TU863 Digital Forensics and Cyber Security

  • Subject Code :  

    TU863

  • Country :  

    IE

  • University :  

    Technological University Dublin

Answers:

Introduction

The covid-19 pandemic has forced organizations to go for work from home policies to keep business running and Provide Services To Customers. However, considering the rising cyber-security attacks during the covid-19 pandemic it seems that organizations have to find ways to deal with cyber-security issues for protecting organizational resources and information from hackers and external cyber-security threats [1]. In this report, a Comparative study has been provided which has analyzed various cyber-security attacks and vulnerabilities which have been identified during Covid-19. It includes all the cybersecurity attacks which have affected organizations around the world during Covid-19 with detailed descriptions provided for each of these cyber-security attacks along with diagrams to provide a comprehensive overview regarding how these cyber-security attacks are executed and how systems are compromised by hackers and other malicious agents executing these cyber-security attacks for compromising information security of organizations.

In addition to this, strategies to improve cybersecurity defense and requirements for the security controls that organizations need to implement to address cyber-security threats as identified during covid-19 have been analyzed in detail in this report.

Cyber Security Issues 

Phishing is a process of acquiring personal information from victims such as account passwords and other sensitive data stored in the systems of victims. Phishing can be implemented through various methods such as email, phone call, voice or text message depending on the intention of hackers [2]. In this method, attackers will represent themselves as a legitimate person so that they can trick people into submitting information they want. During covid-19, phishing email-based data breach has increased significantly. 

Ransomware 

Another important cyber-security incident that has been rising during covid-19 is ransomware where an attacker will target a system and infect that with malware denying access to the system and information stored on such systems [3]. To get back access to that system, the owner of the system has to provide the amount asked by the hackers.

Similarities Between These Cyber-Security Attacks And Vulnerabilities 

Similar to ransomware, denial of service also infuses networks with malware. However, apart from this similarity, there are some important differences between these two types of malware-based cybersecurity attacks which are important to analyze for mitigating these malware-based threats [2].

Differences Between These Cyber-Security Attacks And Vulnerabilities

In order to execute a ransomware attack or DoS attack, it is required to gain access to the internal network of an organization for which phishing attacks is a preferred and widely applied technique often considered by hackers. An important difference between DoS and ransomware is that in a ransomware attack, attackers encrypt files and data on targeted systems and then will ask for money to decrypt them [4]. However, in DoS attack, the main aim of hackers is to simply take the system offline and denying access to these systems for authorized users.

Vulnerabilities During Covid-19 

Following are some of the challenges that are making it difficult for organizations to ensure a smooth and secured workflow while managing employees remotely: 

Increasing Exposure Of Data Due To Weak Password Management 

During covid-19 pandemics employees were given charge of their systems and accounts including creating and managing passwords. However, employees are not good enough at creating and managing their passwords. They often use the same passwords or use passwords that are not strong enough, increasing the chances of passwords being cracked and allowing hackers to access sensitive and confidential organizational data [2]. 

Using The Personal System For Work Purpose 

Employees have often used personal devices such as smartphones and laptops for accessing organizational information during work from due to Covid-19 pandemic. As personal devices are not secured enough due to a lack of security control measures, it increases the chances of data breach providing hackers access to sensitive and confidential business data [5]. 

Strategies To Educate Remote Workers During Covid-19

Analysis Of Requirements To Educate Awareness To The Remote Workers And Issues 

From the perspective of cyber-security control, it is important to identify that employees are the first point of defense and it becomes easier for hackers to establish control of organizational information infrastructure including network and servers if they get through this first point of defense that is the people of the organizations, the employees themselves. If the employees are not made aware enough of emerging cyber-security issues and ways to mitigate them through proper cyber defense techniques, then it affects the quality of cybersecurity controls implemented by the organizations to protect critical assets and information from external access [5]. Therefore, by educating employees on cyber-security issues so that they can follow pepper rules and techniques for mitigating cyber-security threats by exercising cyber-security best practices, organizations can better respond to cyber-security issues as identified during covid-19 as described in this context. 

However, there are some issues regarding educating remote workers for enhancing their level of cyber-security awareness. The issues that organizations need to consider while designing a training program for employees are the followings: 

Mode Of Training 

As employees are working remotely from home, training can be delivered only through virtual platforms. Virtual training is not as effective as training through workshops and seminars. Therefore, providing quality training and ensuring that everyone learns through these training programs as intended is an important issue in this regard [5]. 

Assessment Of Training Outcomes 

The effectiveness of any training program depends on the quality of the training delivered which can be only measured by analyzing the level of knowledge acquired by participants during training programs [1]. However, as employees are working remotely and training is provided only through virtual platforms, assessment of knowledge of employees after training programs is not that easy. 

Policy Implementation 

Another issue regarding providing training to remote employees is the implementation of policies and programs regarding employees training on cyber-security issues. To ensure that training programs are implemented properly through virtual platforms, changes need to be made in current programs and policies in the organization incorporating characteristics and requirements of remote working environments [6]. Therefore, it is an important issue that organizations need to consider designing and implementing training programs for educating employees for mitigating cybersecurity issues. 

Impact Of Moving To Remote Working And Challenges 

During the covid-19 pandemic, organizations had no other option rather than allowing their employees to work from home policies to keep their business and services running for minimizing the impact of a covid-19 pandemic on business and revenue. However, one of the main challenges that the organization is facing is a lack of control over employees who are using organization systems and whether they are following proper methods for accessing organizational networks and data to ensure security and privacy of data [3]. However, considering the rising number of cyber-security incidents, it implies that either organizations have not implemented proper security controls or employees are not following proper security measures for lack of awareness regarding this. Therefore, it has been extremely difficult for organizations to secure organizational assets and information from cyber-security threats [7]. 

Strategies To Improve And Security Controls That Organizations Can Implement 

Installing Remote Tracking Software 

It will help organizations to track employee activities online as well as offline and provide much more control on data security for having detailed insight regarding activities that may compromise security and data privacy [5]. 

Implementing Policy And Guidelines 

Organizations should implement detailed policy and guidelines regarding cyber-security best practices so that employees can comply with them and ensure security of systems and data. It should include areas such as password policy including guidelines on creating and managing passwords, identifying potential cyber security threats, systems allowed to access organizational data and other aspects for enhancing cyber security awareness of employees [6]. 

Installing Vpn In Official Systems 

While connecting to the internet for accessing data, it is required to ensure that connection to the network is safe and secure. If employees connect to the network through authentic VPN, security of connection can be enhanced and therefore, organizations should install legitimate VPNs in employee systems.

Conclusion

During the covid-19 pandemic as organizations have been forced to adopt work from home policies, it has been extremely difficult for them to secure organizational assets and information from cyber-security threats. As several cyber-security incidents like phishing, malware, Denial of Service (DoS) are rising, organizations need to implement proper security tools and security controls for restricting hackers and unauthorized users from accessing sensitive organizational information affecting organizational security and privacy. Therefore, enhancing awareness of employees through policies, education and extensive training along with the implementation of security control tools is important for mitigating cyber-security threats while enhancing security and privacy of data.

References 

[1] T. Weil and S. Murugesan, "IT Risk and Resilience—Cybersecurity Response to COVID-19," in IT Professional, vol. 22, no. 3, pp. 4-10, 1 May-June 2020, doi: 10.1109/MITP.2020.2988330.

[2] M. Hijji and G. Alam, "A Multivocal Literature Review on Growing Social Engineering Based Cyber-Attacks/Threats During the COVID-19 Pandemic: Challenges and Prospective Solutions," in IEEE Access, vol. 9, pp. 7152-7169, 2021, doi: 10.1109/ACCESS.2020.3048839.

[3] P. A. Schneck, "Cybersecurity During COVID-19," in IEEE Security & Privacy, vol. 18, no. 6, pp. 4-5, Nov.-Dec. 2020, doi: 10.1109/MSEC.2020.3019678.

[4] V. Soni, D. Kukreja and D. K. Sharma, "Security vs. Flexibility: Striking a Balance in the Pandemic Era," 2020 IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS), New Delhi, India, 2020, pp. 1-5, doi: 10.1109/ANTS50601.2020.9342779.

[5] F. Almeida, J. Duarte Santos and J. Augusto Monteiro, "The Challenges and Opportunities in the Digitalization of Companies in a Post-COVID-19 World," in IEEE Engineering Management Review, vol. 48, no. 3, pp. 97-103, 1 thirdquarter,Sept. 2020, doi: 10.1109/EMR.2020.3013206.

[6] S. Mandal and D. A. Khan, "A Study of Security Threats in Cloud: Passive Impact of COVID-19 Pandemic," 2020 International Conference on Smart Electronics and Communication (ICOSEC), Trichy, India, 2020, pp. 837-842, doi: 10.1109/ICOSEC49089.2020.9215374.

[7] A. K. Mishra, A. K. Tripathy and S. Swain, "Analysis and Prevention of Phishing Attacks in Cyber Space," 2018 First International Conference on Secure Cyber Computing and Communication (ICSCCC), Jalandhar, India, 2018, pp. 430-434, doi: 10.1109/ICSCCC.2018.8703343.

[8] I. A. Chesti, M. Humayun, N. U. Sama and N. Jhanjhi, "Evolution, Mitigation, and Prevention of Ransomware," 2020 2nd International Conference on Computer and Information Sciences (ICCIS), Sakaka, Saudi Arabia, 2020, pp. 1-6, doi: 10.1109/ICCIS49240.2020.9257708.

[9] S. Dong, K. Abbas and R. Jain, "A Survey on Distributed Denial of Service (DDoS) Attacks in SDN and Cloud Computing Environments," in IEEE Access, vol. 7, pp. 80813-80828, 2019, doi: 10.1109/ACCESS.2019.2922196.

[7] "What is a phishing attack?", cloudflare, 2021. [Online]. Available: https://www.cloudflare.com/learning/access-management/phishing-attack/. [Accessed: 06- Mar- 2021].

[8] "INTERPOL report shows alarming rate of cyberattacks during COVID-19", Interpol.int, 2021. [Online]. Available: https://www.interpol.int/News-and-Events/News/2020/INTERPOL-report-shows-alarming-rate-of-cyberattacks-during-COVID-19. [Accessed: 06- Mar- 2021].

[9] S. Van Horn, "Kaspersky Report: Criminals Targeted Remote Work In 2020", Businesswire.com, 2021. [Online]. Available: https://www.businesswire.com/news/home/20201210005650/en/Kaspersky-Report-Criminals-Targeted-Remote-Work-In-2020. [Accessed: 06- Mar- 2021].

[10] "https://www.mcafee.com/enterprise/en-us/assets/reports/rp-quarterly-threats-july-2020", mcafee, 2021. [Online]. Available: https://www.mcafee.com/enterprise/en-us/assets/reports/rp-quarterly-threats-july-2020. [Accessed: 06- Mar- 2021].

[11] T. Dargahi, A. Dehghantanha, P. Bahrami, M. Conti, G. Bianchi and L. Benedetto, "A Cyber-Kill-Chain based taxonomy of crypto-ransomware features", Journal of Computer Virology and Hacking Techniques, vol. 15, no. 4, pp. 277-305, 2019. Available: 10.1007/s11416-019-00338-7.

Looking for the best assignment help in the UK? Look no further! We have got the best assignment paper writers to back you up with quality solutions on the go. So, if you are wondering, “Who will do my assignment for me?” or “Can I pay someone to do my assignment?” simply count on our expertise and soar high in your academic pursuits. No matter whether you are looking for essay help, coursework help, dissertation help or primary homework help, we have got your back. Connect with us today and allow our experts to craft the finest of academic papers exclusively for you.

Why Student Prefer Us ?
Top quality papers

We do not compromise when it comes to maintaining high quality that our customers expect from us. Our quality assurance team keeps an eye on this matter.

100% affordable

We are the only company which offers qualitative and custom assignment writing services at low prices. Our charges will not burn your pocket.

Timely delivery

We never delay to deliver the assignments. We are very particular about this. We assure that you will receive your paper on the promised date.

Round the clock support

We assure 24/7 live support. Our customer care executives remain always online. You can call us anytime. We will resolve your issues as early as possible.

Privacy guaranteed

We assure 100% confidentiality of all your personal details. We will not share your information. You can visit our privacy policy page for more details.

Upload your Assignment and improve Your Grade

Boost Grades