The Ethical Hacker (Example)

Name Professor Course Date Network Security Breach Having been authorized to work as a white hat for security agents working to uncover a nefarious business firm masquerading as a typical corporate I wish to stipulate that I have no hidden agenda or political gain to benefit. My role is to employ my skills as a security pentester to help uncover their criminal network. The following is a description of the methods I would engage in the attack expected challenges and how I would remain anonymous throughout the whole procedure. Methods of attack The briefing I received stated that the company took their network security seriously and had implemented various layers of protection. The security protocols that I would have to deal with include;firewalls web proxies gateways and VPN for confident I would complete the work. The high caution exercised by the firm would make the challenge more complicated as their security awareness just goes to prove that they were versatile this would force me to act fast and carefully before their security system was updated to avoid compromise and detection. Works Cited Collberg Christian S. and Clark Thomborson. "Watermarking tamper-proofing and obfuscation-tools for software protection." IEEE Transactions on software engineering 28.8 (2002): 735-746. Cheng Tsung-Huan et al. "Evasion techniques: Sneaking through your intrusion detection/prevention systems." IEEE Communications Surveys & Tutorials 14.4 (2012): 1011-1020. Hong Jason. "The state of phishing attacks." Communications of the ACM 55.1 (2012): 74-81. Yang Qinghua and Yu Liu. "What’s on the other side of the great firewall? Chinese Web users’ motivations for bypassing the Internet censorship." Computers in human behavior 37 (2014): 249-257. [...]

• Imagine for a moment that you are a hacker — an ethical one. You are called upon by law enforcement to hack into a business network known to be engaged in criminal activity for financial gain as its primary activity. Assume you are not to be concerned with any politics of the job and that your actions are legal and ethically justified. This nefarious business takes its own security seriously and therefore has implemented several forms of network security. These include firewalls, Web proxies for its Web gateways, and VPNs for remote users. You also know that this business exists much like any normal corporation, renting several floors of office space to accommodate between 100-200 employees. Also imagine that the business’s entire network topology is located in that same location. Your goal is to infiltrate the security sufficiently to find evidence included in the local MSQL database. You need to remain anonymous and operate within the reasonable parameters of the law. Write a paper in which you: 1. Explain your method of attack and operation within reasonable parameters of the law. 2. Discuss specific malware, social engineering, or any other type of attacks you would deploy to achieve your desired goals. 3. Assess the hurdles you expect and how you plan to overcome them. 4. Determine how you would remain anonymous and avoid detection. 5. Use at least four (4) quality resources in this assignment. Note: Wikipedia and similar websites do not qualify as quality resources. The specific course learning outcomes associated with this assignment are: • Explain the essentials of Transmission Control Protocol / Internet Protocol (TCP / IP) behavior and applications used in IP networking. • Explain the concepts of network security and associated ethical issues in addressing exploits. • Use technology and information resources to research issues in network security design. • Write clearly and concisely about Advanced Network Security Design topics using proper writing mechanics and technical style conventions. Grading for this assignment will be based on answer quality, logic / organization of the paper, and language and writing skills.

