Author: clarkoperations

  • OSI in a Nutshell (Open Systems Interconnection)

    Open Systems Interconnection (OSI) is a reference model for understanding and developing compatible networking and communication practices. The OSI model illustrates the relationships between all components of a network and provides a framework that allows each layer to serve distinct purposes and work independently of each other according to their separate functions. Froehlich (2021) argues that the OSI model is “theoretical in nature and should only be used as a general guide,” but it serves an important purpose in creating a clear framework for understanding how a telecommunication system should work. The different terminologies and formats between the different OSI model layers help make distinctions between the specific roles and tasks that take place throughout a network and aid in the planning, design, and troubleshooting of the network. In 1984, the International Organization for Standardization (ISO) proposed Open Systems Interconnection (OSI) as a common framework for networking technology.

    The OSI uses conceptual abstraction to separate the layers into compartmentalized slices based on function that can be evaluated as a piece at a time (Froehlich, 2021). The seven layers of the OSI model work in cascading hierarchy, each layer serving the layer above it and being served by the layer below it. The highest layer is the application layer which is followed by the presentation layer, session layer, transport layer, network layer, data-link layer, and finally the physical layer. The OSI model creates a framework that benefits from its adaptability, security, and flexibility; and has become a standard model in networking.

    The disadvantages of the OSI model include the fact that layers cannot work in parallel with each other and they must wait for the next layer to send data to them, the session layer and the presentation layer aren’t as useful as the other layers, and it is a theoretical model that has physical restrictions on its practical implementation (Froehlich, 2021).

    References

    Froehlich, A. (2021). OSI model (Open Systems Interconnection). TechTargethttps://www.techtarget.com/searchnetworking/definition/OSI

  • WordPress Elementor Pro Vulnerability

    Millions of unpatched WordPress websites are now at risk of a vulnerability that was discovered between the Elementor Pro and the WooCommerce plug-ins for WordPress (Lakshmanan, 2023). The vulnerability is actively being exploited by hackers in the wild and enables the threat actors to gain full administrative control over the victim’s website. Once the attacker has gained administrative access, they can forward the domain to malicious websites, or set up a back door system to further exploit the website in the future. On March 18, 2023, the discovery of the vulnerability was credited to Jerome Bruandet, who is a security researcher for NinTechNet.

    This exploit applies to retail technology in a massive scale due to the popularity of both the WordPress Elementor and WooCommerce plug-ins, and the sheer number of websites that also use a combination of the two plug-ins is immense. WooCommerce allows a vendor’s WordPress site to sell products through an online-store functionality including integration with multiple types of payment vendors. Elementor is used primarily as a quick layout tool to design pages in WordPress. It is important that anyone who administrates an e-commerce website should make daily back-ups and updates to their websites databases and plug-ins so that the consequences of these types of vulnerabilities can be minimized.

    References

    Lakshmanan, R. (2023). Hackers Exploiting WordPress Elementor Pro Vulnerability: Millions of Sites at Risk! TheHackerNewshttps://thehackernews.com/2023/04/hackers-exploiting-wordpress-elementor.html

  • What is Cyber Risk?

    Cyber risk is the exposure to the possibility of incurring a loss of any kind through an information technology infrastructure.

    Losses can include financial resources, operations capabilities, or the receiving of various fees or lawsuits; maybe after some sensitive customer data is affected. Cyber risk can be measured quantitatively by using traditional risk analysis with the added consideration of the additional factors of cyber threats. Cyber security operates at all four of the reputational, operational, legal, and financial levels of a business, and the management of all these levels must be considered in a cyber risk analysis process.

    Social Engineering taking place over the phone.

    One common real-world cyber risk is social engineering which exploits a company’s weakest vulnerability, its people. Social engineering can best be combatted through employee training programs that create awareness about the dangers of social engineering and teach employees how to recognize signs of an attack.

    Another real-world cyber risk is poor cyber-hygiene which describes the unhealthy habits that some users practice when interacting with information technology. Passwords are a part of cyber security that a lot of users practice bad habits with such as writing passwords down on sticky notes. One of the best ways to improve cyber-hygiene is to create awareness around the issues with training and possibly reminders.

    The difference between quantitative and qualitative measurement in cyber risk is in the type of result that is generated from the analysis. Qualitative analysis uses logical speculation to evaluate specific scenarios, their potential for vulnerability, and possible solutions. Quantitative analysis assigns numeric values to components of the risk analysis model for mathematical comparison.

    Showcasing different types of risk analysis as it applies to cyber risk.

    Inherent cyber risk is the amount of risk that exists without security controls. It is quantified by calculating the cost of business interruption, data exfiltration, regulatory fees, insurance needs, etc.

    Residual cyber risk is the amount of risk with cyber security controls in place. Residual risk considers the effectiveness of cyber security controls and assesses their correlations to vulnerabilities, security assessments, research, and security tools.

    Cybersecurity frameworks can outline the effectiveness of tools through a set of tests to find how well the tools are positioned so that they will positively affect the overall security posture.

    Examples of cyber security risk management frameworks in use today include the NIST framework and the ISO 27001 framework.

    The NIST framework takes an approach of combining all the management activities required for acceptability under regulations, laws, and polices; as well as conducting proper security and privacy practices and integrates them into the organization’s development life cycle. The NIST framework is developed by the Joint Task Force (JTF) and can be applied to any organization type, technology type, or even to organizations with legacy systems.

    References

    Evans, A. (2019). Managing Cyber Risk. Taylor & Francis. https://online.vitalsource.com/books/9780429614262