• No results found

Network Security - ISA 656 Review

N/A
N/A
Protected

Academic year: 2021

Share "Network Security - ISA 656 Review"

Copied!
31
0
0

Loading.... (view fulltext now)

Full text

(1)

Network Security - ISA 656

Review

Angelos Stavrou

(2)

The Exam

The Exam The Exam Material Test Conditions Introduction Cryptography Web Security IPsec Applications Intrusion Detection Worms and Denial of Service

7:20pm - 9:30pm, Thursday, Dec 11th, in the

Lab (STI-128)

Same style of questions as the midterm

I’m not asking you to write programs

(3)

Material

The Exam The Exam Material Test Conditions Introduction Cryptography Web Security IPsec Applications Intrusion Detection Worms and Denial of Service

If it’s in my slides or I said it in class, you’re

responsible for it

There may be some questions based on the

Labs

You’re responsible for the assigned Labs and

Homeworks at about the level of class

coverage.

(4)

Test Conditions

The Exam The Exam Material Test Conditions Introduction Cryptography Web Security IPsec Applications Intrusion Detection Worms and Denial of Service

Open book

Open notes, posted code, manuals, Labs. . .

You can bring a calculator but save your

energy; you won’t need it

(5)

Terminology

The Exam Introduction Terminology Kinds of Threats Assets Cryptography Web Security IPsec Applications Intrusion Detection Worms and Denial of Service

Confidentiality, integrity, availability

Threats, attacks, and vulnerabilities

(6)

Kinds of Threats

The Exam Introduction Terminology Kinds of Threats Assets Cryptography Web Security IPsec Applications Intrusion Detection Worms and Denial of Service

Joy hackers

Criminals

Competitors

Nation states

Insiders

(7)

Assets

The Exam Introduction Terminology Kinds of Threats Assets Cryptography Web Security IPsec Applications Intrusion Detection Worms and Denial of Service

Protect what?

Bandwidth, CPU, data, identity

Attacker powers?

(8)

Ciphers

The Exam Introduction Cryptography Ciphers Public Key Cryptography Certificates Web Security IPsec Applications Intrusion Detection Worms and Denial of Service

What is a cryptosystem?

What is a block cipher? What are generic

properties of block ciphers?

What are the different modes of operation?

What are their properties? When would you

use each mode?

(9)

Public Key Cryptography

The Exam Introduction Cryptography Ciphers Public Key Cryptography Certificates Web Security IPsec Applications Intrusion Detection Worms and Denial of Service

What is it? What is it good for? Limitations?

How are public key systems used?

Random numbers and where they come from

Digital signatures

(10)

Certificates

The Exam Introduction Cryptography Ciphers Public Key Cryptography Certificates Web Security IPsec Applications Intrusion Detection Worms and Denial of Service

Trust properties

CAs

Authorization versus identity certificates

Web of trust

Types of certificates

Revocation

(11)

SSL

The Exam Introduction Cryptography Web Security SSL Web Certificates Browser Security Continuing Authentication Web Server Security Email Security Phishing Defenses IPsec Applications Intrusion Detection Worms and Denial of Service

What is SSL?

Client authentication types

Properties and requirements

Uses

(12)

Web Certificates

The Exam Introduction Cryptography Web Security SSL Web Certificates Browser Security Continuing Authentication Web Server Security Email Security Phishing Defenses IPsec Applications Intrusion Detection Worms and Denial of Service

Root certificates

The browser vendor’s role

Bindings

(13)

Browser Security

The Exam Introduction Cryptography Web Security SSL Web Certificates Browser Security Continuing Authentication Web Server Security Email Security Phishing Defenses IPsec Applications Intrusion Detection Worms and Denial of Service

Why is it a problem?

Active content

Javascript

ActiveX

(14)

Continuing Authentication

The Exam Introduction Cryptography Web Security SSL Web Certificates Browser Security Continuing Authentication

Web Server Security Email Security Phishing Defenses IPsec Applications Intrusion Detection Worms and Denial of Service

Cookies

Embedded values

(15)

Web Server Security

The Exam Introduction Cryptography Web Security SSL Web Certificates Browser Security Continuing Authentication

Web Server Security

Email Security Phishing Defenses IPsec Applications Intrusion Detection Worms and Denial of Service

Why?

Trust model

Scripts and their dangers

Injection attacks

(16)

Email Security

The Exam Introduction Cryptography Web Security SSL Web Certificates Browser Security Continuing Authentication Web Server Security

Email Security Phishing Defenses IPsec Applications Intrusion Detection Worms and Denial of Service

Usual evaluation

How to sign and encrypt?

Details

Threats: eavesdropping, password theft, spool

(17)

Phishing

The Exam Introduction Cryptography Web Security SSL Web Certificates Browser Security Continuing Authentication Web Server Security Email Security Phishing Defenses IPsec Applications Intrusion Detection Worms and Denial of Service

What is it?

How it’s done

Tracing

(18)

Defenses

The Exam Introduction Cryptography Web Security SSL Web Certificates Browser Security Continuing Authentication Web Server Security Email Security Phishing Defenses IPsec Applications Intrusion Detection Worms and Denial of Service

Mutual authentication

Personalization

DKIM

Non-reusable credentials

(19)

IPsec

The Exam Introduction Cryptography Web Security IPsec IPsec Packet Processing Attacking IPsec Applications Intrusion Detection Worms and Denial of Service

What is IPsec, and why?

ESP and AH

SPI

SAs

(20)

Packet Processing

The Exam Introduction Cryptography Web Security IPsec IPsec Packet Processing Attacking IPsec Applications Intrusion Detection Worms and Denial of Service

Outbound and inbound

SPD and SADB

(21)

Attacking IPsec

The Exam Introduction Cryptography Web Security IPsec IPsec Packet Processing Attacking IPsec Applications Intrusion Detection Worms and Denial of Service

Cut-and-paste attacks

Probable plaintext

(22)

Applications

The Exam Introduction Cryptography Web Security IPsec Applications Applications SSH SIP Intrusion Detection Worms and Denial of Service

SSH

SIP

(23)

SSH

The Exam Introduction Cryptography Web Security IPsec Applications Applications SSH SIP Intrusion Detection Worms and Denial of Service

Features

Security model

Client authentication

Connection-forwarding

SSH Agent

(24)

SIP

The Exam Introduction Cryptography Web Security IPsec Applications Applications SSH SIP Intrusion Detection Worms and Denial of Service

SIP architecture

What’s at risk?

Protecting voice versus signaling

What type of crypto is used where

Complex scenarios

(25)

What is IDS?

The Exam Introduction Cryptography Web Security IPsec Applications Intrusion Detection What is IDS? Limits of Network IDS IDS Architecture Worms and Denial of Service

Purpose

Host versus network IDS

Logs and traces

(26)

Limits of Network IDS

The Exam Introduction Cryptography Web Security IPsec Applications Intrusion Detection What is IDS? Limits of Network IDS IDS Architecture Worms and Denial of Service

Insertion and evasion attack

Checksum errors

TTLs

(27)

IDS Architecture

The Exam Introduction Cryptography Web Security IPsec Applications Intrusion Detection What is IDS? Limits of Network IDS IDS Architecture

Worms and Denial of Service

Detector

Database

Analyzer

Countermeasure

(28)

Worms

The Exam Introduction Cryptography Web Security IPsec Applications Intrusion Detection Worms and Denial of Service

Worms

Denial of Service Routing Attacks Wireless Security

Worms versus viruses

Spread: program versus social engineering

Payloads

Spam

(29)

Denial of Service

The Exam Introduction Cryptography Web Security IPsec Applications Intrusion Detection Worms and Denial of Service

Worms

Denial of Service

Routing Attacks Wireless Security

Types of DOS attack

TCP attacks

DDoS

(30)

Routing Attacks

The Exam Introduction Cryptography Web Security IPsec Applications Intrusion Detection Worms and Denial of Service

Worms

Denial of Service

Routing Attacks

Wireless Security

Why they happen

Goals

(31)

Wireless Security

The Exam Introduction Cryptography Web Security IPsec Applications Intrusion Detection Worms and Denial of Service Worms Denial of Service Routing Attacks Wireless Security

Evil twin

Battery lifetime

WEP — why the crypto is bad

War-driving

References

Related documents

Companies operating in manufacturing, trading, and knowledge-based service industries show positive performance relationships whereas firms in capital-based service industries

The research results and calculated Pearson correlation coefficient revealed that the share of the population with tertiary education (in the total population

manage efficiently a large database and allows it to persist over long periods of time. CSE 344

To ensure that the phenotype observed in npm1a and npm1b morphants was not a result of p53-mediated morpholino toxicity, the morpholinos directed against npm1a and npm1b were

Another alternative, which I actually prefer as it eliminates the above problem, is to use the default template, create the basic domain, and after the files have been created

From delivering more tailored customer service and improving response time to customer issues to targeting customers for specific energy efficiency programs and avoiding costly

Forrester Research Network Security SIEM Endpoint Security Web Application Firewall Email Security Authentication & User Security.. Database

few English cotton mills. Each mill has some means of identify- ing every lot of material, to ascertain to which workmen it has been ertrusted. A record of output is also