Cybersecurity, Technology, and Society
E-Portfolio Journal entries
Zariah N. Lamb
Professor Bowman
CYSE 200T: Introduction to Cybersecurity
15 January 2023
Journal entry#1
Why are you interested in cybersecurity?
Why am I interested in cybersecurity technology? Though I’ve thought of taking on other majors, my major may have been undecided if it had not been for cybersecurity. I may not have even pursued furthering my education. Cybersecurity was introduced to me by a close family friend. I chose cybersecurity after observing the daily tasks of someone in the career field and then doing extensive research to learn more about the area. After observing and researching, I decided that cybersecurity technology is a field I am capable of pursuing. I was also motivated to pursue the field after having watched reverse hacking videos on YouTube. I decided if I were capable of mastering skills such as that, then I would use them for the greater good as well. I like cybersecurity because I am able to majorly contribute to society without having to be in the midst of danger or go through extensive and rigorous training. I am interested in cybersecurity technology because it is a forgiving field. Whether someone has had multiple years of training and hands-on experience, a master’s Ph.D., or a few months of boot camp coupled with a few certs- there is a position in cybersecurity for everyone. Cybersecurity technology is an ever-growing field that advances by the day. I feel secure knowing there is a demand for cybersecurity professionals and endless job and internship opportunities available. I like that it is a moderate to high-paying field. It is also a “stepping stone” career field. It allows for basic training that can be used as a stepping stone for greater job opportunities within the career field. The writing and research requirements are reasonable. The level of math required for general training and entry-level jobs is rudimentary.
Zariah N. Lamb
Professor Bowman
CYSE 200T: Introduction to Cybersecurity
22 January 2023
Journal entry #2
Select four other majors offered by ODU and explain how those majors relate to cybersecurity.
There are four majors offered by ODU that relate to cybersecurity. Those majors are criminal justice/criminology, information science, information technology, and computer science. Cybersecurity and criminal justice/criminology are both related in the way that they protect property and people from crimes. Some of the same techniques used in criminal justice are similar to cybersecurity techniques.” Criminal justice is the delivery of justice to those who have been accused of committing crimes (Criminal Justice).” Cybersecurity has a system of laws and processes that enable cybersecurity analysts to protect people and property, just like Criminal justice. Cybersecurity analysts are the first line of defense against cybercrime against cyberattacks in the same way that the various departments of criminal justice are. Information technology or IT “is the use of any computers, storage, networking, and other physical devices, infrastructure and processes to create, process, store, secure and exchange all forms of electronic data (Castagna).” Until recently, information technology and cybersecurity were considered the same major. They share many similarities and can almost be considered identical; however, cybersecurity is now considered a more specialized area of IT. Whereas IT deals with computer systems as a whole- cybersecurity deals with protecting computer systems from cyber attacks. “Information science is an academic field which is primarily concerned with analysis, collection, classification, manipulation, storage, retrieval, movement, dissemination, and protection of information (Information Science).” Information science and cybersecurity are similar in the way that they both retrieve, manipulate, disseminate, and protect information. “Computer Science is the study of computers and computational systems. Unlike electrical and computer engineers, computer scientists deal mostly with software and software systems; this includes their theory, design, development, and application (What Is Computer Science? | Undergraduate Computer Science at UMD).” Computer science, like cybersecurity, deals with software systems. The math required of computer science is more extensive than the math required of cybersecurity, but they both do require an understanding of networking, operating systems, programming, and data structures.
References
Castagna, R. (n.d.). What is Information Technology? Definition and Examples. TechTarget. Retrieved April 23, 2023, from https://www.techtarget.com/searchdatacenter/definition/IT
Criminal justice. (n.d.). Wikipedia. Retrieved April 23, 2023, from https://en.wikipedia.org/wiki/Criminal_justiceInformation science. (n.d.). Wikipedia. Retrieved April 23, 2023, from https://en.wikipedia.org/wiki/Information_science
Zariah N. Lamb
Professor Bowman
CYSE 200T: Introduction to Cybersecurity
29 January 2023
Journal entry #3
Describe four ethical issues that arise when storing electronic information about individuals.
Four ethical issues arise when storing electronic information about individuals. They are; vulnerability, threat, risk, and exposure. “Vulnerability is a software, hardware, or procedural weakness that may provide an attacker the open door he is looking for to enter a computer or network and have unauthorized access to resources within the environment. Vulnerability characterizes the absence or weakness of a safeguard that could be exploited. E.g.: a service running on a server, unpatched applications or operating system software, unrestricted modem dial-in access, an open port on a firewall, lack of physical security etc. Threat is any potential danger to information or systems. A threat is a possibility that someone (person, s/w) would identify and exploit the vulnerability. The entity that takes advantage of vulnerability is referred to as a threat agent. E.g.: A threat agent could be an intruder accessing the network through a port on the firewall. Risk is the likelihood of a threat agent taking advantage of vulnerability and the corresponding business impact. Reducing vulnerability and/or threat reduces the risk. E.g.: If a firewall has several ports open, there is a higher likelihood that an intruder will use one to access the network in an unauthorized method. Exposure is an instance of being exposed to losses from a threat agent. Vulnerability exposes an organization to possible damages. E.g.:If password management is weak and password rules are not enforced, the company is exposed to the possibility of having users’ passwords captured and used in an unauthorized manner (Bowman).”
References
Bowman, C. The elements of security.
Zariah N. Lamb
Professor Bowman
CYSE 200T: Introduction to Cybersecurity
03 February 2023
Journal entry #4
Compare cybersecurity risks in the U.S. and another country.
Some of the risks associated with cybersecurity come from other countries. These risks include cyberattacks. Some of the most common forms of cyberattacks from other countries against the U.S. include spam emails and phishing attacks.“Most spam today is sent from a type of malware called a botnet. As much as 76% of all spam is sent from such botnets (Symantec, 2014). A botnet is a network or cluster of malware-infected machines that the cybercriminal can control remotely over the internet. The victim that owns the infected computer is unaware of the botnet installation, and so the botnet master can use as many as thousands of remote PCs running in parallel to flood user inboxes with spam (“Cyber Crime Nation Typologies: K-Means Clustering of Countries Based on Cyber Crime Rates).” “The United States is targeted the most by phishing attacks, suffering 60% of worldwide phishing volumes (“Cyber Crime Nation Typologies: K-Means Clustering of Countries Based on Cyber Crime Rates).” While the U.S. has many cyberattacks, other countries like Pakistan and Vietnam have greater cybersecurity risks. “Pakistan has a cybersecurity concern, with 21.18 percent of PCs vulnerable to local malware attacks and 9.96 percent of mobile devices already infected. Pakistan is also a country that is typically uncooperative on an international level when it comes to dealing with cybercrime, which does not help given that it is not a technology powerhouse like some other nations with a more isolationist approach (Garakh, 2023).” “ In Vietnam Malware infects many computers, and 9.04 percent of mobile devices. Vietnam has made significant progress in terms of its cybercrime framework, but it still has one of the highest rates of infected devices in the world (Garakh, 2023).”
References
Cyber Crime Nation Typologies: K-Means Clustering of Countries Based on Cyber Crime Rates. (n.d.). International Journal of Cyber Criminology, Vol 10(2). https://docs.google.com/document/d/17DNNLoE_VSIM7OgYPfIGlLRAicm3RWk7-ou8vIH09Sk/edit
Garakh, I. (2023, March 3). Understand the risk: the best and worst countries for cybersecurity. Passwork Blog. Retrieved April 23, 2023, from https://blog.passwork.pro/best-and-worst-countries-cybersecurity/
Zariah N. Lamb
Professor Bowman
CYSE 200T: Introduction to Cybersecurity
12 February 2023
Journal entry #5
Use the letters of the word CYBERSECURITY to list legal ways to make money in cybersecurity.
Cyber analyst
Yacht GPS software that is secure
Buy cyber stocks
Ethical hacking
Rapid7 (https://builtin.com/company/rapid7 )
Security auditing
(Fr)Eelance work
Create a start up company
Unit 410 ( https://builtin.com/company/unit-410 )
Red canary ( https://builtin.com/company/red-canary )
IT analyst
Trail of bits ( https://builtin.com/company/trail-bits )
YouTube
Zariah N. Lamb
Professor Bowman
CYSE 200T: Introduction to Cybersecurity
19 February 2023
Journal entry #6
How has cyber technology created opportunities for workplace deviance?
“Employees often create a set of expectations about their workplace; people tend to make psychological contracts with their organizations. When his or her expectations are not met, the employee may “perceive a psychological contract breach by their employers”.[2] This “breach” of the psychological contract then presents potential problems, particularly in the workplace. Workplace deviance may arise from the worker’s perception that their organization has mistreated him or her in some manner. Employees then resort to misbehaving (or acting out) as a means of avenging their organization for the perceived wrongdoing. Workplace deviance may be viewed as a form of negative reciprocity (Workplace Deviance).” Due to the world being so interconnected, with the advancement of the internet and technology employees are exposed to ideas they may have not had before. For example, someone sees a story where employees a few states away hacked the company they work for and stole from them. If they know that they have the ability to do that as well they may feel tempted to do so . There is a certain anonymity that comes with technology as well. Even if you know exactly who the person behind the screen is, there is no direct contact with them. Which enables the person behind the screen too feel emboldened. Just one misworded email from the boss you never see leave their office is enough motive to make a disgruntled employee make choices they otherwise wouldn’t make. Technology also prevents micromanaging. With events like Covid that enabled the wide spread chain of working from home, employees are encouraged by the seemingly endless freedom. They do not have to be as productive because they are not being as closely watched. They can browse the internet, watch tv, or engage in other non-work-related activities during work hours.
References
Workplace deviance. (n.d.). Wikipedia. Retrieved April 24, 2023, from https://en.wikipedia.org/wiki/Workplace_deviance
Zariah N. Lamb
Professor Bowman
CYSE 200T: Introduction to Cybersecurity
05 March 2023
Journal entry #7
What are the costs and benefits of developing cybersecurity programs in business?
“In a medium-sized organization, $5-20 million is typically spent. The annual spending of large organizations is usually $20-50 million (Guide).” While there is no specific outline for the costs of cybersecurity and developing programs the benefits are worth it. Businesses will want to invest in cybersecurity to keep their companies integrity. It is imperative that the companies data, the customers data, and the employees data be protected as well. It would cost less in the long run to keep the business secure in the long run, than to have to fix the after effect of a cyber attack. “The cost of cybersecurity breaches in the United States of America, between August 2019 and April 2020, was $8,640,000 (Guide).” It is also important to implement cybersecurity programs into the business to protect the business from inside attacks as well. If employees know the companies and customers data is vulnerable and easily accessed, they may attempt the attack it. All categories of data are protected by cybersecurity, since it helps keep them from being stolen and damaged. Personal information, identifiable personal data, protected health information, information on intellectual property, and data contained in government and industry systems is included here (Guide).
ReferencesGuide, S. (n.d.). what are the costs and benefits of developing cybersecurity programs in business? Nstec.com. Retrieved April 24, 2023, from https://www.nstec.com/network-security/cybersecurity/what-are-the-costs-and-benefits-of-developing-cybersecurity-programs-in-business/
Zariah N. Lamb
Professor Bowman
CYSE 200T: Introduction to Cybersecurity
19 March 2023
Journal entry #8
How can you tell if your computer is safe?
There is no surefire way to tell whether or not your computer is safe; however, multiple preventatives can be set into place to stop possible cyberattacks and malware. First, make sure that your computer has some form of authentication. “Authentication is the process of verifying the identity of the user to avoid counterfeiting (Bowman).” Authentication can include a password, an access card, or biometrics like fingerprint recognition or facial identification. In this case, since it is a computer, the authentication method will likely be a password. There are two-factor authentication methods, including using more than one method to identify yourself. For example, imputing a password and sending a verification code to an email or phone number. There are certain qualifications that a password must meet in order to be considered strong. It should have at least one capital letter, one lowercase level, and a mix of numbers and punctuation. The password should not include any personal information or personal information of people close to you, and it should be changed every three months. An example of a strong password would be “ Xgsat451!”. Although passwords are a strong preventative measure, they can’t protect computers against most malware, as most malware is granted access beyond the authentication point. Malware is “software that is specifically designed to disrupt, damage, or gain unauthorized access to a computer system (Malware).” Malware includes but is not limited to; ransomware, file-less malware, spyware, adware, trojans, worms, bots, etc., etc. “Fileless malware doesn’t install anything initially, instead, it makes changes to files that are native to the operating system, such as PowerShell or WMI. Because the operating system recognizes the edited files as legitimate, a fileless attack is not caught by antivirus software — and because these attacks are stealthy, they are up to ten times more successful than traditional malware attacks (Baker).” Computers are especially vulnerable to these types of attacks. If you notice that your computer is suddenly acting slow, unexpectedly shutting down, missing files, or lagging a lot your computer may have active malware.
References
Baker, K. (n.d.). 12 Types of Malware + Examples That You Should Know. CrowdStrike. Retrieved April 25, 2023, from https://www.crowdstrike.com/cybersecurity-101/malware/types-of-malware/Malware. (n.d.). Wikipedia. Retrieved April 25, 2023, from https://en.wikipedia.org/wiki/Malware
Zariah N. Lamb
Professor Bowman
CYSE 200T: Introduction to Cybersecurity
26 March 2023
Journal entry #9
Describe three ways that computers have made the world safer and less safe.
Three ways computers have made the world safer are: enhanced healthcare, better education, and broader communication. Three ways that computers have made the world less safe is personal data is more vulnerable, there are a new category of crimes with the advant of the internet, and soceity has become technology dependent. With the help of computers and technology, the world has better access to healthcare and healthcare research. Computers allow for more accurate medical diagnosis. It allows doctors to accsess information on symtoms that they may be unfamiliar with. “Health information technology presents numerous opportunities for improving and transforming healthcare which includes; reducing human errors, improving clinical outcomes, facilitating care coordination, improving practice efficiencies, and tracking data over time (The Impact of Health Information Technology on Patient Safety).” Computers also enable the prevention of the spread of diseases. During Covid quarantine, employees could complete work safely from the comfort of their homes, lessening the endangerment of catching covid and spreading it to their families.
Computers make education safer by presenting more accurate information to students and teachers alike. Students are given more information than they would have at their disposal with libraries and physical sources. Students are exposed to more updated sources with more recent information. Computers also make the world safer by providing a broader range of communication. Families who are countries away from each other and torn apart by war can safely communicate without fear. However, computers make the world less safe as well. Crimes in the physical world are brought to the internet through computers. Crimes like identity theft, sex trafficking, fraud, money laundering, and scamming become easier to commit through the anonymity of the internet. In addition to the crimes that exist in the physical world that are brought to the internet, there are also new crimes that came along with the invention of the internet. For example, cyberbullying, cyberattacks, and cyberstalking. Computers are not inherently good or bad. Therefore, their contributions to the world are neutral and are at the discretion of humans.
References
The impact of health information technology on patient safety. (n.d.). NCBI. Retrieved April 25, 2023, from https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5787626/
Zariah N. Lamb
Professor Bowman
CYSE 200T: Introduction to Cybersecurity
02 April 2023
Journal #10
How do engineers make cyber networks safer?
“Cyber engineers incorporate electrical engineering and computer science to understand cyberspace and use skills developed in digital forensics, security policy, and network defense to perform cybersecurity tasks, as well as work on engineering hardware and software. Cyber engineers design secure systems at the interface of operational technology (sensors and things that move) and information technology (the digital world) (What Does a Cybersecurity Engineer Do?). ” There are numerous ways that engineers make cyber networks safer. Cyber engineers make sure that data is secure between devices with encryption and authentication. “Encryption is a way of scrambling data so that only authorized parties can understand the information (What Is Encryption? | Types of Encryption).”Authentication is the process of verifying the identity of the user to avoid counterfeiting (Bowman).” Authentication can include a password, an access card, or biometrics like fingerprint recognition or facial identification. They ensure that firewalls are stable and strong enough to withstand intrusion. As well as ensuring that all programs within devices have up-to-date and recent software. They prevent hackers and unauthorized users from accessing unauthorized data. Cyber engineers also protect networks from possible cyber attacks. Cyber engineers also are responsible for predicting possible attacks and executing preventative measures. “Security engineers test the effectiveness of their strategies and systems. They find solutions to protect the weaknesses these tests identify. Security engineers may plan tests in larger organizations and have junior cybersecurity personnel conduct them. In smaller organizations, they may perform the testing themselves (What Does a Cybersecurity Engineer Do?). ” “They track an organization’s authorized users, keeping tabs on who accessed what, for how long, and for what purpose. Security engineers also review and address unusual activity. Security engineers conduct or supervise regular audits of the tools and controls they use to safeguard data and networks. These audits also investigate authorizations. Security engineers also maintain contact with upper managers and key decision-makers (What Does a Cybersecurity Engineer Do?).”
References
Tobin, J. M. (n.d.). Day in the Life of a Security Engineer | Cyberdegrees.org. Cyber Degrees. Retrieved April 25, 2023, from https://www.cyberdegrees.org/careers/security-engineer/day-in-the-life/
What Does a Cybersecurity Engineer Do? (n.d.). Houston Christian University. Retrieved April 25, 2023, from https://hc.edu/science-and-engineering/degree-programs/ug-major-cyber-engineering-bs/what-does-a-cyber-security-engineer-do/
What is encryption? | Types of encryption. (n.d.). Cloudflare. Retrieved April 25, 2023, from https://www.cloudflare.com/learning/ssl/what-is-encryption/
Zariah N. lamb
Professor Bowman
CYSE 200T: Introduction to Cybersecurity
09 April 2023
Journal entry #11
What is the overlap between criminal justice and cybercrime? How does this overlap relate to the other disciplines discussed in this class?
Criminal justice is an umbrella term that refers to the laws, procedures, institutions, and policies at play before, during, and after the commission of a crime (Criminal Justice | Wex | US Law | LII / Legal Information Institute).” In short, criminal justice refers to the legal system and its procedures for dealing with crime. Many crimes have been committed via the Internet due to the rapid advancement of technology over the years. Because of this, criminologists have had to find new ways to deal with crime. Some of the crimes committed online include but are not limited to committing fraud, trafficking sexually illicit videos or photos and intellectual property, stealing identities, or violating privacy. Cybersecurity in connection with criminal just is a fairly new sector, as it was accepted not too long ago. It is argued whether the crimes committed online fall under their own terms or can be classified as either a cybercrime or an issue of criminal justice. “Defining cybercrime as a harmful behavior would focus on the specific and general harms that arise from cyber offending. It is widely accepted that cybercrime costs far more than other crimes ..the point here is not to suggest that the consequences of cybercrime are worse than other crimes; rather, the basic point is that cybercrime is similar to other crimes in that it can (and does) harm victims (Home).” The overlap between criminal justice and cybercrime as it relates to other disciplines discussed in this class shows cybersecurity’s importance and its relevance in multiple instances. For example, it shows why SCADA systems, identity management, and risk management procedures are needed infrastructures to put into place.
References
criminal justice | Wex | US Law | LII / Legal Information Institute. (n.d.). Law.Cornell.Edu. Retrieved April 10, 2023, from https://www.law.cornell.edu/wex/criminal_justice
Home. (n.d.). YouTube. Retrieved April 10, 2023, from https://drive.google.com/file/d/1HO4NqLoZzpf9pzIvBAYXfT2rCeuhEttI/view
Zariah N. lamb
Professor Bowman
CYSE 200T: Introduction to Cybersecurity
16 April 2023
Journal entry #12
How does cyber technology impact interactions between offenders and victims?
Technological innovation has significantly impacted the definitions of appropriate and inappropriate behavior, particularly in the context of communication and social interaction. With the advent of social media, messaging apps, and other forms of online communication, the rules and expectations around how we interact with one another have changed dramatically. The ability to hide behind a screen enables people to behave in ways they might not otherwise in person, leading to a rise in negative and harmful behaviors online. Cybercrime is a particularly new sector in criminal justice; criminologists are not as knowledgeable on the subject as they are in other sectors. This can lead to a deficit in knowing how to handle and deal with these crimes. This is a particularly new subject for society as well. Many do not consider the offenses committed online, for example, cyberstalking, harassing, and bullying, as serious as they would take the crimes in reality. This can lead to many crimes going unnoticed or unreported because citizens do not feel valid enough to contact law enforcement or other authorities. Victims are often repeatedly subjected to the harassment of the same offender due to this. Victims of these types of crimes are also often ignored by authority figures. Many supposedly trusted authority figures do not respond in a timely matter or at all in response to the victims of these crimes. Offenders are able to torment, annoy, terrorize, offend, or threaten another individual from miles away through email, messages, and social media with no immediate repercussions. Because offenders suffer no immediate repercussions, they may be tempted to repeat the offense or commit another offense. I myself have also been a victim of cyber harassment. I contacted the cybercrime department of the FBI and was met with no response. Victims like myself who have tried to reach out but were not helped are likely not to reach out again if they were to become victims of other crimes.
Zariah N. lamb
Professor Bowman
CYSE 200T: Introduction to Cybersecurity
23 April 2023
Journal entry #13
How should we approach the development of cyber-policy and -infrastructure given the “short arm” of predictive knowledge?
Given the short arm of predictive knowledge, we should approach the development of cybersecurity and infrastructure in a deliberate manner. There is no way to 100% accurately predict the future of possible attacks and their outcomes. However, we can try to accrue as many preventative measures as possible. “Policies and infrastructure must be consistently evaluated and improved in order to remain physically sound, to prevent unnecessary breaches, as well as ethically sound, to ensure the well-being of those reliant upon the infrastructure is taken into consideration (Crams004).” Developing cybersecurity and infrastructure requires collaboration between technology companies, international organizations, and governments. It is imperative that these organizations share information and exchange best practices that can help in identifying and mitigating cyber risks. Ethical considerations should be considered as well concerning policy development.
Regarding the development of cyber-policy and infrastructure, it is essential that the ethical implications as well as the social impact be considered as technology advances and society evolves. “Policies must build upon a critical investigation of how technologies deeply mediate human affairs and political structures. Endorsing responsibility in a hyperconnected reality requires acknowledging how our actions, perceptions, intentions, morality, and even corporality are interwoven with technologies in general and ICTs in particular. The development of a critical relation to technologies should not aim at finding a transcendental place outside these mediations, but rather at an immanent understanding of how technologies shape us as humans, while we humans critically shape technologies.” Developing cyber policy and infrastructure requires a multifaceted approach that involves continuous monitoring, collaboration, education, and ethical considerations.
References
Crams004. (n.d.). Journal #13. https://sites.wp.odu.edu/cfaught/2021/04/25/journal-13/
Floridi, L. (n.d.). The one life manifesto: Being Human in a hyperconnected era. 10.1007/978-3-319-04093-6