Chapter 15 Penetrating Computer Systems and Networks Chey Cobb, Chey CobbSearch for more papers by this authorStephen Cobb, Stephen CobbSearch for more papers by this authorM. E. Kabay, M. E. KabaySearch for more papers by this authorTim Crothers, Tim CrothersSearch for more papers by this author Chey Cobb, Chey CobbSearch for more papers by this authorStephen Cobb, Stephen CobbSearch for more papers by this authorM. E. Kabay, M. E. KabaySearch for more papers by this authorTim Crothers, Tim CrothersSearch for more papers by this author Book Editor(s):Seymour Bosworth, Seymour BosworthSearch for more papers by this authorMichel E. Kabay, Michel E. KabaySearch for more papers by this authorEric Whyne, Eric WhyneSearch for more papers by this author First published: 02 January 2012 https://doi.org/10.1002/9781118851678.ch15 AboutPDFPDF ToolsRequest permissionExport citationAdd to favoritesTrack citation ShareShareShare a linkShare onFacebookTwitterLinked InRedditWechat Summary This chapter discusses different aspects of penetration of computer systems and networks. Both technical and nontechnical aspects come into play when people attempt to penetrate security systems. Penetration of information systems is possible by means of a wide range of methods, some of which are very hard to defend against. People responsible for securing systems have to defend against this wide range of penetration methods. The cheapest and most effective attacks are often nontechnical, exploiting human frailty rather than weaknesses in the technology. Experienced criminal hackers tend to favor the nontechnical attack over the technical; and the best defense, employee awareness, is also nontechnical. Systems can be attacked at the client, at the server, or at the connection between the two. This chapter looks at methods of tricking people into allowing unauthorized access to systems. It also examines technical measures for overcoming security barriers and specific techniques for penetration, and describes legal and political aspects of system penetration. Computer Security Handbook, Sixth Edition RelatedInformation
Chapter 50 Using Social Psychology to Implement Security Policies M. E. Kabay, M. E. KabaySearch for more papers by this authorBridgitt Robertson, Bridgitt RobertsonSearch for more papers by this authorMani Akella, Mani AkellaSearch for more papers by this authorD. T. Lang, D. T. LangSearch for more papers by this author M. E. Kabay, M. E. KabaySearch for more papers by this authorBridgitt Robertson, Bridgitt RobertsonSearch for more papers by this authorMani Akella, Mani AkellaSearch for more papers by this authorD. T. Lang, D. T. LangSearch for more papers by this author Book Editor(s):Seymour Bosworth, Seymour BosworthSearch for more papers by this authorMichel E. Kabay, Michel E. KabaySearch for more papers by this authorEric Whyne, Eric WhyneSearch for more papers by this author First published: 02 January 2012 https://doi.org/10.1002/9781118820650.ch50Citations: 3 AboutPDFPDF ToolsRequest permissionExport citationAdd to favoritesTrack citation ShareShareShare a linkShare onFacebookTwitterLinked InRedditWechat Summary This chapter discusses use of social psychology for the effective implementation of security policies. Social psychology can help people understand how best to work with human predilections and predispositions to achieve the goals of improving security. The chapter reviews well-established principles of social psychology that help security and network management personnel implement security policies more effectively. It emphasizes that leaders of the security team responsible for implementing security policies should be on the lookout for conflicts of style that interfere with the central task of making the enterprise more secure. Leaders should ensure that if an individual likes short, direct instructions without chitchat about nonessentials, the security team member should adapt and stick to essentials. In every security course or awareness program, instructors and facilitators should explicitly address the question of corporate culture, expectations, and social schemata. They should not rely solely on intellectual discourse when addressing a question of complex perceptions and feelings. They should also use simulations, videos, and role-playing exercises to bridge the gap between intellect and emotion. Citing Literature Computer Security Handbook, Sixth Edition RelatedInformation
Computer security touches every part of our daily lives from our computers and connected devices to the wireless signals around us. Breaches have real and immediate financial, privacy, and safety consequences. This handbook has compiled advice from top professionals working in the real world about how to minimize the possibility of computer security breaches in your systems. Written for professionals and college students, it provides comprehensive best guidance about how to minimize hacking, fraud, human error, the effects of natural disasters, and more. This essential and highly-regarded reference maintains timeless lessons and is fully revised and updated with current information on security issues for social networks, cloud computing, virtualization, and more.
This chapter discusses why it is important to write secure code. Writing secure code takes coordination and cooperation of various functional areas within an organization, and may require fundamental changes in the way software development is designed, written, tested, and implemented. It requires the developer to work in conjunction with the rest of the project team and other key stakeholders to meet the challenges that must be defined, reconciled, and overcome prior to the release of the software or system. The additional push to market that can drive the rapid development process can also have a negative impact on the security of the application. The problem must be dealt with in two ways, technical and procedural. Technically, the programmers must be aware of the pitfalls associated with application development and avoid them. Procedurally, the development team and organization need to adhere to a consistent methodology of development. This consistency also needs to include the identification of security risks at every stage of the process, including the requirements analysis.