Unit 9 Session 1: Computer Security and Unauthorized Access | IT 231 BBA Slides

--:-- --
↓ Scroll for more

Unit 9 · Session 1

Computer Security and Unauthorized Access

IT 231: IT and Applications (BBA)

Today's focus

  1. Computer Security, Ethics, and Privacy
  2. Unauthorized Access and Protection

Computer Security, Ethics, and Privacy

Learning Objectives

By the end of this session, you will be able to:

  • ✅ Define the core concepts of computer security, ethics, and privacy.
  • ✅ Identify major threats to digital information, such as malware and software piracy.
  • ✅ Describe key protective controls like firewalls and encryption.
  • ✅ Recognize the importance of cyber law and copyright in the IT profession.

The Core Concepts: A Digital Triad

This unit revolves around three interconnected pillars that are critical in today's digital world.

🔒 Security

Protecting information and systems from unauthorized access, use, disclosure, disruption, or destruction.

⚖️ Ethics

The moral principles that govern the use of computers and information systems. It's about what is right versus wrong in our digital actions.

👤 Privacy

The right of individuals to control the collection, storage, and dissemination of their personal information.

Why Does This Unit Matter?

Our world is increasingly digital. This reliance creates both incredible opportunities and significant risks.

  • ⚡ Every transaction, communication, and piece of data is a potential target.
  • 📊 Businesses, governments, and individuals are all vulnerable to digital threats.
  • 🎯 The need for skilled, ethical IT professionals has never been greater.

Your Role: To build, maintain, and secure the digital infrastructure we all depend on.

Mapping the Landscape: Major Threats

We will explore several categories of threats to computer security. The most common include:

Key Threats to Investigate:

  • Unauthorized Access: Gaining entry to a system without permission (e.g., hacking).
  • Malware (Malicious Software): Viruses, worms, and ransomware designed to cause harm.
  • Software Piracy: The illegal copying, distribution, or use of software.

Each of these will be covered in detail in upcoming chapters.

Threat Focus: Malware vs. Piracy

🦠 Malware

Software intentionally designed to cause damage to a computer, server, or network.

  • Goal: Damage, disrupt, steal.
  • Examples: Viruses, Ransomware, Spyware.
  • Impact: Data loss, financial theft, system failure.

💿 Software Piracy

The unauthorized copying, distribution, or use of copyrighted software.

  • Goal: Avoid payment, illegal distribution.
  • Examples: Using one license on many PCs, downloading "cracked" software.
  • Impact: Financial loss for developers, security risks from unofficial software.

Building Our Defenses: An Intro to Controls

While threats are numerous, we have powerful tools and strategies to protect our digital assets. These are known as security controls.

🎯 The goal of a security control is to prevent, detect, or minimize the impact of a security incident.

We'll start by looking at two fundamental network security controls...

Key Controls: Firewall & Encryption

🧱 Firewalls

A network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules.

Think of it as a digital security guard at the gate of your network.

🔐 Encryption

The process of converting data into a code (ciphertext) to prevent unauthorized access. The data can only be read after it's decrypted with the correct key.

Think of it as writing a message in a secret language that only the recipient can understand.

The Bigger Picture: Law and Ethics

Technical skills are only part of the story. As an IT professional, you have legal and ethical responsibilities.

Cyber Law: Laws relating to the internet and internet-related technologies. It governs online activities and transactions, defining what is legally permissible.

Copyright: A legal right that grants the creator of an original work exclusive rights for its use and distribution. This is the foundation of anti-piracy laws.

Practical Application: The Nepali Context

These global issues have significant local impact.

Thinking Locally:

  • Cyber Law in Nepal: The Electronic Transactions Act, 2063 (2008) is the primary legislation governing cyber activities. It covers unauthorized access, piracy, and online privacy.
  • Local Challenges: Software piracy is widespread in Nepal, posing risks to both users (malware in cracked software) and the local software economy.
  • Recent Events: High-profile data breaches of Nepali companies and government websites highlight the urgent need for better security practices and skilled professionals.

Key Takeaways

  • ✅ The Digital Triad: Security, Ethics, and Privacy are interconnected and essential for modern IT.
  • ✅ Threats are Real: We must understand threats like unauthorized access, malware, and piracy to combat them effectively.
  • ✅ Controls are Our Tools: Firewalls and encryption are fundamental tools for protecting networks and data.
  • ✅ Responsibility is Key: IT professionals must operate within legal frameworks (Cyber Law, Copyright) and strong ethical guidelines.

Unauthorized Access and Protection

🎯 Learning Objectives

In this part of today's lecture, you will be able to:

  • ✅ Define what constitutes unauthorized access.
  • ✅ Describe the three main types of authentication factors.
  • ✅ Explain the importance of strong passwords and two-factor authentication (2FA).

🔍 The Core Problem: Unauthorized Access

Unauthorized Access: The act of gaining access to a computer system, network, or data without permission.

This is a major security threat that can lead to:

  • Data Theft (personal, financial, corporate)
  • Identity Fraud & Financial Loss
  • System Damage or Disruption

🛡️ Our Defense: Access Control & Authentication

Access Control

The process of restricting who can access a resource.

It's like having a lock on your door.

Authentication

The process of verifying a user's identity.

It's the key that opens the lock.

Access control is the goal; authentication is the method.

📊 The Three Factors of Authentication

Authentication relies on verifying one or more "factors" to prove your identity.

1. Something You Know

Information only you should know.

Examples:

  • Password
  • PIN

2. Something You Have

A physical object in your possession.

Examples:

  • ATM Card
  • Security Token

3. Something You Are

A unique physical trait (biometrics).

Examples:

  • Fingerprint
  • Face ID

🧠 Factor 1: Something You Know

This is the most common factor, but often the weakest link in security.

🤔 Discussion: What makes a password "strong"?

  • Length (12+ characters)
  • Complexity (upper, lower, numbers, symbols)
  • Uniqueness (not reused across sites)

📱 Factor 2: Something You Have

This factor requires you to possess a physical item to prove your identity.

Physical Tokens

  • ATM / Smart Cards
  • Hardware Security Keys (e.g., YubiKey)
  • Company ID Badges

Digital/Virtual Tokens

  • One-Time Passwords (OTP) sent to your phone
  • Authenticator App codes (Google Authenticator, Authy)

🧬 Factor 3: Something You Are

Biometrics: Authentication using unique physical or behavioral characteristics.

Common Examples

  • Fingerprint Scans
  • Facial Recognition (Face ID)
  • Iris or Retina Scans
  • Voice Recognition

Privacy Concerns?

What are the risks if your biometric data is stolen? Unlike a password, you can't change your fingerprint!

⚡ Level Up: Two-Factor Authentication (2FA)

Two-Factor Authentication (2FA): A security method that requires two different factors to verify a user's identity.

Combining factors creates a layered, much stronger defense.

Example: Password (Know) + Code from Phone (Have) = Strong Security

Even if a hacker steals your password, they can't log in without your phone!

🌍 Practical 2FA in Nepal

You probably use 2FA every day without realizing it!

Banking & Digital Wallets

Logging into eSewa, Khalti, or your bank's app often requires:

  • Your password/MPIN (something you know)
  • An OTP sent to your Ncell/NTC number (something you have)

Government & Social Media

Securing your accounts on Nagarik App, Facebook, or Gmail:

  • Your password (something you know)
  • A code from an authenticator app or SMS (something you have)

📝 Summary & Key Takeaways

  • Unauthorized access is gaining entry without permission and is a serious threat.
  • Authentication is how we verify a user's identity to prevent this.
  • The three authentication factors are something you know, have, or are.
  • Two-Factor Authentication (2FA) provides the strongest security by combining two different factors.

Thank You

Questions before we wrap this hour?


Next: Unit 9 · Session 2 — Sabotage, Crime, Piracy, and Anti-Piracy

Course Home · Next session