, and tutors walk you through solutions. Plus, interactive AI‑powered summaries and a social community help you better understand lessons from class.

Channels is an additional tool to help you with your studies. This means you can use Channels even if your course uses a non‑Pearson textbook.

When you choose a Channels subscription, you're signing up for a 1‑month, 3‑month or 12‑month term and you make an upfront payment for your subscription. By default, these subscriptions auto‑renew at the frequency you select during checkout.

When you purchase a Channels subscription it will last 1 month, 3 months or 12 months, depending on the plan you chose. Your subscription will automatically renew at the end of your term unless you cancel it.

We use your credit card to renew your subscription automatically. To make sure your learning is uninterrupted, please check your card details.