BTEC FPT INTERNATIONAL COLLEGE INFORMATION TECHNOLOGY ASSIGNMENT 1 UNIT: SECURITY STUDENT : LE VAN HANH CLASS : IT 05102 STUDENT ID : BD00130 SUPERVISOR: Nguyen The Xuan Ly Da Nang, March 2023 Performed Student: LE VAN HANH ASSIGNMENT 1 FRONT SHEET Qualification BTEC Level 4 HND Diploma in Computing Unit number and title Unit2: Security Date received (1st Submission date 13/3/2023 13/03/2023 submission) Re-submission date Date received (2nd submission) Student name Student ID LE VAN HANH BD00130 Class IT 102 Assessor name Nguyen The Xuan Ly Student declaration I certify that the assignment submission is entirely my own work and I fully understand the consequences of plagiarism. I understand that making a false declaration is a form of malpractice. Student’s signature: LE VAN HANH Grading grid P1 P2 P3 P4 M1 M2 D1 Performed Student: LE VAN HANH ❒ Summative Feedbacks: ❒Resubmission Feedbacks: Grade: Assessor Signature: Date: Internal Verifier’s Comments: Signature & Date: Performed Student: LE VAN HANH ACKNOWLEDGMENTS First of all, allow me to thank my family for giving me so much encouragement, love and timely help. They were clearly the most important motivators for me to complete this report.
Secondly, I also appreciate Mr. Xuan Ly NGUYEN THI because his lectures and instructions are a rich source of knowledge for me to refer to. Third, a big thank you to all my BTEC friends for the memorable times we had. Last but not least, I express my deep gratitude to all the authors who have generously provided excellent wisdom to be used as a reference throughout this document.
Performed Student: LE VAN HANH ASSURANCE I certify that this assignment is my own work, based on my own research and my own acknowledges all materials and sources used in the preparation, whether it is books, articles, lecture notes and any other type of material, electronic or personal communication. I also certify that this assignment has not previously been submitted for review in any other unit, unless specifically authorized by all relevant unit coordinators, or at any other time. in this unit and I have not copied in whole or in part plagiarism or otherwise plagiarism of the work of others. Learners declaration I certify that the work submitted for this assignment is my own and research sources are fully acknowledged.
Student signature: Student signature Date: Performed Student: LE VAN HANH TABLE OF CONTENT BTEC FPT INTERNATIONAL COLLEGE. 2 ASSIGNMENT 1 FRONT SHEET.6 Chapter: I ASSESS RISK TO IT SECURITY. Identify types of security threat to organisations (P1). Identify threats agents to organizations.
List type of threats that organizations will face. Give an example of a recently publicized security breach and discuss its consequences. What are the recent 2018/2019/2020 security breach? List and give examples with dates. Discuss the consequences of this breach?.
Suggest solutions to organizations. Describe at least 3 organizational security procedures (P2). 19 Chapter: II Describe IT security solutions. Identify the potential impact to IT security of incorrect configuration of firewall policies and IDS (P2).
Discuss briefly firewall and policies, its usage and advantages in a network. How does a firewalls provide a security to a network?. Define IDS, its usage, show with diagrams examples. Write down the potential impact(Threat-Risk) of FIREWALL and IDS incorrect configuration to the network.
Show, using an example for each, how implementing a DMZ, static IP and NAT in a network can improve Network Security (P4). Define and discuss with the aid of a diagram DMZ focus on usage and security function as advantage. Define and discuss with the aid of a diagram static IP focus on usage and security function as advantage. Define and discuss with the aid of a diagram NAT focus on usage and security function as advantage.
Propose a method to assess and treat IT security risks (M1). Discuss methods required to assess it security threat? E. What are the current weakness or threat of the organization?. What tools will you propose to treat the IT security risk?.
39 Performed Student: LE VAN HANH IV. Discuss three benefits to implement network monitoring systems with supporting reasons (M2). List some of the networking monitoring devices and discuss each. Why do you need to monitor network?.
What are the benefits of monitoring a network? .43 Performed Student: LE VAN HANH LIST OF FIGURES Figure 1 Infrastructure of Happy company. 11 Figure 2: Photo threat security. 14 Figure 3: Photo proceduce of security. 19 Figure 4 Definition of firewall.
23 Figure 5 Photo diagram of firewalls. 26 Figure 6 Photo IDS. 28 Figure 7 Photo IDS. 28 Figure 8 Photo of DMZ.
30 Figure 9 Photo statics IP for server. 32 Figure 10 Definition of NAT in security. 34 Figure 11 Tool Nessus vulnerability scanner. 36 Figure 12 Tool Qualys vulnerability management.
37 Figure 13 Tool metaspiloit framework. 38 9 LIST OF THE ACRONYM Entity relationship Diagram DMZ Demilitarized Zone IP Internet Protocol NAT Network address translation 10 INTRODUCTION In the current 4.0 technology era, information technology develops as fast as the wind, exploiting and ensuring information security is increasingly prioritized and concerned, posing a great concern for data security. is quite important of joint enterprises. So how and how to ensure good security is not known to everyone, but today McAfee is a company specializing in providing information security solutions for businesses and organizations.
Our project today has the participation of a company specializing in providing food from rural to urban areas, which is Happy Company. Before going into the analysis, I would like to discuss a few things about Happy Company. The company is a four-story building located in the countryside far from the city with the following distribution system: Figure 1 Infrastructure of Happy company The 1st, 2nd and 3rd floors are for employees, engineers, marketing, accounting, 11 materials, human resources and the 4th floor is for directors and staff, divided into 30 departments. There are 28 departments for employees including departments such as engineering, accounting and sales, each with 10-12 computer desks, 1 printer and 1 surveillance camera.
Each floor has 10 identical rooms. A VLAN system is created for each branch. The remaining rooms are allocated for private purposes such as storage rooms, document rooms, meeting rooms, event rooms and reception halls. The wireless system provides wireless connection for 300 devices at the same time, the access point is installed on the floor between the 1st and 2nd floors in the center of the reception hall.
The 3rd floor is installed with a separate VLAN. Finally, the fourth floor belongs to the company's executive board, which includes the chief executive officer, CEO, CFO, CTO, and their secretary. Because this floor is full of people with important company information, when accessing wifi, it is necessary to have high security and reduce IP for it to increase security. At the floor, there are 3 building guards on duty from 6:30 to 23:00, the building is covered with a surveillance camera system in key areas, many people pass by.
The control system is located in the security room. The same requirements are required by Happy Company to use services such as FTP, DNS and Web. Some additional services are added like VPN, remote access, VoIP. As an employee of the IT Security Specialist of Vietnam's leading security consulting group McAfee Information Security Le Van Hanh, authorized and authorized by Mr.
Kha Tran, I would like to introduce briefly below summarizes the tools and techniques involved in identifying and assessing IT security risks, along with the organization's policies for data protection. equipment and business-critical data, and simulate and provide basic recommendations for the security of your Happy Company. 12 When usage it? - Static IP addresses are often used in situations where you need consistent and reliable access to a device or service, such as a website hosting service or email server. They are also useful in situations where network administrators want to maintain control over which devices are allowed to access the network.
The following static IP addresses can be configured for use in the following scenarios: - First, static IP addresses are often used for hosting services, such as web servers, email servers, or FTP servers, because the service needs to be accessed consistently on the same IP address. - Static IP addresses can be used in network monitoring because they make it easy to identify specific devices and track their activity over time. Then it can be more secure to have fewer dynamic IP addresses as they are less susceptible to attacks like IP spoofing. - Static IP addresses can be useful for remote network access because they allow access to devices from anywhere with an internet connection.
- Limited availability: Static IP addresses can be more difficult and expensive to obtain than dynamic IP addresses, as they are typically reserved for business and enterprise use. - Configuration and maintenance: Setting up and maintaining a static IP address can be more complicated and time consuming than a dynamic IP address, as each device needs to be manually configured with its own IP address. Disadvantages and Advantages of statics IP. o Advantages of statics IP.
- Let's talk about reliability first: it is many times more reliable with DHCP configurable ip because it cannot be changed, making it easier to access devices or services that require a consistent IP address. - About security: set up advanced security measures such as firewalls, access control lists and intrusion detection systems to restrict access to the network. - Easier remote access: remote devices or services are easier because you can access them with the same IP address all the time. - Improve network performance: Static IP addresses can improve network performance as they eliminate the overhead associated with dynamic IP address assignment.
o Disadvantages of statics IP. - With many advantages in terms of security, it also has the following disadvantages: - The first is time consuming: because when we configure with a small number of machines and servers, it will feel normal, but if the number is large, it is very time consuming and it leads to complications when re-linking and transferring data. 33 - Difficult to configure as the first drawback because of the large number it cannot remember or do anything. - Next comes the static IP address which is not flexible and cannot be changed easily.
- Higher cost: Since a large number of static IP addresses are needed, it can be more expensive than using dynamic IP addresses, which are often included in basic network packages. Define and discuss with the aid of a diagram NAT focus on usage and security function as advantage. Definition of NAT. Figure 10 Definition of NAT in security.
- Network Address Translation (NAT) is used in computer networks to allow multiple devices of one or more private networks to share a public IP address. NAT is usually implemented by a router such as a Router or firewall device located between a private network and the public internet. - Purpose of NAT. - The main purpose of NAT is to preserve, or so-called protection, public IP addresses, by allowing multiple devices to share a single public IP address.
Without NAT, each device on a private network would require its own public IP address to connect to the internet, which would quickly deplete the supply of available public IP addresses, and when not NAT then it can also face risks such as stealing information from the computer's private ip. When usage it? - In a NAT environment, a router or firewall device sits between a private network and the public internet. When a device on a private network sends a request to the internet, the router/firewall replaces the private IP address with its own public IP address. Hence NAT is used to preserve public IP 34 addresses, as it allows multiple devices to share one IP address.