Computer Security Literacy
Staying
Safe
in
a
Digital
World
Douglas
Jacobson and
Joseph
Idziorek
CRC Press
Taylor& FrancisGroup Boca Raton London New York CRC Press isanimprint ofthe
Taylor& FrancisGroup,aninforma business
Preface,
xvAbout the
Authors,
xxiii
Chapter 1
What Is Information Security?
11.1
INTRODUCTION
11.2 HOW MUCH OF
OUR DAILY
LIVES RELIES ONCOMPUTERS?
21.3 SECURITY TRUISMS 4
1.4
BASIC SECURITY
TERMINOLOGY 61.5 CYBER ETHICS 11
1.6
THE PERCEPTION
OF SECURITY 121.7 THREAT
MODEL
13 1.8 SECURITYIS
A MULTIDISCIPLINARYTOPIC
171.9 SUMMARY 17
BIBLIOGRAPHY 19
Chapter
2Introduction
toComputers
and the Internet21
2.1
INTRODUCTION
21 2.2 COMPUTERS 21 2.2.1 Hardware 22 2.2.2Operating Systems
24 2.2.3Applications
25 2.2.4 Users 25 vvi Contents
2.3 OPERATION OF A COMPUTER 25 2.3.1
Booting
aComputer
262.3.2
Running
anApplication
272.3.3
Anatomy
ofanApplication
282.4 OVERVIEW OF THE INTERNET 30
2.4.1 Protocols 32 2.4.2 Internet
Addressing
362.4.3 Internet Protocol Addresses 38 2.4.4 PublicversusPrivate IP Addresses 41
2.4.5
Finding
an IPAddress
422.4.6 Domain Name Service 43
2.4.7 Network
Routing
462.4.8 World Wide Web 50
2.5 COMPUTERS AND THE INTERNET 51
2.6 SECURITY ROLE-PLAYING CHARACTERS 53
2.7 SUMMARY 54
BIBLIOGRAPHY 56
Chapter
3 Passwords Under Attack57
3.1 INTRODUCTION 57 3.2 AUTHENTICATION PROCESS 58 3.3 PASSWORD THREATS 61
3.3.1 Bob Discloses Password 62 3.3.2 Social
Engineering
63 3.3.3Key-Logging
65 3.3.4 WirelessSniffing
66 3.3.5 Attacker Guesses Password 67 3.3.6Exposed
Password File 703.3.7
Security
Questions
753.3.8
Stop Attacking
My
Password 76 3.4 STRONG PASSWORDS 773.5
PASSWORD
MANAGEMENT: LET'S BE PRACTICAL 813.6 SUMMARY 84
BIBLIOGRAPHY
86Chapter
4 EmailSecurity
894.1 INTRODUCTION 89 4.2 EMAIL SYSTEMS 89
4.2.1
Message
TransferAgent
904.2.2 User
Agents
914.2.3
Addressing
93 4.2.4 EmailMessage
Structure 934.3
EMAIL SECURITY
AND PRIVACY 964.3.1
Eavesdropping
96 4.3.2Spam
andPhishing
98 4.3.3Spoofing
98 4.3.4 Malicious Email Attachments 994.3.5
Replying
and
Forwarding
1004.3.6
To,
CarbonCopy,
and Blind CarbonCopy
1014.4 SUMMARY 102
BIBLIOGRAPHY 103
Chapter
5 Malware: The DarkSide
ofSoftware
105
5.1 INTRODUCTION 105 5.2 WHAT
IS
MALWARE? 106 5.3 HOW DO I GET MALWARE? 108 5.3.1 Removable Media 108 5.3.2 Documentsand Executables
110 5.3.3 InternetDownloads 112 5.3.4 Network Connection 113 5.3.5Email Attachments
115 5.3.6Drive-By
Downloads 116 5.3.7Pop-Ups
117 5.3.8 MaliciousAdvertising
120viii Contents
5.4 WHAT DOES
MALWARE DO?
120
5.4.1 Malicious
Adware
121 5.4.2Spyware
122 5.4.3 Ransomware 122 5.4.4 Backdoor 1235.4.5 Disable
Security Functionality
123 5.4.6 Botnets 1245.5 SUMMARY 124
BIBLIOGRAPHY
126Chapter
6Malware: Defense
in Depth129
6.1
INTRODUCTION
129
6.2 DATA
BACKUP
130
6.3
FIREWALLS
132
6.3.1 Function ofa Firewall 132
6.3.2 What
Types
of MalwareDoes aFirewall ProtectAgainst?
1356.3.3
Two
Types
of Firewalls 1366.3.4
Putting
aHolein aFirewall 1386.3.5
Firewalls
Are Essential 1396.4
SOFTWARE
PATCHES140
6.4.1
Patch
Tuesday
andExploit Wednesday
1416.4.2 Patches Are Not
Limited
toOperating
Systems
1416.4.3
Zero-Day
Vulnerabilities
142 6.4.4Just
Patch it 1426.5
ANTIVIRUS
SOFTWARE 1436.5.1 Antivirus
Signatures
143 6.5.2 Function ofAntivirus Software
145 6.5.3 Antivirus Limitations 145 6.5.4 False Positivesand False
Negatives
147 6.5.5Sneaky
Malware
147 6.5.6 Antivirus Is NotaSafety
Net 1496.6
USER EDUCATION
1496.7
SUMMARY
151BIBLIOGRAPHY
153Chapter
7Securely Surfing
theWorld
Wide Web155
7.1 INTRODUCTION 155 7.2 WEB BROWSER 155
7.2.1 Web Browser
and
Web Server Functions 1567.2.2 Web
Code
1577.2.3 HTML:
Images
and
Hyperlinks
157 7.2.4File and Code
Handling
160 7.2.5 Cookies 1647.3
"HTTP SECURE"
1687.4 WEB
BROWSER
HISTORY 1747.5 SUMMARY 177
BIBLIOGRAPHY 179
Chapter 8
Online
Shopping
181
8.1
INTRODUCTION
1818.2
CONSUMER DECISIONS
1828.2.1 Defensein
Depth
183 8.2.2 Credit Cardversus Debit Card 183 8.2.3Single-Use
Credit Cards 184 8.2.4 Passwords 185 8.2.5 Do YourHomework 1858.3
SPYWARE AND KEY-LOGGERS
1868.4 WIRELESS SNIFFING 186 8.5 SCAMS AND PHISHING WEBSITES 186
8.5.1 Indicators of Trust 188
8.6 MISUSE AND EXPOSURE OF INFORMATION 189
8.6.1
Disclosing
Information
189x Contents
8.7 SUMMARY 190
BIBLIOGRAPHY 191
Chapter
9 Wireless InternetSecurity
193
9.1
INTRODUCTION
1939.2
HOW WIRELESS NETWORKS WORK
1949.3
WIRELESS SECURITY
THREATS 1969.3.1
Sniffing
1969.3.2 Unauthorized Connections 199 9.3.3
Rogue
Router 200 9.3.4 EvilTwin Router 2019.4 PUBLIC WI-FI SECURITY 202 9.5 WIRELESS NETWORK ADMINISTRATION 203
9.5.1
Default
Admin Password 2049.5.2 Service Set Identifier 205 9.5.3 Wireless
Security
Mode 206 9.5.4 MAC AddressFiltering
207 9.5.5 Firewall 209 9.5.6 Power Off Router 2099.6 SUMMARY 209
BIBLIOGRAPHY 211
Chapter 10
Social Networking
21310.1 INTRODUCTION 213 10.2 CHOOSE YOUR FRIENDS WISELY 214 10.2.1 AccessControl 214 10.2.2
Friend
Gluttony
215 10.2.3 RelativePrivacy
215 10.2.4Why
Do You WanttoBeMy
Friend? 21610.3
INFORMATION SHARING
21710.3.1
Location, Location,
Location 217 10.3.2 What ShouldI NotShare?
21910.3.3
Opt
In versusOpt
Out 22010.3.4
Job
Market 22110.4 MALWARE AND PHISHING 223
10.4.1 Koobface 223 10.4.2
Applications
225 10.4.3Hyperlinks
226 10.4.4Phishing
227 10.5 SUMMARY 228REFERENCES
229Chapter 11
Social
Engineering:Phishing
forSuckers
233
11.1 INTRODUCTION 233 11.2 SOCIAL ENGINEERING: MALWARE
DISTRIBUTION
234 11.2.1 InstantMessages
234 11.2.2 Fake Antivirus 236 11.2.3 Emails 237 11.2.4 PhoneCalls
239 11.3 PHISHING 239 11.3.1Phishing
Emails 239 11.3.2 No Shame Game 241 11.3.4Other
Types
ofPhishing
24211.4 DETECTING A PHISHING URL 243 11.4.1
Reading
aURL 24511.4.2 Protocol 245
11.4.3
Top-Level
Domain Name 247 11.4.4 Domain Name 248 11.4.5 Subdomain Name 249 11.4.6File Path
250 11.4.7 File 25111.5
APPLICATION OF KNOWLEDGE
25211.5.1 Tools of the Trade 254
11.6 SUMMARY 256
xii Contents
Chapter 12
Staying Safe Online: The Human Threat
259
12.1
INTRODUCTION
25912.2
THE DIFFERENCES
BETWEEN CYBERSPACE ANDTHE
PHYSICAL WORLD 260
12.3 CONSIDER THE CONTEXT: WATCH WHAT YOU SAY AND HOW IT IS
COMMUNICATED
262 12.4 WHAT YOUDO
ONTHE INTERNET LASTS FOREVER
264 12.5 NOTHING ISPRIVATE,
NOW OR
IN THEFUTURE
265 12.6 CAN YOU REALLYTELL
WHO YOU ARE TALKINGWITH? 266
12.7 CAMERAS
AND PHOTO
SHARING 268 12.8 I AM AGOOD
PERSON,
THAT WOULD NEVERHAPPEN TO
ME 26912.9
IS THERE
ANYTHING I CAN DO TO MAKE THEINTERNET A SAFER PLACE FOR MY CHILD? 271
BIBLIOGRAPHY
272Chapter 13
Case Studies
27513.1 INTRODUCTION 275 13.2 UNABLE TO REMOVE MALWARE: HELP! 275 13.3 SECURELY HANDLING SUSPICIOUS EMAIL
ATTACHMENTS 278
13.4 RECOVERING FROM A
PHISHING ATTACK
281 13.5 EMAIL ACCOUNT HACKED? NOWWHAT?
282
13.6 SMART PHONES AND MALWARE 284
13.7
HEY! YOU! GET OFF MY WIRELESS NETWORK 28613.8
BAD BREAKUP? SEVER YOUR DIGITAL TIES 28713.9
"DISPLAY
IMAGES BELOW"? THE MEANINGBEHIND THE
QUESTION
287 13.10 PHISHING EMAIL FORENSICS 288 13.11IT'S
ON THEINTERNET,
SO IT MUST BE TRUE 292 13.12 BUYINGAND
SELLING ONLINE 294Chapter
14Moving Forward
withSecurity
andBook
Summary
29714.1 INTRODUCTION 297
14.2
AFTER
THECOMPLETION
OF THEBOOK
29714.3
DEFENSE-IN-DEPTH TASKS
29914.4 CHAPTER
SUMMARIES
300
Chapter
1: Introduction 300Chapter
2:Computers
and
the Internet 300Chapter
3: Passwords 301Chapter
4: Email 301Chapter
5: Malware 302Chapter
6: Malware Defense 303Chapter
7:Securely Surfing
the Web 303Chapter
8:Online
Shopping
303Chapter
9: Wireless InternetSecurity
304Chapter
10:Social
Networking
304Chapter
11: SocialEngineering: Phishing
for Suckers
305Chapter
12:Staying
Safe
Online: The Human Threat 305Chapter
13:Case Studies 306GLOSSARY,
307APPENDIX A: READING