Ask Operating System Expert

Assignment

(In)security Controls

Have you ever walked on a new sidewalk? If so, you might have noticed how clean and smooth it was. You also might have been impressed with how seemingly impenetrable it was. If you were to revisit that same sidewalk years later, you likely would see cracks running through it. Although concrete is one of the toughest and most durable materials in existence today, it has vulnerabilities that the forces of nature can exploit.

OSs and browsers are like sidewalks. New versions are clean and smooth, with seemingly hard, unassailable attack surfaces. However, like tiny cracks in new sidewalks that are invisible to the naked eye, design flaws are inherent in any new version's source code. Each flaw is a potential vulnerability just waiting to be discovered. Will the good guys or the bad guys discover a particular flaw first? If it is the good guys, they will patch it as quickly as possible. If it is the bad guys, they likely will keep it secret until they decide to exploit it.

To prepare for this Discussion, read the notes in the Unit 4 Notes, located in this unit's Learning Resources, before proceeding.

In light of the Pwn2Own annual contests, explain why the combination of security controls present in modern OSs and browsers is still failing to prevent exploitation by determined attackers.

Notes

Since 2007, information security professionals have been able to gauge the relative robustness of the major web browsers thanks to the Pwn2Own annual browserbreaking contest. In this annual contest, held in conjunction with the CanSecWest conference in Vancouver, Canada, security researchers can demonstrate their ability to compromise a machine by attacking the one application that everyone on the Internet is using-the web browser. In exchange for the prize monies, the security researchers share the particular vulnerabilities exploited with browser vendors, who in turn, work to resolve the issues quickly.

While today's browsers and OSs are more robust against attacks with technologies like Data Execution Prevention (DEP), Address Space Layout Randomization (ASLR), and sandboxing, attackers and security researchers have demonstrated year after year that a determined opponent can still find and exploit weaknesses at the OS or browser level.

Required Resources Readings

• Oriyano, S.-P. (2014). Hacker techniques, tools, and incident handling. (2nd ed.) Burlington, MA: Jones & Bartlett Learning.
• Chapter 9, "Web and Database Attacks"

This chapter discusses common web server and database vulnerabilities and how they are typically exploited.

• Wikipedia. (n.d.). Pwn2Own at CANSEC west. Retrieved July 27, 2012, from http://en.wikipedia.org/wiki/Pwn2Own

This entry contains the history of the Pwn2Own competition from 2007 to the current year.

• Nachreiner, C. (2012). Radio free security: April 2012 episode. WatchGuard Security Center. Retrieved from http://watchguardsecuritycenter.com/tag/pwn2own/

This site contains a number of short security related articles.

• Naked Security. (2012). Pw2Own. Retrieved from http://nakedsecurity.sophos.com/tag/pwn2own/

This page contains several links to articles related to Pwn2Own.

Operating System, Computer Science

  • Category:- Operating System
  • Reference No.:- M92057925
  • Price:- $25

Priced at Now at $25, Verified Solution

Have any Question?


Related Questions in Operating System

Research types of operating systems that are currently

Research types of operating systems that are currently available and provide a scenario in which the operating system you chose would be appropriate to be used in this situation. Explain why you think the choice you made ...

Question research hex editors available for mac os and

Question : Research hex editors available for Mac OS and Linux. Based on the documentation, how easy would validating these tools be? Select at least two hex editors for each OS, and discuss what you would do to validate ...

Foundation of information technologyresearch types of

Foundation of Information Technology Research types of operating systems that are currently available and provide a scenario in which the operating system you chose would be appropriate to be used in this situation. Expl ...

Assignment -building a multi-threaded web server using c

Assignment - Building a multi-threaded web server using C and p threads, following the model from the lecture. Your program will have one thread acting as a dispatcher thread, listening fornetwork connections with reques ...

Question you are a security administrator responsible for

Question: You are a security administrator responsible for providing secure configuration requirements for new laptop deployments. After reading Module 2 of Certified Secure Computer User v2exercises, apply the configura ...

Question what do you see as the major differences between

Question : What do you see as the major differences between UNIX/Linux and other operating systems, such as Windows and Mac OS X? The response must be typed, single spaced, must be in times new roman font (size 12) and m ...

Question description of lasa in this assignment you will

Question: Description of LASA: In this assignment, you will select a real-world operating system (can be for a PC, server, tablet, handheld, or embedded device). You will introduce the operating system and its components ...

Discussion question this research assignment will give

Discussion Question : This research assignment will give further information on the nature and workings of multi-tasking and multi-processing operating systems. All information reported in this assignment is to be in the ...

Taskyour job in this assignment is to create two virtual

Task Your job in this assignment is to create two Virtual machines each running a different but the latest distribution of Linux e.g. Ubuntu Server and CentOS. Each of these VM's is to offer services to a user base. The ...

State the required answer precisely and then provide proper

State the required answer precisely and then provide proper explanation. It is not enough to provide one- word or one-line answers. Briefly describe the following concepts and indicate how they are related in the context ...

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As