
How to deal with the wave of cyberattacks:
Revisiting the Essence of Cyber Security
Paper serving as a basis for presentation to the academic conference of BAASANA August 2021
Dr. Frank Owarish, CEO, International Institute for Strategic Research and Training (NYS registered think tank), New York City, USA
&
Dr. Donald Hsu, Professor Dominican College, Doctoral Faculty University of Phoenix, President Chinese American Scholars Association, New York City, USA
Introduction
Cyberattack 101
A cyberattack is any offensive maneuver that targets computer information systems, infrastructures, computer networks, or personal computer devices. An attacker is a person or process that attempts to access data, functions, or other restricted areas of the system without authorization, potentially with malicious intent.[1] Depending on the context, cyberattacks can be part of cyberwarfare or cyberterrorism. A cyberattack can be employed by sovereign states, individuals, groups, society, or organizations, and it may originate from an anonymous source. A product that facilitates a cyberattack is sometimes called a cyberweapon.
(source: Wikipedia)
Cyber attacks
There has been a wave of cyberattacks recently.
The pandemic is a factor, with increasing use of computer systems
Most of these systems do not have sophisticated security systems and are thus vulnerable
Cyberattacks, ransomware
We have made strides in computer technology yet we keep hearing of cyberattacks. Is this a technical or political issue or both?
The Colonial Pipeline showed the agony that can happen. In a statement June 07, 2021 Pipeline CEO Joseph Blount said he was grateful for the FBI’s efforts and said holding hackers accountable and disrupting their activities “is the best way to deter and defend against future attacks of this nature. “The private sector also has an equally important role to play and we must continue to take cyber threats seriously and invest accordingly to harden our defenses,” he added.
Thought
Is not that reasoning faulty?
Being reactive compared with proactive
Is not prevention better than cure?
Review of the basics: computer security, cyber security, IT security
The protection of computer systems and networks from information disclosure, theft of or damage to their hardware, software, or electronic data, as well as from the disruption or misdirection of the services they provide.
The field is becoming increasingly significant due to the increased reliance on computer systems, the Internet and wireless network standards such as Bluetooth and Wi-Fi, and due to the growth of “smart” devices, including smartphones, televisions, and the various devices that constitute the “Internet of things“. Owing to its complexity, both in terms of politics and technology, cybersecurity is also one of the major challenges in the contemporary world.[3]
(Source: Wikipedia)
The 4 Fundamentals to IT Security are:
Data Confidentiality. One of the biggest roles of IT security is protecting sensitive information, especially concerning the data that needs to be kept confidential. …
Data Integrity. …
Data Authenticity. …
Data Availability.
www.pacetechnical.com
More cyberattacks
Thousands of companies affected worldwide
Survey finds
Massive gaps in awareness of cyberattacks
https://www.zdnet.com/article/survey-finds-massive-gap-in-awareness-of-cyberattacks
Ransomware
Hackers may be in over their heads
Cyberattacks on email system
https://www.tessian.com/blog/email-attack-types/: Cyber SecurityHow to protect against cyberattacks
Many companies are using systems which are old and under protected
The question is why don’t we invest in the necessary security mechanism considering that the protective technologies are available?
Universities can help at relatively low costs (training, system design); government agencies as well
High level strategy and action
As cyberattacks surge, President Biden is seeking to mount a better defense
International agreement
In June 2021, Russia, US and other countries reached an agreement on cyber hacking
Protection mechanisms
Obviously, Microsoft (exchange servers worldwide) and Kaseya (technical support to businesses worldwide) did not do enough to protect their clients
New threats
With the pandemic, more workers do their work from home; more online purchases and so vulnerabilities are everywhere; even education from home facing challenges (children at risks sex predators)
Protection through several layers of security
Almost like an onion, for example, for gift card transaction, Macy’s asks for and correlate several sets of information including the bank or credit or debit card company to verify; at times, canceling the order and asks the one making the order to call a special phone number when there is a verification process and the order goes through
Bunch of tools
Encryption, firewalls: bunch of tools with necessary investment of resources
Conclusion 1
UK Comprehensive approach
National Cyber Security Centre
Conclusion 2
All the tools are available, but costs and skill of implementation depends on organizations: companies have to develop and maintain adequate security systems with clear policies to employees and clients; offsite back up
and individuals have to be properly informed and vigilant.
Above all. regular review of the adequacy of security systems with upgrade as needed
Conclusion 3