Question

In an operating system, whenever the user is about to install new software, a pop-up screen...

In an operating system, whenever the user is about to install new software, a pop-up screen appears displaying details and asks the user to approve installation or to abort. Many programs are signed by a software vendor, with a certi cate for that vendor from a trusted CA; in this case, the pop-up screen displays the (certi ed) name of the vendor and the (signed) name of the program. Other software programs are not signed, or the software vendor is not certi ed; in these programs, the pop-up screen displays the names given by the program for itself and the vendor, but with a clear statement that this was not validated.

1 Explain how an attacker can exploit human vulnerability/oversight to get malicious programs installed.

2.An organization wishes to prevent the installation of malware, so it publishes to its employees a list of permitted software vendors so that employees would verify their names before installing. Does this improve the situation? If yes how, else if not why not?

0 0
Add a comment Improve this question Transcribed image text
Answer #1

1. In this case, the attacker can make the name of the application to be very generic that we use a lot and we trust a lot.
In this case, we will not see the validity of the certificate and will simply install the certificate. Thus in this way, he can oversight and let the user install the software and hence he will get the malicious software installed.

2. This can improve the situation a little, but it is very tedious task for an employee to go and check in the list each time, he installs any certificate. Thus it would be better to install a anti-virus or software that can check and track for the malicious software and let the user know before installation.

Friend, That was a nice question to answer
If you have any doubts in understanding do let me know in the comment section. I will be happy to help you further.
Please like it if you think effort deserves like.
Thanks

Add a comment
Know the answer?
Add Answer to:
In an operating system, whenever the user is about to install new software, a pop-up screen...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • A new version of the operating system is being planned for installation into your department’s production...

    A new version of the operating system is being planned for installation into your department’s production environment. What sort of testing would you recommend is done before your department goes live with the new version? Identify each type of testing and describe what is tested. Explain the rationale for performing each type of testing. [ your answer goes here ] Would the amount of testing and types of testing to be done be different if you were installing a security...

  • Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around...

    Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT