CS 225: Secure Programming Case Study - Target’s Point-of-Sale Systems - POS - Viruses and Malware - IT Assignment Help

Download Solution Order New Solution
Assignment Task:

Secure Programming Case Study:

The Target data breach started during an unspecified time in the year of 2013. However, it became publicly known around Dec. 2013. Hackers gained access to more than 40 million credit and debit card information through malware on Target’s Point-Of-Sale (POS) systems. The Target Company never publicly released details of the breach, and probably never will, but enough information exists online and within the cybersecurity community to piece together what likely happened during the breach. This information can help people prevent similar attacks in the future. Figure 1 is a diagram illustrating the Target data breach with a timeline. Information was collected from a number of sources (US Senate Report, 2014; Kassner, 2015; Krebs on Security, 2015; Cyphort, 2014). The Target breach represents a typical class of cyber threats called Advanced Persistent Threat (APT). APT is a set of stealthy and continuous cyber hacking processes with the intention of stealing high-value data and information from targeted organizations. Second, the Target breach happened in 2013, short enough so that lessons learned are not out of date, also long enough so that there are sufficient details available to piece things together. Third, the Target breach is a high-profile case.

high profile Target breach Case

Discussion questions:

1. Use your own word to explain what happened in the Target data breach.

2. The HVAC contractor’s credentials were compromised by email phishing. Please propose at least two security mechanisms to guard against email phishing. 

3. If you are the hacker, please propose a scheme for phishing email attack. Be as real as possible.

4. The stolen credentials alone are not enough to access the company’s POS devices. The hackers then acquired elevated rights that allowed them to navigate the company’s network and to deploy malware. This process is called Privilege Escalation. Name as many ways as you know to do privilege escalation. 

5. For privilege escalation, the hackers need to do vulnerability scanning on the Target network. Please propose as many ways as you know to do vulnerability scanning? 

6. POS machines on the market are vulnerable to viruses and malware. Please propose a few measures to enhance POS security.

7. Target ignored many alerts from their network security devices because of alert overload and false positives. If you are the Target CTO, what would you do to alleviate the problem of alert overload?


This CS225: IT Assignment has been solved by our IT Experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our experts are well trained to follow all marking rubrics & referencing style.

Be it a used or new solution, the quality of the work submitted by our assignment experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.