Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Saturday, 1 February 2014

Cloud Data Security And Searchable Encryption Technique

Cloud computing minimizes resource wastage risk by reducing the entrance barrier for cloud service providers.By extensive usage of cloud services unstructured data volume is increasing over it.Therefore security considerations to save data from hackers are also becoming a necessary aspect.Different encryption techniques are used to protect data on cloud.
With the commencement of cloud computing composite data management systems from local site are transformed to viable public cloud.Data owners are encouraged to outsource the data management system to public cloud to achieve flexible and commercial benefits. Cloud computing is all about transferring services,applications and data. Also attaining commercial assistances,location transparency, and centralized facilitation are the significant resources in cloud computing.
Cloud storage has the capability to save a bulk of data for a large number of users. This minimizes the storage capacity problem. To provide different competencies  multiple isolated applications and services are disseminated over the internet in cloud environment. When sensitive data storage is done on the cloud,existence of large number of users can cause cloud security to be affected. Thus for achieving data privacy complex data has to be outsourced on the cloud after encryption. Therefore to hide data from hackers and malicious attackers a protected system is needed.

Searchable encryption is a technique by which the outsourced data placed on cloud can be kept private. Searchable encryption will let this data to be difficult to hack when searched. With searchable encryption techniques encrypted data is placed on the cloud server on which search can be performed. Processing of encrypted data placed on cloud server is done without decrypting it. The encrypted data is placed on the cloud in the form of code words which are difficult to hack by unauthorized users or hackers. The encrypted data will be accessible by authenticated users only. These users will be able to perform search on this data and retrieve desired results.

Friday, 31 January 2014

Internet: Myths of IT Security

In the world of Information Security myths exist that influence senior executives, business managers and sometimes the same industry professionals, causing misunderstandings and exaggerations about the threats to computer systems and technologies used to combat them.
Many of these myths exist because people tend to overreact and emotional in unfamiliar situations, rather than make an objective analysis.
The result is overstate the problem by relying on the first solution that is proposed or worse underestimate the risks, thinking thus to avoid additional charges.
Myth #1 - It will not happen to me
Believing that your company will never be subject to security problems. Many times this statement is said by someone who does not want to spend (or rather, invest), hoping that the risk does not materialize. Instead it is good that when a problem is recognized, or even suggested, there is a phase of risk analysis and, if appropriate are given the resources necessary to mitigate or resolve completely.
Other times the opposite happens: you go too far in assessing the impact of the vulnerability. The best thing is to use a framework of metrics to give an objective value to the risk of vulnerability.
Myth #2 - All risks can be quantified
In companies there is the misconception that everything can have a number attached to it. There is the illusion that the security manager's manager can get the budget they need only if justified by an Excel spreadsheet. We must instead help the upper echelons to understand what can and can not be quantified, and obtain the necessary budget to implement a strong architecture based security checks.
Myth #3 - We have physical security or SSL so your data is safe
More simply: If we have anti-virus and firewall, we're safe! This is not true. Often this conception is inculcated by outside vendors who try to sell their products and link all their peculiarities. buying products and appliances, will not make you magically safe! And even in the event that the product is "good" we want to ensure that it is properly configured and works to its full potential?
In fact, safety will be developed as architecture starting from the risk assessment, taking into account what you're protecting, so as to implement the correct controls. This allows you to not be distracted by non-essential elements to security.
Myth #4 - Use strong passwords reduces the risks
It is not true. The passwords are not effective, and the whole scheme has huge gaps. It 's just an obsolete historical precedent in which business can cling.
Passwords are not sufficient, since cracking is not the only way to jump the firewall. there is also sniffing and the reuse of credentials between systems with different levels of security. Finding a valid alternative to passwords is difficult, and not always authenticate to two or more factors can be easily implemented. Meanwhile, companies can advise employees not to use passwords to work, and perform periodic checks on the strength of passwords.
Myth #5 - Buy one device security, will solve all the problems
We have just been informed of a new product, that solves the 95% of problems, easy to install and costs as one of many server that we have in the company. Maybe As we have said before, we stop to buy software and "iron" hoping that magically solve our problems. Without serious analysis and auditing work of those who are the real problems to which our business is exposed spend money unnecessarily increasing the complexity of our infrastructure. This myth is a common understanding of the problem and wrong "security" as a whole.
Relying on myths is wrong. That is why there EasyAudit, a professional tool and an inexpensive way to get a second opinion on information security of your business!

Cyber Security - A Top Priority Issue

History of Internet Security
Computers have become ubiquitous and indispensable today. The traditional system of documenting things on paper is being rapidly replaced by computers. The growing dependency on computers, especially since the advent of the Internet, has also made the integrity, confidentiality and availability of information and resources vulnerable.
Internet Security Measures
Here's an overview of the most important security measures and technologies widely implemented over the Internet. Implementing one or more of these methods will go a long way in securing your data online.
Routers with Encryption Facility
Using routers with in-built encryption technology can secure your wireless Internet connection and prevent snooping by external sources.
firewall:
Firewall is a software or hardware-based network security system that controls the incoming and outgoing network traffic by analyzing the data packets and determining whether they should be allowed through or not, based on applied rule set.
Using Antivirus Software
Using Antivirus Software: Computers may be affected by viruses, trojans, worms etc. due to some infected files downloaded from the Internet. These viruses are nothing but programs that install themselves and operate whenever the host programs run, causing malicious attacks.
Password Usage:
Passwords are used to prevent illegal access to networks to secure the entire system as a whole. Construction of passwords should be in a way that the other people do not easily guess it. Alphanumeric passwords with symbols used in between can be harder to crack.
antivirus
antivirus is protective software designed to defend your computer against malicious software. Malicious software, or "malware" includes: viruses, Trojans, keyloggers, hijackers, dialers, and other code that vandalizes or steals your computer contents. In order to be an effective defense, your antivirus software needs to run in the background at all times, and should be kept updated so it recognizes new versions of malicious software.Phishing is a type of Internet fraud that seeks to acquire a user's credentials by deception. It includes theft of passwords, credit card numbers, bank account details and other confidential information.
Phishing
Phishing messages usually take the form of fake notifications from banks, providers, e-pay systems and other organizations. The notification will try to encourage a recipient, for one reason or another, to urgently enter/update their personal data. Such excuses usually relate to loss of data, system breakdown, etc.
Preventing Spyware:

Several software programs pose a threat to Internet security. The software that runs along with other applications, without the permission of a user, gathering information and sending it to hackers through the internet, is known as spyware. Another software called ad-ware works similar to spyware. In addition, it pops up advertisements during Internet access and increases the CPU cycles, slowing down the computer. Antivirus software, with inbuilt antispyware or adware removal functionality, can be of great help in preventing such intrusions.