1 of 36

NETWORK SECURITY

Presented by :

Sangeeta Bhandari

PG Department of Computer Sc. & I.T.

HMV, Jalandhar

2 of 36

What is Computer Network?

  • A computer network is a group of computers that are interconnected by wired or wireless media.
  • Purpose : To exchange data(any form) between them or their users.

Network Security Basics

2

8/15/2022

3 of 36

What is “Security”?

    • 1. Freedom from risk or danger; safety.
    • 2. Freedom from doubt, anxiety, or fear; confidence.
    • 3. Something that gives or assures safety, as:
      • 1. A group or department of private guards: Call building security if a visitor acts suspicious.
      • 2. Measures adopted by a government to prevent espionage, sabotage, or attack.
      • 3. Measures adopted, as by a business or homeowner, to prevent a crime such as burglary or assault

Network Security Basics

3

8/15/2022

4 of 36

Why do we need security?

  • Protect vital information while still allowing access to those who need it
    • Trade secrets, medical records, etc.
  • Provide authentication and access control for resources
  • Guarantee availability of resources

Network Security Basics

4

8/15/2022

5 of 36

Why Network Security?

To protect company assets: One of the primary goals of computer and network security is the protection of company assets.

      • “Assets" means the hardware and software that constitute the company's computers and networks.
      • “Information" that is housed on a company's computers and networks.
      • Network and computer security is concerned, above all else, with the protection, integrity, and availability of information.

To gain a competitive advantage: Developing and maintaining effective security gives competitive advantage in the market. Eg. A bank with proven record of security will attract more customers.

Network Security Basics

5

8/15/2022

6 of 36

Why Network Security? Cont..

To comply with regulatory requirements : Corporate officers of every company have a responsibility to ensure the safety and soundness of the organization. Accordingly, organizations that rely on computing devices(PCs, Mobiles, Tabs, Laptops etc. for their continuing operation must develop policies and procedures that address organizational security requirements.

To keep your job: Finally, to secure one's position within an organization and to ensure future career prospects. Failure to perform adequately can result in termination.

Network Security Basics

6

8/15/2022

7 of 36

Who is vulnerable?

  • Financial institutions and banks
  • Internet service providers
  • Pharmaceutical companies
  • Government and defense agencies
  • Contractors to various government agencies
  • Multinational corporations
  • ANYONE ON THE NETWORK(Facebook, Twitter, Whatsapp etc.)

Network Security Basics

7

8/15/2022

8 of 36

Basic terms in Network Security

  • Identification

Identification is simply the process of identifying one's self to another entity or determining the identity of the individual or entity with whom you are communicating.

  • Authentication

Authentication serves as proof that you are the one, who you claim to be.

Authentication is normally based on combination of following three schemes:

    • Something you know: The most commonly employed scheme is "something you know." eg. password, code, or sequence.
    • Something you have: "Something you have" requires a key, badge, or token card, some device or "thing" that provides you with access.
    • Something you are: "Something you are" authentication relies upon some physical or behavioral characteristic. It is referred to as biometric authentication. Biometrics can authenticate one's identity based on fingerprints, a voice print, or an iris scan. These systems, when designed properly, can be extremely difficult to circumvent or compromise. The trick is finding one that works correctly.

Network Security Basics

8

8/15/2022

9 of 36

Basic terms in Network Security

Authentication is normally based on combination of following three schemes:

    • Something you know: The most commonly employed scheme is "something you know." eg. password, code, or sequence.
    • Something you have: "Something you have" requires a key, badge, or token card, some device or "thing" that provides you with access.
    • Something you are: "Something you are" authentication relies upon some physical or behavioral characteristic. It is referred to as biometric authentication. Biometrics can authenticate one's identity based on fingerprints, a voice print, or an iris scan. These systems, when designed properly, can be extremely difficult to circumvent or compromise. The trick is finding one that works correctly.

Network Security Basics

9

8/15/2022

10 of 36

Basic terms in Network Security

  • Access Control (Authorization) This refers to the ability to control the level of access that individuals or entities have to a network or system and how much information they can receive.
  • Availability

This refers to whether the network, system, hardware, and software are reliable and can recover quickly and completely in the event of an interruption in service.

  • Confidentiality

This can also be called privacy or secrecy and refers to the protection of information from unauthorized disclosure.

Usually achieved either by restricting access to the information or by encrypting the information so that it is not meaningful to unauthorized individuals or entities.

  • Integrity

This can be thought of as accuracy. This refers to the ability to protect information, data, or transmissions from unauthorized, uncontrolled, or accidental alterations.

Network Security Basics

10

8/15/2022

11 of 36

Security Models�

Three basic approaches used to develop a network security model.

  1. Security by Obscurity

Security by obscurity relies on stealth for protection. The concept behind this model is that if no one knows that a network or system is there, then it won't be subject to attack.

The problem with this approach is that it never works in the long term, and once detected, a network is completely vulnerable.

Network Security Basics

11

8/15/2022

12 of 36

Security Models�

2. The Perimeter Defense

When using this model in network security, organizations harden or strengthen perimeter systems and border routers, or an organization might "hide" its network behind a firewall that separates the protected network from an untrusted network. Not much is done to secure the other systems on the network. The assumption is that perimeter defenses are sufficient to stop any intruders so that the internal systems will be secure. There are several flaws in this concept:

Network Security Basics

12

8/15/2022

13 of 36

Security Models Contd..

Problems of Perimeter Defense

First, this model does nothing to protect internal systems from an inside attack. As we have discussed, the majority of attacks on company networks are launched from someone internal to the organization. Second, the perimeter defense almost always fails eventually. Once it does, the internal systems are left wide open to attack.

Network Security Basics

13

8/15/2022

14 of 36

Security Models Contd..

3. The Defense in Depth

The most robust approach to use is the defense in depth model. The defense in depth approach strives for security by hardening and monitoring each system; each system is an island that defends itself. Extra measures are still taken on the perimeter systems, but the security of the internal network does not rest solely on the perimeter systems..

Network Security Basics

14

8/15/2022

15 of 36

Common security attacks and their countermeasures

  • Finding a way into the network
    • Firewalls
  • Exploiting software bugs, buffer overflows
    • Intrusion Detection Systems
  • Denial of Service
    • Ingress filtering, IDS
  • TCP hijacking
    • IPSec
  • Packet sniffing
    • Encryption (SSH, SSL, HTTPS)
  • Social problems
    • Education

Network Security Basics

15

8/15/2022

16 of 36

Firewalls

  • Basic problem – many network applications have multiple entry points and protocols have security problems that are fixed over time
    • Difficult for users to keep up with changes and keep host secure
    • Solution
      • Administrators limit access to end hosts by using a firewall which provides single point of entry and exit.
      • Firewall is kept up-to-date by administrators

Network Security Basics

16

8/15/2022

17 of 36

Firewalls

  • A "firewall" is a specialized defense system for a

computer network.

  • The term comes from construction, where specialized fire-prevention systems involve fire-resistant walls being placed strategically in buildings and cars to slow the spread of a fire.
  • In the case of computers, the term describes hardware or software that slows the invasion of a computer system by blocking viruses and hackers.�Only one point of access into the network
    • This can be good or bad
  • Can be hardware or software
    • Ex. Some routers come with firewall functionality

Network Security Basics

17

8/15/2022

18 of 36

Types of firewalls

  • Packet filter: Looks at each packet entering or leaving the network and accepts or rejects it based on user-defined rules..
  • Application gateway: Applies security mechanisms to specific applications, such as FTP and Telnet servers. This is very effective, but can impose a performance degradation.
  • Circuit-level gateway: Applies security mechanisms when a TCP or UDP connection is established. Once the connection has been made, packets can flow between the hosts without further checking.
  • Proxy server: Intercepts all messages entering and leaving the network. The proxy server effectively hides the true network addresses.

Network Security Basics

18

8/15/2022

19 of 36

Intrusion Detection

  • Used to monitor for “suspicious activity” on a network
    • Can protect against known software exploits, like buffer overflows
  • Open Source IDS: Snort, www.snort.org
  • Uses “intrusion signatures”
    • Well known patterns of behavior
      • Ping sweeps, port scanning, web server indexing, OS fingerprinting, DoS attempts, etc.
  • However, IDS is only useful if contingency plans are in place to curb attacks as they are occurring

Network Security Basics

19

8/15/2022

20 of 36

Dictionary Attack

  • We can run a dictionary attack on the passwords
    • The passwords in /etc/passwd are encrypted with the crypt(3) function (one-way hash)
    • Can take a dictionary of words, crypt() them all, and compare with the hashed passwords
  • This is why your passwords should be meaningless random junk!
    • For example, “sdfo839f” is a good password

Network Security Basics

20

8/15/2022

21 of 36

Denial of Service

  • Purpose: Make a network service unusable, usually by overloading the server or network
  • Many different kinds of DoS attacks
    • SYN flooding
    • SMURF
    • Distributed attacks
    • Mini Case Study: Code-Red

Network Security Basics

21

8/15/2022

22 of 36

Denial of Service

  • How can we protect ourselves?
    • Ingress filtering
      • If the source IP of a packet comes in on an interface which does not have a route to that packet, then drop it
    • Stay updated with the latest security patches
      • A fix for the IIS buffer overflow was released sixteen days before CodeRed had been deployed!

Network Security Basics

22

8/15/2022

23 of 36

TCP Attacks

  • Recall how IP works…
    • End hosts create IP packets and routers process them purely based on destination address alone
  • Problem: End hosts may lie about other fields which do not affect delivery
    • Source address – host may trick destination into believing that the packet is from a trusted source
      • Especially applications which use IP addresses as a simple authentication method
      • Solution – use better authentication methods

Network Security Basics

23

8/15/2022

24 of 36

  • TCP connections have associated state
    • Starting sequence numbers, port numbers
  • Problem – what if an attacker learns these values?
    • Port numbers are sometimes well known to begin with (ex. HTTP uses port 80)
    • Sequence numbers are sometimes chosen in very predictable ways

Network Security Basics

24

8/15/2022

TCP Attacks

25 of 36

TCP Attacks

  • If an attacker learns the associated TCP state for the connection, then the connection can be hijacked!
  • Attacker can insert malicious data into the TCP stream, and the recipient will believe it came from the original source
    • Ex. Instead of downloading and running new program, you download a virus and execute it

Network Security Basics

25

8/15/2022

26 of 36

Packet Sniffing

  • When someone wants to send a packet to some else …
  • They put the bits on the wire with the destination MAC address …
  • And remember that other hosts are listening on the wire to detect for collisions …
  • It couldn’t get any easier to figure out what data is being transmitted over the network!

Network Security Basics

26

8/15/2022

27 of 36

Packet Sniffing

  • This works for wireless too!
  • In fact, it works for any broadcast-based medium

Network Security Basics

27

8/15/2022

28 of 36

Packet Sniffing

  • How can we protect ourselves?
  • Cryptography( Public Key, Private Key)
  • HTTP over SSL i.e. https not http
    • Especially when making purchases with credit cards!
  • SFTP, not FTP
    • Unless you really don’t care about the password or data
    • Can also use KerbFTP (download from MyAndrew)
  • IPSec
    • Provides network-layer confidentiality

Network Security Basics

28

8/15/2022

29 of 36

Social Problems

  • People can be just as dangerous as unprotected computer systems
    • People can be lied to, manipulated, bribed, threatened, harmed, tortured, etc. to give up valuable information
    • Most humans will breakdown once they are at the “harmed” stage, unless they have been specially trained.

Network Security Basics

29

8/15/2022

30 of 36

Social Problems

  • Example 1:
    • Someone calls you in the middle of the night
      • “Have you been calling Egypt for the last six hours?”
      • “No”
      • “Well, we have a call that’s actually active right now, it’s on your calling card and it’s to Egypt and as a matter of fact, you’ve got about $2000 worth of charges on your card and … read off your credit card number and PIN and then I’ll get rid of the charge for you”

Network Security Basics

30

8/15/2022

31 of 36

Social Problems

  • Example 2:
    • Who saw Office Space?
    • In the movie, the three disgruntled employees installed a money-stealing worm onto the companies systems
    • They did this from inside the company, where they had full access to the companies systems
      • What security techniques can we use to prevent this type of access?

Network Security Basics

31

8/15/2022

32 of 36

Social Problems

  • There aren’t always solutions to all of these problems
    • Humans will continue to be tricked into giving out information they shouldn’t
    • Educating them may help a little here, but, depending on how badly you want the information, there are a lot of bad things you can do to get it
  • So, the best that can be done is to implement a wide variety of solutions and more closely monitor who has access to what network resources and information
    • But, this solution is still not perfect

Network Security Basics

32

8/15/2022

33 of 36

Conclusions

  • The Internet works only because we implicitly trust one another
  • It is very easy to exploit this trust
  • The same holds true for software
  • It is important to stay on top of the latest CERT security advisories to know how to patch any security holes

Network Security Basics

33

8/15/2022

34 of 36

References

  • http://www.robertgraham.com/pubs/network-intrusion-detection.html
  • http://online.securityfocus.com/infocus/1527
  • http://www.snort.org/
  • http://www.cert.org/
  • http://www.nmap.org/
  • http://grc.com/dos/grcdos.htm
  • http://lcamtuf.coredump.cx/newtcp/
  • http://creativecommons.org/licenses/by-nc-sa/2.0
  • http://www.artechhouse.com
  • “Computer Networks” , Andrew S. Tanenbaum, Pearson Education
  • Network Security Architecture, Sean Convery, Pearson Education, ISBN-81297-0615-6

Network Security Basics

34

8/15/2022

35 of 36

Network Security Basics

35

8/15/2022

?

Any Questions

36 of 36

THANKS

A

LOT

Network Security Basics

36

8/15/2022