Hosts attached to a network - particularly the worldwide Internet - are exposed to a wider range of security threats than are unconnected hosts. Network security reduces the risks of connecting to a network. But by nature, network access and computer security work at cross-purposes. A network is a data highway designed to increase access to computer systems, while security is designed to control access. Providing network security is a balancing act between open access and security.
The highway analogy is very appropriate. Like a highway, the network provides equal access for all - welcome visitors as well as unwelcome intruders. At home, you provide security for your possessions by locking your house, not by blocking the streets. Likewise, network security generally means providing adequate security on individual host computers, not providing security directly on the network.
In very small towns, where people know each other, doors are often left unlocked. But in big cities, doors have deadbolts and chains. In the last decade, the Internet has grown from a small town of a few thousand users to a big city of millions of users. Just as the anonymity of a big city turns neighbors into strangers, the growth of the Internet has reduced the level of trust between network neighbors. The ever-increasing need for computer security is an unfortunate side effect. Growth, however, is not all bad. In the same way that a big city offers more choices and more services, the expanded network provides increased services. For most of us, security consciousness is a small price to pay for network access.
Network break-ins have increased as the network has grown and become more impersonal, but it is easy to exaggerate the extent of these security breaches. Over-reacting to the threat of break-ins may hinder the way you use the network.
Common sense is the most appropriate tool that can be used to establish your security policy. Elaborate security schemes and mechanisms are impressive, and they do have their place, yet there is little point in investing money and time on an elaborate implementation scheme if the simple controls are forgotten.
Translate into English the following passage.
Система распознавания атак должна обеспечивать реализацию следующих функций:
- обнаружение подготовки к атаке;
- сборка пакетов;
- выявление типовых атак на основе базы сигнатур атак;
- выявление атак; отсутствующих в базе сигнатур, при помощи использования нейронной сети для анализа сетевого трафика;
- автоматическое осуществление ответной реакции системы в случае обнаружения атаки.
Средства моделирования атак также разрабатываются на основе архитектуры захвата пакетов WinPcap.
Scan the text and mark the sentences about the main disadvantage of using credit cards. Point out the ways to solve the problem mentioned in the text.
Text 2.
Credit Card Security.
This is the age of plastic money. It's not uncommon for the typical consumer in the western world to go weeks at a time without ever handling a coin or bill. Everything we need is available to us with the simple "swik-swik' sound of a credit card sliding through a reader.
The big question is: "How safe is all this plastic?"
Cash has its obvious benefits. When you buy a sandwich for $2.95 and you hand the cashier a $5 bill, you know you haven't been ripped off when he hands you $2.05 right then and there. But when you hand your card to a waitress at the local chain restaurant, how do you know she hasn't taken a moment to sneak into the office and copy your card number and signature?
In response to these issues, the big credit card companies have developed more secure ways to do business. MasterCard International and Visa got together and came up with a set of guidelines called the Payment Card Industry Data Security Standards. This is a list of 12 guidelines that imposes strict regulations on all transactions taking place between the card company and the merchants it trades with. While these standards have been in place since 2005, merchants are taking some time to catch up to them. However, in the past year there has been marked improvement, and both credit card companies have stepped up their tactics to the point where merchants may be experiencing losses of service if they do not fall in line soon.
Discover Card has responded to the pressure for more secure methods with its own program. They call it the Secure Online Account Number program. Anytime you use your Discover card to purchase a product online, their program will generate a random account number to "stand-in" for the one on your card. You then send this number to the merchant in place of the real number. When the number is verified with Discover Card, it will link to your account and the purchase is charged to you. The benefit of this system is that the merchant never sees your true account number. Only you and Discover Card have access to it. Once the transaction is completed the randomly generated account number is no longer valid, so any attempts to use it result in denial.
A security method that online merchants are employing is the requirement of a shipping address that matches the billing address on your credit card. This is to guard against thieves who may steal your account number but will have no access to your billing address. This way, if your card is stolen, it can only be used to make purchases that will ship to your address. Any prospective thieves will have to pick up their orders from your mailbox, not something the average anonymity-seeking thief will want to do.
There are also third party systems in place for ensuring online credit card security. VeriSign's SSL (Secure Sockets Layer) technology is the leader in the field. VeriSign will give each merchant it conducts business with 2 "keys" (like coding alphabets), a public key and a private key. The public key is used to encrypt information, and the private key is used to decipher it. VeriSign's technology now offers this encryption in 128- to 256-bit encryption, which provides a nearly un-guessable number of possible combinations of codes.