Wednesday, May 6, 2020
The Importance Of Motivation And Inspiration By Natasha...
ââ¬Å"The ones who say ââ¬Å"you canââ¬â¢tâ⬠and ââ¬Å"you wonââ¬â¢tâ⬠are probably the ones who are afraid that you will.â⬠(MGQ) During my entire life, there was always someone who did not want to see me excel in life. They were always hoping for the negative outcomes instead of pushing me to keep going. They always tell me that ââ¬Å"you canââ¬â¢tâ⬠or ââ¬Å"you wonââ¬â¢tâ⬠, but they never motivated me to go for something worth trying! When I was little I always dreamed of being a softball player. I thought the red clay, the helmet hair, the scars, the bruises, and the sisterly love bond was what I wanted to be a part of. I would walk around throwing everything, running and sliding as if I was on a field. Motivation and inspiration comes from the positive ones around you. Throughout my younger days and to this day, Natasha Watley has inspired me to be who I am today. She has experienced a life comparable to my own, therefore she could pass her positive inspiration down to those like me. This is why I continuously try my best. Giving up is never an option. When I was around six years old, my mother asked me ââ¬Å"Do you want to play little league tee-ball?â⬠Of course, my response was ââ¬Å"Yesâ⬠because being a part of a team was what I had been waiting for. As the big day approached, it was a sunny, bright day; the birds were whistling and the sun was beaming down like never before. About midday, it was time for our first practice. By this time, I was so thrilled that I was smiling from ear to ear, I was dressed from head to
Tuesday, May 5, 2020
Social Networking and Digital Learning â⬠MyAssignmenthelp.com
Question: Discuss about the Social Networking and Digital Learning. Answer: Introduction It has been found that the social networking sites have been successful in widening the abilities of the students to perform their work. This has been possible through the practise of the twenty-first century skills that would enable students to develop themselves as successful and meaningful individuals (Manca Ranieri, 2017). The aim of this paper is to engage in a research review though identification of social networking sites as a mean of imparting education along with the social and pedagogical implications of social networking sites. This is followed by a discussion on the use of social networking sites through a critical review of selected literature and the reflection and supportive research of the social networking sites in the field of education. Facebook, Twitter, Myspace and Instagram have become names in the lives of the millennials. But these are more than social networking sites for the present generation. The existing education systems have understood the importance of virtual communication in imparting education. Virtual communication and online technology facilitates connection between people who are situated in different parts of the world (Lamberton Stephen, 2016). It is believed that the role of social media in the field of education is not to substitute traditional form of learning with digital learning. It was believed that instead of using white board and powerpoint as a tool of communicating with the class, the materials elicited from the social networking sites like photos, online videos, interactive dialogues, blogs can emerge from the discussion boards, virtual meetings, recorded text messages and the online forums present on the social media sites. The educator through the usage of social media transforms from being a educator to a content provider. This has led to the learning environment being fluid enabling students to provide instant feedback and facilitate exchange in terms of study tools. Kalasi (2014) have stated that social media have become increasingly important in the lives of individual. She contends about the social constructivist theory and how it is based on the interaction and socialization with other people that have the potential to help students so that they construct and learn from their personal learning processes. Social media she argues is a range of constructive tools that can catalyse participative learning module that ahve been incorporated into the new-age teaching. Hung Yuen, (2010), in their paper argues about the concept of communities of practice, this emphasise on learning in-context. Social networking technology provides people with an unrecognizable force and enables them to communicate. Social networking platforms provides the students additional channels to learn electronically. It can also be employed for the purpose of extension and reaching out to learners who otherwise might not have been involve in the process of learning. These tec hnologies will turn out to be useful for students who are reticent and may find it difficult to show up in class. In the present context, students are using the Facebook Social Learning Project that includes posts by instructors, teaching assistants. It was found that the popular social media platform , Facebook provides the students an opportunity to utilize the it for their educational purpose. In future, they would want Facebook to incorporate quizzes, mobile features, games that would make the classes all the more interesting and informative. A 2010 Pew study conducted in the National School Boards Association showed that Facebook is used by 58 per cent of the millennials out of the 96 per cent who are on Facebook utilize it for the discussion of their school homework (Ngai et al., 2015). Despite these, schools have been apprehensive in employing social media as an educational tool. It has been found that there has been a high interest in the harnessing of social networking sites for the objectives of education. The survey found that people who have used social networks were more positive ab out the advantages of social media as compared to people who have not made much use of social media. Social networking sites have the power to improve the motivation of the students and foster engagement in education. Students would develop a collaborative standpoint of learning and make a connection with the real world. Social networking sites enable the educators to share information, create a professional space for learning and improvise on the worldwide communications of schools with the staff and the students. . Students in the world of social networking sites are not only making use of the online material but generating content and are interacting with the fellow students. Conclusion Therefore, from the above discussion it can be understood that if utilized properly, social networking sites have the potential to become an integral and indispensable part of tthe educational environment. References Hung, H. T., Yuen, S. C. Y. (2010). Educational use of social networking technology in higher education.Teaching in higher education,15(6), 703-714. Kalasi, R. (2014). The impact of social networking on new age Teaching and learning: an overview.Journal of education social policy,1(1), 23-28. Lamberton, C., Stephen, A. T. (2016). A thematic exploration of digital, social media, and mobile marketing: Manca, S., Ranieri, M. (2017). Implications of social network sites for teaching and learning. Where we are and where we want to go.Education and Information Technologies,22(2), 605-622. Newman, G., Wiggins, A., Crall, A., Graham, E., Newman, S., Crowston, K. (2012). The future of citizen science: emerging technologies and shifting paradigms.Frontiers in Ecology and the Environment,10(6), 298-304. Ngai, E. W., Moon, K. L. K., Lam, S. S., Chin, E. S., Tao, S. S. (2015). Social media models, technologies, and applications: an academic review and case study. Industrial Management Data Systems,115(5), 769-802.
Monday, April 6, 2020
The Young Offenders Act - The Truth Essays - Criminology
The Young Offenders Act - The Truth? This essay was written to show the advantages and disadvantages of the Young Offenders Act over the previous Juvenile Delinquents Act. Also it should give a theoretical understanding of the current Canadian Juvenile-Justice system, the act and it's implications and the effects of the young offenders needs and mental health on the outcome of the trials. In the interest of society the young offenders act was brought forth on april second 1984. This act was created to ensure the rights and the needs of a young person. Alan W. Leshied says "On one hand the justice and legal objectives of the act are being effectively realized while on the other hand the needs and treatment aspects of it leave much to be desired." The research of the Young offenders act is still ongoing but Leshied says that it is becoming clear that the custody positions have been in dispute since the act came into effect. The old Juvenile delinquency act states in section 38 "The care and custody and discipline of a juvenile delinquent shall approximate as nearly as maybe that which should be given by his parents, and... as far as practability every juvenile delinquent shall be treated, not as a criminal, but as a misguided and misdirected child . . . needing aid, encouragement, help and assistance."(Page 72) If a youth is close to the adult age of 18 years they could be transfered to the adult justice system. This means that they would be given the same sentences as an adult including and up to life in prison. Many people have tried to correct this problem that they see as a weakness. Yet, so far their attempts have failed. Another weakness they find, is that the courts are expensive and unsatisfactory methods of dealing with crime that is not very serious. Before the fabrication of legal aid most young offenders were not able to obtain legal services. "Subsection 11 (4) provides that, were a young person wishes to obtain counsel but is not able to do so, the youth-court judge shall refer the young person to the provincial legal-aid, or assistance program. If no such program is available or the young person is unable to obtain counsel through an available program, the youth court judge may, and on the request of the young person shall direct the young person to be represented by counsel." To establish a relationship between the young offender and the lawyer, thew lawyer must be able to receive instructions from his/her client. Usually there is little difficulty either receiving or carrieing out the instructions of his/her client. Special problems can arise when the client is a young person. The problems faced by this, is the young person may not be able to communicate with counsel. While the lawyer and young person need not a specific statement for the client as to a preferred outcome it should take form of a general expression of the client's feelings or attitudes in the major issues of the precedings the young person must be able to make decisions that may hold significant repercussions. Mental health of the young offender can also be a problem. Currently this issue is not addressed in the Young Offenders Act, before the mental health act can be enacted, extremely dangerous behaviour must be displayed. Before the age of 16 they are sometimes placed in hospitals for a short time under the authority of the legal guardians.
Sunday, March 8, 2020
Free Essays on Why Adult Stem Cells Are Better Than Embryonic Stem Cells
STEM CELL RESURCH By: Zacchaeus Nash Why adult stem cells are better than embryonic stem cells. In this paper I will try to inform you the reader of the importance and adaptability of Biotechnologyââ¬â¢s finest researchers. In the beginning they started with embryonic stem cells which found resistance from the American public, in the way of pro-life advocates. Which, lead the strike that the human embryo should be treated in a respectful manner and not to be used for research. With this challenge in the way the Biotechnologist looked for another way to secure the all necessary stem cells. They would find them in adult patients and in doing so they by pass the controversy. Letââ¬â¢s start off with the definition of a stem cell. It is a cell that can replicate indefinitely and which can differentiate into other cells; stem cells serve as a continuous source of new cells (from the biotech life science dictionary). Now, if stem cells can form into a cell in the body it is only logical to look for them in the first part of human life: the embryo. Since humans start from one cell which in turn forms into a fully functional human being. With this said the Biotechnologist looked in the most logical place to find them in the embryo, in which they did. As their research became public, the American people began to question the moral issue at hand. It did not take them long to deem it morally and socially wrong. From their stand point the embryo is a life and should be treated with the same respect of all human life. As, the president of the United States would say ââ¬Å"We should not, as a society, grow life to destroy it.â⬠He soon would push congress and the house into passing legislation against human cloning and stem cell research. Telling the researchers that the 77 strains of cells would be more than enough to perform the required research. This meant that the Biotechnologist had to look for a less controversial source o... Free Essays on Why Adult Stem Cells Are Better Than Embryonic Stem Cells Free Essays on Why Adult Stem Cells Are Better Than Embryonic Stem Cells STEM CELL RESURCH By: Zacchaeus Nash Why adult stem cells are better than embryonic stem cells. In this paper I will try to inform you the reader of the importance and adaptability of Biotechnologyââ¬â¢s finest researchers. In the beginning they started with embryonic stem cells which found resistance from the American public, in the way of pro-life advocates. Which, lead the strike that the human embryo should be treated in a respectful manner and not to be used for research. With this challenge in the way the Biotechnologist looked for another way to secure the all necessary stem cells. They would find them in adult patients and in doing so they by pass the controversy. Letââ¬â¢s start off with the definition of a stem cell. It is a cell that can replicate indefinitely and which can differentiate into other cells; stem cells serve as a continuous source of new cells (from the biotech life science dictionary). Now, if stem cells can form into a cell in the body it is only logical to look for them in the first part of human life: the embryo. Since humans start from one cell which in turn forms into a fully functional human being. With this said the Biotechnologist looked in the most logical place to find them in the embryo, in which they did. As their research became public, the American people began to question the moral issue at hand. It did not take them long to deem it morally and socially wrong. From their stand point the embryo is a life and should be treated with the same respect of all human life. As, the president of the United States would say ââ¬Å"We should not, as a society, grow life to destroy it.â⬠He soon would push congress and the house into passing legislation against human cloning and stem cell research. Telling the researchers that the 77 strains of cells would be more than enough to perform the required research. This meant that the Biotechnologist had to look for a less controversial source o...
Friday, February 21, 2020
Geology Essay Example | Topics and Well Written Essays - 1750 words
Geology - Essay Example Communities concerns about cause of continuous coastline erosion, oceanographic hazards, coastline modification, mining of aggregates in islands and vulnerability of shores to coastal erosion and other oceanographic hazards. Beaches in the UK area are not excepted from these threats. In the crown of Britains Bournemouth, premier tourist resorts are located. Today, there are about 5.2 million European, global and UK visitors who arrive in the town annually to enjoy the magnificent sweep of Poole Bay. In UK, no other beach draws so many visitors as these premier resorts. The seafront is extremely important leisure and recreational amenity particularly among local residents in the the areas of Bournemouth, Christchurch Poole Conurbation and outlying Hinterland (Bournemouth Borough Council, 2006; p 3). The Bournemouth Borough Council serves as the steward of the several works ranging from commercial, public and voluntary stakeholders who find seafront as a significant economic driver for their town. The public is challenged to sustain their seafront both as a public amenity and a visitor attraction; at the same time preserving the fragile qualities of its environment. The Bournemouth Seafront has a local and global reputation which is family and customer-centered. The project envisioned to manage the project within the context of long term sustainability so the future generations can be provided with important public recreational amenity. The project is viewed as one with economic relevance of the seafront; comprises of volume attraction that can be achieved in a most environmentally effective and cost efficient manner (p 6). Bournemouth seafront can be seen with large infrastructure and diverse range of buildings that supported the use of beaches with 7 miles length set in a very harsh, natural yet changing environment. The management of this tourist spot is in partnership private and public
Wednesday, February 5, 2020
Antitrust and Regulation Term Paper Example | Topics and Well Written Essays - 1250 words
Antitrust and Regulation - Term Paper Example The law is premised on the belief that free trade benefits the economy, businesses and the consumers by forbidding various restrains of trade and monopolization. It falls under four areas namely agreement between competitors, contractual arrangements between sellers and buyers the pursuit or maintenance of monopoly power and mergers (Wilberforce, 98). The law of competition can be dated two centuries ago, the medieval monarchs and the Roman Empire used tariff systems to control prices and support local production. The formal study of competition can be dated in the 18th century with works of Adam Smith when he wrote about the wealth of Nation. Different terms were used to describe the law which include restrictive practices, the law of monopolies, combination acts, and the restraint of trade. The law can be seen to have three main elements which include prohibiting agreements or practices that restricts free trade and competition between business premises, it element focuses mainly on repression of cartels. Second is the banning of abusive behaviors by firms dominating a market or anti competitive practices that may tend to lead to dominance (Bork, 126). Among the practices controlled by this are predatory pricing, tying, and refusal to deal, among others. Lastly there is the supervision of mergers and acquisition of large corporations including joint values. Transactions thought to threaten competitive process can be prohibited all together. Approved subjects to remedies for example an obligation to divest part of the merged business the merged business, that is, to offer license or access to facilities that enable other businesses to continue competing. The contents and practice of competition law varies s from one jurisdiction to another. In many countries the main objective of the law is to protect the interests of thee consumer or safeguarding the consumer welfare, and ensuring that entrepreneurs have an equal opportunity to compete in the market economy. The law is also closely related to the law of deregulation of access to the market, state aids and subsidies, privatization of state assets, and the establishment of independe nt sector regulators. In the past decades the law has been viewed as way to provision of better public services (Whish, 198). According to Robert Bork competition has been found to have created adverse effects when they reduce competition through protecting the inefficient competitor and when the cost of legal intervention is higher then the consumer benefits more. The business practices of market traders' guilds and governments have always been scrutinized and sometimes severe sanctions have been placed. Dating back from the 19th century competition law has been now embraced globally. The largest and the most influential law systems being the United States antitrust law and the European community competition law. National and regional competitions authorities across the world have formed to incorporate international support and enforcement networks (Bork, 127). In microeconomics and strategic management horizontal merger refers to a type of ownership and control. It is used by businesses as a strategy that seeks to sell a type of products in many markets or numerous markets. It is much more common compared to vertical
Tuesday, January 28, 2020
Computers Insiders Threat
Computers Insiders Threat While attacks on computers by outside intruders are more publicized, attacks perpetrated by insiders are very common and often more damaging. Insiders represent the greatest threat to computer security because they understand their organizations business and how their computer systems work. They have both the confidentiality and access to perform these attacks. An inside attacker will have a higher probability of successfully breaking into the system and extracting critical information. The insiders also represent the greatest challenge to securing the company network because they are authorized a level of access to the file system and granted a degree of trust. A system administrator angered by his diminished role in a thriving defense manufacturing firm whose computer network he alone had developed and managed, centralized the software that supported the companys manufacturing processes on a single server, and then intimidated a coworker into giving him the only backup tapes for that software. Following the system administrators termination for inappropriate and abusive treatment of his coworkers, a logic bomb previously planted by the insider detonated, deleting the only remaining copy of the critical software from the companys server. The company estimated the cost of damage in excess of $10 million, which led to the layoff of some 80 employees. An application developer, who lost his IT sector job as a result of company downsizing, expressed his displeasure at being laid off just prior to the Christmas holidays by launching a systematic attack on his former employers computer network. Three weeks following his termination, the insider used the username and password of one of his former coworkers to gain remote access to the network and modify several of the companys web pages, changing text and inserting pornographic images. He also sent each of the companys customers an email message advising that the website had been hacked. Each email message also contained that customers usernames and passwords for the website. An investigation was initiated, but it failed to identify the insider as the perpetrator. A month and a half later, he again remotely accessed the network, executed a script to reset all network passwords and changed 4,000 pricing records to reflect bogus information. This former employee ultimately was identified as the perpetrator and prosecuted. He was sentenced to serve five months in prison and two years on supervised probation, and ordered to pay $48,600 restitution to his former employer. A city government employee who was passed over for promotion to finance director retaliated by deleting files from his and a coworkers computers the day before the new finance director took office. An investigation identified the disgruntled employee as the perpetrator of the incident. City government officials disagreed with the primary police detective on the case as to whether all of the deleted files were recovered. No criminal charges were filed, and, under an agreement with city officials, the employee was allowed to resign. These incidents of sabotage were all committed by ââ¬Å"insiders:â⬠individuals who were, or previously had been, authorized to use the information systems they eventually employed to perpetrate harm. Insiders pose a substantial threat by virtue of their knowledge of, and access to, employer systems and/or databases. Keeney, M., et al (2005) The Nature of Security Threats The greatest threat to computer systems and information comes from humans, through actions that are either malicious or ignorant 3 . Attackers, trying to do harm, exploit vulnerabilities in a system or security policy employing various methods and tools to achieve their aims. Attackers usually have a motive to disrupt normal business operations or to steal information. The above diagram is depicts the types of security threats that exist. The diagram depicts the all threats to the computer systems but main emphasis will be on malicious ââ¬Å"insidersâ⬠. The greatest threat of attacks against computer systems are from ââ¬Å"insidersâ⬠who know the codes and security measures that are in place 45. With very specific objectives, an insider attack can affect all components of security. As employees with legitimate access to systems, they are familiar with an organizations computer systems and applications. They are likely to know what actions cause the most damage and how to get away with it undetected. Considered members of the family, they are often above suspicion and the last to be considered when systems malfunction or fail. Disgruntled employees create mischief and sabotage against systems. Organizational downsizing in both public and private sectors has created a group of individuals with significant knowledge and capabilities for ma licious activities 6 and revenge. Contract professionals and foreign nationals either brought into the U.S. on work visas to meet labor shortages or from offshore outsourcing projects are also included in this category of knowledgeable insiders. Common Insider Threat Common cases of computer-related employee sabotage include: changing data; deleting data; destroying data or programs with logic bombs; crashing systems; holding data hostage; destroying hardware or facilities; entering data incorrectly, exposing sensitive and embarrassing proprietary data to public view such as the salaries of top executives. Insiders can plant viruses, Trojan horses or worms, browse through file systems or program malicious code with little chance of detection and with almost total impunity. A 1998 FBI Survey 7 investigating computer crime found that of the 520 companies consulted, 64% had reported security breaches for a total quantifiable financial loss of $136 millions. (See chart) The survey also found that the largest number of breaches were by unauthorized insider access and concluded that these figures were very conservative as most companies were unaware of malicious activities or reluctant to report breaches for fear of negative press. The survey reported that the average cost of an attack by an outsider (hacker) at $56,000, while the average insider attack cost a company in excess $2.7 million. It found that hidden costs associated with the loss in staff hours, legal liability, loss of proprietary information, decrease in productivity and the potential loss of credibility were impossible to quantify accurately. Employees who have caused damage have used their knowledge and access to information resources for a range of motives, including greed, revenge for perceived grievances, ego gratification, resolution of personal or professional problems, to protect or advance their careers, to challenge their skill, express anger, impress others, or some combination of these concerns. Insider Characteristics The majority of the insiders were former employees. â⬠¢ At the time of the incident, 59% of the insiders were former employees or contractors of the affected organizations and 41% were current employees or contractors. â⬠¢ The former employees or contractors left their positions for a variety of reasons. These included the insiders being fired (48%), resigning (38%), and being laid off (7%). Most insiders were either previously or currently employed full-time in a technical position within the organization. â⬠¢ Most of the insiders (77%) were full-time employees of the affected organizations, either before or during the incidents. Eight percent of the insiders worked part-time, and an additional 8% had been hired as contractors or consultants. Two (4%) of the insiders worked as temporary employees, and one (2%) was hired as a subcontractor. â⬠¢ Eighty-six percent of the insiders were employed in technical positions, which included system administrators (38%), programmers (21%), engineers (14%), and IT specialists (14%). Of the insiders not holding technical positions, 10% were employed in a professional position, which included, among others, insiders employed as editors, managers, and auditors. An additional two insiders (4%) worked in service positions, both of whom worked as customer service representatives. Insiders were demographically varied with regard to age, racial and ethnic background, gender, and marital status. The insiders ranged in age from 17 to 60 years (mean age = 32 years)17 and represented a variety of racial and ethnic backgrounds. Ninety-six percent of the insiders were male. Forty-nine percent of the insiders were married at the time of the incident, while 45% were single, having never married, and 4% were divorced. Just under one-third of the insiders had an arrest history. Thirty percent of the insiders had been arrested previously, including arrests for violent offenses (18%), alcohol or drug related offenses (11%), and nonfinancial/ fraud related theft offenses (11%). Organization Characteristics The incidents affected organizations in the following critical infrastructure sectors: â⬠¢ banking and finance (8%) â⬠¢ continuity of government (16%) â⬠¢ defense industrial base (2%) â⬠¢ food (4%) â⬠¢ information and telecommunications (63%) â⬠¢ postal and shipping (2%) â⬠¢ public health (4%) In all, 82% of the affected organizations were in private industry, while 16% were government entities. Sixty-three percent of the organizations engaged in domestic activity only, 2% engaged in international activity only, and 35% engaged in activity both domestically and internationally. What motivate insiders? Internal attackers attempt to break into computer networks for many reasons. The subject has been fruitfully studied and internal attackers are used to be motivated with the following reasons [BSB03]: â⬠¢ Challenge Many internal attackers initially attempt to break into networks for the challenge. A challenge combines strategic and tactical thinking, patience, and mental strength. However, internal attackers motivated by the challenge of breaking into networks often do not often think about their actions as criminal. For example, an internal attack can be the challenge to break into the mail server in order to get access to different emails of any employee. â⬠¢ Revenge Internal attackers motivated by revenge have often ill feelings toward employees of the same company. These attackers can be particularly dangerous, because they generally focus on a single target, and they generally have patience. In the case of revenge, attackers can also be former employees that feel that they have been wrongfully fired. For example, a former employee may be motivated to launch an attack to the company in order to cause financial losses. â⬠¢ Espionage Internal attackers motivated by espionage, steal confidential information for a third party. In general, two types of espionage exists: Industrial espionage Industrial espionage means that a company may pay its own employees in order to break into the networks of its competitors or business partners. The company may also hire someone else to do this. International espionage International espionage means that attackers work for governments and steal confidential information for other governments. Definitions of insider threat 1) The definition of insider threat should encompass two main threat actor categories and five general categories of activities. The first actor category, the ââ¬Å"true insider,â⬠is defined as any entity (person, system, or code) authorized by command and control elements to access network, system, or data. The second actor category, the ââ¬Å"pseudo-insider,â⬠is someone who, by policy, is not authorized the accesses, roles, and/or permissions they currently have but may have gotten them inadvertently or through malicious activities. The activities of both fall into five general categories: exceeds given network, system or data permissions; conducts malicious activity against or across the network, system or data; provided unapproved access to the network, system or data; circumvents security controls or exploits security weaknesses to exceed authorized permitted activity or disguise identify; or non-maliciously or unintentionally damages resources (network, system or data) by destruction, corruption, denial of access, or disclosure. (Presented at the University of Louisville Cyber Securitys Day, October 2006) 2) Insiders ââ¬â employees, contractors, consultants, and vendors ââ¬â pose as great a threat to an organizations security posture as outsiders, including hackers. Few organizations have implemented the policies, procedures, tools, or strategies to effectively address their insider threats. An insider threat assessment is a recommended first step for many organizations, followed by policy review, and employee awareness training. (Insider Threat Management Presented by infoLock Technologies) 3)Employees are an organizations most important asset. Unfortunately, they also present the greatest security risks. Working and communicating remotely, storing sensitive data on portable devices such as laptops, PDAs, thumb drives, and even iPods employees have extended the security perimeter beyond safe limits. While convenient access to data is required for operational efficiency, the actions of trusted insiders not just employees, but consultants, contactors, vendors, and partners must be actively managed, audited, and monitored in order to protect sensitive data. (Presented by infoLock Technologies) 4) The diversity of cyber threat has grown over time from network-level attacks and password cracking to include newer classes such as insider attacks, email worms and social engineering, which are currently recognized as serious security problems. However, attack modeling and threat analysis tools have not evolved at the same rate. Known formal models such as attack graphs perform action-centric vulnerability modeling and analysis. All possible atomic user actions are represented as states, and sequences which lead to the violation of a specie safety property are extracted to indicate possible exploits. (Ramkumar Chinchani, Anusha Iyer, Hung Ngo, Shambhu Upadhyaya) 5) The Insider Threat Study, conducted by the U.S. Secret Service and Carnegie Mellon Universitys Software Engineering Institute CERT Program, analyzed insider cyber crimes across U.S. critical infrastructure sectors. The study indicates that management decisions related to organizational and employee performance sometimes yield unintended consequences magnifying risk of insider attack. Lack of tools for understanding insider threat, analyzing risk mitigation alternatives, and communicating results exacerbates the problem. (Dawn M. Cappelli, Akash G. Desai) 6) The insider threat or insider problem is cited as the most serious security problem in many studies. It is also considered the most difficult problem to deal with, because an insider has information and capabilities not known to other, external attackers. But the studies rarely define what the insider threat is, or define it nebulously. The difficulty in handling the insider threat is reasonable under those circumstances; if one cannot define a problem precisely, how can one approach a solution, let alone know when the problem is solved? (Matt Bishop 2005) Five common insider threat Exploiting information via remote access software A considerable amount of insider abuse is performed offsite via remote access software such as Terminal Services, Citrix and GoToMyPC. Simply put, users are less likely to be caught stealing sensitive information when they can it do offsite. Also, inadequately protected remote computers may turn up in the hands of a third-party if the computer is left unattended, lost or stolen. 2.) Sending out information via e-mail and instant messaging Sensitive information can simply be included in or attached to an e-mail or IM. Although this is a serious threat, its also one of the easiest to eliminate. 3.) Sharing sensitive files on P2P networks Whether or not you allow peer-to-peer file sharing software such as Kazaa or IM on your network, odds are its there and waiting to be abused. The inanimate software in and of itself is not the problem its how its used that causes trouble. All it takes is a simple misconfiguration to serve up your networks local and network drives to the world. 4.) Careless use of wireless networks Perhaps the most unintentional insider threat is that of insecure wireless network usage. Whether its at a coffee shop, airport or hotel, unsecured airwaves can easily put sensitive information in jeopardy. All it takes is a peek into e-mail communications or file transfers for valuable data to be stolen. Wi-Fi networks are most susceptible to these attacks, but dont overlook Bluetooth on smartphones and PDAs. Also, if you have WLANs inside your organization, employees could use it to exploit the network after hours. 5.) Posting information to discussion boards and blogs Quite often users post support requests, blogs or other work-related messages on the Internet. Whether intentional or not, this can include sensitive information and file attachments that put your organization at risk. Views of different authors about insider threat 1) Although insiders in this report tended to be former technical employees, there is no demographic ââ¬Å"profileâ⬠of a malicious insider. Ages of perpetrators ranged from late teens to retirement. Both men and women were malicious insiders. Their positions included programmers, graphic artists, system and network administrators, managers, and executives. They were currently employed and recently terminated employees, contractors, and temporary employees. As such, security awareness training needs to encourage employees to identify malicious insiders by behavior, not by stereotypical characteristics. For example, behaviors that should be a source of concern include making threats against the organization, bragging about the damage one could do to the organization, or discussing plans to work against the organization. Also of concern are attempts to gain other employees passwords and to fraudulently obtain access through trickery or exploitation of a trusted relationship. Insiders can be stopped, but stopping them is a complex problem. Insider attacks can only be prevented through a layered defense strategy consisting of policies, procedures, and technical controls. Therefore, management must pay close attention to many aspects of its organization, including its business policies and procedures, organizational culture, and technical environment. Organizations must look beyond information technology to the organizations overall business processes and the interplay between those processes and the technologies used. (Michelle Keeney, J.D., Ph.D. atal 2005) 2) While attacks on computers by outside intruders are more publicized, attacks perpetrated by insiders are very common and often more damaging. Insiders represent the greatest threat to computer security because they understand their organizations business and how their computer systems work. They have both the confidentiality and access to perform these attacks. An inside attacker will have a higher probability of successfully breaking into the system and extracting critical information. The insiders also represent the greatest challenge to securing the company network because they are authorized a level of access to the file system and granted a degree of trust. (Nam Nguyen and Peter Reiher, Geoffrey H. Kuenning) 3) Geographically distributed information systems achieve high availability that is crucial to their usefulness by replicating their state. Providing instant access at time of need regardless of current network connectivity requires the state to be replicated in every geographical site so that it is locally available. As network environments become increasingly hostile, we have to assume that part of the distributed information system will be compromised at some point. The problem of maintaining a replicated state in such a system is magnified when insider (or Byzantine) attacks are taken into account. (Yair Amir Cristina Nita-Rotaru) 4) In 2006, over 60% of information security breaches were attributable to insider behavior, yet more than 80% of corporate IT security budgets were spent on securing perimeter defenses against outside attack. Protecting against insider threats means managing policy, process, technology, and most importantly, people. Protecting against insider threats means managing policy, process, technology, and most importantly, people.The Insider Threat Assessment security awareness training, infrastructure reconfiguration, or third party solutions, you can take comfort in knowing that you have made the right choice to improve your security posture, and you will achieve your expected Return on Security Investment. (Presented by infoLock Technologies) 5) The threat of attack from insiders is real and substantial. The 2004 ECrime Watch Survey TM conducted by the United States Secret Service, CERT à ® Coordination Center (CERT/CC), and CSO Magazine, 1 found that in cases where respondents could identify the perpetrator of an electronic crime, 29 percent were committed by insiders. The impact from insider attacks can be devastating. One complex case of financial fraud committed by an insider in a financial institution resulted in losses of over $600 million. 2 Another case involving a logic bomb written by a technical employee working for a defense contractor resulted in $10 million in losses and the layoff of 80 employees. (Dawn Cappelli, Andrew Moore, Timothy Shimeall,2005) 6) Insiders, by virtue of legitimate access to their organizations information, systems, and networks, pose a significant risk to employers. Employees experiencing financial problems have found it easy to use the systems they use at work everyday to commit fraud. Other employees, motivated by financial problems, greed, or the wish to impress a new employer, have stolen confidential data, proprietary information, or intellectual property from their employer. Lastly, technical employees, possibly the most dangerous because of their intimate knowledge of an organizations vulnerabilities, have used their technical ability to sabotage their employers system or network in revenge for some negative work-related event. (Dawn M. Cappelli, Akash G. Desai ,at al 2004) 7) The insider problem is considered the most difficult and critical problem in computer security. But studies that survey the seriousness of the problem, and research that analyzes the problem, rarely define the problem precisely. Implicit definitions vary in meaning. Different definitions imply different countermeasures, as well as different assumptions. (Matt Bishop 2005) Solution: User monitoring Insiders have two things that external attackers dont: privileged access and trust. This allows them to bypass preventative measures, access mission-critical assets, and conduct malicious acts all while flying under the radar unless a strong incident detection solution is in place. A number of variables motivate insiders, but the end result is that they can more easily perpetrate their crimes than an outsider who has limited access. Insiders can directly damage your business resulting in lost revenue, lost customers, reduced shareholder faith, a tarnished reputation, regulatory fines and legal fees. With such an expansive threat, organizations need an automated solution to help detect and analyze malicious insider activity. These are some points which could be helpful in monitoring and minimizing the insider threats: Detecting insider activity starts with an expanded log and event collection. Firewalls, routers and intrusion detection systems are important, but they are not enough. Organizations need to look deeper to include mission critical applications such as email applications, databases, operating systems, mainframes, access control solutions, physical security systems as well as identity and content management products. Correlation: identifying known types of suspicious and malicious behavior Anomaly detection: recognizing deviations from norms and baselines. Pattern discovery: uncovering seemingly unrelated events that show a pattern of suspicious activity From case management, event annotation and escalation to reporting, auditing and access to insider-relevant information, the technical solution must be in line with the organizations procedures. This will ensure that insiders are addressed consistently, efficiently and effectively regardless of who they are. Identify suspicious user activity patterns and identify anomalies. Visually track and create business-level reports on users activity. Automatically escalate the threat levels of suspicious and malicious individuals. Respond according to your specific and unique corporate governing guidelines. Early detection of insider activity based on early warning indicators of suspicious behavior, such as: Stale or terminated accounts Excessive file printing, unusual printing times and keywords printed Traffic to suspicious destinations Unauthorized peripheral device access Bypassing security controls Attempts to alter or delete system logs Installation of malicious software The Insider Threat Study? The global acceptance, business adoption and growth of the Internet, and of Internetworking technologies in general, in response to customer requests for online access to business information systems, has ushered in an extraordinary expansion of electronic business transactions. In moving from internal (closed) business systems to open systems, the risk of malicious attacks and fraudulent activity has increased enormously, thereby requiring high levels of information security. Prior to the requirement for online, open access, the information security budget of a typical company was less then their tea and coffee expenses. Securing cyberspace has become a national priority. In The National Strategy to Secure Cyberspace, the Presidents Critical Infrastructure Protection Board identified several critical infrastructure sectors10: banking and finance information and telecommunications transportation postal and shipping emergency services continuity of government public health Universities chemical industry, textile industry and hazardous materials agriculture defense industrial base The cases examined in the Insider Threat Study are incidents perpetrated by insiders (current or former employees or contractors) who intentionally exceeded or misused an authorized level of network, system, or data access in a manner that affected the security of the organizations data, systems, or daily business operations. Incidents included any compromise, manipulation of, unauthorized access to, exceeding authorized access to, tampering with, or disabling of any information system, network, or data. The cases examined also included any in which there was an unauthorized or illegal attempt to view, disclose, retrieve, delete, change, or add information. A completely secure, zero risk system is one which has zero functionality. Latest technology high-performance automated systems bring with them new risks in the shape of new attacks, new viruses and new software bugs, etc. IT Security, therefore, is an ongoing process. Proper risk management keeps the IT Security plans, policies and procedures up to date as per new requirements and changes in the computing environment. To implement controls to counter risks requires policies, and policy can only be implemented successfully if the top management is committed. And policys effective implementation is not possible without the training and awareness of staff. The State Bank of Pakistan recognizes that financial industry is built around the sanctity of the financial transactions. Owing to the critical role of financial institutions for a country and the extreme sensitivity of their information assets, the seriousness of IT Security and the ever-increasing threats it faces in todays open world cannot be overstated. As more and more of our Banking Operations and products services become technology driven and dependent, consequently our reliance on these technology assets increases, and so does the need to protect and safeguard these resources to ensure smooth functioning of the financial industry. Here are different area in which we can work and check insider threat, but I chose textile industry as in textile industry there is less awareness of the insider threat. If an insider attack in an industry then industrialist try to cover up this news as these types of news about an industry can damage the reputation of the industry. CHAPTER 2 REVIEW OF LITRATURE S, Axelsson. ,(2000) Anonymous 2001 Continuity of operations and correct functioning of information systems is important to most businesses. Threats to computerised information and process are threats to business quality and effectiveness. The objective of IT security is to put measures in place which eliminate or reduce significant threats to an acceptable level. Security and risk management are tightly coupled with quality management. Security measures should be implemented based on risk analysis and in harmony with Quality structures, processes and checklists. What needs to be protected, against whom and how? Security is the protection of information, systems and services against disasters, mistakes and manipulation so that the likelihood and impact of security incidents is minimised. IT security is comprised of: Confidentiality: Sensitive business objects (information processes) are disclosed only to authorised persons. ==> Controls are required to restrict access to objects. Integrity: The business need to control modification to objects (information and processes). ==> Controls are required to ensure objects are accurate and complete.
Subscribe to:
Posts (Atom)