Security Technologies: Implementation Problems and its Strengths and Weaknesses
Biometric identification is a technology that identifies and authenticates individuals based on physical characteristics. A biometric identification system includes fingerprint identification, iris and retina, facial recognition, gait, or voice.
It’s faster and more convenient for users (no need to remember passwords)
Strong authentication since biological characteristics are distinct
Eliminates friction associated with traditional security measures
Biometric servers usually require less database memory
Environment and usage can affect measurements
Systems are not 100% accurate.
Require integration and/or additional hardware
Cannot be reset once compromised
i. Biometrics aren’t private
Biometrics seem secure on the surface. After all, you’re the only one with your ears, eyes, and fingerprint. But that doesn’t necessarily make it more secure than passwords. A password is inherently private because you are the only one who knows it. Of course hackers can acquire it by brute force attacks or phishing, but generally, people can’t access it. On the other hand, biometrics are inherently public.
Think about it: your ears, eyes, and face are exposed. You reveal your eyes whenever you look at things. With fingerprint recognition you leave fingerprints everywhere you go. With voice recognition, someone is recording your voice. Essentially, there’s easy access to all these identifiers.
Your image is stored in more places than you realize. Not only does Facebook recognize your face, but every store you visit records and saves your image in its database to identify you and analyze your buying habits. In fact, it’s legal in 48 states to use software to identify you using images taken without your consent for commercial purposes. And law enforcement agencies nationwide can store your image without consent.
The problem is identity management and security. Personal identifiable information (PII) needs to have access control in place to protect from identity theft. All it takes is for a hacker to breach any of those databases to leak and steal your biometric identification.
ii. Biometrics are Hackable
Once a hacker has a picture of someone’s ear, eye, or finger, they can easily gain access to their accounts. While Apple’s TouchID was widely accepted as a biometric advancement, famous hacker Jan Krissler was able to beat the technology just a day after the iPhone was released. Likewise, researchers from the Chaos Computer Club created fake fingers to unlock iPhones.
Krissler showed how easy it is to steal a public figure’s identification when he recreated German Minister of Defense Ursula von der Leyen’s fingerprint. The hacker obtained high-resolution photos of the politician’s thumb from press conferences and reconstructed the thumbprint using VeriFinger software.
If you think an eye scan may be more secure, think again. Hackers fooled the Samsung S8 iris recognition system by placing a contact lens over a photo of a user’s eye. And it wasn’t a high-priced hack either. The S8 phone was the most expensive purchase of the hack project.
iii. Biometrics Hacks May Have Greater Consequences
Since a biometric reveals part of a user’s identity, if stolen, it can be used to falsify legal documents, passports, or criminal records, which can do more damage than a stolen credit card number.
The Office of Personnel Management breach in 2015 compromised 5.6 million people’s fingerprints. And unlike passwords, credit cards, or other records, you can’t replace physical identifiers. If someone has photos of your iris, you can’t get another eye.
Biometric companies are aware of these flaws in the technology and should aim to improve identification. There are some ways to deter inherent downfalls of biometrics like requiring more than one fingerprint scan to improve accuracy. Bank of America said its iris scan will be a part of multi-factor authentication instead of the sole way to access accounts.
Biometrics may be the security measure of the future, but it isn’t time to discard your passwords yet. Biometrics provide another level of security, but it’s not foolproof.
https://blog.ipswitch.com/3-reasons-biometrics-are-not-secure
https://www.sestek.com/2016/11/advantages-disadvantages-biometric-authentication/
Encryption is the process of encoding data, making it unintelligible and scrambled. In a lot of cases, encrypted data is also paired with an encryption key, and only those that possess the key will be able to open it.
An encryption key is a collection of algorithms designed to be totally unique. These are able to scramble and unscramble data, essentially unlocking the information and turning it back to readable data.
Provides Security for Data at All Times
Encrypted Data Maintains Integrity
Encryption is Part of Compliance
Protects Data across Devices
There are many different levels at which you need to encrypt your data. Strong security means thinking about physical security — if someone is able to gain physical access to your server or data center, they can potentially decrypt your data if they steal the device. Using disk-level encryption of data at rest helps protect against physical theft of data. If someone were to pull out a few drives from a storage array, they wouldn't be able to recover any of the data.
Aiello also describes the challenges with commercial software and encryption. Another challenge is the administration of the server. One question to ask is if your cloud provider allows you the option of using a VPN (Virtual Private Network) so you can manage your own servers securely.
https://www.techworld.com/security/what-is-encryption-3659671/
https://www.smartdatacollective.com/5-advantages-using-encryption-technology-data-protection/
https://smallbusiness.chron.com/disadvantages-public-key-encryption-68149.html
http://www.onlinetech.com/resources/videos/challenges-to-encrypting-data
3. Access control software
Access control is a security technique that regulates who or what can view or use resources in a computing environment. It is a fundamental concept in security that minimizes risk to the business or organization.
Varying Levels of Security
i. A Need for Consistency
Access control is a security measure that requires consistency in order to successfully protect data within a system. With this, there can sometimes be many inconsistencies in its implementation, as there are many different ways that data is transported within a company. Some examples of this include data that moves across cloud storage, servers, and mobile wifi that can put data at risk.
ii. Determining Your Control Model
While there are several different control models available to suit your access control system, the most common is the Role Based Access Control (RBAC) model, in which user access is determined by need and privilege associated with their role in the organization. This model prevents other users from accessing sensitive information that is not necessary to their role.
iii. A Need for Various Solutions
Most access control models, including the above mentioned RBAC model, often require more than one form of technology to successfully implement the security measure. This can sometimes involve multi factor authentication to ensure secure access from only specific individuals who should be accessing that information.
iv. Strengthening Authorization Measures
Accurately determining authorization measures for every employee within an organization can be a challenge for any business. One of the greatest challenges in this is consistently monitoring your access control system for any unusual activity so that you can proactively stop security threats before they start. Part of this is regularly conducting compliance and vulnerability checks on your system to ensure that everything is running properly and no data is at risk.
v. A Need for Flexibility
Just as technology is ever changing in the world today, your access control system should be well equipped to adapt to any changes as necessary. This includes updated applications and increased security checks to safeguard your system and eliminate any minor risks before they grow and pose a major threat to your organization.
https://searchsecurity.techtarget.com/definition/access-control
https://www.techwalla.com/articles/advantages-and-disadvantages-of-access-control-systems
https://www.arksysinc.com/blog/5-challenges-faced-implementing-access-control-organization/
A firewall denotes the set of related programs which are situated between a private network and external networks. It is normally located at the network’s gateway server and helps protect the resources of a private network. The term can also denote security policy. It can take on different forms while doing its job of blocking unauthorized and unwanted traffic from entry into a protected system. A firewall can be a specialized software program or a specialized hardware or physical device. It could also be a combination of both. Examples of these are Zone Alarm which is a software only firewall and Linksys, hardware firewall.
Strengths: (Software Firewall)
Ideal for home or personal use.
Very easy to configure and reconfigure with no requirement of specialised skills.
Easier to install and upgrade especially in comparison with hardware routers. The levels of security can be set with a few simple clicks of the mouse during installation.
Flexibility – they allow the specification of applications that will be allowed to connect with the internet.
Mobility – a software firewall moves with the computer regardless of the location it is on.
Weakness: (Software Firewall)
May slow down system applications since it is installed on the system itself and requires more memory and disk space.
May also prove costly because such a firewall has to be purchased separately for each computer on the network.
It maybe unwieldy to remove from the system.
Such firewalls cannot be configured to mask IP addresses. They only close unused ports and monitor traffic to and from open ports.
May not be capable of fast reaction.
Strengths: (Hardware Firewall)
A single such firewall can provide protection for an entire network regardless of multiple computers.
They work independent of system performance and speed since they are not situated on computers.
They are more effective when companies use broadband internet connections like DSL or cable modem.
It is less prone to malicious software.
They are tailored for swift response and can handle more traffic load.
Since it has its own operating system, it is less prone to attacks. They also have enhanced security controls.
Ease of maintenance since a hardware firewall is typically situated in a standalone box, it is easier to disconnect or shutdown the box and minimize interference or downtime to the rest of the system.
Weakness: (Hardware Firewall)
They treat outgoing traffic as safe and may fail if a malware is attempting to connect to the internet from within.
They may be more complex to configure.
Takes up more physical space with its added wiring.
Software firewalls that only block inwards traffic such as the Windows XP default firewall are useless at detecting programs on your system that are trying to communicate without your knowledge. This has become a big problem, particularly if you have the bad luck to install malware by mistake, because with this type of Firewall you will miss easily generated warnings that you have a problem.
Two software firewalls are dysfunctional. They usually fight each other and your system grinds to a halt (Honourable exception Unix where an Itables firewall like configuration might well coexist with a higher level firewall but this is detail for Nerds)
Configuring a firewall can be difficult if you want maximum security and functionality. Luckily most decent firewalls now come with reasonable defaults with good interfaces.
Software firewalls need to be enabled during the bootup process just after network connections enabled and disabled just before the network connection is closed. Vanilla Windows XP failed to do this, by not switched on its default firewall by default, and then only switched it on late in the bootup process. Some of us watched the ensuring virus infection disaster from safer sidelines.
Software firewalls can be disabled by user action or during updates. Hardware firewalls are safer.
Some say you only need a hardware firewall. The problem is that few hardware firewalls will stop outward traffic from an unwanted program. Also they do not protect you if you bypass them via say a dial up modem when your broadband connection goes down. This is potentially particularly problematical if you have Windows file or printing sharing enabled as computers out there are testing all the time for this wonderful exploitable back door into a computer system. It is also probably part of the explaination Microsoft did not switch on the original XP firewall by default...all software development and most beta testing would have been done behind hardware firewalls.
Uninstalling Software Firewalls can be problematical. Problems have been reported with Norton ++ and ZoneAlarm. Some have never uninstalled the free ZoneAlarm and have just updated it for over 5 years so are happy with this software.
https://www.certificationkits.com/cisco-certification/ccna-security-certification-topics/ccna-security-implement-firewalls-with-sdm/ccna-security-operational-strength-a-weaknesses-of-firewalls/
http://www.ganfyd.org/index.php?title=Issues_with_Firewalls