• Verkeerd document? Gratis ruilen
  • Geschreven door studenten die geslaagd zijn
  • Direct beschikbaar na je betaling
  • Online lezen of als PDF
Verkopen
Kies je studieland
Kies je taal
Document preview thumbnail
Voorbeeld 4 van de 135 pagina's
College aantekeningen

Cybersecurity — Lecture Notes — complete course material

Document preview thumbnail
Voorbeeld 4 van de 135 pagina's

Comprehensive lecture notes covering the foundations of cyberspace and cybersecurity, including internet architecture, cybersecurity concepts, cyber harm, cyber accidents, regulation, and internet governance. The material also addresses cybercrime, cyber warfare, cyber espionage, critical infrastructure protection, disinformation, human behaviour and the psychology of cybersecurity, as well as organisational cybersecurity and security strategies.

Voorbeeld van de inhoud

Lecture 1: Introduction
Part I: Introduction to cybersecurity
➢​ When people talk about cybersecurity, it is often described as a rather vague phenomenon that
includes digits, hackers, dark hoodies, no face, etc., giving the impression that cybersecurity is
technical. However, cybersecurity concerns many areas beyond the technical aspects.
➢​ The people who work in cybersecurity tend to focus on what can go wrong, and they tend to
overdramatise the situation. At the end of this course, one should know how cybersecurity affects
you and various aspects of life.
➢​ Examples of cybersecurity cases:
➢​ The millennium bug.
○​ This incident concerned a coding error. At the end of 1999, systems built before that year could
not process the shift from two digits to more than two digits. They were afraid that computers
would calculate backwards instead of forward, as the digits would change from 99 to 00 and
shut down. The systems were modified promptly, making it all turn out fine. A more recent
example occurred a few years ago when the TomTom calendar would only go to one particular
date because it could not count further. If people did not update the program, they would have
some problems. We see that (some) systems are still not "future proof and perhaps are not
expected to last as long as they do. Thereby, they are causing some problems because people
simply thought there would be new computer systems.
➢​ Cambridge Analytica
○​ Cambridge Analytica came in the news, stating that they had influenced how people would
vote in the upcoming elections by using their data. People were provided with messages and
posts aligned with their data, increasing voters. The problem here was that this profiling was
based on Facebook data, which Cambridge Analytica should not have had access to. This
means that somebody found a way to extract all sorts of data off Facebook, and Facebook kind
of allowed it to happen. Cambridge Analytica ended up with millions of user-profiles and
information to build up a system like this. This example clearly shows that the data was not
used in a way the people who owned it intended it to be used.
➢​ The Strava case.
○​ Strava thought it would be favourable to use all that data to create a world map of where all of
their users were exercising to show how global they were. However, it showed a lot of activity
in a place that was supposed to be a desert. This turned out to be a secret military base where
military personnel used Strava to track their daily exercise. As a result, the US Army had to
explain why this area was on Strava's map, as it was supposed to be deserted. Since everybody
could access this map, potential attackers could vaguely determine the size and the layout of
this secret base. During this event, the question was, "who is responsible or should be held
accountable?". Should it be Strava, as they should have known this might cause certain privacy
or security issues? Should the soldiers or other military personnel decide to download this app,
knowing that it would share their location? Or should it be the US Department of Defence
allowing their soldiers to have this app on their phones?
➢​ Hacking attempt at the OPCW.
○​ In October/November of 2018, Russia was accused of a cyberattack on the chemical weapons
watchdog. According to the lecturer, this case comes close to what people think hacking is.
➢​ Diginotar.
○​ Diginotar is a company that handles trust certificates, which are a type of "ID check” that
makes sure you end up on the correct website. In other words, it makes sure that when you
click on a link for Google, you end up on Google. The lecturer illustrates it as a big vault that
ensures this process. One had to go through physical security to change these certificates, such
as a key to plug in and a password. The employees, however, thought it was too much of a
hassle to go through all that security every time and eventually just neglected particular
security measures. As a result, a hacker managed to infiltrate the system and add some
websites to the "reliable list". Diginotar eventually went bankrupt due to trust issues.

1

, ➢​ Ransomware incident at Maastricht University.
○​ The idea of ransomware is that the hacker will lock people out from the - in this case -
university's documents and refuse to give back access to the credentials unless a ransom is
paid. Maastricht University eventually decided to pay the €200.000 ransom because it was
cheaper than fixing the problem by themselves. Ransomware attacks are often carried out on
companies dependent on their systems and documents. As ransomware criminals are
becoming more and more sophisticated, "ransomware help-desks" will help you prevent these
attacks in the future.
➢​ The dating app Grindr
○​ The app standardly collects a lot of your data. This can vary from your gender or academic
achievements and more sensitive details such as your HIV status. Grindr decided to sell that
data to a third-party marketing bureau which used that data to decide what kind of messages
certain people would get to see.
➢​ Stuxnet case.
○​ The Stuxnet incident was aimed to reduce and sabotage the productivity of the Iranian nuclear
program. More about this will be discussed in one of the guest lectures. Additionally, he
mentioned the fuelling problem at Schiphol, where an error in the airport's software caused a
lot of flights to be cancelled. He mentions DDoS attacks, which are used to crash websites.
DDoS attacks have been conducted on Dutch banks.
Part II: Some basic concepts
➢​ Cyberspace, which is defined by Ben Israel & Tabansky (2011):
○​ "Cyberspace is composed of all the computerised networks globally and all computerised
endpoints, including telecommunications networks, special purpose networks, the internet,
computer systems, and computer-based systems. The concept also includes the information
stored, processed, and transmitted in the devices and between these networks.’’
➢​ Generally speaking, it concerns everything that has internet access and a connection to a network
and the network and data (or information) between these. However, it is debatable which exact
devices do not fall under this concept.
➢​ Cybersecurity is defined as follows:
○​ "Cyber security comprises technologies, processes, and controls designed to protect systems,
networks, and data from cyberattacks."
○​ Cybersecurity is not solely concerned with the technical aspects of the digital realm: the focus
is on purpose to protect rather than the technologies behind it.
○​ "Effective cyber security reduces the risk of cyberattacks and protects organisations and
individuals from the unauthorised exploitation of systems, networks and technologies. *
○​ Cybersecurity ideally does not interfere with people authorised to use a system. Effective
cybersecurity aims to provide thorough and convenient security so that users may work
efficiently rather than go through all sorts of security checks. Furthermore, the aim is never to
prevent all cyber-attacks but to reduce their risk adequately. It is essential to realise this
because, on the one hand, every improvement is sensible as they are not always followed up.
On the other hand, it is not always the company's fault under attack.
➢​ We care about cybersecurity for several reasons.
○​ The protection of critical national infrastructure would significantly affect the entire country if,
e.g., telecommunication systems were obstructed.
○​ To protect our privacy and sensitive data and, in other words, prevent cases like Cambridge
Analytica and Grindr from taking place. We need to trust that our systems will not share our
information with third parties without our knowledge.
○​ For financial reasons. If a company does not have its cybersecurity in place, it can cost them
much money.
➢​ Three-Layer Model
➢​ The Three-Layer Model has three rings
○​ Technical aspects: concerned with the systems, devices, and machines themselves.
2

, ○​ Socio-technical aspects: assess how humans interact with machines.
○​ The governance aspects: mainly occupied with the rules and regulations surrounding these
devices
➢​ Protection of Data: CIA-triad. There are three aspects of your data that can be affected.
○​ CONFIDENTIALITY, your information is available. High confidentiality means your data is
guarded against unwanted parties. It should be noted that confidentiality is not only
INFORMATION breached through hacking but also when an incorrect file is attached to an
email or when someone accidentally sees your laptop screen in public.
○​ INTEGRITY refers to the extent to which we can trust that unauthorised persons have
unmodified the data. This includes changing, adding, or deleting specific data, e.g. a student
changing their grades without the teachers noticing. The availability is concerned with whether
data is always available and accessible to those with authority.
○​ AVAILABILITY: concerned with if data is always available and accessible to those in authority.




3

, Lecture 2: What is the Internet, and how does it work?
Part I: History of the Internet & how does it work?
➢​ Back in 1943, the size of a computer would take up a whole building, and people did not expect that
computers would be such a big part of daily life in the future.
➢​ The history of the Internet started at the Advanced Research Projects Agency (ARPA), which still
exists under the name DARPA.
➢​ ARPA was set up in response to the Sputnik 1 launch and its impact in 1957 by the Soviet Union.
➢​ ARPA was mainly concerned with protecting critical infrastructure and telephone lines as they
were vulnerable at the time and could easily be sabotaged or damaged.
➢​ Made use of computer time-sharing. As computers were expensive, the idea emerged that multiple
institutions could share computers to save both time and resources. In other words, when
institution A was not using the computer, institution B would use it.
➢​ Leonard Kleinrock came up with packet switching to replace circuit switching.
○​ Circuit switching entails sending a message from point A to B without interference. If you lose
your connection, your message will not be sent, and you have to start all over again.
○​ Packet switching entails that every message you send will be broken into smaller "packages"
and sent over the network. Once these packages arrive at the endpoint, they will be put
together again. By breaking your message up into smaller pieces, the chances of having to
resend your message all over again will decrease. Instead, only a fraction of the original
message must be resent if anything goes wrong.
➢​ Because the Internet is built from scratch, Joseph Licklider said we should also decide how it
works. He envisioned a network in the following three ways.
○​ It should be a combination of hardware and software. Licklider meant that we should rely on
hardware and use software to upgrade it to make full use of it.
○​ The interaction between man and machine means that machines should only do the things
they are better at than humans, and vice versa. For example, when it comes to repetitive
calculations, it is much better just to let machines handle them. However, it is better to let
humans brainstorm than machines when it comes to creativity. The main idea was that if you
get this interaction working efficiently, humans will benefit from what machines could get off
their hands.
○​ The last thing he found important was establishing a network of people. He saw that the online
network enables many people to add their expertise and bring people together into one
collaborating body. As a result, the first packet-switching message was sent between two
computers in 1965. However, these computers were standing next to each other, making it
more a proof of concept than an actual helpful happening.
➢​ Long-distance connections
○​ By the end of the 60s, most technologies had been invented, but they were scattered across
different universities and institutions that had to work together. In other words, there was no
centralisation.
○​ The first link between two institutions - UCLA and SRI – was made in 1969. They initially tried
to send "LOG IN" but then lost connection halfway through. They managed to get a message
across saying "LO".
➢​ ARPANET
○​ ARPA kept working on this concept of sending messages across from computer A to computer
B and created ARPANET, which can be considered a predecessor of the Internet.
○​ ARPANET took the following three aspects into account:
■​ formulating technological problems and solutions, which focussed on fixing what was
currently not working;
■​ a focus on the relevance of community of users by crowdsourcing (e.g., like Wikipedia is
doing);
■​ Open architecture by enabling people to add on their expertise when necessary.


4

Documentinformatie

Studie
Geüpload op
26 september 2026
Aantal pagina's
135
Geschreven in
2022/2023
Type
College aantekeningen
Docent(en)
Dr. t. van steen
Bevat
Alle colleges
$9.22

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Verkocht
0
Volgers
0
Items
14
Laatst verkocht
-




Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen