4/24/2009

Exercise 15

1. What makes a firewall a good security investment? Accessing the Internet, find two or three firewall vendors. Do they provide hardware, software or both?

Wikipedia (2009) states that a firewall is a part of a computer system or network that is designed to block unauthorized access while permitting outward communication. It is also a device or set of devices configured to permit, deny, encrypt, decrypt, or proxy all computer traffic between different security domains based upon a set of rules and other criteria.

Bidgoli (2004) tells me that security is a critical aspect of extranet development, which extends to both the orgranization and its partners. Security issues must be considered through the design, implementation, and management of any extranet applications. Developing a security plan for an extranet application should begin with a risk assessment to identify the pontential sources of threat to the network, how likely these threats are to occur, and the investment (cost) in security that will be required. The level of security investment will vary depending on the nature of the extranet application, the threats of intrusion, and the sensitivity of the information shared on the extranet. Extranet security should consider authentication and access control, privacy and data integrity.

As firewall is used in access control, it makes a good security investment.

I have found that Cisco is a hardware firewall vendor and ZoneAlarm is a software firewall vendor. Please see the following link which introduces their famous product:

For Cisco, please go to
http://www.cisco.com/en/US/products/ps5708/Products_Sub_Category_Home.html

For ZoneAlarm, please go to
http://www.zonealarm.com/security/en-us/zonealarm-pc-security-free-firewall.htm

2. Find our if your university or workplace has a backup policy in place. Is it followed and enforced?

I can't find any backup policy from my university and workplace


3. Most of the antivirus software perform an active scanning of the use of activity on the internet, detecting downloads and attachments in e-mails. Hackers have readily available resources to create new viruses. How easy is it to find a virus writing kit? Search the Internet and find such a tool, For example, see what you can find at http://vx.netlux.org/dat/vat.shtml.

I use a search engine named google and input the search criteria such "virus writing kit" or "virus creation kit" or "virus construction kit", i can find there is a lots of that type of tools for me to download....


For example:

From netlux web (http://vx.netlux.org) which contains a massive, continuously updated collection of magazines, virus samples, virus sources, polymorphic engines, virus generators, virus writing tutorials, articles, books, news archives etc.

References:

Wikipedia (2009). “Firewall”. Received 20th April, 2009 from URL - http://en.wikipedia.org/wiki/Firewall

Bidgoli (2004). John Wiley and Sons. "The Internet encyclopedia ", "securtiy of internet", p278.

沒有留言:

發佈留言