17
Computer Security Security does not to be a nightmare Mohammed Khonizi IT Security Consultant Certified Ethical Hacker M.S. Information Security & Assurance January 19, 2015

Security Doesn't Have to Be a Nightmare

Embed Size (px)

Citation preview

Page 1: Security Doesn't Have to Be a Nightmare

Computer SecuritySecurity does not to be a nightmare

Mohammed Khonizi

IT Security Consultant

Certified Ethical Hacker

M.S. Information Security & Assurance

January 19, 2015

Page 2: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

Agenda

Introduction

Hacking Techniques

Security Life Cycle

Security Tips

Weakest link in Security

Intrusion Prevention Solutions

Fraudulent Chargebacks

Recovery Plan

Page 3: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

As seen on TV news

Page 4: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

Cyber Attacks in Numbers

Sony: $100 Million

Target: $148 Million

Home Depot: $90 Million

CHS: $150 Million

J.P. Morgan: 83 Million Account breached

Page 5: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

Introduction

In 2012, more than 30,000 websites

hacked a Day [SophosLabs]

According to IDC 71% of security

breaches targets small businesses

95% of credit card breaches discovered

by Visa Inc are for its smallest business

customers

Page 6: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

Hacking Techniques

DDoS

Cross Site Scripting

Broken Authentication & Session

Management Attacks

Remote Command Execution

DNS CACHE POISONING

Trojan, Viruses, Bots

Spammers, Scammers

Page 7: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

Security Tips

Website Assement

Passwords & 2 Factor Authentication

Intrusion Prevention System

Fraud Detection System

Backup Recovery Plan

Page 8: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

Weakest link in Security

Page 9: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

Security Life Cycle?

Page 10: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

Intrusion Prevention Solutions

Outsourcing

Cost

Extra services

Keep in mind

Page 11: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

How they work?

Page 12: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

How they work?

Multi-layered DDoS protection system

Web Application firewall (WAF)

Encryption

Bot Mitigation

Backdoor Protection

Page 13: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

Fraudulent Chargebacks

Definition

How it happens?

95% of them on small business

Its effeteness

Page 14: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

Fraud Detection

Fraud analysis and scoring

IP address geolocation & proxy

validation

Email address validation

Credit card issuing bank validation

Transaction velocity validation

Device transaction validation

Blacklist validation

Custom rules trigger

Email notification of fraud orders

Page 15: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

Simple Integration, Safe Transaction

What they offer

How they work

Cost

Be balanced

Page 16: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

Recovery Plan

What they do

Backup

Cost

No 100% guarantee

Page 17: Security Doesn't Have to Be a Nightmare

Affiliate

Summit

2015

Thank You

Mohammed Khonizi

@MohammedKhonizi

[email protected]