Below you will find a collection of Journal Entries demonstrating my ability to research, evaluate, and provide critical analysis on different topics.
Journal Entry #1: Review the NICE Workforce Framework. Are there certain areas that you would want to focus your career on? Explain which areas would appeal the most to you and which would appeal the least.
The areas of the NICE Framework that I would want to focus my career at this time would be Protect and Defend, Analyze, and Investigate. I am very interested in becoming an expert in building a robust network that is well defended against attack so that the network is safe. The Analyze skills are important regarding my ability to evaluate my network defenses adequately. My ability to evaluate my network for vulnerabilities is the safest way to ensure that I discover them before a threat agent, and properly close those vulnerabilities. The ability to investigate penetration into my network is another key element in being able to find the source of an attack, and how to close the loop on both their presence inside the network and prevent another attack on the same vulnerability. While I recognize that operation and maintenance are vital skills they are the least interesting presently.
Journal Entry #2: Explain how the principles of science relate to cybersecurity.
The principles of science relate to cybersecurity through multiple fronts. Relativism shows us that all things are related. Almost every facet of daily life centers around technology, and that technology is utilized to facilitate improvements to multiple fields such as medicine, education, and the economy. Technology will inevitably have weaknesses that can be exploited for illicit gains. It is important to understand how to discover and close those weaknesses before they can be exploited by a malicious actor. Objectivity is the principle in which all studied topics should be evaluated from a value-free perspective. When working in cybersecurity, it is essential to remain objective so that problems can be evaluated from as many perspectives as possible. This leads to a more thorough approach to network and device security. Parsimony is the principle that the explanations should be given in the simplest terms. This is a complicated principle to apply to cybersecurity because it can be extremely difficult to explain why a cybercrime took place. However, one principle of cybersecurity that can be applied is that some cybercrimes are a result of opportunity. If a network is adequately hardened, then a hacker may choose to move on to an easier target. This is simply a baseline approach to prevent low hanging fruit opportunities for hackers. It is still essential to make sure that your system is protected from more determined attacks. The principle of empiricism, studying behaviors that can be perceived with the senses, can also be complicated to apply to cybersecurity. By applying empiricism to a security approach, we can avoid applying opinions and instinct to our work. Using hunches in cybersecurity can lead to a narrow focus that misses the necessary solution. It is important to keep our focus broad until we find the actual source of an issue so that we do not miss anything vital. Ethical neutrality is important regarding preserving the rights of individuals. When studying the various areas of cybersecurity, we cannot infringe upon the rights of others during our research. This is vital because violating the rights of others is unethical, and can affect the results of that research. Accurate conclusions cannot be drawn if areas of the research are diluted through ethical impropriety, lack of objectivity, and lack of empirical data.
Journal Entry #3: Visit PrivacyRights.org to see the types of publicly available information about data breaches. How might researchers use this information to study breaches?
The information provided by PrivacyRights.org focuses on information surrounding the data breach notification laws in each state in the United States. It lists how each state defines a breach and personally identifiable information. It also provides a breakdown of what those definitions cover under that state’s laws such as, biometric information, medical information, government IDs, etc. Furthermore, it shows whether triggers exist for notifying an individual, conditions for delay in notification, time limits for notification, method of delivering notification, what notification must include in writing, where in the government notification must be delivered, how many residents of the state must be affected before notification is required, whether consumer reporting agencies must be notified, whether the law provides exceptions for entities complying with other laws, exceptions for entities maintaining their own notification procedures, and finally whether the law provides the right of action for individuals. Researchers could use this information to gather data on how each state handles data breaches. Since each state drafts and enacts their own laws, there are differences depending on which state’s laws are evaluated. When a data breach occurs, researchers could analyze the data by sorting affected individuals and which states they live in. This information could prove valuable to determining states that have laws that are less effective at data breach responses. This data could also show which states have individuals with lower awareness of how to protect their data. Because cybercrime is a relatively new field of criminal activity, lawmakers have struggled to create laws that provide appropriate responses to breaches without overstepping the right to privacy for individuals. Having a unified database that shows the discrepancies between states can give researchers the tools to propose more robust laws that offer better data breach responses.
Journal Entry #4: Review Maslow’s Hierarchy of Needs and explain how each level relates to your experiences with technology. Give specific examples of how your digital experiences relate to each level of need.
The bottom most level is physiological needs including food, water, warmth, and rest. Technology provides resources to acquire all of these things. Food and water can be purchased online and delivered to your home. Warmth can be controlled by thermostats, and there are systems that can be installed that allow you to control the thermostat remotely. The next level up is safety and security. There are electronic security systems that can be installed to alert you to intruders and contact the authorities. There are also doorbells that can be installed that provide live video to the user showing when someone comes to your door. The next level is belongingness and love needs. The internet provides a wide varieties of means to keep in touch with loved ones and friends. Email, instant messaging, and social media make keeping in touch as easy as clicking and typing a message. Next is esteem needs, including a feeling of accomplishment, and this can be accomplished through something like competitive resources such as gaming. The top level is self actualization and achieving your full potential. I am personally achieving this level of the hierarchy through my online education.
Journal Entry #5: Review the articles linked with each individual motive in the presentation page or Slide #4. Rank the motives from 1 to 7 as the motives that you think make the most sense (being 1) to the least sense (being 7). Explain why you rank each motive the way you rank it.
- Multiple Reasons: There are multiple motives to commit cybercrime, and because of this it is unlikely that a hacker would commit these crimes for one reason only. For example, if a hacker is seeking revenge they could also desire financial gain that would make their revenge more painful to their victim. A hacker who is bored and short on cash, may commit an attack. In fact, each motive could be tied to the desire to make money from their crime. I have placed multiple reasons at the top of my rankings because choosing to commit cybercrimes will nearly always contain multiple motives.
- Money: According to the article, hackers tend to make lavish expenditures because their income is easily made. Some of their income is spent to reinvest in better equipment and further their abilities to continue hacking more lucrative targets. There are also hackers that use their income to invest in stocks that allow them to earn secondary income from the interest. A lot of their proceeds go towards valuable items that are meant to increase their status among other people including, other hackers and romantic partners. This particular financial expense provides more support for my thoughts on how most attacks are carried out for more than one reason. Each of these reason for financial gain reinforce that when it comes to singular motives, money is the highest priority among them.
- Recognition: Something many people want, almost as much as money, is fame and recognition. Because of the impact cybercrime has on countless individuals and how cybercrime is sensationalized in the media, it is an easy avenue for cybercriminals to gain recognition in many ways. Successful cybercrimes can help an individual gain clout in the hacking community. They can gain fame and notoriety in the public eye either through boasting about their success online or during their prosecution. In my opinion, the desire for fame is the next highest motivator for attempting cybercrime other than money.
- Political: The political landscape has become more volatile and divisive than ever before. The reliance on technology for spreading information, campaigning, and other political propaganda has made politicians prime targets for hackers. Hacktivists and leakivists have made it their mission to expose the illicit activities happening behind closed doors of political campaigns and governments. Because of the impact of politics on society hacktivists use the information they find to further their own personal goals. These goals make hacktivists highly motivated to penetrate their targets. I have placed political motives here because they are more altruistic and less selfishly motivated, at least in the eyes of the hacker.
- Revenge: Hackers can use their skills and resources to exact revenge on someone they feel have done wrong by them. This is often done by leaking pornographic material created by the victim, and these crimes are usually done to ex-partners as a way of getting back at them for ending a relationship. Revenge is ranked here because, while the motive is linked to intense emotional choices, it is more risky to the hacker for prosecution with very little reward outside of harming their victim.
- Entertainment: Some hackers choose to commit their crimes because they enjoy the challenge. They have a desire to test their skills and see just how much information they can gather before they are stopped or caught. As I approach the lowest rankings I am factoring in my perception on the risk vs. reward of cybercrimes. I feel that most hackers would not risk prosecution simply for thrills.
- Boredom: The article discussing boredom focuses on how children become victims of cyberbullying by sharing information or photos and videos of themselves due to boredom. This cybercrime is ranked lowest on my list because, it is more the result of crimes of opportunity than hackers penetrating devices for information. The various information shared by bored children is used against them, and this particular issue is more readily avoided if the information is never shared in the first place. I consider these crimes to be the least likely motive because the personal gain for the attacker is minimal, but the risk of prosecution is high.
Journal Entry #6: Can you spot three fake websites and compare the three fake websites to three real websites, plus showcase what makes the fake websites fake?
One example I found was a website designed to look like the login page for Facebook. Looking at the page itself, it looks legitimate. However, when you look at the URL it is clearly not Facebook’s URL. You can also see in the section with language options multiple question marks which also raises red flags.

Another example I found is a poorly designed website attempting to get users to submit information about a change in address to the United States Postal Service. This website is very basic in appearance and clearly does not belong to the USPS. Once again, the URL obviously is very different from what the USPS would use. An important note is that the USPS would use the .gov top level domain instead of .com.

My final example is for Ace Hardware. This website is similar to the USPS example because it is poorly designed. The Ace Hardware logo is nowhere to be found, and the page itself is very simple in design. This page also has the same issue of the URL being incorrect, however this example is the closest to accurate of my examples. This is an example of URL spoofing. The user has accessed a URL with similar, but incorrect spelling. The URL on the fake page is spelled using wear instead of ware. This mistake could be easily made and put the user at risk of providing payment information that the fake website could use to make fraudulent purchases.

Journal Entry #7: Review the following ten photos through a human-centered cybersecurity framework. Create a meme for your favorite three, explaining what is going on in the individual’s or individuals’ mind(s). Explain how your memes relate to Human-centered cybersecurity.

This dog has to create a password that is “secure”. Since it wants the password to be easy to remember and meet the guidelines, the “obvious” choice is their favorite snack with easy to remember numbers. This relates to human-centered cybersecurity because it is common failing to believe easy to remember passwords with minor adjustments as being secure. Most passwords can be guessed using dictionary words and simple number or character combinations.

This gentleman is thrilled to find free Wi-Fi at a coffee shop. This relates to human-centered cybersecurity because a common scam centers around free Wi-Fi. Commonly called the Starbucks scam, threat agents will broadcast SSID’s that are named so that they appear to be legitimate access points from a business for guests. What actually happens is users connect to these access points and the attacker can see traffic and information being accessed on the connected device.

This woman had a pop-up appear while visiting a website telling her she won $1000. She just has to click the link and provide personal information to claim her prize. This relates to human-centered cybersecurity because this is another common scam that affects people frequently. When clicking on links like this they can contain several different types of attack. They can run scripts that collect data, infect your devices with malware, and many other possible attacks. There is also the data that the link destination asks the user to input. Many users will fill out the requested information and provide the attacker everything they need to take advantage.
Journal Entry #8: Watch this YouTube video and pay attention to the way that movies distort hackers.
After watching the video, write a journal entry about how you think the media influences our understanding about cybersecurity
I think the media presents a mixed bag of accuracy in how they portray cybersecurity. The video included several examples that were very plausible efforts at hacking a system. Other examples were wildly inaccurate, and one of the most frequent inaccuracies was the speed with which an attack was executed. The media tends to focus on flashy representations of cyberattacks with quick results. However, the reality is that many of the attacks portrayed in these examples would have taken multiple days at a minimum to complete. When considering the wide range of examples of cybersecurity portrayed my media, I think the influences tend to lead most people to the wrong conclusion. The idea that a few keystrokes on a keyboard can lead an attacker to success is very exaggerated. I feel that like most things portrayed by media, cybersecurity representations should be met with much skepticism to avoid believing narratives that are wildly different than real life.
Journal Entry #9: Complete the Social Media Disorder scale. How did you score? What do you think about the items in the scale? Why do you think that different patterns are found across the world?
I answered “No” to all nine questions. A key to the scale is “in the last year”, and had I taken this assessment a few years ago, my results would be been “disordered social media user”. Fortunately, I have disassociated with persistent social media usage. I rarely post on any platform, and I never post any personal information. As for the items in the scale, I find that they are all relevant to evaluating an individual’s social media usage and whether they can be labeled “disordered”. Social media has an ever growing presence and many people are reliant upon the various platforms. I think there are different patterns around the world because, there are significant cultural differences depending on location. The presence and usage of social media are going to be different depending on the region being evaluated for data.
Journal Entry #10: Read this article and write a journal entry summarizing your response to the article on social cybersecurity.
This article illustrates how the field of cybersecurity expands far beyond what is achieved at the technological level. Threat actors and defenders interact with information as it is distributed online. This is especially true of social media. As a platform, social media is used to spread misinformation to manipulate the population of a given area. The worldwide access to technology means that a state actor can manipulate information for their targets from anywhere. This access provides the ability to create mistrust and sow discord among the intended audience. These techniques can be used to destabilize a region from within and weaken it without a physical military presence. Furthermore, automation and the use of “bots” provides attackers with the ability to spread information much more quickly. This stems from the ability of machine learning and artificial intelligence to gather data at the speed of algorithms and redistribute it as instructed by the threat actor. Defensively, it is very difficult to adequately defend against these types of attack. Government interference and policies to curb misinformation is seen as an attack on the freedom of speech. Social media platforms frequently will take down posted misinformation, but they face their own difficulties with this practice. When social media platforms remove posts and flag it as misinformation it can create a perception of political bias. This in turn can hurt their reputation as a fair and impartial resource and hurt their bottom line. Defenders can also implement automation to scan for, flag, and remove misinformation, but this can inadvertently remove posts that are meant to be satirical, comedic, or otherwise meant for entertaining. Conversely, attackers can hide behind entertainment in their efforts to spread misinformation. Understanding social cybersecurity requires an interdisciplinary understanding of several disciplines. This is a difficult expectation to meet because of how many disciplines are a factor in the social and technological setting. Overall, this article paints a bleak but important picture of the role that social resources play in the cyberspace, and the ebb and flow of attack and defense on the cyber battlefield.
Journal Entry #11: Watch this YouTube video. As you watch the video, think about how the description of the cybersecurity analyst job relates to social behaviors. Write a paragraph describing social themes that arise in the presentation.
The social theme that comes up during the presentation is providing guidance and training for user awareness on proper security protocols and measures. Specifically, the social aspect of this job function centers around the ability to effectively communicate with coworkers from different cultures and backgrounds on the importance of proper cybersecurity policies, procedures, and protocols. Developing training for a diverse group requires understanding social nuances. This is key because it will increase the effectiveness of the training and how well it is received and followed. The different locations of the best paying cybersecurity analyst positions is also relevant in much the same way. Depending on where someone chooses to work requires the ability to learn and adapt to different environments. Understanding the region one is working in from a social standpoint is critical. Cybersecurity analysts must be able to learn and adapt to different environments, and be able to evaluate the priorities and goals in their location. Once these social aspects are learned, a good cybersecurity analyst can apply their own perspectives to their work. The more diverse social education the analyst has, the better they will be able to apply their knowledge to their work. This provides a prime opportunity to create a more robust security system and evaluate threats and attacks from more angles.
Journal Entry #12: Read this sample breach letter “SAMPLE DATA BREACH NOTIFICATION” and describe how two different economics theories and two different social sciences theories relate to the letter.
Rational choice is an economic theory that factors well into this case. The businesses involved in the breach are acting in both their own best interest. While their actions following the breach as described in the letter are presented as benefiting the affected consumer, the business is also attending to their own need to mitigate the damage to their reputation. The laissez-fare economic theory also is relevant. The government is not directly involved outside of assisting in the investigation and carrying out relevant laws regarding cybersecurity and data breaches. Behavioral theory is relevant from the social sciences due to the fact that environmental factors for the attackers are likely relevant such as peers that have taught them to hack, or their own financial difficulties. Reinforcement Sensitivity Theory is also relevant. Hackers could be seeking financial gain, recognition by their hacking peers, and other reasons that achieve various rewards for the hackers.
Journal Entry #13: A later module addresses cybersecurity policy through a social science framework. At this point, attention can be drawn to one type of policy, known as bug bounty policies. These policies pay individuals for identifying vulnerabilities in a company’s cyber infrastructure. To identify the vulnerabilities, ethical hackers are invited to try explore the cyber infrastructure using their penetration testing skills. The policies relate to economics in that they are based on cost/benefits principles. Read this article and write a summary reaction to the use of the policies in your journal. Focus primarily on the literature review and the discussion of the findings.
I think that bug bounty policies can be very effective in finding many vulnerabilities for various programs. Considering that hackers of various skill levels can participate in these bounties, programs are likely to draw many hackers to attempt to find vulnerabilities. This will help provide a more comprehensive overview of the program’s current security standing. There is a drawback when considering the most prolific hackers are typically on retainer by major corporations, and they are less likely to engage in bounties that are not as financially rewarding. Lesser skilled hackers are more willing to ignore price for their services because they are also trying to gain reputation, recognition, and experience. This is mutually beneficial for both the less experienced hackers and companies that have fewer resources. Bug bounties also have drawbacks that can be exploited by malicious hackers. If the right kind of vulnerability is discovered by a malicious hacker, they could forgo the bug bounty and sell the information on the dark web. Overall, I feel that bug bounties have benefits that outweigh the risks associated. They help programs of different means have their vulnerabilities found and subsequently closed.
Journal Entry #14: Andriy Slynchuk has described eleven things Internet users do that may be illegal. Review what the author says and write a paragraph describing the five most serious violations and why you think those offenses are serious.
In my opinion, I think that searches for illegal topics on the Internet is the most serious violation. While internet searches about illegal topics could be conducted for scientific research, users searching for illegal topics may be attempting to conduct illegal activity. This can include searching for child pornography, how to create illegal substances such as methamphetamines or explosives, or hiring an individual for illegal activity. Searches for any of these topics is a very serious concern as they are likely to be the precursor to crimes being committed. Equally concerning is internet activity designed to collect information on minors under thirteen years of age. Any attempt to deliberately collect information for children under thirteen years old is inappropriate at best. This information could be used for the purposes of human trafficking of minors. Reputable sites and applications have age restrictions in place designed to prevent children under a certain age from sharing their information, however users can lie about their age to gain access. It is imperative that parents monitor their children’s internet usage to prevent their information being shared and placing them at risk. The next offense I consider serious is bullying and trolling. These actions are carried out by malicious users to inflict psychological and emotional harm to their victims. This behavior is particularly troubling because prior to the proliferation of the Internet and social media victims had more effective methods for avoiding or stopping bullying behavior if the right resources were used. With modern access bullies are able to create a relentless stream of abusive behavior. Even if a victim blocks their bully on the Internet, the bully can simply create a new account and resume their malicious behavior. Next up, I find sharing passwords, addresses, or photos of others to be very serious. This topic is critical because it can lead to a user’s information and identity from being stolen. Many users are guilty of using identical passwords for each login they create. So, if a password is shared a malicious actor has a reasonably high chance of gaining access to multiple accounts. Sharing an address pinpoints a user’s location, and this provides an actor with malicious intent the opportunity to be precise with an attack. Sharing photos of others online may seem innocuous however, you never know if someone with malicious intent may be able to use such photos to locate someone they are victimizing. Finally, I feel that using torrent services is a very serious illicit online activity. The criminal use of copyrighted material is bad in its own right. There is also high risk that the downloaded files contain malware designed to penetrate the user’s network and information. Users that use torrent services are doubly placing themselves at risk for both criminal prosecution and cyber attacks.
Journal Entry #15: Watch this YouTube video and think about how the career of digital forensics investigators relate to the social sciences. Write a journal entry describing what you think about the speaker’s pathway to his career.
It’s very interesting how the speaker transitioned from accounting into digital forensics. The speaker was able to integrate his interests in accounting and information technology into a joint focus that allowed him to transition into a wholly different field of work. The way he describes his career path does an excellent job highlighting how intertwined the digital world is with economics. Most of the examples provided during the lecture were rooted in a financial need to solve the problem. One client needed help discovering how their company managed to violate a governmental law from one of their IP addresses, and they had to pay a fine to avoid a lawsuit. The client’s goal was to ensure that such a breach never occurred again due to the financial penalties and risk to their integrity. Another example centered around an art dealer who managed to delete messages relating to a sale. The lost messages were likely to cost the client approximately twenty million euros, and the client needed the data recovered to avoid losing the deal. These examples are excellent resources for showing how economics has become a foundational motivation for high quality digital forensics experts.