Add the rest of university notes

This commit is contained in:
John Gatward committed 2026-10-04 14:02:35 +01:00
1 parent c1b84c7f7d
commit d0f27f276b
366 files changed
+9844 -110

No files matched your search

+166
View File
@@ -0,0 +1,166 @@
# Secure By Design
> “Security vulnerabilities are to some extent an exception; the overwhelming majority of security vulnerabilities reported in software products – and exploited to attack the users of such products – occur at the implementation level.” - Daniel Jackson
**Integrity**: Ensuring the security of both a system and its data, including unauthorised disclosure of data.
Security is legally required for systems that process personal data.
> GDPR Requires that personal data be secured through the implementation of technical **and** organisational measures. Technical measures include the pseudonymisation and encryption of personal data; the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; and the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident.
#### Why is Security so Important
In the UK 46% of businesses and 26% of charities have delt with cyber attacks
Ransomware is the fastest growing type of cybercrime and costs are predicted to reach 20 billion dollars by 2021, which is 57 times greater than it was in 2015.
Cyber security breaches have increased globally by 67% since 2014. They essentially operate in 2 ways:
1. Through bad actors, particularly people who try to phish for and otherwise elicit usernames and passwords to access systems
2. Through bad computing, particularly the use of viruses, malware and denial of service attacks that compromise systems.
It is broadly acknowledged that IoT devices, which typically exploit low cost sensors, suffer from extremely poor and indeed non-existent security.
#### Causes of poor Security
In addition to internal reasons to do with poor coding and testing, and poor specification of technical and usability requirements, poor security has also been attributed to the law and limits of liability.
In the US, for example, the courts have consistently interpreted software licenses in a way that allows vendors to disclaim almost all liability for software defects.
**The economic loss**: rule states that if a product causes no personal injury or property damage, other than to the product itself, then such damages are determined by contract law and limited to a breach of contract claim.
- This prevents customers from suing as most often claims consist of
- Loss of sensitive & personal data
Then there is the fact that any data entered into a computer system by the user is **not considered part of the software**, and hence **not part of the product**. The data and the software are separate. The data can be read and manipulated by the software, but it is created by the user or a third party, not the software vendor. Therefore, destruction of data due to insecure software is not deemed damage to or destruction of the software itself.
Now GDPR, the EU’s updated data protection regulation, goes some way towards incentivising secure treatment of personal data with its 20 million euro fines for anyone who **fails to put adequate technical and organisational safeguards in place**, but that of course only **applies to the parties who process such data**, and **not to those who build**, **distribute**, **sell**, or **maintain** the software they use.
#### National Cyber Security Strategy
UK Govement invested £1.9 bn in its National Cyber Security strategy in 2016.
The UK’s National Cyber Security Strategy stands on 3 pillars:
1. **DEFEND**: the country against evolving cyber threats, which involves responding effectively to incidents, ensuring UK networks, systems and data are protected and resilient, and providing UK citizens and businesses with the knowledge needed to defend themselves.
2. **DETER**, which involves detecting, investigating and disrupting hostile action, and pursuing and prosecuting offenders.
3. **DEVELOP** a self-sustaining pipeline of talent providing the skills to meet national needs across the public and private sectors.
#### Secure By Design
Cyber-physical systems include software systems that not only compute but also act in the world, e.g., IoT devices such as smart thermostats or smart door locks or autonomous systems such as self-driving cars.
**Secure by design:** software has been designed from its foundations up to be secure.
NCSC articulates **5 core secure by design principles**. These include:
1. Establishing the context before designing a system
- Risk analysis is **critical**
- Component-driven analysis and system-driven analysis (see below)
2. Making compromise difficult
- External data inputs cannot be trusted
- Data inputs must be sanitised, validated
- Attack surfaces should be minimised, exposing as few components as possible
- Read-only views should be enforced where ever possible
- All privileged actions should be accessed through control functions and must be attributed to individuals
3. Making disruption difficult
- Identify system bottlenecks
- Test systems with unreasonably high loads and Ddos attacks
- Understanding how the system responds to failure
- Monkey testing
4. Making compromise detection easier
- Monitoring system behaviour
- Logging security events
- Like a log of all logins and logouts
- Ensuring the monitoring is independent of the software itself
5. Reducing the impact of compromise.
- Removing unnecessary functionality such as debug or test functionality
- Segmenting assets on networks to contain breaches to particular segments
- Designing systems so that they can be quickly rebuilt to a known clean state
###### Component-driven Analysis
Focuses on the technical components a system is composed of, the threats and vulnerabilities that may effect those components, and the impact caused if any of the components was compromised.
This type of analysis allows the specific risks faced by specific components within a system to be identified and prioritised
1. According to the **ease** with which a vulnerablity could be exploited and a component comprimised.
2. According to the **severity** of impact.
The purpose of prioritising risks in this way is to mitigate the worst risks first.
###### System-driven Analysis
Focuses on understanding the purposes of the system, i.e., what it is being built to do, its functionality or the services it offers. System-driven analysis should not only identify what a system should do but also what it should not do.
NCSC suggests we rarely consider what a system should not do at the beginning of the project’s lifecycle.
### Securing the IoT
There are more the 10 billion IoT devices as of 2021. This inevitably creates an exponential increase in the attack surface and opens up society to cyber attack on an unprecedented scale, especially as IoT devices are broadly recognised to have very poor cyber security.
#### Guidelines
1. **No longer set default passwords**
- Many IoT devices are compromised by the Mirai botnet, which exploits default passwords set by manufacturers.
- All IoT device passwords should be unique and should not reset to a universal factory default.
2. **Vulnerability disclosure policy**
- Provide a public point of contact to enable security researchers and users to report issues.
- This enables the continual monitoring, identification and rectification of security vulnerabilities as part of a device’s security lifecycle.
3. **Keep their software updated**
- Security patches should be delivered over a secure channel and their provenance be assured.
4. **Secure data storage**
- Sensitive data, including cryptographic keys, device identifiers and initialisation vectors, should be **stored securely** using mechanisms provided by a Trusted Execution Environment.
5. **Secure Communications**
- All data should be encrypted in transit to ensure **secure communications**.
6. **Minimise the attack surface of devices**
- Device manufacturers and service providers should ensure hardware does not unnecessarily expose access points
- Unused ports should be closed, services should not be available if they are not used, and code should be minimised to the functionality necessary for the service to operate.
- All devices should operate on the principle of least **privilege**
- Giving users or processes only those privileges essential to the performance of their intended function.
7. **Ensure software integrity**
- Using secure boot mechanisms to verify software.
- If an unauthorised change is detected, the device should alert the consumer and not connect to wider networks, other than those necessary to perform the alerting function.
8. **Resilient to outages**
- Whenever possible, IoT systems should remain operating and be **locally functional** in the case of a loss of network connectivity and should recover cleanly in the case of restoration of a loss of power.
9. **Easy to install and maintain**
- User interfaces should be easy to use and clear guidance should be provided to users to set up devices securely and reduce their exposure to threats.
10. **Monitor telemetry data**
- Telemetry data (such as usage and measurement data) allows for unusual circumstances to be identified and dealt with, minimising security risks and allowing quick mitigation of problems.
11. **Sanitise Inputs**
- Manufacturers, service providers and mobile app developers should ensure that **data input** via user interfaces, and any transferred via APIs or between networks, is **validated**.
12. **Protect personal data**
- Device manufacturers, service providers, mobile app developers and retailers should also ensure that any **personal data** collected by IoT devices is **protected**
- Users are provided with means to preserve their privacy through configuring device and service functionality.
13. **Delete personal data**
- Users should be able to **delete personal data** easily if they wish to, when there is a transfer of ownership, or when they dispose of a device.