Information Security Education and Awareness project (ISEA)

From IIITM-k-wiki

Jump to: navigation, search


Contents

About the Programme

Information Security is an emerging area. At present there are very few information security professionals in the country. Also, the information security awareness level is low in the country. This necessitates development of specialized manpower, both at the high end and the low end. Realising the importance of cyber/Information security, the “Information Security Education & Awareness” project has been initiated by Department of Information Technology (DIT) under Ministry of Communication and Information and Technology (MCIT). The project is being implemented by 9 Resource Centers (RCs) and 32 Participating Institutes (PIs). DIT, MCIT has initiated this project with the following broad objectives.


Broad Aim of the Project

  • Introduction of Information Security Curriculum at M.Tech & B.Tech level and Research Activity/PhD
  • Education Exchange Programme
  • Train System Administrators/Professionals
  • Train Government Officers – Center and State, on Information Security issues i.e. computer networking, cyber hygiene, data security etc.
  • Bring Information Security Awareness in the country
  • Start Education Exchange Programme

Funded by

The project is funded by Department of Information Technology, Ministry of Communication and Information Technology, Government of India.

Launched by

The project is launched by Department of Information Technology, Ministry of Communication and Information Technology, Government of India in association with the following institutions.

Resource Centres

  • IIT Delhi
  • IIT Bombay
  • IIT Madras
  • IIT Guwahati
  • IIT Kharagpur
  • IIT Roorkee
  • IIT Kanpur
  • IISc Bangalore
  • TIFR Mumbai

Participating Institutions

  • NITs
  • IIITs
  • Premier Engineering Colleges
  • Societies of DIT


Short courses on Security

Security Awareness Program

Target Audience: Govt officials Organisd by IIITM-K Duration: 50 Hours

Course Wiki College essay guidelines

Security Training Program

Target Audience: Fresh Graduates, System Administrators, Research Community

Duration: Two Weeks

Pre-requisites: Basic knowledge of computer systems


Learning Module I: Introduction to System Administration (4 hrs Lecture + 4 hrs Lab)

  1. Overview of Systems and network services - 20 min
  2. Introduction to Network Devices - 15 min
  3. Duties of System Administrators - 15 min
  4. Planning the Network - 30 min
  5. Shell Commands - 60 min
  6. Editors vi, pico, emacs - 40 min
  7. Shell Scripts - 60 min Total 240 min Lecture
  8. Lab: Exposure to network devices (NIC, Hub, Switch, router, Cables, sockets etc.., Shell commands, editors, shell scripts)

Learning Module II: System Installation and Management (4 hrs Lecture + 4 hrs Lab)

  1. Overview of System. Installation - 30 min
  2. Startup scripts and Configuration Files - 60 min
  3. Managing user accounts. - 30 min
  4. User/Group privileges [umask, groupadd, etc..] - 30 min
  5. SUID, GUID, Sticky bit - 45 min
  6. Software Package Installation - 45 min Total 240 mins Lecture
  7. Lab: OS installation – CD, Network-NFS, FTP,HTTP, Kickstart

Learning Module III: File Systems & Hierarchy

  1. Historical Perspective - 15 min
  2. Concept of File System and its types - 30 min
  3. Working with File Systems. [Hierarchy etc.] - 60 min
  4. Different types of files - 25 min
  5. File attributes and permissions[chattr, lsattr, setfacl etc..] - 60 min
  6. Mounting local and networked file system - 50 min Total 240 mins Lecture
  7. Lab: Exposure to file systems. [Exercise on locating important files and directories.], hard/soft links, changing attributes of a file, setting access controls, mounting file systems.

Learning Module IV: Networking

  1. Network resources- overview - 30 min
  2. TCP/IP Networking - 80 min
  3. Overview of Network Services - 40 min
    1. Network File Systems (NFS)
    2. Network Information Systems (NIS)
  4. Internetworking Concepts - 30 min Total 180 mins Lecture
  5. Lab:

Learning Module V: Internet Services and Security

  1. History of Internet - 20 min
  2. Internet Services - 60 min
    1. Domain name service
    2. Web and Email Service
    3. Remote Access Service
  3. Security - 90 min
    1. Definition of security & threat
    2. Concept of CIA
    3. Broad Classification
    4. Configuring iptables
    5. Best Practices Total 170 mins Lecture
  4. Lab:

Learning Module VI: Maintenance and Troubleshooting

  1. Periodic Maintenance [importance, highlights] - 20 min
  2. Performance Monitoring - 30 min
  3. Log Management [ syslog, logrotate etc.] - 60 min
  4. Upgradation and Patch - 20 min
  5. System analysis tools - 30 min Total 160 mins Lecture
  6. Lab:

Learning Module VII: Backup and Recovery

  1. Archiving and Compressing Files - 30 min
  2. Local and Remote backup. - 30 min
  3. Backup tools [dump etc] - 30 min
  4. Best Practices - 30 min Total 120 mins Lecture
  5. Lab:


Hands-On Session

Application Level Security

WebGoat Project is insecure Java application built to teach web application security vulnerabilities. The application presents some kind of security lapse and the users have to figure it out. The current version WebGoat 5.0 supports

  • Cross Site Scripting (XSS)
  • Thread Safety
  • Hidden Form Field Manipulation
  • Weak Session Cookies
  • SQL Injection Fail
  • Open Authentication
Network Level Security

Dsniff Project is collection of tools for penetration testing at the network level. Some of the tools and corresponding functionality available is listed as under: Passive Monitoring of network for passwords, e-mail, files, etc

  • filesnarf
  • mailsnarf
  • msgsnarf
  • urlsnarf
  • webspy

Facilitate the interception of network traffic normally unavailable to an attacker (e.g, due to layer-2 switching).

  • arpspoof
  • dnsspoof
  • macof

Implement active monkey-in-the-middle attacks against redirected SSH and HTTPS sessions by exploiting weak bindings in ad-hoc PKI

  • sshmitm
  • webmitm

Snort Project is a an open source lightweight intrusion detection system (IDS)utilizing a rule-driven language, which combines the benefits of signature, protocol and anomaly based inspection methods as compared to comercially available systems. Over the years, Snort has evolved into a mature, feature rich technology that has become the de facto standard in intrusion detection and prevention.

RADIUS (Remote Authentication Dial In User Service) is an AAA (authentication, authorization and accounting) protocol for applications such as network access or IP mobility. It is intended to work in both local and roaming situations.

FakeAP The polar opposite of hiding your network by disabling SSID broadcasts- Black Alchemy's Fake AP generates thousands of counterfeit 802.11b access points. As part of a honeypot or as an instrument of one's web-site security plan, Fake AP confuses Wardrivers, NetStumblers, Script Kiddies, and other scanners.

eISSA

Discussion with Prof K Subramanian, Monday October 01, 2007 Members Present

  1. Prof. K Subramanian
  2. Prof. KRS
  3. Dr. Venkatesh
  4. Prof. Peethambram
  5. Md. Meraj Uddin

Points Discussed

  1. Bring experts on various areas related to security and video record the entire session
  2. Prof. Balaki, IISc: Stegnography, Encryption...
  3. No digital watermarking, DRM
  4. Building Security at Design Level
  5. International curriculum on Information Security by USA... Prof. KS will make available a copy of the curriculum.
  6. 4 Compartment
    1. Cryptography
  7. Security holes lie with Application Program not with crypto algo...
  8. How to write secure code, Start a new course in this area
  9. Right management and Digital watermarking
  10. Course on IT
    1. Infrastructure
    2. Network
    3. Application
    4. Access Control
    5. Control System
    6. Delivery System
    7. Environment
  11. Courses are different for the different audience... Manager, IT experts
  12. Industry Academia Consortium
  13. Virtual Currency
  14. ISEA: There is no coordination among the members of RCs and PIs

eAudit

PPT

Information Security Lab

Personal tools
<
May 2012
>
SMTWTFS
12345
6789101112
13141516171819
20212223242526
2728293031
Events Upcoming
More »