The Internet: Cybersecurity and Crime Hi, my name's Jenny Martin and I'm the director of cyber security investigations at Symantec. Today cybercrime causes huge problems for society personally, financially, and even in matters of national security. Just in the last few years hundreds of millions of credit card numbers have been stolen, tens of millions of Social Security numbers and healthcare records were compromised, even nuclear centrifuges that have been hacked, and unmanned aerial drones have been hijacked. This is all done by exploiting vulnerabilities in hardware and software or more often by taking advantage of unintentional decisions made by the people using the software. People committing these cyber crimes don't a single profile or motivation it could be anyone from an international terrorist to a teenager competing for bragging rights. Today the largest countries not only have a regular army but also have a well armed cyber army. In fact the next World War may not be fought with traditional weapons, but with computers used to shut down national water supplies, energy grids, and transportation systems.
Hi my name is Parisa and I'm Google Security Princess. I've worked on a lot of different products and a lot of different ways to try and make our software as secure as possible. Now let's take a look at how cybercrime works under the hood will learn about software viruses, denial-of-service attacks, and phishing scams. In biology and life, a virus is an organism that is spread by coughing, sneezing, or physical contact. Viruses work by infecting cells, injecting their genetic material, and using those cells to replicate. They can make people really sick and then spread to other people. A computer virus works bit similarly. A virus is an executable program that gets installed, usually unintentionally, and harms the user and their computer. It's also possible for a virus to spread itself to other computers. Now how does a virus get on your computer in the first place?
There are a couple ways an attacker can infect someone's computer. They might lure a victim into installing a program with deception about the program's purpose, so for example a lot of viruses are disguised as security updates. It's also possible that the software on your computer has a vulnerability, so an attacker can install itself without even needing explicit permission. Once a virus is on your computer it can steal or delete any of your files, control other programs, or even allow someone else to remotely control your computer. Using computer viruses, hackers can take over millions of computers world wide and then use them as a digital army, otherwise known as a botnet, to attack and take down websites. This kind of attack is called a distributed denial of service. A denial of service is when hackers overwhelm a website with too many requests. We call it a distributed denial-of-service when the attack comes from many computers all at once.
Most websites are ready to respond to millions of requests a day, but if you hit them with billions or trillions of requests, coming from different places, the computers are overloaded and stop responding. Another trick used by cybercriminals is to send large amounts of spam email in an attempt to trick people into sharing sensitive personal information. This is called a phishing scam. A phishing scam is when you get what seems like a trustworthy email asking you to log into your account, but clicking the email takes you to a fake website. if you log in anyway you've been tricked into giving your password away. Hackers can then use your login credentials to access your real accounts to steal information or maybe even to steal your money. Fortunately there are many companies, laws, and government organizations working to make the internet safer, but these efforts are not enough.
You may think when a computer system gets hacked the problem was the security design or the software. Ninety percent of the time the system gets hacked however, it's not because of the security bug, but because of a simple mistake made by a human. It turns out there are steps we can all take to protect ourselves. Often your actions not only impact the security of your own data and computer, but the security of everyone at your school, workplace, and home. With billions or trillions of dollars at stake cybercriminals get smarter each year and we all need to keep up.
ladies and gentlemen families and friends the Cape May County Technical High School class of 2015 good morning and welcome to the first day of your next step towards graduation so our incoming freshman we're all very excited to extend a very warm Cape May tech welcome to you and we're excited to watch you take this journey over the next four years to our returning sophomores you're no longer the new kids you've learned what it's like to be a part of the Cape May tech family I ask you to take the lessons that you learn from your experiences last year and make this year even better to our juniors today you are officially upperclassmen what a great group of kids to become role models for our younger students and we also look forward to watching you meet the challenges and opportunities of this very important year and finally to our seniors at the class of 2016 you have no idea how quickly this year is going to fly by every day make decisions that ensure that at the end of this year you will all be gathered together with your family and friends to celebrate the wonderful accomplishment of your high school graduation if you have any questions or concerns throughout the year our office is always open you can come in and visit me or assistant principal mr.
Langan Eddie or assistant principal mr. Powell so once again from all of us here at Cape May Tech we wish you all the best for a great and successful school year and at this time I'd like to introduce you to the person who's leading us all on this journey our superintendent dr. Nancy who danach welcome students as you look around I'm sure you can see that the staff has prepared the school for you your teachers are ready for you and now it's your turn to be the best that you can be engaging in your learning have a great school year you
Seven, six, five, four, three, two, one [Music] Hi, my name is Lynn Root. I am a software engineer here at Spotify and I’ll be the first to admit that I often take for granted the reliability of the internet. The sheer amount of information zooming around the internet is astonishing. But how is it possible for every piece of data to be delivered to you reliably? Say you want to play a song from Spotify. It seems like your computer connects directly to Spotify servers and Spotify sends you a song on a direct, dedicated line. But actually, that’s not how the internet works. If the internet were made of direct, dedicated connections it would be impossible to keep things working as millions of users join, especially since there is no guarantee that every wire and computer is working all the time. Instead, data travels on the internet in a much less direct fashion.
Many, many years ago in the early 1970s, my partner Bob Khan and I began working on the design of what we now call the internet. Bob and I had the responsibility and the opportunity to design the internet’s protocols and its architecture. So, we persisted in participating in the internet’s growth and evolution for all of this time, up to and including the present. The way information gets transferred from one computer to another is pretty interesting. It need not follow a fixed path. In fact, your path may change in the midst of a computer-to-computer conversation. Information on the internet goes from one computer to another in what we call a packet of information. And a packet travels from one place to another on the internet a lot like how you might get from one place to another in a car. Depending on traffic congestion or road conditions you might choose or be forced to take a different route to get to the same place each time you travel.
And just as you can transport all sorts of stuff inside a car, many kinds of digital information can be sent with IP packets, but there are some limits. What if, for example, you need to move a space shuttle from where it was built to where it will be launched. The shuttle won’t fit in one truck so it needs to be broken down into pieces and transported using a fleet of trucks. They could all take different routes and might get to the destination at different times, but once all the pieces are there you can reassemble the pieces into the complete shuttle, and it’ll be ready for launch. On the internet, the details work similarly. If you have a very large image that you want to send to a friend or upload to a website, that image might be made up of tens of millions of bits or ones and zeros, too many to send along in one packet.
Since it’s data on a computer, the computer sending the image can quickly break it into hundreds or even thousands of smaller parts, called packets. Unlike cars or trucks, these packets don’t have drivers and they don’t choose their route. Each packet has the internet address of where it came from and where it’s going. Special computers on the internet, called routers, act like traffic managers to keep the packets moving through the networks smoothly. If one route is congested, individual packets may travel different routes through the internet and they may arrive at the destination at slightly different times, or even out of order. So let’s talk about how this works. As part of the Internet Protocol, every router keeps track of multiple paths for sending packets, and it chooses the cheapest available path for each piece of data based on destination IP address for the packet. Cheapest in this case doesn’t mean cost but time and nontechnical factors such as politics and relationships between companies. Often the best route for data to travel isn’t necessarily the most direct.
Having options for paths makes the network fault tolerant, which means the network can keep sending packets even if something goes horribly, horribly wrong. This is the basis for a key principle of the internet: reliability. Now, what if you want to request some data and not everything is delivered? Say you want to listen to a song. How can you be 100 percent sure all the data will be delivered so the song plays perfectly? Introducing your new best friend, TCP (Transmission Control Protocol). TCP manages the sending and receiving of all your data as packets. Think of it like a guaranteed mail service. When you request a song on your device, Spotify sends a song broken up into many packets. When your packets arrive, TCP does a full inventory and sends back acknowledgments of each packet received. If all packets are there, TCP signs for your delivery and you’re done.
[Music] If TCP finds some packets are missing, it won’t sign. Otherwise, your song wouldn’t sound as good, or portions of the song could be missing. For each missing or incomplete packet, Spotify will resend them. Once TCP verifies the delivery of many packets for that one song request, your song will start to play. [Music] What’s great about the TCP and router systems is they’re scalable. They can work with eight devices or eight billion devices. In fact, because of these principles of fault tolerance and redundancy, the more routers we add, the more reliable the internet becomes. What’s also great is we can grow and scale the internet without interrupting service for anybody using it. [Music] The internet is made of hundreds of thousands of networks and billions of computers and devices connected physically. These different systems that make up the internet connect to each other, communicate with each other, and work together because of agreed-upon standards for how data is sent around on the internet.
Computing devices or routers along the internet help all the packets make their way to the destination, where they’re reassembled, if necessary, in order. This happens billions of times a day, whether you and others are sending an email, visiting a web page, doing a video chat, using a mobile app, or when sensors or devices on the internet talk to each other.
Paola: Hi! My name is Paola, and I am a software engineer here at Microsoft. Let’s talk about how the internet works. My job relies on networks being able to talk with one another, but back in the 1970s, there was no standard method for this. It took the work of Vint Cerf and Bob Kahn to invent the internetworking protocol to make communication possible. This invention laid the groundwork for what we now call the internet. Vint: The internet is a network of networks. It links billions of devices together all around the globe. So maybe you’re connected with a laptop or a phone through wifi, but then that wifi connection connects to an internet service provider (or ISP), and that ISP connects you to billions and billions of devices around the world through hundreds of thousands of networks that are all interconnected. One thing that most people do not appreciate is that the internet is really a design philosophy and an architecture expressed in a set of protocols. A protocol is a well-known set of rules and standards that, if all parties agree to use it, will allow them to communicate without trouble. How the internet actually physically works is less important than the fact that this design philosophy has allowed the internet to adapt and absorb new communication technologies. This is because in order for a new technology to use the internet in some fashion, it just needs to know which protocols to work with.
Vint: All the different devices on the internet have unique addresses. An address on the internet is just a number, similar to a phone number or a sort of street address, that’s unique to each computer or device at the edge of the network. This is similar to how most homes and businesses have a mailing address. You don’t need to know a person to send them a letter in the mail, but you do need to know their address and how to write the address properly so the letter can be carried by the mail system to its destination. The addressing system for computers on the internet is similar, and it forms part of one of the most important protocols used in internet communication, simply called the internet protocol (or IP). A computer’s address, then, is called its IP address. Visiting a website is really just your computer asking another computer for information. Your computer sends a message to the other computer’s IP address, and it also sends along its origin address, so the other computer knows where to send its response.
Paola: You may have seen an IP address. It’s just a bunch of numbers! These numbers are organized in a hierarchy. Just like a home address has a country, a city, a street, and a house number, an IP address has many parts. Just like all digital data, each of these numbers is represented in bits. Traditional IP addresses are 32 bits long with 8 bits for each part of the address. The earlier numbers usually identify the country and regional network of the device. Then come the subnetworks, and then finally the address of the specific device. This version of IP addressing is called IPv4. It was designed in 1973 and widely adopted in the early 80s and provides for more than 4 billion unique addresses for devices connecting to the internet. But the internet has turned out to be much more popular than even Vint Cerf imagined, and 4 billion unique addresses won’t be enough.
We’re now in the middle of a multi-year transition to a longer IP address format called IPv6 which uses 128 bits per address and provides over 340 undecillion unique addresses. That’s more than enough for every grain of sand on Earth to have its own IP address. Vint: Most users never see or care about internet addresses. A system called the “domain name system” (or DNS) associates names like www.example.com with the corresponding addresses. Your computer uses the DNS to look up domain names and get the associated IP address, which is used to connect your computer to the destination on the internet. (Then it goes a little somethin’ like this!) Voice 1: Hey, hi there, I want to go to www.code.org. Voice 2: Mm… yeah I don’t know the, uh— the IP address for that domain; let me ask around. Hey, do you know how to get to, uh, code.org?
Voice 3: Yeah, I got it right here; it’s a 174.129.14.120. Voice 2: Oh, okay, great. Thanks. Yeah I’m gonna— I’m gonna write that down and save it for later in case I need it. Hey, here’s that address you wanted. Voice 1: Awesome! Thank you. Paola: So how do we design a system for billions of devices to find any one of billions of different websites? There is no way one DNS server can handle all the requests from all devices. The answer is that DNS servers are connected in a distributed hierarchy and are divided into zones, splitting up responsibility for the major domains such as .org, .com, .net, etc. DNS was originally created to be an open and public communication protocol for government and educational institutions. Because of its openness, DNS is susceptible to cyberattacks. An example attack is DNS spoofing. That’s when a hacker taps into a DNS server and changes it to match a domain name with the wrong IP address.
This lets the attackers send people to an imposter website. If this happens to you, you are vulnerable for more problems because you are using that fake website as if it is real. The internet is huge and getting bigger every day, but the domain name system and internet protocol are designed to scale, no matter how much the internet grows.