Latest news

 

HACKING- The Misinterpretation
The individual who involves in the act of Hacking is referred to as a ‘Hacker’. The Dictionary provides a positive interpretation stating him to be “a person who enjoys learning the details of computer systems and how to stretch their capabilities—as opposed to most users of computers, who prefer to learn only the minimum amount necessary and one who programs enthusiastically or who enjoys programming rather than just theorizing about programming.

With the advent of technology and Globalization, computers have become easily available and accessible. Computers and its related systems contribute a large extent to the various activities covered around the world. Dependence over computers and cyberspace has multiplied manifold and this is exploited for undue advantage by cyber criminals.

TRANSITION IN THE USAGE OF COMPUTERS
Initially these computer intrusions were fairly benign, with the most damage of computer time. However, it did not stay so for long and intruders began to purposefully revolt by adopting injurious methods when entry was restricted or denied. Eventually, the number of computer intrusions resulting in damages became noticeable and circulated as ‘news’. The media began to utilize the word ‘hacker’ as against the word ‘computer criminal’. The term ‘Hacker’ and the act referred to as hacking instead of implying a compliment, is stated to be synonymous to an ‘intruder’ or a ‘cracker’ according to computer security professionals. It thus stands in a misinterpreted position and is applied so widely.

What is ethical hacking?
With the growth of the internet, security has become a major concern for businesses and governments. They want to be able to take advantage of the Internet for electronic commerce, advertising, information distribution and access, and other pursuits, but they are worried about the possibility of being “hacked”. Moreover, the potential customers of these services are worried that personal data such as credit card numbers to social security numbers and other private information maybe exposed.

Ethical Hacking can be stated to be in relation to the notion “Prevention is better than cure”. Various organizations while approaching the problem came to realize that the best way to evaluate the intruder threat to their interests would be to have independent computer security professionals attempt to break into their computer systems. These ethical hackers would employ the same tools and techniques applied by the intruders but, would neither damage the target systems nor steal information. Instead, they would evaluate the target systems security and report back to the owners with the vulnerabilities they found and instructions for how to remedy them.

Who is an ethical Hacker?
Ancal Hacker is an expert hired by a company to attempt to attack their network and computer system the same way a hacker would. Ethical Hackers use the same techniques and tactics as those used by illegal hackers to breach corporate security systems. The end result is the company's ability to prevent an intrusion before it ever occurs.

The ethical hackers are required to posses certain characteristics that are highly essential for qualifying as one. Primarily, ethical hackers are required to be trustworthy in nature owing to the fact that they are capable of obtaining access to data which maybe highly confidential. Secondly, they are required to possess extensive knowledge and practice in this specified area with the capacity of formulating a report to be submitted to the owners. Finally, these ethical hackers are required to be highly patient in carrying out the investigative process and enquiring into the security of the system. The report so formed is required to be unambiguous in nature.

An ethical hacker is to be aware of the techniques employed by the criminal hacker in conducting malicious activity and must be knowledgeable enough to stop and combat the same. A general rule adopted while employing ethical hackers is to prevent hiring ex-hackers (IBM).

What do ethical hackers do?
An ethical hacker's evaluation of a system's security seeks answers to three basic questions:

  • What can an intruder see on the target systems?
  • What can an intruder do with that information?
  • Does anyone at the target notice the intruder's attempts or successes?

While all the above stated are important, the last point is of great significance as it is of utmost importance that the owners or operators of the target systems notice the breach. In the absence of this, the intruders may continue their malicious activities without being noticed.

The Get out of Jail Free Card
Generally, the Client and the Ethical Hacker write a contractual agreement together prior to the beginning of work. This agreement mainly aims at protecting the Ethical Hackers against any prosecution, since as much as what they do in the course of evaluation would be illegal in most countries. The agreement provides a precise description, usually in the form of network addresses or modem telephone numbers, of the systems to be evaluated. Precision on this point is of the utmost importance, since a minor mistake could lead to the evaluation of the wrong system at the client's installation or, in the worst case, the evaluation of some other organization's system.

Once the target system is specified, the agreement should state how the system is to be evaluated. The best evaluation is done under a “No-holds -barred” approach. In this approach, the ethical hacker is required to employ any technique known so as to evaluate the security of the system. This approach however is opposed as the target systems are utilized for varied activities and such an evaluation employing any technique may result in damage.

 

Previous

 

 
 
Copyrights. All Rights Reserved. Webdesign by Trivamsolutions