• No results found

Active Defense and Prevention

N/A
N/A
Protected

Academic year: 2021

Share "Active Defense and Prevention"

Copied!
11
0
0

Loading.... (view fulltext now)

Full text

(1)

Cyber Defense Overview Active Defense – 1 / 11

Active Defense and Prevention

Coleman Kane

[email protected]

(2)

Introduction

Introduction

Firewalls

Firewall Example Proxy Servers Proxy Server Uses Network Applications File Sharing E-Mail Interactive CLI References

Active Defense and Prevention are the strategies employed to prevent, obstruct, or otherwise block

unwanted access to the system. This lecture will discuss some preventative systems, an overview of their operation, as well as measures which can be taken at the application configuration level for common services to enforce

(3)

Firewalls

Introduction

Firewalls

Firewall Example Proxy Servers Proxy Server Uses Network Applications File Sharing E-Mail Interactive CLI References

Cyber Defense Overview Active Defense – 3 / 11

(4)

Firewall Example

Introduction Firewalls

Firewall Example

Proxy Servers Proxy Server Uses Network Applications File Sharing E-Mail Interactive CLI References

Some examples using Linux’s iptables. iptables uses a firewall appraoch where a list of firewall rules are evaluated against every packet, and the first matching rule is used to determine the action to be taken. Linux supports a

"default" action, typically either a permissive "ACCEPT" or restrictive "DROP" action.

■ iptables -A INPUT -s 192.168.0.4 -j ACCEPT # Allow one client if default is DROP

■ iptables -A INPUT -s 192.168.0.0/24 -j ACCEPT # Allow an entire network

■ iptables -A INPUT -p tcp –dport 6881 -j ACCEPT # Allow all hosts on a certain port

(5)

Proxy Servers

Introduction Firewalls

Firewall Example

Proxy Servers

Proxy Server Uses Network Applications File Sharing E-Mail Interactive CLI References

Cyber Defense Overview Active Defense – 5 / 11

A proxy server is an application-level gateway which can be used to control access, hide implementation details from view, and add visibility to application traffic. Some example proxy servers are:

■ Privoxy http://www.privoxy.org/

Squid http://www.squid-cache.org/

■ Apache mod_proxy

(6)

Proxy Server Uses

Introduction Firewalls

Firewall Example Proxy Servers

Proxy Server Uses

Network Applications File Sharing E-Mail Interactive CLI References

A few applications for proxy servers:

■ Place an HTTPS proxy server in front of an HTTP server, gaining visibility on the encrypted network traffic without sacrificing confidentiality or authentication

■ Route user traffic through a central device to enable filtering and policies

■ Conceal the underlying organization of a system using URL "rewrite" rules

(7)

Network Applications

Introduction Firewalls

Firewall Example Proxy Servers Proxy Server Uses

Network Applications File Sharing E-Mail Interactive CLI References

Cyber Defense Overview Active Defense – 7 / 11

(8)

File Sharing

Introduction Firewalls

Firewall Example Proxy Servers Proxy Server Uses Network Applications File Sharing E-Mail Interactive CLI References

A common legacy Internet file-sharing protocol is called FTP (File Transfer Protocol). Many FTP servers come pre-configured with authorization for unauthenticated

"anonymous" users to write arbitrary into a public folder. The SSH protocol (Secure SHell) now provides a similar encapsualted protocol called SFTP (Secure File Transfer Protocol), and there exist many Windows-compatible

(9)

E-Mail

Introduction Firewalls

Firewall Example Proxy Servers Proxy Server Uses Network Applications File Sharing E-Mail Interactive CLI References

Cyber Defense Overview Active Defense – 9 / 11

The original SMTP, POP3, and IMAP protocols were originally designed as plain-text protocols with simple

authentication methods. Since their publication, a number of new features have been added:

■ STARTTLS supporting secure-sockets with modern

encryption

■ Challenge-based authentication

(10)

Interactive CLI

Introduction Firewalls

Firewall Example Proxy Servers Proxy Server Uses Network Applications File Sharing E-Mail Interactive CLI References

(11)

References

Introduction Firewalls

Firewall Example Proxy Servers Proxy Server Uses Network Applications File Sharing E-Mail Interactive CLI References

Cyber Defense Overview Active Defense – 11 / 11

[1] Christoph Galuschka. Howtos network iptables.

References

Related documents

The Business and IT Co-evolution (BITC) aims to coordinate business and IT through continuous adaptation and learning. A series of BITC studies have been conducted since the 2000s.

y E.ON opts for the integration of Denmark and Sweden into the single European gas market since we regard this as the most probable solution granting competitive gas and

Proxifier is a program that allows network applications that do not support working through proxy servers to operate through a SOCKS or HTTPS proxy or a chain of proxy servers..

Incorporation of the coal combustion in the model enables examinations of the effect of the flame on model enables examinations of the effect of the flame on the flow field

2 The term VALENCIA HONORS SCHOLARS is reserved for those students who successfully complete at least 18 hours of honors coursework, who earn no less than a “C” in each

زرا ی با ي گدولآ ي نوتوف ي لپا ي روتاك Beam Shaper صت ی ر هراش 4 : ینینم بش زا لداح یامع زود ددرد یاه هی تنوم یزاقس لکقش( ولراقک هزادقنا و )یلاقخوت یاقه

• Web-based log file analysis software designed to analyze Web server, streaming media server, FTP server, proxy server and firewall log files?. • Generates detailed and

The server cluster includes one primary SIP proxy server and up to five standby proxy servers under active-standby mode or six active servers under load balancing mode.. The address