← Back to Security Menu | 🏠 Hub
လျှို့ဝှက်မှု
Authorized users ပဲ data ဖတ်ခွင့် ရမယ်
Encryption, Access Control
တိကျမှု
Data ကို unauthorized ပြောင်းလဲမှု မဖြစ်ရ
Hashing, Digital Signatures
အသုံးပြုနိုင်မှု
Authorized users တွေ လိုတဲ့အချိန် access ရမယ်
Backups, DDoS protection
| Type | ဘယ်သူ | Motivation |
|---|---|---|
| Script Kiddie | Tool ပဲ သုံးတတ်တဲ့ beginner | Fun, recognition |
| Cybercriminal | Criminal hacker group | 💰 Money |
| Hacktivist | Political/social cause | Ideology |
| Nation-state | Government-sponsored | Espionage, warfare |
| Insider Threat | ကုမ္ပဏီ ကိုယ်တိုင်ထဲ ကြ employee | Revenge, money |
Attack Surface လျှော့ချနည်း: ✅ မသုံးတဲ့ services/ports ပိတ် ✅ Software update လုပ် ✅ Access control — least privilege ✅ Employees security training ✅ Third-party dependencies audit
Attacker Mindset (Offensive): - "ဘယ်နေရာမှ ဝင်လို့ ရမလဲ?" - Vulnerability hunt လုပ် - Bug bounty, Penetration testing Defender Mindset (Defensive): - "ဘာတွေ ကာကွယ်ရမလဲ?" - Monitoring, patching, hardening - SOC (Security Operations Center) Defense in Depth: - Layer-by-layer protection - Firewall → IDS → Auth → Encryption → Logging - တစ်ခု fail ဖြစ်ရင် တစ်ခုက ဆက် protect
| Role | ဘာလုပ်တယ် |
|---|---|
| Penetration Tester | ခွင့်ပြုချက်နဲ့ systems hack လုပ်ကြည့် (ethical hacking) |
| SOC Analyst | Security alerts monitor, incidents respond |
| Security Engineer | Security systems build and maintain |
| Bug Bounty Hunter | Companies ရဲ့ bugs ရှာ → reward ယူ |
| Malware Analyst | Malware reverse engineer လုပ် analyze |
| Cloud Security | AWS/Azure security architecture |
← Security Menu | Next: Security 02 → Threats →