Answer To: Research Report task Value: 15% Due Date: 24-Aug-2018 Return Date: 14-Sep-2018 Length: Submission...
Soumi answered on Aug 22 2020
Running Head: COMPUTER SECURITY BREACHES 2017-18 1
COMPUTER SECURITY BREACHES 2017-18 7
INFORMATION TECHNOLOGY
ASSESSMENT: COMPUTER SECURITY BREACHES 2017-18
Executive Summary
The report discusses in-depth the nature and meaning of Ransomwares and their types namely WannaCry and Petya. The reports explain the latest security breach of Reddit, in which users’ data was compromised between 2005 and 2007. It further discusses the methods to prevent the occurrence of security breach in the future. In the other part, it explains the differences, scope and operational details of the attack and finally methods to prevent the same and how vigilance is important on the part of users to prevent further security lapses in the future.
Table of Contents
Part A 4
Reddit Security Breach 4
The methods to prevent security breach 5
Part B 7
A Comparative analysis between WannaCry and Petya Cyber Attack 7
Scope of the WannaCry and Petya Cyber Attack 8
Operational details of the WannaCry and Petya Cyber Attack 8
Actionable steps to prevent the attacks 9
Conclusion 10
References 10
Part A
The hackers breaking into the computer systems and using it to access the user data is becoming a major problem with the firms on internet platform. This part discusses the recent Reddit security breach incident which happened in June,2018 and explains the reason for its occurrence and the possible methods to prevent the occurrence of same in the future.
Reddit Security Breach
Reddit is a news aggregation and discussion website, where participants posts content on the site. It was founded in 2005. On June 19, 2018 Reddit learnt that hackers attacked its system between 14 June and 18 June,2018 and got access to some of the user data. The data included e-mail addresses, employee accounts and passwords stored in the old database, that means, the complete database back up from 2005 and 2007, containing username, hashed passwords, email content including private messages was stolen. Reddit confirmed that the attacker gained only the read-only access to the data and did not gain the writing access to the database, which means that attacker could not change the database intentionally, they could only know the information (Kamat, & Gautam 2018).
Reddit claimed that the attacker compromised the information of the employee accounts with its cloud service provider and source code providers. The information breach from the old database effected particularly those users who haven’t changed their credentials yet and have also used the same credentials in another web platform, because the attacker could then use the stolen information to access other accounts (Leukfeldt & Yar 2016).
Reason for occurrence of security breach
According to experts, security breach wasn’t difficult for the attackers because Reddit was using the outdated form of two-factor authentication for its employee accounts. Whenever the user logged into their accounts, they received an SMS message with a one-time code, which needs to be entered after the password. This SMS based version of authentication was not secure, as the attackers could hack the message. Hackers performed the SMS intercept attack on the phone numbers of the Reddit employees to intercept the 2FA codes, which were necessary to access the employee accounts. The hackers also knew the employees’ account passwords. The US National Institute for Standards and Technology (NIST) has advised and warned against using the SMS-based 2FA. The attacker got access for the old database backup that contained old-information about Reddit’s user data from 2005 to 2007, which contained information like account credentials- username and salted hashed passwords, email addresses and other content like private messages. The breach won’t affect those users who signed after 2007 (Singer, Flöck, Meinhart, Zeitfogel & Strohmaier 2014).
The methods to prevent security breach
As soon as the incident was reported, Reddit reported the matter to the law enforcement agencies and the search and investigation began to find out the real attacker. Reddit is making its users change the credentials information on its website. It is making sure that users and employees are prompted to regularly change their password-related information. Since, the attacker had only read-only access to the account, they could not...