Security = Safety?
Security =/= Safety
Safety =
physische Sicherheit –> alerting if the situation becomes unsafe for humans and environment
Security =
process of ensuring safety and maintaining safeguards –> defending against humans with malicious or criminal intent.
IT Security =
Verteidgung von Computern gegen Intrusion und unauthorized use of resources.
Auf was baut Security auf?
Safety
Security breaches may have … consequences
serious safety
Bspw. Steuerung von AKW etc.
Perimeter Security Devices
Firewall, App Gateways
Hilft Perimeter Security Software-Bugs zu mitigieren?
Nein, hilft es nicht.
Defense in depth =
Is Perimiter security enough anymore?
No, therefore Zero-Trust
What are reasons that Perimeter Security is not enough anymore?
What are generally the challenges regarding security:
Zero-Trust Grundsatz:
never trust, always verify
Was passiert bei Zero-Trust?
Jeder Zugriff wird authentisiert.
Weshalb wurde Perimetersicherheit immer priorisiert?
Intrusion =
unathorized act of bypassing security mechanisms of network or information system
Intrustion - unauthorized access to:
To prevent intrusions, we have to avoid…
Vulnerabilites
Vulnerability =
programming errors, which allow exploitation
Exploit =
technique to breach security of a network or information system
0-Day exlpoit =
öffentliche unbekannter Exploit –> kein Security Patch
Malware benutzt …
einen Exploit
Payload =
Schädlicher Programmcode
Malware =
Malicious Software