CHAPTER 7 – PROCEDURES FOR RESPONDING TO ATTACKS ON
COMPUTERS
TRUE/FALSE
1. Most disasters result from natural causes.
2. Theft of proprietary information was the source of the most serious financial loss in companies
surveyed.
3. The most expensive code attack was the Code Red virus at $8.75 billion.
4. The FBI defines Cyberterrorism as a violent act that intimidates a government and its citizens.
5. An internal threat would originate from any employee who has physical access to equipment and
legitimate rights to information within the organization.
6. Managing external threats is much easier than managing the risks from inside the organization.
7. Securing a system against intrusion is an immense and difficult task.
8. Most organizations have insurance that covers damage produced by major privacy violations.
9. The explosive growth of networks and Internet connections gives attackers almost limitless
opportunities to probe until they find a network with a security flaw they can exploit.
10. If an organization detects and confirms a breach in system security, its next step should be to collect as
much information as it can about the intrusion.
MODIFIED TRUE/FALSE
1. Small systems consist of file servers, applications servers, workstation servers, Web servers, and
mainframes. _________________________
2. The striping technique saves data simultaneously to separate hard drives or drive arrays.
_________________________
3. RAID also uses a technique called parity to determine whether data has been lost or over-written.
_________________________
4. When people or groups use computer technology, software, and networks to attack systems, they
launch a malicious code attack. _________________________
5. In the information warfare model, victims are classified as individuals, corporations, or countries.
_________________________
6. Threats, such as industrial espionage or a malicious act toward a senior staff member, are deliberate.
_________________________
7. Securing systems against direct or indirect attack requires dividing internal and external threats into
cohesive and manageable elements early in the business analysis. _________________________
8. The CERT Coordination Center provides professional information and security awareness services to
defense contractors, governments, and industrial security executives. _________________________
9. Until recently, the Organization for Cooperation and Development has been at the forefront of
addressing privacy issues ._________________________
10. Application-layer attacks often use ports that are allowed through a firewall.
_________________________
MULTIPLE CHOICE
1. In the Computer Crime and Security Survey 2002, what was the most frequent point of attack?
a.
Denial-of-service
c.
Internet connections
b.
Inappropriate e-mail
d.
Internal attacks
2. In the information warfare model, which of the following is a classification of victim?
a.
Personal
c.
Business
b.
Country
d.
Individual
3. With ____ attacks, an intruder takes control of many systems to launch an attack.
a.
application-layer
c.
denial-of-service
b.
TCP SYN flood
d.
IP-spoofing
4. What type of threat could originate from any employee who has physical access to equipment and
legitimate rights to information within the organization?
a.
Internal
d.
Indirect
b.
External
e.
a, c, and d
c.
Direct
5. Which of the following are all important parts of comprehensive IT security policies and procedures?
a.
Access controls
c.
System audits
b.
Physical security of sensitive systems
d.
All of the above
6. The ____ Web site provides information on the cost of downtime.
a.
SANS Institute
c.
Network Security Center
b.
Alternative Power Systems
d.
Downtime Central
7. The ____ Web site provides training and useful resources.
a.
Cisco Systems Inc.
c.
SANS Institute
b.
Microsoft Corporation
d.
FEMA
8. The ____ Web site provides information for protecting computer systems and handling computer
security incidents.
a.
FEMA
c.
CERT Coordination Center
b.
NSA
d.
FBI
9. The ____ Web site provides information that can serve as an introduction to disaster recovery
planning.
a.
Alternative Power Systems
c.
DHS
b.
Computer Security Products Inc.
d.
FEMA
10. The ____ Web site provides data on the hidden cost of downtime from a variety of articles, research
reports, and consulting firms.
a.
Downtime Central
c.
Computer Security Products Inc.
b.
Creative Data Concepts Ltd.
d.
SANS Institute
11. Which act was implemented to protect the privacy of people identified in information systems
maintained by federal executive branch agencies, and to control the collection, use, and sharing of
information?
a.
Privacy Act of 1974
b.
Telecommunications Act of 1996
c.
The Gramm-Leach-Bliley Act of 1999
d.
The Electronic Communications Privacy Act of 1986
12. Which legislation limits the use and disclosure of customer proprietary network information (CPNI) by
telecommunications service providers?
a.
Electronic Communications Privacy Act of 1986
b.
Communications Policy Act of 1984
c.
Telecommunications Act of 1996
d.
Video Privacy Protection Act of 1988
13. Which act authorizes sharing of the federal government information-gathering efforts with relevant
foreign, state, and local officials?
a.
The Electronic Communications Privacy Act of 1986
b.
The USA PATRIOT Act of 2001
c.
The Gramm-Leach-Bliley Act of 1999
d.
The Homeland Security Act of 2002
14. Which legislation requires financial institutions to disclose their privacy policies to customers?
a.
The Gramm-Leach-Bliley Act of 1999
b.
Children’s Online Privacy Protection Act of 1998
c.
Telecommunications Act of 1996
d.
Privacy Act of 1974
15. Which legislation requires Web site operators and online service providers to obtain parental consent
to collect a child’s personal information, and requires sites that collect information from children to
disclose how they plan to use the data?
a.
The Homeland Security Act of 2002
b.
Children’s Online Privacy Protection Act of 1998
c.
The Electronic Communications Privacy Act of 1986
d.
Privacy Act of 1974
16. ____ are programs that allow intruders to scan hundreds of thousands of systems quite quickly.
a.
Application-layer attack
c.
TCP SYN flood
b.
Autorooters
d.
Packet sniffers
17. ____ attacks focus on making a service unavailable for normal use, typically by exhausting some
resource within a network, operating system, or application.
a.
Application-layer
c.
TCP SYN flood
b.
Denial-of-service (DoS)
d.
IP-spoofing
18. ____ attacks can occur during the client-server “handshake”, a sequence of messages required when a
client attempts to establish a TCP connection to a server.
a.
Denial-of-service (DoS)
c.
TCP SYN flood
b.
Ping of death
d.
Stacheldraht
19. ____ attacks occur when a hacker inside or outside a network pretends to be a trusted computer.
a.
Ping of death
c.
Man–in-the-middle
b.
IP-spoofing
d.
Trojan horse
20. ____ combines features of several DoS attacks, including TFN.
a.
Man–in-the-middle
c.
Trojan horse
b.
Stacheldraht
d.
Trust exploitation
21. ____ are software applications that use a network adapter card in “promiscuous” mode.
a.
Trojan horses
c.
Autorooters
b.
Application-layer attacks
d.
Packet sniffers
22. ____ attacks can occur when a hacker has access to packets that come across a network.
a.
Trojan horse
c.
Port redirection
b.
Man–in-the-middle
d.
Trust exploitation
23. ____ attacks are repeated attempts to identify a user account and password.
a.
Backdoors
c.
Password attacks
b.
Trust exploitation
d.
Trojan horse
24. ____ are a type of trust exploitation attack that uses a compromised host to pass traffic through a
firewall that would otherwise be dropped.
a.
Password
c.
Man–in-the-middle
b.
IP-spoofing
d.
Port redirection
25. ____ attacks refer to malicious software that is attached to another program to execute an unwanted
function on a user workstation.
a.
Trojan horse
c.
IP-spoofing
b.
Backdoors
d.
Application-layer
26. Which of the following are procedures to follow after a computer attack?
a.
Prepare for law enforcement to enter the facility
b.
Review system logs for clues about the attackers point of entry
c.
Recommend security upgrades or changes
d.
All of the above
27. How many FBI field offices have established an InfraGard chapter?
a.
52
c.
56
b.
54
d.
58
28. What type of negative economic impact from computer attacks might include damage to systems, the
direct costs of repairing or replacing systems, and disrupted business and revenues?
a.
Immediate
c.
Short-term
b.
Mid-term
d.
Long-term
29. What type of negative economic impact from computer attacks might include lost contracts, sales, or
customers, a tarnished reputation, and problems in developing new business?
a.
Immediate
c.
Long-term
b.
Short-term
d.
Mid-term
30. What type of negative economic impact from computer attacks might include reduced market
valuation, stock prices, investor confidence, and goodwill toward the organization?
a.
Immediate
c.
Mid-term
b.
Short-term
d.
Long-term
31. In the table above, what does “B” represent?
a.
Dial-up modem
c.
Frame relay
b.
ISDN
d.
ATM
32. In the table above, what does “E” represent?
a.
T-1
c.
ATM
b.
T-3
d.
Frame relay
33. In the table above, what does “F” represent?
a.
Frame relay
c.
SONET
b.
T-3
d.
ATM
34. In the table above, what does “H” represent?
a.
T-1
c.
Wireless LAN bridge
b.
Frame relay
d.
VPN
YES/NO
1. Any business that uses computers and network technology must incorporate computer security into its
disaster recovery planning.
2. The motivations for computer attacks are all very similar.
3. The Senate is alone in writing cybersecurity legislation.
4. Mark Pollitt, a senior research fellow at the Institute for Security and Intelligence in California, was
credited for creating the term “cyberterrorism” – the convergence of cybernetics and terrorism.
5. The DHS strategy includes several points for protecting computer systems and telecommunications
systems.
6. The theft of national security information from a government agency or the interruption of electrical
power to a major metropolitan area would be more serious than the defacement of a Web site.
7. Dangers from inside the organization are usually created on purpose.
8. Any machine or network that is linked to another network is a potential target – the only secure system
is one with no outside connections.
9. Does the restriction of data access automatically safeguard the privacy of users?
10. Are social pressures on organizations to protect personal information increasing?
COMPLETION
1. The NIPC, with help from private industry, the academic community, and government agencies,
developed the ____________________ initiative to share information about cyberintrusions, exploited
vulnerabilities, and infrastructure threats.
2. ____________________ impacts include damage to systems, the direct costs of repairing or replacing
systems, and disrupted business and revenues.
3. ____________________ is lost if unauthorized changes are made to the data or IT system, either
intentionally or accidentally.
4. An organization may have to develop ____________________ estimates for damages, business losses,
and system restoration after a computer attack. This information might be needed by insurance
companies, law enforcement, and attorneys.
5. ____________________ sponsored the development of the Contingency Planning Guide for
Information Technology Systems:Recommendations of the National Institute of Standards and
Technology.
6. ____________________ are centralized groups of interconnected processors.
7. ____________________ ensures that data is always available by providing disk redundancy and
spreading data storage across multiple disk drives, rather than one.
8. According to the 2002 survey, ____________________ connections were the most frequent point of
attack.
9. International ____________________ is the unlawful use of force or violence by a group or person
with connections to a foreign power, or by a group whose activities transcend national boundaries.
10. The ____________________ was formed as a central authority to coordinate these efforts and develop
a seamless flow of information.
MATCHING
Match the following terms to the appropriate definitions.
a.
Autorooters
f.
Ping of death
b.
Information warfare
g.
Stacheldraht
c.
Loss of availability
h.
Terrorist incident
d.
Malicious code attack
i.
Trust exploitation attack
e.
Network reconnaissance
j.
Virus
1. An attack that combines features of several DoS attacks
2. Lost system functionality and effectiveness
3. A hacker takes advantage of a trust relationship within a network
4. Attacks that send oversized IP packets to a computer system
5. An organized effort to use cyberattacks to disrupt computer systems
6. Malicious software that is attached to another program
7. Computer code that is meant to damage or disrupt computer systems
8. Programs that automate the entire hacking process
9. A violent act that endangers human life
10. Gathering of information about a target network using publicly available data
SHORT ANSWER
1. The National Strategy for the Physical Protection of Critical Infrastructures and Key Assets document
calls for cooperation among government, industry ,and private citizens to protect which key assets?
(List 5)
ANS:
2. What steps can organizations take to cooperate with the DHS cyberspace strategy? (List 5)
ANS:
3. One popular model for categorizing threats separates information warfare into three categories. What
are they?
ANS:
4. What should organizations consider when developing procedures to deal with information warfare
threats and damages? (List all 5)
ANS:
5. To protect against cyberattacks and create an appropriate defense plan, organizations need a
combination of what 4 things?
ANS:
6. The national InfraGard program provides what 4 basic services to members?
ANS:
7. List and describe the negative economic effects an organization could endure as a result of computer
attacks or intrusions.
ANS:
8. The adverse impact of a hacking attack or intrusion can also be described in terms of what three types
of losses?
ANS:
9. List each of the systems and networks in an organization that require recovery.
ANS:
10. What should organizations do to help recover small systems after a computer attack?
ANS: