The Malta Independent 26 August 2026, Wednesday
View E-Paper

Why Ethical hacking training is useful

Malta Independent Sunday, 3 January 2010, 00:00 Last update: about 13 years ago

Information breaches and the importance of having a sound network security programme have been in the headlines lately with increasing frequency, coinciding with larger annual expenditures on security-related equipment, training, and services

Why is adequate security such a difficult objective?

It seems intuitive enough at first glance: reduce potential security risks without incurring too high an expense. What becomes apparent is that as with most other endeavours in life, there is an easy way to run a network, and then there is the proper way to run a network. The two do not necessarily happen together.

There is a fundamental trade-off between secure, usable, and cheap, and the vast majority of networks are built to be usable and cheap, where cheap means “simple to deploy”. The problem is that the easy way is not always the secure way. In many cases, operational practices that are simple also simplify an attack. In other cases, those practices enable attacks.

To simplify things, we can look at the security goals another way. Fundamental to every information security approach is protecting the network from attack. Once that is in place, an administrator begins to consider how to ensure the IT is available when needed and that it is dependable over time. With security and productivity under control, the next objective is ensuring privacy – shutting off spamming for example is one of the most time consuming tasks that can be undertaken; also, users are prone to visit websites where malware is unwittingly downloaded. Finally, the administrator turns his attention to business practices and maintaining open, conventional standards.

For the security administrator, the decision looks like this. On one hand there is the risk of letting users connect with the outside world… on the other, there is the expense of keeping that connection safe. At some point one normally draws a line in the sand and accepts that some things will continue to be a risk…while other things are too important to expose.

How easy is it to define what creates risk?

Let’s look at this in another way. High security in the sense of the most restrictive security possible is not for everyone. In fact, implementing strong security measures often causes users to experience problems in other areas – frequently changing passwords for example means end users have to be more creative with their login information. Locking a user account after 30 seconds of inactivity means users have to contend with moving the mouse as they conference with important clients in Europe.

Financial institutions for example are often the target of automated probes and advance scanning techniques. If these systems are compromised, lots of people will suffer from identify theft, nobody will know who anybody is, and society as we know it will collapse. Other systems contain far less sensitive information and thus need not be subjected to the same level of security.

How does an administrator start defining network risk?

The most effective approach is to take a course in ethical hacking (CEH). This exposes a person to the exploits and provides a clear understanding of the risks that already exist in his network. The programme also helps to demonstrate the importance of software security practices found in Microsoft training programmes and in hardware security guides offered by popular equipment manufacturers like Cisco and Checkpoint. Once the elements of risk and how to address it are understood, a programme like CISSP is a reasonable capstone programme.

So ethical hacking is really about the foundational – risk analysis – stuff required to build a reliable network security programme. How? By explaining the ways that hackers are using technology to get in in the first place. From there an administrator gets to learn where an intruder is likely to go to find the most important information.

When we talk about network security, we sometimes refer to the eggshell principle: typically hard and crunchy on the outside and soft and gooey on the inside.

This principle is critically important to understand. The fact is that if an attacker can gain a foothold on the network, the rest of the network will usually fall like dominoes. Once inside, the most difficult part is often to figure out what to attack next and where to go for the really juicy bits of information. However, it does not have to be this way.

Ethical Hacking Course (CEH)

This course is focused on attacking a target network or computer based on real-life practical sessions. Before we start attacking our target network, we have to take a look at what we are up against. Obviously, a real attacker going after a real network would only rarely have access to network diagrams.

One of the target networks used for the course is a standard dual-screened subnet with a firewall at the front and a filtering router at the back. The perimeter network (also known as DMZ, demilitarised zone, or screened subnet) has a pretty common set up with a front-end Web server, a back-end database server, and a DMZ domain controller (DC). There is a corporate DC on the back end. The end goal is to take over that DC.

The first step in attacking any network is to figure out what to attack—to develop a “footprint” of the target network. There are many techniques for this. The basic goal is to learn more about the network. There is a lot to discover, including, but not limited to, the following:

Network address ranges

Host names

Exposed hosts

Applications exposed on those hosts

OS and application version information

Patch state of the host and the applications

Structure of the applications and back-end servers

Implementation details the sys admin posted to newsgroups or told a reporter about

The first step is to find the logical locations for the networks of interest. It has to be kept in mind the first principle of successful attacks: Sometimes the shortest path to your goal is not through the front door.

Other interesting hacking procedures are included in the course including DOS attacks and virus creation. CEH (Certified Ethical) course should be followed by those people concerned with IT security.

Computer Domain is the exclusive representative of the EC-Council in Malta for the delivery of CEH course. A CEH course is being organized in November and delivered by a foreign certified professional Ethical Hacker. Computer Domain can be contacted on 21433688 or [email protected]. Their web site is www.computerdomain.net

  • don't miss