• No results found

HP Education Services

N/A
N/A
Protected

Academic year: 2021

Share "HP Education Services"

Copied!
6
0
0

Loading.... (view fulltext now)

Full text

(1)

HP Education Services

HP-UX Security (H3541S)

Concerned about system security? HP’s updated

and enhanced HP-UX Security course can help you

secure your systems and mitigate risks. Designed

for experienced administrators, this course covers

all aspects of HP-UX security. Configure an IPFilter

firewall. Monitor suspicious activity with RBAC

keystroke logging and HP Host Intrusion Detection

System. Lockdown your system with Bastille. Create

secure isolated execution environments for an

Apache server and Oracle database with SRP.

Encrypt a logical volume with EVFS. You will do all

this and more in this exciting hands-on class!

Course title: HP-UX Security

HP product number: H3541S

Category/Subcategory: HP-UX / UNIX

Course length: 5 days

Level: Advanced

Delivery language: English

To order: To review course schedules and to register for a course, visit www.hp.com/learn/unix and select your country from the drop down menu, or, contact your HP sales representative or HP authorized channel partner.

Audience

Experienced system and network administrators responsible for securing and monitoring HP-UX systems

Prerequisites

HP-UX System and Network Administration I (H3064S) and HP-UX System and Network Administration II (H3065S) or

HP-UX System and Network Administration for Experienced UNIX® System Administrators (H5875S) or

Equivalent experience •

Course objective

At the conclusion of this course you should be able to: Identify software vulnerabilities and prevent buffer overflow attacks

• Manage user passwords, enable password aging,

and verify user password security •

Manage user security attributes and user accounts •

(2)

Install, configure, and manage RBAC •

Configure and use JFS ACLs to secure files and directories

Protect data with EVFS •

Identify, configure, and disable network services to improve security

Install and configure an IPFilter system firewall to block and allow service access

Configure HIDS to monitor security incidents on client systems

Enable and configure Bastille for standardized security policies

Managing security patches with SWA •

Create an isolated execution environment with SRP •

Benefits to you

Learn how to use Role Based Access Control (RBAC), Secure Shell (SSH), Host Intrusion Detection System (HIDS), Software Assistant (SWA), IPFilter, Bastille, and other HP supported tools to harden and secure HP-UX systems •

Create secure, isolated execution environments for applications with HP-UX security compartments and Secure Resource Partitions

Learn how to use Tripwire, John the Ripper, nmap, lsof, and other open source tools to further improve HP-UX system security

Why education services from HP?

Focus on job-specific skills •

Hands-on practice •

Experienced and best-in-the-field HP instructors •

Comprehensive student materials •

More than 80 training locations worldwide •

Customized on-site delivery •

Next steps

HP-UX Troubleshooting H4264 •

or HP-UX Virtualization Tools Boot Camp HG869 •

Detailed course outline

Introduction

Why security?HP-UX security tools

HP-UX security certificationsCourse agenda

Securing user accounts: user passwords

Understanding the /etc/passwd fileUnderstanding the /etc/shadow fileEncrypting passwords

Enabling shadow passwordsEnabling long passwordsConfiguring password aging

Cracking passwords with John the RipperAuthenticating users via PAM

Configuring /etc/pam.conf

Securing user accounts: special cases

Protecting user accounts: guidelinesProtecting the root account: guidelinesLimiting root and operator access via

/etc/security

Limiting root and operator access via sudoLimiting root and operator access via the

restricted SAM builder

Limiting root and operator access via the

SMH

Configuring accounts for guest usersConfiguring accounts for single application

users

Configuring accounts for teams and groupsPreventing dormant accounts

Securing user accounts: Standard Mode Security Extensions (SMSE)

Configuring SMSE user security

Understanding Standard Mode Security

Enhancements benefits

Understanding SMSE attributesConfiguring /etc/security.dscConfiguring /etc/default/security

Configuring /etc/passwd and /etc/shadowConfiguring /var/adm/userdb/ via

userdbset, userdbget, and userdbck

Enforcing SMSE security policies

Securing user accounts: Role Based Access Control (RBAC)

RBAC features and benefitsInstalling RBAC

Configuring & assigning RBAC roles

Configuring & assigning RBAC authorizationsConfiguring RBAC commands & privilegesVerifying the RBAC database

(3)

Configuring RBAC logging & auditingRunning commands with privrunEditing files with privedit

Enabling RBAC keystroke logging

Protecting data via file permissions and JFS Access Control Lists (ACLs)

Understanding how hackers exploit improper

file and directory permissions

Viewing and changing file permissionsSearching for files with improper permissionsConfiguring and using the SUID bit

Configuring and using the SGID bitConfiguring and using the sticky bitConfiguring and using JFS ACLs

Protecting data via swverify, md5sum, and Tripwire

File integrity checking overview

Verifying executable integrity with swverifyVerifying file integrity with md5sumVerifying file integrity with TripwireInstalling Tripwire

Creating Tripwire keys

Creating the Tripwire configuration fileCreating the Tripwire policy fileCreating the Tripwire databasePerforming a Tripwire integrity checkUpdating the Tripwire databaseUpdating the Tripwire policy file

Protecting data via Encrypted Volumes and File Systems (EVFS)

EVFS featuresEVS architectureEVS volumes

EVS volume encryption keys, user keys, and

recovery keys

Step 1: Installing and configuring EVFS

software

Step 2: Creating user keysStep 3: Creating recovery keys

Step 4: Creating an LVM or VxVM volume

Step 5: Creating EVS device files

Step 6: Creating and populating the volume’s

EMD

Step 7: Enabling the EVS volume

Step 8: Creating and mounting a file systemStep 9: Enabling autostart

Step 10: Migrating data to the EVS volumeStep 11: Backing up the EVS configurationManaging EVS volume users

Managing the EVS key databaseExtending an EVS volumeReducing an EVS volumeRemoving EVS volumesBacking up EVS volumesEVS limitations

EVS and TPM/TCS integration overview

Securing network services: inetd & tcpwrapper

inetd service overview

inetd configuration file overviewSecuring inetd

Securing the inetd internal servicesSecuring the RPC services

Securing the Berkeley servicesSecuring FTP

Securing FTP service classesSecuring anonymous FTPSecuring guest FTP

Securing other ftpaccess security featuresSecuring other inetd services

Securing other non-inetd servicesSecuring inetd via TCPwrapper

Securing network services: SSH

Legacy network service vulnerabilities: DNSLegacy network service vulnerabilities:

Sniffers

Legacy network service vulnerabilities: IP

spoofing

Solution: Securing the network infrastructureSolution: Using symmetric key encryptionSolution: Using public key encryptionSolution: Using public key authentication

(4)

HP-UX encryption & authentication productsConfiguring SSH encryption & server

authentication

Configuring SSH client/user authenticationConfiguring SSH single sign-on

Managing SSH keysUsing the UNIX SSH clientsUsing PuTTY SSH clients

Securing network services: IPFilter

Firewall overviewPacket filtering firewalls

Network Address Translation firewallsHost versus perimeter firewallsInstalling IPFilter

Managing IPFilter rulesets

Configuring a default deny policyPreventing IP and loopback spoofingControlling ICMP service accessControlling access to UDP servicesControlling access to TCP services

Controlling access via active and passive FTPTesting IPFilter rulesets

Monitoring IPFilter

Hardening HP-UX with Bastille

Bastille overviewInstalling Bastille

Generating a Bastille assessmentCreating a Bastille configuration fileApplying a Bastille configuration fileApplying a pre-configured Bastille

configuration file

Applying a pre-configured Bastille

configuration via Ignite-UX

Reviewing the Bastille logs

Monitoring changes with bastille_driftReverting to the pre-Bastille configurationIntegrating Bastille and HP SIM

Monitoring activity via system log files

Monitoring log files

Monitoring logins via last, lastb, and whoMonitoring processes via ps, top, and whodo

Monitoring file access via ll, fuser, and lsofMonitoring network connections via netstat,

idlookup, and lsof

Monitoring inetd connections

Monitoring system activity via syslogdConfiguring /etc/syslog.conf

Hiding connections, processes, and

arguments

Doctoring log files and time stamps

Monitoring activity via SMSE auditing

Auditing overview

Trusted system versus SMSE auditingEnabling and disabling auditingVerifying auditing

Selecting users to audit

Selecting events & system calls to auditCreating and applying an audit profileViewing audit trails

Switching audit trails

Understanding audomon AFS & FSS switchesUnderstanding audomon audit trail namesConfiguring audomon parameters

Configuring audomon custom scripts

Monitoring suspicious activity via HP’s Host Intrusion Detection System (HIDS)

HIDS overviewHIDS architecture

Installing HP’s HIDS product

Configuring HIDS detection templates and

properties

Configuring HIDS surveillance groupsConfiguring HIDS surveillance schedulesConfiguring HIDS response scriptsAssigning surveillance schedules to clientsMonitoring HIDS alerts and errors

Managing security patches with Software Assistant (SWA)

Security patch overviewSWA overview

Reading US-CERT advisory bulletinsReading HP-UX security bulletins

(5)

Installing swa

Generating swa reportsViewing swa reports

Retrieving swa recommended patchesInstalling swa patches

Installing other products recommended by

swa

Applying other manual changesRegenerating swa reportsPurging swa cachesViewing swa logsCustomizing swa defaultsIntegrating SWA and HP SIM

Preventing unauthorized swa and swlist

access

Preventing buffer overflow attacks

Setting the executable_stack kernel parameterSetting the chatr +es executable stack option

Isolating applications via security compartments

Security compartment conceptsCompartment rule conceptsINIT compartment conceptsInstalling compartment softwareEnabling compartment functionalityCreating and modifying compartmentsViewing compartments

Adding network interface rulesAdding file permission rules

Adding a compartment-specific directoryViewing compartments

Launching applications in compartmentsConfiguring compartment users

Executing commands in compartmentsRemoving compartments

Disabling compartment functionality

Using discovery compartments to determine

an application’s compartment requirements

Isolating Applications via Secure Resource Partitions

SRP conceptsSRP example

SRP subsystemsSRP templatesSRP servicesInstalling SRP

Enabling and configuring SRPVerifying the SRP configurationCreating an SRP interactivelyCreating an SRP non-interactively

Adding the init, prm, network, ipfilter, login,

and ipsec services to an SRP

Adding the ssh, apache, tomcat, and oracle

templates to an SRP

Adding the custom template to an SRPDeploying an application in an SRPUpdating an SRP

Viewing the SRP configuration & statusStarting & stopping an SRP

Accessing an SRPRemoving an SRP

Appendix: Improving user and password security with trusted systems

Trusted system overview

Configuring password format policiesConfiguring password aging policiesConfiguring user account policiesConfiguring terminal security policiesConfiguring access control policiesConfiguring password aging policiesUnderstanding the /tcb directory structure

Appendix: Implementing chroot()

Limiting file access via chroot()Configuring chroot()ed applications

Appendix: Implementing Fine Grained Privileges (FGP)

Limiting privileges via FGPInstalling FGP SoftwareInstalling FGP SoftwareRecognized Privileges

Permitted, Effective, and Retained Privilege

Sets

(6)

Configuring FGP Privileges via RBACConfiguring & Using FGP TRIALMODE

Appendix: Process Resource Manager (PRM) Overview

Allocating resources without PRMAllocating resources with PRMPRM advantages

PRM managersPRM groups

PRM Fair Share Scheduler concepts &

configuration

PRM PSET concepts & configurationPRM memory manager concepts &

configuration

Reviewing available resourcesAnalyzing application requirementsEnabling PRM

Creating and updating the PRM configuration

file

Monitoring resource usage

© Copyright 2010 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein.

References

Related documents

There are no joint ventures or wholly foreign owned companies serving this market, but the two Chinese firms with 25 percent foreign investment, Taikang and New China Life, have

Any provision of law to the contrary notwithstanding, a contractor may be ranged a right to cut trees or timber within his mining area as may be necessary for his mining

Longitudinal DNA methylation data from birth to early childhood and from birth to adolescence were analysed for the three or more adjacent Bonferroni significant 1276 CpGs found to

However, these points are not reliable enough to be used in ICP registration if the capture points are far from each other because two possible sources of errors exist: errors in

We use individual level, monthly, bank account data to examine how expected income shocks from final mortgage payments impact credit card consumption, and the repayment of credit

Payment service and fraud management provider Ogone was acquired by payments company Ingenico Group, while fraud prevention and risk management company Retail Decisions

Palmer (1998) mentions that there are eight ways to make the students participate at the interaction by creating routine activities including encouraging the students to answer