NUST Institutional Repository

Assessment & Remediation of Common Human Errors Leading to Potential Data Loss from an Air-Gapped Network

Show simple item record

dc.contributor.author Shaikh, Rizwan Ahmed
dc.contributor.author Supervised by Dr. Imran Rashid.
dc.date.accessioned 2020-12-09T04:27:02Z
dc.date.available 2020-12-09T04:27:02Z
dc.date.issued 2020-10
dc.identifier.other TIS-310
dc.identifier.other MSIS-17
dc.identifier.uri http://10.250.8.41:8080/xmlui/handle/123456789/17066
dc.description.abstract Many organizations process and store classified data within their computer networks. Owing to the value of data that they hold; such organizations are more vulnerable to targets from adversaries. Accordingly, the sensitive organizations resort to an ‘air-gap’ approach on their networks, to ensure better protection. However, despite the physical and logical isolation, the attackers have successfully manifested their capabilities by compromising such networks; examples of Stuxnet and Agent.btz in view. Such attacks were possible due to the successful manipulation of the human being. It has been observed that to build up such attacks, persistent reconnaissance of the employees, and their data collection often forms the first step. With the rapid integration of social media into our daily lives, the prospects for data-seekers through that platform are higher. The inherent risks and vulnerabilities of social networking sites/apps, such as WhatsApp, Facebook, LinkedIn, and Twitter, etc.; have cultivated a rich environment for foreign adversaries to cherry-pick personal information and carry out successful profiling of employees assigned with sensitive appointments. With further targeted social engineering techniques against the identified employees and their families, attackers extract more and more relevant data to make an intelligent picture. Finally, all the information is fused to design their further sophisticated attacks against the air-gapped facility for data pilferage. In this regard, the success of the adversaries in harvesting personal information of the victims largely depends upon the common errors committed by legitimate users while at workplace, in transit, and after their retreat. Such errors would keep on repeating unless these are aligned and mitigated keeping in view the underlying human behaviours and weaknesses. en_US
dc.language.iso en en_US
dc.publisher MCS en_US
dc.title Assessment & Remediation of Common Human Errors Leading to Potential Data Loss from an Air-Gapped Network en_US
dc.type Thesis en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account