VJC Chapter 27 Network Security
Uploaded by cheesemuffin · 10 December 2025
Preview
Text from the first pagesVJC/H2Computing/9569 Chapter 27 Network Security Content 1 Introduction to Network Security 2 Threats 2.1 Malware 2.2 Denial of Service (DoS) 3 Protection Mechanisms 3.1 Firewalls 3.1.1 Software and hardware firewalls 3.1.2 Host-based vs Network-based firewalls 3.1.3 Functionality and Structure of firewalls 3.1.4 Limitations to firewalls 3.2 Intrusion Detection System and Intrusion Prevention System 4 Secure access method 4.1 Encryption 4.2 Symmetric key encryption 4.3 Public key encryption 4.4 Digital signature 4.5 Authentication Annex 1 - What is the Internet of Things (IoT)? Annex 2 - Packet Sniffer Annex 3 - IP Spoofing Annex 4 - Security Tokens (Two-Factor Authentication) References Syllabus Learning Outcomes 4.3 Network Security Understand computer network security in terms of threats, protection mechanisms, and secure access. 4.3.1 Understand how malware (e.g. worms and viruses) and denial of service (DOS) attacks can compromise computer systems. 4.3.2 Understand how firewall (filtering function), intrusion detection system (IDS), and intrusion prevention system (IPS) can be used to restrict network access and their limitations. 4.3.3 Understand how encryption, digital signature, and authentication can ensure the security of network applications.
1 VJC/H2Computing/9569 1 Introduction to Network Security In today's digital world, our reliance on computer networks is undeniable. We use them for everything from online banking to social media, making them a prime target for malicious actors. This is where network security comes in. Network security is the shield that protects the confidentiality , integrity , and availability (CIA triad) of information and resources within a network. Confidentiality : This principle ensures that only authorised users can access sensitive information within the network. Think of it as keeping your secret documents locked away in a safe, accessible only to those with the proper key (authorization). Encryption and access controls are crucial for maintaining confidentiality. Integrity : This principle ensures that data within the network is accurate and hasn't been tampered with. Imagine working on a crucial report and someone changing the data without your knowledge. Intrusion detection systems (IDS) and digital signatures help guarantee the integrity of data by identifying unauthorized modifications. Availability : This principle ensures that authorised users can access the information and resources they need whenever they require them. A network that's constantly under denial-of-service attacks or experiences frequent outages fails to meet the availability criteria. Firewalls and network redundancy strategies play a vital role in keeping resources accessible. Imagine your network as a castle. Network security acts like the guards, firewalls, and secure gates, ensuring only authorised users can enter, and your valuables (data) are safe from theft or destruction. This introduction provides an overview of network security, highlighting its importance in protecting our increasingly digital lives. We'll delve deeper into specific threats, protection mechanisms, and secure access methods in the following sections.
2 VJC/H2Computing/9569 2 Threats 2.1 Malware Malware (malicious software) is the general term for software that is specifically designed to disrupt, damage, or gain unauthorised access to a computer system. The site https://threatmap.checkpoint.com/ allows us to visualise some types of live cyberattacks worldwide. Malware Description Ransomware A type of malware that blocks access to the victim’s computer system until a certain amount of money, usually in bitcoin or other cryptocurrency is paid. The most recent category of malware is ransomware, which garnered headlines in 2016 and 2017 when ransomware infections encrypted the computer systems of major organizations and thousands of individual users around the globe. Scareware It is a program that attempts to frighten the victim into buying unnecessary software or providing their financial data. Scareware pops up on a user's desktop with flashing images or loud alarms, announcing that the computer has been infected. It usually urges the victim to quickly enter their credit card data and download a fake antivirus program.
Spyware A hidden program that secretly collects personal information about users and sends the information to attackers without the user’s knowledge, without causing data corruption or data loss. Spyware may record the websites the user visits, information about the user's computer system and vulnerabilities for a future attack, or the user’s keystrokes. Spyware that records keystrokes is called a keylogger. Keyloggers steal credit card numbers, passwords, account numbers, and other sensitive data simply by logging what the user types. Adware Adware pushes unwanted advertisements at users and spyware secretly collects information about the user. Fileless malware Unlike traditional malware, fileless malware does not download code onto a computer, so there is no malware signature for a virus scanner to detect. Instead, fileless malware operates in the computer's memory and may evade detection by hiding in a trusted utility, productivity tool, or security application. An example is Operation RogueRobin, which was uncovered in July 2018. RogueRobin is spread through Microsoft Excel Web Query files that are attached to an email. It causes the computer to run PowerShell command scripts, providing an attacker access to the 3 VJC/H2Computing/9569 system. As PowerShell is a trusted part of the Microsoft platform, this attack typically does not trigger a security alert. Some fileless malware is also clickless, so a victim does not need to click on the file to activate it. Cookies A small piece of data used by websites to store personal information on a user’s web browser. It is misused by attackers to collect personal information about users. Pharming The interception of requests sent from a computer to a legitimate website and redirection to a fake website to steal personal data or credit card details. The attacker can use the personal details to access the victims’ bank account in the bank’s actual website. Phishing The use of emails and fake websites that appear to be from reputable companies. It is used to steal personal information such as passwords and credit card numbers from users.
Spamming The mass distribution of unwanted messages or advertising sent to email addresses collected from sources such as public mailing lists, social networking sites, company websites and blogs. Emails are usually easily sent to users and the emails sent are used to lure users to ente
Content continues in the PDF. Download PDF
Related notes
- NYJC 2026 Prelim P2Exam Papers · 2026
- NYJC 2026 Prelim P1Exam Papers · 2026
- DHS 2026 Y6 H2 Computing Prelim Paper 2_finalExam Papers · 2026
- ACJC 2026 JC2 Computing Prelim Paper 2 (Practical)Exam Papers · 2026
- 2026_NJC Prelim_Computing_P2.pdfExam Papers · 2026
- 2026_JPJC_Computing_Prelim_P2_finalExam Papers · 2026
- 2026_JPJC_Computing_Prelim_P1_markschemeExam Papers · 2026
- 2026_JPJC_Computing_Prelim_P1_finalExam Papers · 2026
- 2026 ACJC Prelim Computing Paper 2Exam Papers · 2026
- 2024 ACJC Computing PromoExam Papers · 2024
- 2023 ACJC Promo QPExam Papers · 2023
- 2022 ACJC Computing Promo Paper 2Exam Papers · 2022
- See all H2 Computing notes

