Network Intrusions Responder Program (NITRO). Instructor Guide - page 16

 

  Index      Manuals     Network Intrusions Responder Program (NITRO). Instructor Guide

 

Search            copyright infringement  

 

   

 

   

 

Content      ..     14      15      16      17     ..

 

 

 

Network Intrusions Responder Program (NITRO). Instructor Guide - page 16

 

 

TCP/IP Message Routing
ƒ TCP/IP is routable protocol that enables computers on different
networks to communicate as if on same network
ƒ IP part of protocol provides routing capability
ƒ Sent message divided into packets
ƒ TCP/IP determines travel path and transmits packets
ƒ When packet reaches destination, confirmation sent to source
ƒ Confirmation is why TCP/IP is considered to be so reliable
U.S. Department of
Homeland Security
United States
Secret Service
TCP/IP Suite Protocols
ƒ Simple Mail Transfer Protocol (SMTP) - Used to send email
ƒ File Transfer Protocol (FTP) - Used to transfer files
ƒ Simple Network Management Protocol (SNMP) - Used to
monitor network activities
ƒ Telnet - Allows logon to remote computer to run program
ƒ Domain Name Service (DNS) - Matches domain names of
host computers with corresponding IP addresses
U.S. Department of
Homeland Security
United States
Secret Service
TCP/IP Model
ƒ Application layer
ƒ Transport layer
ƒ Network layer
ƒ Link layer
U.S. Department of
Homeland Security
United States
Secret Service
Encapsulation
ƒ A TCP/IP process for handling data packets
ƒ As data travel down TCP/IP model when a device transmits
packets, each layer adds leading information, or headers
U.S. Department of
Homeland Security
United States
Secret Service
De-capsulation
ƒ The process of removing headers as data travels up TCP/IP
model on receiving network device
U.S. Department of
Homeland Security
United States
Secret Service
TCP/IP vs. OSI Model
ƒ OSI considered conceptual model of how communications
should flow from one network to another
ƒ OSI Provides standard for other protocols to use
ƒ TCP/IP represents actual implementation of how internetwork
communications occur
ƒ TCP/IP Application layer absorbs functions of OSI Model’s
Presentation and Session layers
ƒ TCP/IP combines functions of Data Link and Physical layers of
OSI Model
U.S. Department of
Homeland Security
United States
Secret Service
TCP/IP vs. OSI Model Illustration
TCP/IP Protocol
OSI
Stack
Application Layer
Presentation Layer
Application Layer
Session Layer
Transport Layer
Transport Layer
Network Layer
Network Layer
Data Link Layer
Link Layer
Physical Layer
U.S. Department of
Homeland Security
United States
Secret Service
Internetwork Packet Exchange (IPX)
ƒ Novell Netware protocol
ƒ Easy to configure for small networks and compatible with other
network operating systems
ƒ IPX is connectionless network protocol operates on Network
Layer
ƒ IPX data packets sent without prior knowledge of current state
of recipient system
ƒ Packet delivery not guaranteed
U.S. Department of
Homeland Security
United States
Secret Service
Sequenced Packet Exchange (SPX)
ƒ Novell Netware protocol
ƒ Easy to configure for small networks and compatible with other
network operating systems
ƒ Connection-oriented, ensures proper delivery of packets by
establishing virtual connection between sender and receiver
before packets sent
ƒ Guarantees delivery of packets and provides error correction
and packet sequencing
U.S. Department of
Homeland Security
United States
Secret Service
NetBIOS
ƒ Standard networking protocol for Windows networks
ƒ Provides programming interface for applications on Session
Layer
ƒ Combined with NetBIOS Extended User Interface (NetBEUI),
which serves as default transport protocol for Windows
networks
U.S. Department of
Homeland Security
United States
Secret Service
NetBEUI
ƒ Each computer on NetBEUI network has unique NetBIOS
name (no more than 15 characters)
ƒ Non-routable, cannot pass data through router to leave LAN
ƒ Broadcasts many packets which makes it difficult to scale
ƒ Easy to configure with low overhead
ƒ Fast, self-tuning
ƒ Best suited for small LANs
U.S. Department of
Homeland Security
United States
Secret Service
Point-to-Point Protocol (PPP)
ƒ Designed for simple links between two peers
ƒ Offers full-duplex operation to both peers
ƒ Packets delivered in order (circuit-switched)
ƒ Used to link PC to Internet
ƒ Creates session between PC and ISP
ƒ Works well with many protocols including IPX
U.S. Department of
Homeland Security
United States
Secret Service
Point-to-Point Tunneling Protocol
(PPTP)
ƒ Enables other protocols to transmit over IP network
ƒ For example, used to encapsulate NetWare IPX packets and
send them over Internet
ƒ Also used to carry TCP/IP, IPX/SPX, and NetBEUI traffic
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 4 - Wireless Networks
ƒ What is a Wireless Network?
ƒ Types of Wireless Networks
ƒ Hardware Components
ƒ Security Concerns
ƒ Vulnerabilities
U.S. Department of
Homeland Security
United States
Secret Service
Wireless Network
ƒ Does not require cables to connect computers and peripherals
ƒ Network communications transmitted across airwaves using
infrared and various forms of radio technology
ƒ Uses radio frequencies between 2 and 5 gigahertz
ƒ Growing in popularity
ƒ Effective range between 300 and 1,500 feet
U.S. Department of
Homeland Security
United States
Secret Service
802.11
ƒ Established global rules for wireless networking at speed of
2Mb/sec
ƒ 802.11b, extension of original standard, increased throughput
from to 11Mb/sec
ƒ 802.11b operates at frequency of 2.4 gigahertz, backward
compatible with original standard
U.S. Department of
Homeland Security
United States
Secret Service
802.11
ƒ Extensions 802.11a and 802.11g, both offer throughput as
high as 54Mb/sec
ƒ 802.11g, backward compatible with 802.11b, both operate at
2.4 gigahertz
ƒ 802.11n claims to be twice as fast as 802.11g,
ƒ 802.11i addresses security concerns over current 802.11
standards
ƒ 802.11n incorporates Multiple Input Multiple Output (MIMO)
antennas
U.S. Department of
Homeland Security
United States
Secret Service
Hot Spots
ƒ 802.11 networking feature often packaged under label Wi-Fi
and Centrino, an Intel trademark
ƒ Intel partnered with companies like Hilton Hotels & Resorts,
Borders Group, and McDonalds to develop concept called hot
spots
ƒ Enables user of wireless-enabled notebooks and PDAs to
connect to Internet while using other services business offers
ƒ Strategy is two-fold: wireless hardware sales increase, and
hosting businesses attract more customers
U.S. Department of
Homeland Security
United States
Secret Service
Types of Wireless Networks
ƒ In general, two types of wireless networks: ad-hoc and
infrastructure
ƒ Type of network simply indicates how wireless devices are
configured to communicate
ƒ Configuration can be easily changed from one type to other
making wireless networking flexible and easy to use
U.S. Department of
Homeland Security
United States
Secret Service
Ad-Hoc Wireless Network
ƒ When group of wireless computers configured to communicate
with each other in peer-to-peer configuration, result is
independent wireless network
ƒ Combination of wireless computers and modern operating
systems allow enough flexibility for wireless computers to join
network with ease
ƒ Provides easy setup, ideal for groups who wish to collaborate
on project
ƒ Ad-hoc nature of network provides wireless network its name
U.S. Department of
Homeland Security
United States
Secret Service
Ad-Hoc Wireless Network
U.S. Department of
Homeland Security
United States
Secret Service
Infrastructure Wireless Network
ƒ Computers configured in infrastructure wireless network look
for other wireless devices attached to wired network
ƒ Devices, called access points, usually attached directly to hub
or switch in wired network
ƒ Primary function is to provide wireless computers with access
to wired network
ƒ Once connected to wired network, wireless devices can use
resources available to wired network including Internet access
U.S. Department of
Homeland Security
United States
Secret Service
Infrastructure Wireless Network
U.S. Department of
Homeland Security
United States
Secret Service
Hardware Components
ƒ A wireless local area network (WLAN) is rarely wireless
ƒ Shared resources, such as Internet gateway, printers, file
servers, etc., are typically all interconnected with cables
U.S. Department of
Homeland Security
United States
Secret Service
Wireless NIC
ƒ Network interface card (NIC) is essential part of any wireless
network
ƒ Wireless NIC functions as interface between PC and media
used to connect PC to network
ƒ NICs typically have visible antennae as shown in examples on
following slide
U.S. Department of
Homeland Security
United States
Secret Service
Wireless NIC Illustration
U.S. Department of
Homeland Security
United States
Secret Service
Wireless Access Points (WAP)
ƒ Provides connection for Wireless NIC to wired network
ƒ Generally small hardware device connected by cable to hub or
switch on wired network
ƒ Can also be wireless cable/DSL router that provides routing
protection and functionality to broadband Internet service
U.S. Department of
Homeland Security
United States
Secret Service
Wireless Access Points (WAP)
ƒ Usually equipped with one or two visible antenna
ƒ Antennae receive signals from wireless NIC and converts to
format compatible with cable that connects WAP to network
ƒ Single WAP can support connections from multiple wireless
devices
U.S. Department of
Homeland Security
United States
Secret Service
WAP Illustrations
U.S. Department of
Homeland Security
United States
Secret Service
Security Concerns
ƒ Wireless network communications extremely vulnerable to
eavesdropping and attack
ƒ In broadcast network, data transmissions are sectioned into
packets broadcast to all devices attached to network
ƒ Packets broadcast over wireless connections can easily be
intercepted and examined
ƒ Data being transmitted can be viewed and reassembled by
intercepting party
U.S. Department of
Homeland Security
United States
Secret Service
WEP
ƒ Networking devices manufactured under 802.11 standards
employ method of encryption called wired equivalent privacy or
WEP
ƒ Provides encryption of communications based on 64 or 128 bit
key
ƒ Wireless computer and WAP must use same key to
communicate
ƒ Wireless devices have ability to turn WEP on or off
ƒ Default state of WEP for most devices is off
U.S. Department of
Homeland Security
United States
Secret Service
WEP
ƒ WEP intended to secure wireless networks
ƒ Flaws well documented
ƒ Slightly better than no security at all
ƒ With right combination of hardware and software WEP key can
be cracked within minutes
U.S. Department of
Homeland Security
United States
Secret Service
WPA
ƒ Wi-Fi Alliance, in cooperation with several members of IEEE
802.11i task group, developed Wi-Fi Protected Access (WPA)
to address wireless security
ƒ WPA uses dynamic keys so same encryption key never used
twice
ƒ WPA encryption key derived from up to 500 trillion possibilities
ƒ Key virtually uncrackable if strong password used
U.S. Department of
Homeland Security
United States
Secret Service
LEAP
ƒ Lightweight Extensible Authentication Protocol (LEAP)
provides authentication services on wireless network
ƒ When wireless client attempts to access network, wireless
access point (WAP) blocks all ports except for authentication
ports to allow input of authentication credentials
ƒ Once received, WAP forwards credentials to special
authentication server for validation
ƒ If credentials valid, unique key generated for session and
access to network through WAP is granted
U.S. Department of
Homeland Security
United States
Secret Service
LEAP
ƒ Key generated is per-user and per-session, complicating and
hopefully frustrating hacking attempts
ƒ Time-out settings of key can be adjusted to force devices to re-
authenticate frequently
ƒ Re-authentication results in new session, new key
ƒ Keys change frequently and sessions become short
ƒ Packet sniffing becomes useless as means of deriving session
keys
U.S. Department of
Homeland Security
United States
Secret Service
Service Set Identifier (SSID)
ƒ Unique, user configurable name used to communicate with
WAP
ƒ Most wireless access points have SSID indicative of
manufacturer or model of device
ƒ Example, Linksys brand of WAP uses name LINKSYS as
default SSID
ƒ SSID can be any combination of alpha and numeric characters
with maximum length of 32 characters
U.S. Department of
Homeland Security
United States
Secret Service
Service Set Identifier (SSID)
ƒ When WAP powered on, begins broadcasting SSID to any
wireless device within range
ƒ Feature intended to simplify connectivity by mobile devices
ƒ Can be disabled in some WAPs eliminating necessity for
notebook PC or PDA users to know SSID before connecting
U.S. Department of
Homeland Security
United States
Secret Service
MAC Filtering
ƒ Enabling WPA and MAC filtering are methods that can harden
wireless network against attack
ƒ If MAC filtering enabled, (disabled by default), list of MAC
addresses is created for devices allowed to join network
ƒ As connection attempts made, MAC address of each device
validated against list
ƒ Device denied access if device’s MAC not on filter list
ƒ Can be circumvented through MAC spoofing
U.S. Department of
Homeland Security
United States
Secret Service
Wireless Detection Systems
ƒ Wireless detectors developed as result of security concerns
ƒ Among solutions are small inexpensive detectors like
examples shown on next slide
ƒ Both devices cost less than $25 and only detect presence of
802.11 wireless signals and signal strength
ƒ Devices not well suited for determining WAP SSID, MAC
address of WAP, or other information that can be detected
using more sophisticated and expensive solutions
U.S. Department of
Homeland Security
United States
Secret Service
Wireless Detection Devices
U.S. Department of
Homeland Security
United States
Secret Service
Wireless Detection Systems
ƒ Unauthorized or rogue wireless devices can appear on
network for short durations, making them hard to detect
ƒ Solution providers have developed detection systems
comprised of specialized software and customized sensors to
address issue
ƒ Sensors placed strategically throughout network, constantly
monitoring for rogue devices
ƒ When device detected, location triangulated using strategically
placed sensors
U.S. Department of
Homeland Security
United States
Secret Service
Wireless Detection Systems
ƒ Once identified and approximate position determined,
notebook computer or PDA equipped with directional antenna
used to pinpoint device
ƒ Can be accomplished by sweeping antenna in a 360-degree
rotation while monitoring signal strength
ƒ Number of freeware applications available to perform function
ƒ Net Stumbler for MS Windows and Pocket PC, Kismet for
Linux
U.S. Department of
Homeland Security
United States
Secret Service
War Driving Roots
ƒ Hacker groups collaborated, developed software configured to
search for BBS or modem-enabled mainframe computer by
sequentially dialing telephone numbers within given area code
and exchange
ƒ As number dialed, hacker’s computer waited for carrier signal
of modem on other end
ƒ No carrier detected, call ended and next number in sequence
dialed
ƒ If carrier detected, calling computer saved telephone number
to log file, disconnect, moved to next number in sequence
U.S. Department of
Homeland Security
United States
Secret Service
War Driving
ƒ Process called war dialing and became foundation for many
hacking applications
ƒ Concept was applied to wireless networks, but without
modems
ƒ Just as modems sat waiting for someone to connect, in
wireless network, WAP waits
ƒ Airwaves can be scanned for 802.11 signals, and SSIDs
U.S. Department of
Homeland Security
United States
Secret Service
War Driving
ƒ Tools can be used with notebook computer to scan for and
identify wireless networks
ƒ Data these programs collect include:
ƒ SSID (if broadcasted)
ƒWhich of 14 wireless channels or frequencies used (only 11
used in U.S.)
ƒWhether or not WEP or WPA is enabled
ƒ MAC address of WAP
U.S. Department of
Homeland Security
United States
Secret Service
War Driving
ƒ Hackers have developed software similar to war dialer that
attempts to connect to computers or WAPs
ƒ Name War Driving derived from running programs on laptop
with wireless NIC and external antenna while driving along
major traffic routes in effort to locate wireless networks
ƒ Common for War Drivers to record GPS coordinates of
wireless networks for use with mapping software and for
publication to various sites on Internet
U.S. Department of
Homeland Security
United States
Secret Service
Overlapping Signals
ƒ Wireless network signals typically radiate in elliptical pattern
ƒ Can vary depending upon physical structure in which WAP
deployed
ƒ Walls, floors, ceilings, and other obstacles affect radio waves
U.S. Department of
Homeland Security
United States
Secret Service
Overlapping Signals
U.S. Department of
Homeland Security
United States
Secret Service
Overlapping Signals
ƒ Four buildings with wireless networks in illustration on previous
slide
ƒ Building C far enough away from other buildings, overlapping
signals not an issue
ƒ Building D has two wireless access points deployed with
minimal signal overlap
ƒ If two signals in building D are owned by different businesses,
could pose a significant problem
ƒ Buildings A and B wireless access points generate overlapping
signals
U.S. Department of
Homeland Security
United States
Secret Service
Overlapping Corrective Action
ƒ Relocation of the WAP
ƒ Reducing power output of the WAP
U.S. Department of
Homeland Security
United States
Secret Service
Accidental Access
ƒ Wireless end user operating in overlapping signal area could
possibly connect to wrong network accidentally
ƒ If wireless networks configured to use WEP, possibility of
accidental access eliminated
U.S. Department of
Homeland Security
United States
Secret Service
Known Attacks
ƒ Wireless network technology constantly improving
ƒ There are known vulnerabilities that lead to attack
ƒ Wireless network attacks usually result from improperly
managed or improperly secured wireless technology
U.S. Department of
Homeland Security
United States
Secret Service
Session Hijacking
ƒ Attacker monitors active sessions, connections between WAP
and remote station, identifying information used to facilitate
attack
ƒ Once enough information collected, attacker sends spoofed
message to target workstation to disconnect
ƒ Workstation responds by ending session allowing attacker to
masquerade as disconnected workstation
U.S. Department of
Homeland Security
United States
Secret Service
Man-in-the-Middle
ƒ Exploits one-way authentication of 802.11 design, allows
attacker to configure computer to act as wireless access point
ƒ Attacker waits for users to connect to wireless network
ƒ Remote computers pass WEP key to attacker’s computer
ƒ Attacker’s computer connects to real WAP and passes remote
computers packets transparently between user and WAP
ƒ Result is captured WEP key that will allow attacker access to
wireless network
U.S. Department of
Homeland Security
United States
Secret Service
WEP Key Cracking
ƒ When WEP enabled, encrypted key used to connect to, and
transfer data across wireless network
ƒ Only computers with WEP key allowed to communicate
ƒ Software tools, such as Airsnort and WEPcrack, simplify job of
cracking WEP key
ƒ By monitoring packets transmitted across airwaves, attacker
can save packets to log file
ƒ After several thousand packets have been collected, cracking
tools can analyze collected packets to determine WEP key
U.S. Department of
Homeland Security
United States
Secret Service
WPA-PSK Cracking
ƒ WPA-PSK uses pre-shared key for its encryption algorithm
ƒ Method much more secure than using WEP, but still
susceptible to cracking
ƒ Attack method used to crack WPA-PSK is dictionary attack
ƒ Captured data between transmitting access point and user can
be run through dictionary to find correct key to unlock data
ƒ Countered by use of long key not found in dictionary, such as
complete phrase with additional special characters, etc
U.S. Department of
Homeland Security
United States
Secret Service
U.S. Department of
Homeland Security
United States
Secret Service
Module 7 - IP Addresses and Subnets
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
ƒ IP Addresses
ƒ Ports
ƒ Subnets
ƒ Network Security
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - IP Addresses
ƒ IP Address Basics
ƒ IP Address Classes
ƒ More about IP Addresses
U.S. Department of
Homeland Security
United States
Secret Service
Network Addressing Overview
ƒ In TCP/IP network, IP (Internet Protocol) addressing essential
to physical routing of network communications
ƒ Every device on LAN must have unique IP address
ƒ Addresses essential for internetworking over WANs
U.S. Department of
Homeland Security
United States
Secret Service
Network Addressing Overview
ƒ Media Access Control (MAC) address is unique hardware
identification number specific for each network device
ƒ To send data packet to host on LAN, sending device must first
know receiver’s MAC address
ƒ MAC addresses exist at Data Link Layer 2 of OSI model
U.S. Department of
Homeland Security
United States
Secret Service
Network Addressing Overview
ƒ IP addresses identify every device attached to TCP/IP
network, including PCs, servers, switches, printers, and any
other networked device
ƒ Each device has unique IP address so it can be identified for
internetwork data packet routing
ƒ IP addresses exist at Network Layer 3 of OSI model
U.S. Department of
Homeland Security
United States
Secret Service
Network Addressing Overview
ƒ Workstations can have permanent (static) IP address, or
dynamically assigned address each time network connection
established
ƒ For clients on isolated LAN, administrator can assign unique
static IP addresses
ƒ To communicate with Internet, hosts must have unique
registered Internet routable IP address
U.S. Department of
Homeland Security
United States
Secret Service
What’s in an IP Address
ƒ IP address, 32-bit numeric address written as four sets of
numbers, called octets, separated by periods
ƒ For example, 131.160.10.240 is example of class B IP address
ƒ Each octet can range from 0 to maximum of 255
ƒ Valid IP addresses cannot consist of all zeros or all ones
U.S. Department of
Homeland Security
United States
Secret Service
What’s in an IP Address
ƒ For each networked device, IP address consists of network
address (netid) and host address (hostid)
ƒ Each octet of IP address contains eight bits or one byte
ƒ Address has total of four bytes
U.S. Department of
Homeland Security
United States
Secret Service
Example Class B IP Address
131.107.10.7
U.S. Department of
Homeland Security
United States
Secret Service
Binary IP Addressing
ƒ IP addresses read as set of four decimals
ƒ Computer only reads ones and zeros
ƒ IP addresses are binary, each of four decimals translated into
eight binary numbers consisting of ones and zeros
ƒ Binary numbering system used in IP addresses based on
number 2, called Base2
ƒ Each octet in address limited to eight bits, corresponding
binary numbers range from 20 to 27 (1 to 255)
U.S. Department of
Homeland Security
United States
Secret Service
Converting Decimal 131 to Binary
Binary Conversion of Decimal 131
Base2
27
26
25
24
23
22
21
20
Decimal
128
64
32
16
8
4
2
1
Binary Number is
1
0
0
0
0
0
1
1
10000011
U.S. Department of
Homeland Security
United States
Secret Service
Classes of IP Addresses
ƒ IP addresses divided into several class types
ƒ Class A, B, and C used for government and commercial
addresses
ƒ Class D and E reserved for multicasting, transmission of data
to many recipients simultaneously
ƒ Class D and E not commonly used
ƒ Each class allows for specific maximum number of subnets
and end nodes
U.S. Department of
Homeland Security
United States
Secret Service
Class A
Classes of IP Addresses Defined
Class
First
Maximum
Maximum
Other
Octet
Networks
Hosts
Characteristics
A
1 -
126
16,777,214
Most often
126
allocated to
government and
large institutions;
Address Range:
1.X.X.X to
126.X.X.X
U.S. Department of
Homeland Security
United States
Secret Service
Class B
Classes of IP Addresses Defined
Class
First
Maximum
Maximum
Other
Octet
Networks
Hosts
Characteristics
B
128 -
16,384
65,534
Most often
191
allocated for
commercial use
and ISPs;
Address Range:
128.X.X.X to
191.X.X.X
U.S. Department of
Homeland Security
United States
Secret Service
Class C
Classes of IP Addresses Defined
Class
First
Maximum
Maximum
Other
Octet
Networks
Hosts
Characteristics
C
192 -
2,097,152
254
Most often
223
allocated for
commercial use
and ISPs;
Address Range:
192.X.X.X to
223.X.X.X
U.S. Department of
Homeland Security
United States
Secret Service
Class D
Classes of IP Addresses Defined
Class
First
Maximum
Maximum
Other
Octet
Networks
Hosts
Characteristics
D
224 -
N/A
N/A
Reserved class
239
used for
multicasting;
does not contain
network or host
IDs
U.S. Department of
Homeland Security
United States
Secret Service
Class E
Classes of IP Addresses Defined
Class
First
Maximum
Maximum
Other
Octet
Networks
Hosts
Characteristics
E
240 -
N/A
N/A
Reserved class
247
used for
experimentation;
does not contain
network or host
IDs
U.S. Department of
Homeland Security
United States
Secret Service
Reserved IP Addresses
Description
IP Address Range
Reserved for non-
• 10.0.0.0 to 10.255.255.255
routable networks
• 172.16.0.0 to 172.31.255.255
• 192.168.0.0 to 192.168.255.255
Reserved for loopback
127.0.0.1
NIC testing
U.S. Department of
Homeland Security
United States
Secret Service
Reserved IP Addresses
Description
IP Address Range
Reserved for routing
128.5.0.0
tables; refers to entire
network
IDs an entire network
X.0.0.0 (Class A)
X.X.0.0 (Class B)
X.X.X.0 (Class C)
Broadcast
X.255.255.255 (Class A)
X.X.255.255 (Class B)
X.X.X.255 (Class C)
U.S. Department of
Homeland Security
United States
Secret Service
New Methods for IP Addressing
ƒ Class system provides a finite number of IP addresses
ƒ Number of unassigned Internet addresses running out
ƒ New scheme called Classless Inter-Domain Routing (CIDR)
introduced as replacement for system based on classes A, B,
and C
U.S. Department of
Homeland Security
United States
Secret Service
Classless Inter-Domain Routing
ƒ With CIDR, IP addresses assigned in blocks
ƒ Single IP address can be used to identify many unique IP
addresses
ƒ CIDR IP address looks like normal IP address except it ends
with a slash followed by a number
ƒ End number is called IP prefix length, represents how many
bits used for network partition of address
ƒ An example of a CIDR address is 162.200.0.0/12
U.S. Department of
Homeland Security
United States
Secret Service
Classless Inter-Domain Routing
ƒ Prefix length designates how many addresses available for
network and hosts in CIDR address
ƒ In example 162.200.0.0/12, first 12 bits of address identify
network and remaining 20 bits identify host
10100010.1100|1000.00000000.00000000
212 = 4098 Networks
220 = 1,048,576 Hosts per Network
ƒ CIDR addresses also reduce size of routing tables and allows
more IP addresses for subnetting and supernetting
U.S. Department of
Homeland Security
United States
Secret Service
IPv6
ƒ Internet Protocol version 6 (IPv6), new method for IP
addressing, significantly increases amount of available IP
addresses
ƒ Expands IP address from 32 bits to 128 bits
ƒ Will provide over 3.4x10**38 power new addresses
ƒ Enough IP addresses that every cell of human body could be
assigned one with addresses to spare
U.S. Department of
Homeland Security
United States
Secret Service
IPv6
ƒ Addresses presented in hexadecimal format, such as:
FE80:325B:134C:5555:678D:9C4D:3EEE:2D5F
ƒ Format consists of eight groups of hexadecimal digits
ƒ Initially, many addresses will have zeros in groups
U.S. Department of
Homeland Security
United States
Secret Service
IPv6
ƒ Shorthand notation exists to expresses groups of zeros, :: (the
colon-colon operator)
ƒ All groups in colons are zeros
ƒ For example, IPv6 address, FE80::3E4F
ƒ First group is FE80
ƒ Second through 7th groups are all zeros
ƒ Eighth group is 3E4
U.S. Department of
Homeland Security
United States
Secret Service
IPv6 Special Addresses and Prefixes
Address
Description
::FFFF:0:0/96
Used for IPv4 mapped addresses
FC00::/7
Unique local IPv6 unicast addresses.
Routable only within set of cooperating
sites. Replaced “site-local” used in
earlier implementation of IPv6.
U.S. Department of
Homeland Security
United States
Secret Service
IPv6 Special Addresses and Prefixes
Address
Description
FE80::/10
Local link for use within a LAN. Similar
to 169.254.x.x, the autoconfig IP
address in IPv4.
FF00::/8
Multicast prefix. No address ranges
reserved for broadcast. Applications are
to use multicast.
U.S. Department of
Homeland Security
United States
Secret Service
IPv6 Special Addresses and Prefixes
Address
Description
::1 /128
Loopback or “localhost” address. Similar
to 127.0.0.1 IPv4 loopback address.
FE80::/10 through
Private address ranges. Similar to IPv4
FEB0::/10
private LAN addresses. Local link
addresses. Stateless and
autoconfigured for use within LAN
segment.
U.S. Department of
Homeland Security
United States
Secret Service
IPv6 Special Addresses and Prefixes
Address
Description
FEC0::/10 through
Private address ranges. Similar to IPv4
FEF0::/10
private LAN addresses. Local site
addresses.
FF00::/8 prefix
Multi-cast prefix
( 2000 to 3FFF )::/16
Global unicast prefix
prefix
U.S. Department of
Homeland Security
United States
Secret Service
IPv6 Special Addresses and Prefixes
Address
Description
2001::/16
Assigned to Regional Internet Registrar
(RIR)
2002::/16
Assigned to 6to4 Transition Methods
3FFE::/16
Temporary address assigned to 6bone
U.S. Department of
Homeland Security
United States
Secret Service
Dual Stacks
ƒ Routers and computers can be configured to use both IPv4
and IPv6
ƒ Routers that route both IPv4 and IPv6 packets called dual-
stack
ƒ No need for subnet mask address or NAT (Network Address
Translation) with IPv6, although NAT can be implemented
U.S. Department of
Homeland Security
United States
Secret Service
Pseudo-Interfaces
ƒ Network card can be configured with multiple IPv6 addresses
ƒ For example, one address can be for just a segment, another
for the site, and third can be for Internet
ƒ IPv6 protocol assigns pseudo-interfaces or zone IDs for each
of these
ƒ An address may look like ABCD::1234:B2C3 %4
ƒ %4 would be its zone ID
U.S. Department of
Homeland Security
United States
Secret Service
Domain Name Service
ƒ Most networks and Web sites have text-based domain names
people can remember, such as www.google.com
ƒ Internet based on numerical IP addresses
ƒ Domain name service (DNS) translates text domain names
into numerical IP addresses before Internet connection made
ƒ Type Web address to favorite site, DNS server receives site
request and translates into corresponding IP address
U.S. Department of
Homeland Security
United States
Secret Service
Dynamic Host Configuration
Protocol
ƒ Dynamic Host Configuration Protocol (DHCP) used to assign
dynamic IP addresses to devices on network
ƒ Addresses are assigned from pool of pre-registered addresses
ƒ Eliminates need and time to manually assign IP addresses to
new network equipment
ƒ Tracks all assigned addresses automatically
U.S. Department of
Homeland Security
United States
Secret Service
Dynamic Host Configuration
Protocol
ƒ Computer or other device can be assigned different IP address
every time it accesses network
ƒ Device can change IP address between logon and logoff
ƒ ISPs frequently use DHCP for dial-up and broadband users
ƒ DHCP6 will run in networks that have implemented IPv6
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - Ports
ƒ Overview of Ports
ƒ How Ports are Used
ƒ Configuring TCP/IP
U.S. Department of
Homeland Security
United States
Secret Service
Ports
ƒ Communications over computer networks similar to telephone
system in sense that thousands of conversations between
computers occur every second
ƒ For computers and applications to communicate, need means
of channeling communications, called service ports, or simply
ports
U.S. Department of
Homeland Security
United States
Secret Service
Ports
ƒ When computer receives data from network, TCP/IP protocol
stack must know data’s user application destination
ƒ For example, Web server sends Web page to computer,
TCP/IP must know Web page data goes to Web browser to
display page
U.S. Department of
Homeland Security
United States
Secret Service
Ports
ƒ TCP/IP maps data to an application using a port, number that
represents an application
ƒ Each transmission is labeled with source and destination port
ƒ The source port identifies application sending data
ƒ Destination port identifies application to process data
U.S. Department of
Homeland Security
United States
Secret Service
Well-Known Ports
ƒ Over 65,000 ports available to network applications
ƒ Ports 1 - 1023 usually map to specific applications, regardless
of computers involved
ƒ For this reason, they are often called well-known ports
U.S. Department of
Homeland Security
United States
Secret Service
Well-Known Ports
Service
Protocol
Port Number
World Wide Web
TCP
80
(HTTP)
Telnet
TCP
23
Simple Mail Transfer
TCP
25
Protocol (SMTP)
File Transfer Protocol
UDP
21
(FTP) Control
U.S. Department of
Homeland Security
United States
Secret Service
Communication Through Ports
U.S. Department of
Homeland Security
United States
Secret Service
Port Use
ƒ Network hardware devices such as firewalls, routers and
gateways offer ability to close or open certain ports
ƒ Provides or denies access to specific types of information
ƒ Some network devices can open port, but restrict packets
traveling through port
ƒ For example, port 21 (File Transfer Protocol) can be opened,
but monitored to disallow packets carrying the put command
ƒ Conversely, the get command would not be blocked
U.S. Department of
Homeland Security
United States
Secret Service
Port Management
ƒ Computer’s ports can be enabled or disabled using features of
operating system
ƒ Windows XP, for example, provides built-in software firewall
that automatically restricts port access
ƒ Terminating an active service on server can also disable ports
ƒ Example, FTP service can be disabled using features of
operating system, disabling port 21
U.S. Department of
Homeland Security
United States
Secret Service
Port Management
ƒ Often, ports managed through configuration of hardware
firewalls
ƒ Hardware firewalls can be managed locally by attaching
special cable from PC to network device and running standard
communications software, such as Telnet or HyperTerminal
ƒ Devices can be managed remotely with Telnet
ƒ Can be managed through Web browser, such as Internet
Explorer, pointing browser to device’s IP address
U.S. Department of
Homeland Security
United States
Secret Service
Port Management
ƒ Regardless of management technique, device will most likely
have administration account requiring login ID and password to
configure device
ƒ Windows XP firewall has rules that block inbound
communication attempts
ƒ Windows Vista firewall includes rules that block both inbound
and outbound communication attempts
U.S. Department of
Homeland Security
United States
Secret Service
Port Misuse
ƒ Most government agencies and corporations publish policies
specifying port configurations for network devices
ƒ Blocking certain ports mandatory in many instances
ƒ Policies intend to minimize risk of intrusion standard
ƒ Technical personnel might “bend the rules” to accomplish
specific task and open unauthorized port on network device
long enough to accomplish task
ƒ Policies protecting network violated and network becomes
vulnerable
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Create a TCP/IP LAN via a
Router with Microsoft Vista
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Subnets
ƒ Subnet Overview
ƒ Subnet Masks
ƒ Virtual LAN
U.S. Department of
Homeland Security
United States
Secret Service
Subnets
ƒ Class A, B, and C networks can be subdivided into subnets
ƒ Subnet is segment of network that shares common IP network
address component with other devices on same subnet
ƒ Devices with same IP address prefix belong to same subnet on
TCP/IP network
ƒ Networks on Internet view other networks as single entities
ƒ No way of viewing another network’s subnet structure, helps
reduce size of routing tables
U.S. Department of
Homeland Security
United States
Secret Service
Subnets
ƒ When data packet is sent over Internet, it goes to router of
destination network
ƒ Router determines destination node by deciphering packet’s
subnet address
U.S. Department of
Homeland Security
United States
Secret Service
Advantages of Subnetting
ƒ Enhances security by creating subnets that have restricted
access
ƒ Extends capabilities of network
ƒ Enhances network performance, eliminating traffic on other
segments
U.S. Department of
Homeland Security
United States
Secret Service
Advantages of Subnetting
ƒ Allows subnets to be invisible to outside world
ƒ Provides flexibility to deploy additional subnets without
registering new network numbers
ƒ Allows data route changes within network without affecting
Internet routing table
U.S. Department of
Homeland Security
United States
Secret Service
Subnet Addressing
ƒ Like IP addresses, each subnet address is unique
ƒ Recall each IP address has four octets, address divided into
two major segments: network and host
ƒ By comparison, subnet address contains three segments:
network address, subnet address, host address
U.S. Department of
Homeland Security
United States
Secret Service
IP Address vs. Subnet Address
U.S. Department of
Homeland Security
United States
Secret Service
Creating Subnets
ƒ Subnets created as extensions of network number
ƒ To create, take bits from host number and reassign to subnet
field
ƒ The more bits taken from host number, the fewer host
addresses that can be assigned to subnet
U.S. Department of
Homeland Security
United States
Secret Service
Subnet Masks
ƒ A subnet mask conceals a subnet from outside networks
ƒ Two main functions of a subnet mask:
ƒ Identify subnet of an IP address
ƒ Notify communicating devices which part of IP address is
network ID (including subnet) and which part is host ID
U.S. Department of
Homeland Security
United States
Secret Service
Default Classes of Subnet Masks
ƒ Class A - 255.0.0.0
ƒ Class B - 255.255.0.0
ƒ Class C - 255.255.255.0
U.S. Department of
Homeland Security
United States
Secret Service
Subnet Masks Components
ƒ Subnet masks use same 32-bit, four-octet structure as IP
addresses
ƒ Subnet mask addresses have three parts: network address,
subnet address, host address
ƒ Subnet mask has all ones in network and subnet segments of
address and contains all zeros in host segment
ƒ With subnetting, part of host address used to identify subnet
ƒ Subnet mask is network address plus bits reserved to identify
subnet
U.S. Department of
Homeland Security
United States
Secret Service
Virtual LAN
ƒ Virtual LAN (VLAN), another way to divide local area network
into logical subgroups
ƒ VLAN uses software to connect group of computers and
devices instead of manually moving cables and wiring
ƒ Can be used to combine workstations and other devices into
single group regardless of physical location
ƒ Improves traffic flow within workgroup
U.S. Department of
Homeland Security
United States
Secret Service
Virtual LAN
ƒ VLANs used in LAN switches
ƒ Network changes and additions quickly implemented with
VLAN software making group solutions easy to create
ƒ VLANs operate at Data Link Layer 2 and Network Layer 3 of
OSI model
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 4 - Network Security
ƒ Data Encryption
ƒ Anti-Virus Software
ƒ Firewalls
ƒ IDS
ƒ Logs
ƒ Network Security Summary
U.S. Department of
Homeland Security
United States
Secret Service
Data Encryption
ƒ Conversion of data into form that cannot be easily deciphered
ƒ Encrypted text called cipher text
ƒ Decryption converts encrypted data into plain text
ƒ Encryption provides highly effective method for data protection
U.S. Department of
Homeland Security
United States
Secret Service
Two Types of Encryption
ƒ Asymmetric encryption uses two types of cryptographic keys to
encode messages
ƒ Public key is known to everyone
ƒ Private key is only known to recipient
ƒ Method works because public key relates to private key so
that messages can be decrypted upon receipt
ƒ Symmetric encryption uses same key to encode and decode
messages
U.S. Department of
Homeland Security
United States
Secret Service
Virus
ƒ Small piece of code that executes when opening a real
program or file
ƒ Example, virus might attach itself to word processing file
ƒ When file opened, virus code attaches itself to word
processing program
ƒ Each time program runs, virus runs
ƒ Has chance to replicate by attaching to other programs or
wreak havoc, such as deleting entire contents of hard drive
U.S. Department of
Homeland Security
United States
Secret Service
E-mail Viruses
ƒ Spreads in e-mail messages
ƒ Usually automatically mails itself to every address in victim's e-
mail address book
U.S. Department of
Homeland Security
United States
Secret Service
Worms
ƒ Small piece of code uses computer networks and
vulnerabilities, known as security holes, to replicate itself
ƒ Worm scans network for any machine that has specific security
hole
ƒ Copies itself to new machine using security hole, and starts
replicating from there
U.S. Department of
Homeland Security
United States
Secret Service
Trojan Horses
ƒ A computer program, not a virus
ƒ Program claims to do one thing, instead could do deliberate
damage when run
ƒ For example, Trojan horse may claim to be a game, but
instead may erase hard disk or create “back door”
ƒ Trojan horses have no way to replicate automatically
U.S. Department of
Homeland Security
United States
Secret Service
Boot Sector Viruses
ƒ Boot sector viruses spread by infecting boot sector of boot
media, usually hard drive or floppy diskette
ƒ Once infected, every time computer boots, virus is loaded
automatically into memory
ƒ Thereafter, attempts to infect every other program and file
opened
U.S. Department of
Homeland Security
United States
Secret Service
Firewalls
ƒ Method of securing a network from unauthorized access
ƒ Most often, protect against intruders who seek access via
Internet
ƒ Enterprises install firewalls to secure Internet access for
employees, separate and protect intranet from unauthorized
public Web site traffic
ƒ Also installed to protect organization’s internal departments or
domains, such as firewall that secures accounting department
U.S. Department of
Homeland Security
United States
Secret Service
Firewalls
ƒ Protection can be software, hardware, or combination of both
ƒ Each performs specific security activities
ƒ Firewalls are access control devices that only detect failed
attempts at access
ƒ If intruder defeats corporate firewall, intrusion may or may not
be logged, depending on firewall configurations
U.S. Department of
Homeland Security
United States
Secret Service
Intranet Protected by Firewall
U.S. Department of
Homeland Security
United States
Secret Service
How Firewalls Work
ƒ All messages going in or out of the network pass through
firewall
ƒ Messages checked using specified security criteria
ƒ Firewall blocks those that do not meet criteria
ƒ Different types of firewalls work at various layers of OSI model
or TCP/IP protocol
U.S. Department of
Homeland Security
United States
Secret Service
Network Address Translation (NAT)
ƒ NAT allows use of internal non-routable IP addresses on
intranet to connect to Internet with one registered IP address
ƒ Registered IP address assigned to software or hardware
device running NAT
ƒ Process allows any computer behind NAT device to be
invisible to Internet
ƒ Only NAT device’s registered IP address is used
U.S. Department of
Homeland Security
United States
Secret Service
How NAT Works
ƒ Intranet computer sends data packet to NAT device
ƒ NAT device examines packet header and records intranet
computer making request
ƒ NAT device replaces IP address with its own registered IP
address and sends request to Internet
ƒ When packet returns, it goes to IP address of NAT device
ƒ NAT device examines packet, places appropriate IP address
for intranet computer in packet, and sends to computer
U.S. Department of
Homeland Security
United States
Secret Service
Stateful Inspection
ƒ Stateful inspection firewall architecture has ability to look into
packet and allow only certain types of application commands
while rejecting others
ƒ For example, stateful packet-filtering firewall allows FTP
command Get and rejects Put command
U.S. Department of
Homeland Security
United States
Secret Service
Stateful Inspection
ƒ Stateful inspection firewalls record User Datagram Protocol
(UDP) packet requests permitted to cross firewall in state table
ƒ Incoming UDP packets examined and verified against ones
waiting for response in state table
ƒ If information matches, request is permitted to enter network,
otherwise packet rejected
U.S. Department of
Homeland Security
United States
Secret Service
Packet-filtering Firewalls
ƒ Packet-filtering firewalls check header of packets for specific
information and accepts or rejects packets based on user-
defined rules
ƒ Checks are made for:
ƒ Source and destination IP address
ƒ Source and destination port numbers
ƒ Protocol type
ƒ Direction of the packet (inbound or outbound)
U.S. Department of
Homeland Security
United States
Secret Service
Packet-filtering Firewall Advantages
ƒ Good performance
ƒ NAT shields internal addresses from external users
ƒ No code modifications are needed
ƒ Closes ports when not in use
ƒ Stateful inspection checks packets and only allows those
through that were requested
U.S. Department of
Homeland Security
United States
Secret Service
Packet-filtering Firewalls
Disadvantage
ƒ Subject to IP spoofing or port spoofing
ƒ Cannot filter or authenticate URL information
ƒ Little or no auditing or alert mechanisms
ƒ Rules need to be entered for stateful inspection type firewalls
and then changed
U.S. Department of
Homeland Security
United States
Secret Service
Circuit-level Firewall
ƒ Validates TCP and UDP sessions before opening connection
ƒ After validation, passes everything through until session ends
ƒ Establishes a virtual circuit between client and host on
session-by-session basis
ƒ Maintains table of connections including session and
sequencing information
ƒ When session ends, table information removed and virtual
connection is closed
U.S. Department of
Homeland Security
United States
Secret Service
Circuit-level Firewall
ƒ Only packets associated with session are allowed through
ƒ If packet is valid according to session table, packet is passed
through without any further security checks
ƒ Session consists of two connections: one between client and
firewall and one between firewall and server
ƒ All outgoing packets appear to have originated from firewall in
method similar to NAT
U.S. Department of
Homeland Security
United States
Secret Service
Circuit-level Firewall Advantages
ƒ Good performance because packets are not examined after
initial connection is allowed
ƒ No direct connection between client and application server
ƒ Similar to NAT’s method of shielding internal IP address
U.S. Department of
Homeland Security
United States
Secret Service
Circuit-level Firewall Disadvantages
ƒ Client programs need to be recompiled and relinked to a
special library containing set of rules for sessions
ƒ Does not examine application level information in packets
allowing them to be subverted by inside user or outside hacker
U.S. Department of
Homeland Security
United States
Secret Service
Application-Gateway Firewall
ƒ Runs on proxy server application that acts as intermediary
between two systems
ƒ Evaluates all requests from internal computers to connect to
external service, such as FTP
ƒ Determines whether to permit or deny request based on rules
defined for individual network
U.S. Department of
Homeland Security
United States
Secret Service
Application-Gateway Firewall
ƒ Application-gateway running on proxy server understands
protocols of service it is evaluating
ƒ Can deny packets that do not comply with protocol for service
ƒ Provides detailed audit records or session information, user
authentication, URL filtering, and caching
U.S. Department of
Homeland Security
United States
Secret Service
Application-Gateway Firewall
ƒ Application-gateway firewalls are application specific and
require proxy addresses for FTP, HTTP, SMTP, etc
ƒ These firewalls operate at Application Layer of OSI model
ƒ Able to look down through packets to application layer
information to determine if packet is altered or not complying
with appropriate protocol rules
ƒ Additional steps cause application-gateway firewall to be
slower than other types of firewalls
U.S. Department of
Homeland Security
United States
Secret Service
Application-Gateway Firewall
Advantages
ƒ No direct connection between internal client and external
server
ƒ Can deny packets that do not comply with protocol for service,
such as FTP, HTTP, SMTP, etc
ƒ Ability to screen data streams for potential threats, such as
send mail attacks, and Java or ActiveX scripts riding on top of
HTTP services
ƒ Provide NAT services
U.S. Department of
Homeland Security
United States
Secret Service
Application-Gateway Firewall
Advantages
ƒ Transparent to individual user
ƒ Can implement features such as HTTP object caching, URL
filtering and user authentication
ƒ Provide audit logs for administrators to monitor for violations of
security policy
U.S. Department of
Homeland Security
United States
Secret Service
Application-Gateway Firewall
Disadvantages
ƒ Slower than other firewall methods
ƒ Vulnerable to operating system and application level bugs
because highly dependant on operating system, TCP/IP
stacks, and runtime libraries
ƒ New services require new proxy servers
U.S. Department of
Homeland Security
United States
Secret Service
Intrusion Detection Systems (IDS)
ƒ Monitor network for attacks
ƒ Two basic types of IDSs:
ƒ Network-based IDS monitors entire network for signs of
intrusion
ƒ Host-based IDS monitors individual computer
ƒ IDS must be installed consistent with network’s type and
topology
U.S. Department of
Homeland Security
United States
Secret Service
Network-based IDS
ƒ Monitors entire network and uses information in data packets
to detect intrusion
ƒ Analyzes packets for attack signature, known pattern in packet
or packets that match specific attack type
ƒ Analyzes packets in real time using recognition files
ƒ Most common method used by IDS pattern expression is byte
code matching, also known as signature analysis or misuse
detection
U.S. Department of
Homeland Security
United States
Secret Service
Network-based IDS
ƒ When attack identified, IDS can be programmed to perform
any of following actions:
ƒ Send alert to console
ƒ Log event and send email
ƒ Initiate connection kill (TCP reset)
ƒ Reconfigure firewall or router, or use SNMP trap
ƒ Important to keep list of known attack signatures current
U.S. Department of
Homeland Security
United States
Secret Service
Host-based IDS
ƒ Host-based IDS installed on individual computer to monitor
only that computer
ƒ Host-based IDSs are used to:
ƒ Monitor logs
ƒ Detect file access
ƒ Detect attempts to install executables
ƒ Monitor remote user activities
U.S. Department of
Homeland Security
United States
Secret Service
Host-based IDS
ƒ Specific to OS installed on computer
ƒ On host with NT OS, IDS will monitor system, event, and
security logs
ƒ On host with Unix OS, IDS will monitor syslog
ƒ Host-based IDS examines each log’s entry to see if it matches
any known attack pattern
ƒ Some can monitor ports on computer
ƒ Can also detect attacks initiated from local keyboard
U.S. Department of
Homeland Security
United States
Secret Service
Host-based IDS Actions
ƒ Log event
ƒ Alert console and send an e-mail
ƒ Initiate a SNMP trap
ƒ Terminate user login and disable user account
U.S. Department of
Homeland Security
United States
Secret Service
Logs
ƒ Record of network activity that provide details of transactions
and traffic
ƒ Routinely used for backup, recovery, and statistical purposes
ƒ Also used to detect failed and successful intrusions, abnormal
network activity, and system activities
ƒ Many different types of logs generated by both software and
hardware devices
ƒ Can be integral part of computer forensic investigations
U.S. Department of
Homeland Security
United States
Secret Service
Common Logs
ƒ System logs
ƒ Firewall logs
ƒ Router logs
ƒ IDS logs
U.S. Department of
Homeland Security
United States
Secret Service
System Logs
ƒ Most networking operating systems able to maintain log files
ƒ Can include system activities, application activities, and
security activities
ƒ Most systems can be configured to maintain logs for Internet
access, FTP sessions, etc
U.S. Department of
Homeland Security
United States
Secret Service
System Logs
ƒ Example, Windows NT/2000/XP maintains three main logs that
can be accessed through Event Viewer
ƒ System log
ƒ Security log
ƒ Application log
U.S. Department of
Homeland Security
United States
Secret Service
Firewall Logs
ƒ Type of attempted access (Web access, FTP access, Telnet
access etc.)
ƒ Port that attempted access
ƒ Date and time of attempted access
ƒ IP address from which attempt came
ƒ Application-level firewall logs can also provide detailed
information of session information, user authentication, and
security policy violations
U.S. Department of
Homeland Security
United States
Secret Service
Router Logs
ƒ Can log information about network traffic and potential network
problems
ƒ Can be configured to log abnormal activity that contains host
information of possible intruder and what was accessed on
network during attempt
ƒ Dial-up-access routers, can log dial-up connection information
including username, IP address assigned, date, time, duration
of connection
ƒ Can be very beneficial during an intrusion investigation
U.S. Department of
Homeland Security
United States
Secret Service
IDS Logs
ƒ Intrusions
ƒ Intrusion attempts
ƒ Unauthorized access to a computer
ƒ Attempts to access unauthorized data
ƒ Attempts to manipulate privileged files
ƒ Attempts to render a network system inoperable
U.S. Department of
Homeland Security
United States
Secret Service
Network Security Summary
ƒ Layered approach commonly used
ƒ Intrusion Detection to provide real-time monitoring of network
ƒ Firewalls to restrict unauthorized access to network
ƒ Anti-virus protection to reduce risk of infection
ƒ Encryption to prevent stolen data packets from being read
ƒ Logs to record activity and provide documentation should a
breach of security occur
U.S. Department of
Homeland Security
United States
Secret Service
U.S. Department of
Homeland Security
United States
Secret Service
Module 8 - Common Network Crimes
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
ƒ E-Mail Scams
ƒ On-line Fraud
ƒ Identity Theft
ƒ Social Threats
ƒ Internal Threats
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
ƒ Malicious Code
ƒ Denial of Service Attacks
ƒ Extortion
ƒ Network Attacks
ƒ Terrorism
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - E-Mail Scams
ƒ Overview
ƒ Attack Methodologies
ƒ Investigative Response
U.S. Department of
Homeland Security
United States
Secret Service
E-Mail Scams
ƒ Scam defined as a dishonest act or fraud
ƒ Postal system used for fraudulent means since the 1660’s
ƒ Simple step for surface-mail scammers to make leap to
Internet E-mail
U.S. Department of
Homeland Security
United States
Secret Service
Why E-mail Scams Works
ƒ People do not look closely at e-mail header information
ƒ Few notice or question origin of messages
ƒ Some scams use HTML encoded E-mail to display logos and
other items to give impression of respectability
ƒ Easy to hide code in HTML formatted E-mail that launches
Trojans or other malicious code when E-mail viewed
ƒ Chain E-mails and solicitations for money using every
imaginable story and trick are prevalent on Internet
U.S. Department of
Homeland Security
United States
Secret Service
Nigerian, or 419 Scam
ƒ Legendary among E-mail frauds
ƒ Virtually all originate from foreign countries that have no
agreement with U.S. pertaining to prosecution of fraud
ƒ Person making request claims to be government official, or
relative of deposed leader or potentate
ƒ Requests involve large, usually multi-million dollar, sums of
money
ƒ Tap into greed of recipient
U.S. Department of
Homeland Security
United States
Secret Service
Nigerian, or 419 Scam
ƒ Reason person making request can’t get money themselves,
but recipient, being an upstanding American can
ƒ Will ask sum of money be deposited in account in other
country
ƒ Transfers of money to foreign account
ƒ Requestor absconds with money
ƒ Perpetrator outside reach of U.S. Law Enforcement
U.S. Department of
Homeland Security
United States
Secret Service
Where 419 Comes From
ƒ Nigerian government has taken hard line against frauds
ƒ Section 419 of Nigerian Criminal Code outlaws activity
ƒ Nigerian Government also considers anyone trying to remove
funds from their country a criminal
ƒ Victims who have gone to Nigeria to try get money back have
been imprisoned
U.S. Department of
Homeland Security
United States
Secret Service
Phishing
ƒ Perpetrator sends out legitimate looking E-mail in attempt to
gain financial or personal information
ƒ Compromised information used for other network crimes
ƒ E-Bay/PayPal
ƒ Banks
ƒ Cross Site Scripting
U.S. Department of
Homeland Security
United States
Secret Service
Spam
ƒ Unsolicited advertisement or bulk E-mail
ƒ Use of network bandwidth consumed
ƒ Storage space on mail servers
ƒ Estimated cost to companies in U.S. is over $12 billion dollars
a year
U.S. Department of
Homeland Security
United States
Secret Service
E-mail Scam Investigative Response
ƒ Capture
ƒ Preservation
ƒ Warrants
ƒ Reporting
ƒ Education
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - Online Fraud
ƒ Overview
ƒ Attack Methodologies
ƒ Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Online Fraud
ƒ Any form of trickery or deceptive gain practiced on Internet
U.S. Department of
Homeland Security
United States
Secret Service
Common Attack Vectors
ƒ Price to good to be true
ƒ Short time to decide
ƒ Fine print
ƒ Hijacked sites
ƒ Box-of-rocks
ƒ Stall tactics
U.S. Department of
Homeland Security
United States
Secret Service
Attack Methodologies
ƒ Bogus web sites
ƒ Auctions
ƒ Bogus Charities
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
ƒ Capture
ƒ Preservation
ƒ Warrants
ƒ Reporting
ƒ Education
ƒ Recording Observations
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Identity Theft
ƒ Overview
ƒ Attack Methodologies
ƒ Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Identity Theft
ƒ In 2007 estimated 8.4 million reported cases of identity theft in
U.S.
ƒ Number down from reported 10.1 million in 2003
ƒ Even with decline identity theft problem is major problem
U.S. Department of
Homeland Security
United States
Secret Service
Gathering Personal Information
ƒ Search Engines
ƒ Public information sites
ƒ Group sites
ƒ Commercial sites
ƒ Membership sites
U.S. Department of
Homeland Security
United States
Secret Service
Attack Methodologies
ƒ Name
ƒ Phone
ƒ Social Security Number
ƒ Address
ƒ License plate
U.S. Department of
Homeland Security
United States
Secret Service
Attack Methodologies
ƒ Pretexting - using small bits of information about subject to
gather more details from businesses and vendors
ƒ Attacker calls business or service that victim is member of and
pretends to be victim
ƒ Using information already gathered, attacker persuades
business to disclose further information, or change information
in account of victim to allow attacker full control of account
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
ƒ Capture
ƒ Preservation
ƒ Warrants
ƒ Reporting
ƒ Education
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 4 - Social Threats
ƒ Overview
ƒ Attack Methodologies
ƒ Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Social Threats
ƒ Predators
ƒ Stalkers
ƒ Cyberbullying
U.S. Department of
Homeland Security
United States
Secret Service
Attack Methodologies
ƒ E-mail
ƒ Chat
ƒ Texting
ƒ Impersonation
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
ƒ Capture
ƒ Preservation
ƒ Warrants
ƒ Reporting
ƒ Education
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 5 - Internal Threats
ƒ Overview
ƒ Attack Methodologies
ƒ Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Internal Threats
ƒ Inappropriate Usage
ƒ Embezzlement
ƒ Extortion
ƒ Espionage
ƒ Sabotage
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
ƒ Capture
ƒ Preservation
ƒ Warrants
ƒ Reporting
ƒ Education
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 6 - Malicious Code
ƒ Overview
ƒ Attack Methodologies
ƒ Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Malicious Code Attacks
ƒ Viruses
ƒ Trojans
ƒ Worms
ƒ Spyware
ƒ Adware
ƒ Rootkits
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
ƒ Capture
ƒ Preservation
ƒ Warrants
ƒ Reporting
ƒ Education
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 7 - Denial of Service Attacks
ƒ Overview
ƒ Attack Methodologies
ƒ Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Denial of Service
ƒ Flooding target with more information than it can handle,
causing system crash or reset
ƒ Interfering with communications channel in such a way that
others can’t access system
ƒ Starting so many processes on target system that available
resources are used and system cannot respond to requests
ƒ Changing access codes so that normal users can no longer
access system
U.S. Department of
Homeland Security
United States
Secret Service
Distributed Denial of Service Attack
ƒ When multiple systems attack target system
ƒ Multiple systems usually compromised systems over which
attacker has control
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
ƒ Capture
ƒ Preservation
ƒ Warrants
ƒ Reporting
ƒ Education
U.S. Department of
Homeland Security
United States
Secret Service

 

 

 

 

 

 

 

Content      ..     14      15      16      17     ..