1 of 33

“Network Security”

Lecture 1. The concept of network security and its essence

The concept of safety and its essence

2 of 33

Plan:

1. Introduction to the subject of network security.

2. The concept of security in computer networks.

3. Fundamentals of ensuring information security in the network.

4. Requirements for network security.

3 of 33

List of topics

Topic 1. Concept of network security and its essence.

Introduction to the science of network security, the concept of security in computer networks, fundamentals of ensuring information security in the network, requirements for network security.

Topic 2. Modern threats to network security.

Modern forms of network threats and methods of protection against them, classification of network security threats and ways to mitigate them.

Topic 3. Security policies and models in computer systems and networks.

Concept of security policies and models in computer systems and networks. Security monitor (kernel) and main types of security policies.

Topic 4. Network security standards (Uz DSt ISO/IEC 27033).

Network security. Commentary and concepts. Guidelines for designing and implementing network security. Reference network scenarios. Threats, design methods, and management issues.

Topic 5. Security policy in the OSI model.

Fundamental principles of organizing network security and its tasks. Reference model for interoperability of open systems. Network protocols. Capabilities and protocols of the OSI model.

  • Topic 6. Information protection infrastructure at the application and presentation layers.

Security issues of application‑layer protocols. Identification and usage management. Organization of protected remote usage. Protection mechanisms at the presentation layer.

Topic 7. Protocols for establishing protected channels at the channel and session layers.

Protocols for establishing protected channels at the channel layer. PPTP, L2F and L2TP protocols. Protocols for establishing protected channels at the session layer. SSL/TLS and SOCKS protocols.

4 of 33

List of Topics

Topic 8. Protecting data at the transport layer.

Capabilities and features of the transport layer of the OSI model. Transport layer security protocols.

Topic 9. Protecting data at the network layer.

IPSec security tool architecture. Implementation of the IPSec tool. Protecting data transmitted using AH and ESP protocols. IKE cryptographic key management protocol.

Topic 10. Protecting a computer network at the physical layer.

Organizational and technical methods of information protection. Physical layer security.

11-topic. Remote attacks in computer networks.

Concept of remote attack. Classification of remote attacks and mechanisms for their execution. Analyzing network traffic.

Topic 12. Fundamentals of secure virtual network technologies.

Secure virtual network technologies. IPsec VPN components and functions. Implementing site-to-site IPsec VPN using CLI (command-line interface). ASA VPN configuration.

Topic 13. Inter-network firewall technologies.

Access Control List (ACL). Inter-network firewall technologies. Additional capabilities of inter-network firewalls. Zone-based policy inter-network firewall. Introduction to ASA (Adaptive Security Appliance). Configuration of ASA inter-network firewall.

Topic 14. Detection and mitigation of attacks.

Attack detection system. IDS/IPS technologies. IPS signatures. Using IPS.

Topic 15. Information security in “cloud” computing systems.

Information security issues when using cloud computing services, types of cloud computing platform models, ensuring the security of user data in cloud systems.

5 of 33

Main literature

1. William Stallings, Network Security Essentials: Applications and Standards, 6th Edition, 2017.

2. Oliefer V.G., Oliefer N.A. “Computer Network Security” 2017.

3. Ol'kov Evgeny – Practical Network Security – 2017.

4. Ol'kov Evgeny – Corporate Network Architecture – 2014.

5. Ganiev Salim Karimovich, Kuchkarov Tahir Anvarovich, Network Security, 2019. p. 148.

6. Ganiev Salim Karimovich, Kuchkarov Tahir Anvarovich, Network Security, 2019. p. 139.

7. N.V. Maksimov, I.I. Popov “Computer Networks”. Textbook. Moscow “Forum”, 2018, p. 454.

8. Biryukov A.A. Information Security: Defense and Attack. Second Edition. 2017.

9. Shangin V.F. “Information Security and Information Protection”, Textbook. Moscow, 2017.

10. Ganiev S.K., Karimov M.M., Tashev K.A. “Information Security”, “Science and Technology” Publishing, Tashkent 2016.

Additional literature

1. Decree No. PF‑4947 of 7 February 2017 of the President of the Republic of Uzbekistan “On the Strategy of Measures for Further Development of the Republic of Uzbekistan”.

2. Mirziyoyev Sh.M. The Supremacy of Law and Ensuring Human Interests – the Guarantee of National Development and People’s Welfare. 2017.

3. Tim Boyles. CCNA Security Study Guide. Copyright © 2010 by Wiley Publishing, Inc., Indianapolis, Indiana. Published simultaneously in Canada. ISBN: 978‑0‑470‑52767‑2.

4. Mark Ciampa. Security+. Guide to Network Security Fundamentals. Fifth Edition. Printed in the United States of America. Print Number: 01. Print Year: 2014.

5. Emad S. Hassan. Security and Data Reliability in Cooperative Wireless Networks. © 2018 by Taylor & Francis Group, LLC.

6. William Stallings. Cryptography and Network Security: Principles and Practice. Fifth Edition. Copyright © 2011, 2006 Pearson Education, Inc., publishing as Prentice Hall.

7. Joseph MiggaKizza. Computer Network Security and Cyber Ethics. Fourth Edition. McFarland & Company, Inc., Publishers Jefferson, North Carolina © 2014.

Internet sites

http://www.ziyonet.uz

http://www.nasa.gov\statistics\

http://www.security.uz

6 of 33

Goal and objectives

It consists of familiarizing students with the results of international and national normative, theoretical and practical research in the field of network security, as well as acquiring knowledge and skills in the methods, hardware and software tools used to ensure network security, their usage, and the application of protection devices and tools for ensuring network security.

GOAL

TASK

Providing students with theoretical knowledge, practical skills, as well as revealing the basic concepts of network security, types of networks and modern threats to network security, network security standards, and the importance of tools used to ensure network security.

1/29/26

6

7 of 33

What is Network security?

  • 1. What is Network Security? (Conceptual Essence)
  • “A network is how systems communicate. Network security is how we keep that communication trustworthy and reliable.”
  • “Network security is not only tools. It is a combination of goals + risks + architecture + controls + operations.”
  • Network security is a set of technologies, rules, processes, and behaviors designed to protect computer networks and the data inside them from unauthorized access, misuse, modification, destruction, or disruption.

In simple words:

  • Network security ensures that only the right people and systems can access network resources, and that data remains safe during transmission.
  • Network security is not just software or hardware — it is a strategy.

2. Why Network Security Exists (The Core Reason)

  • Modern society depends on networks:
  • Internet
  • Corporate networks
  • Banking systems
  • Government infrastructure
  • Healthcare systems
  • Educational platforms
  • Without security: What happens????
  • Data can be stolen
  • Systems can be manipulated
  • Services can be stopped
  • Trust is lost

.

7

1/29/26

8 of 33

8

1/29/26

9 of 33

Main concepts of network security

1/29/26

9

Confidentiality

- Rules that ensure that only authorized subjects can use system data and information.

- These rules ensure that information can only be “read” by legitimate users.

Without confidentiality:

  • Passwords leak
  • Private data is exposed

Integrity (completeness)

- Gaining confidence that the data is accurate and reliable.

- That is, protecting information from unauthorized alteration or “writing”.

Without integrity:

  • Data can be modified silently
  • Transactions become unreliable

Availability

- The possibility of using data, information, and the system.

- That is, protecting against unauthorized “execution”.

Without availability:

  • Systems crash
  • Services become unusable

10 of 33

What Is Being Protected in Network Security?�

10

1/29/26

11 of 33

Passive attacks

  • 🔹 Definition
  • Passive attacks are those where an attacker does not alter the network traffic or systems.�They only observe, listen, or collect information without affecting the system’s operation.
  • 🔹 Main Goal
  • The goal is to gain information, such as:
  • Data content
  • Communication patterns
  • User behavior
  • 🔹 Key Features
  • Hard to detect because the network is not changed.
  • Usually done silently.
  • Used to gather data for later attacks.

🔹 Examples

  • Eavesdropping
  • Listening to network traffic to capture sensitive information.
  • Example: capturing unencrypted login credentials.
  • Traffic Analysis
  • Analyzing patterns of communication.
  • Even if data is encrypted, the attacker can learn:
    • Who is communicating
    • When communication occurs
    • How much data is transferred
  • This can reveal important information like network structure, user habits, and critical systems.
  • 📌 Essence of Passive Attacks:
  • Attackers observe and collect data without changing anything.

11

1/29/26

12 of 33

Threats to Network SecurityA threat is anything that can exploit a vulnerability.

12

1/29/26

13 of 33

Active Attacks (Interference-Based)�

  • 🔹 Definition
  • Active attacks involve altering, interrupting, or destroying network operations.�Attackers modify data, inject false messages, or disrupt services.
  • 🔹 Main Goal
  • The goal is to damage the network, steal data, or gain unauthorized access by directly interfering with communication.
  • 🔹 Key Features
  • Easier to detect because the network behavior changes.
  • Often causes noticeable impact.
  • Can be used to cause immediate damage or breach.
  • 🔹 Examples
  • Man-in-the-Middle (MITM)
  • The attacker intercepts communication between two parties.
  • They can:
    • Read messages
    • Modify messages
    • Insert false messages
  • Example: attacker intercepts a bank transaction and changes the recipient.

13

14 of 33

  • Spoofing
  • Pretending to be another user or device.
  • Types:
    • IP spoofing
    • MAC spoofing
    • Email spoofing
  • Example: attacker sends fake emails from a trusted source.
  • DoS / DDoS (Denial of Service)
  • Flooding network resources to make a service unavailable.
  • DDoS uses multiple systems to attack one target.
  • Example: making a website crash.
  • Malware Propagation
  • Malware spreads across the network.
  • Examples:
    • Worms
    • Ransomware
    • Trojans
  • Purpose:
    • Steal data
    • Destroy systems
    • Encrypt files
  • 📌 Essence of Active Attacks:
  • Attackers change or interrupt network operations

14

1/29/26

15 of 33

Vulnerability, thread, attack

15

1/29/26

16 of 33

Network Security Mechanisms

  • Network security mechanisms are methods and tools used to protect a network from threats and attacks. These mechanisms are typically classified into three major categories:

1. Preventive Controls

  • Preventive controls are designed to stop security incidents before they occur. They aim to reduce vulnerabilities and block unauthorized access.
  • Firewalls
  • A firewall is a security device (hardware or software) that controls the flow of traffic between different network segments based on predefined security rules.
  • Firewalls can be software-based, hardware-based, network-based, cloud-based, or application-based.
  • Firewall Goals:
  • Block unauthorized access
  • Protect network perimeter
  • Enforce security policies

16

1/29/26

17 of 33

  • Network Segmentation
  • Network segmentation divides a network into smaller parts (segments). This improves security by limiting access between different segments.
  • Benefits:
  • Limits the spread of malware
  • Improves performance
  • Provides better control over network traffic
  • Example:
  • A company may separate:
  • Finance department network
  • HR department network
  • Guest Wi-Fi network
  • This prevents a compromised guest device from accessing sensitive internal systems.

17

1/29/26

18 of 33

  • Access Control Lists (ACLs)
  • ACLs are rules applied to routers and switches to allow or deny traffic based on IP address, port number, and protocol.
  • Key Uses:
  • Block suspicious IP addresses
  • Restrict access to specific services
  • Control traffic between network segments
  • Example:
  • An ACL can prevent outside users from accessing an internal database server.

18

1/29/26

19 of 33

VPNs (Virtual Private Networks)�

  • A VPN creates a secure, encrypted tunnel over an untrusted network like the Internet.
  • Purpose:
  • Protect data in transit
  • Provide secure remote access
  • Connect branch offices securely
  • Key benefits:
  • Encryption prevents data interception
  • Authentication ensures only authorized users connect

19

1/29/26

20 of 33

2. Detective Controls

  • Detective Controls
  • Detective controls do not prevent attacks directly. Instead, they identify suspicious activities and alert administrators.
  • IDS (Intrusion Detection System)
  • An IDS monitors network traffic and detects potential security incidents.
  • Types:
  • Network-based IDS (NIDS): monitors traffic across the network
  • Host-based IDS (HIDS): monitors activities on individual systems
  • Detection Methods:
  • Signature-based detection
  • Anomaly-based detection
  • IDS Role:
  • Detect suspicious activity
  • Generate alerts for investigation

20

1/29/26

21 of 33

  • Traffic Monitoring
  • Traffic monitoring involves analyzing network traffic to identify abnormal patterns.
  • What it monitors:
  • Bandwidth usage
  • Unusual IP addresses
  • Port scanning
  • Unexpected traffic spikes
  • Benefits:
  • Helps detect intrusions
  • Helps understand network behavior

21

1/29/26

22 of 33

  • Log Analysis
  • Logs are records of network and system activities. Analyzing logs helps identify incidents, detect breaches, and support investigations.
  • Common log sources:
  • Firewalls
  • Routers
  • Servers
  • Applications
  • Log analysis helps in:
  • Forensic investigation
  • Compliance
  • Incident response

22

1/29/26

23 of 33

Corrective Controls

  • Corrective controls are actions taken to restore systems and mitigate damage after a security incident has occurred. These controls focus on recovery and reducing the impact of attacks.
  • IPS (Intrusion Prevention System)
  • An IPS is similar to an IDS but has the ability to actively block or prevent detected threats. When suspicious activity is detected, an IPS can:
  • Drop malicious packets
  • Reset connections
  • Block traffic from specific IPs
  • IPS provides automated response to security threats.

23

1/29/26

24 of 33

  • Incident Response
  • Incident response is the structured process used to manage and handle security incidents. It includes phases such as:
  • Identification
  • Containment
  • Eradication
  • Recovery
  • Lessons learned
  • A well-defined incident response plan helps organizations respond effectively and reduce damage.

24

1/29/26

25 of 33

  • Isolation and Recovery
  • Isolation involves separating infected or compromised systems from the network to prevent further spread of attacks. Recovery involves restoring systems using backups and ensuring that the systems are secure before returning them to operation.
  • Corrective controls ensure that systems are returned to a secure state after an incident.

25

1/29/26

26 of 33

Defense-in-Depth

  • Defense-in-depth is a security strategy that uses multiple layers of defense to protect network assets. It assumes that no single security control is perfect, and therefore multiple overlapping controls should be implemented.
  • Examples of defense-in-depth layers:
  • Perimeter security (firewall)
  • Network segmentation (VLANs)
  • Endpoint security (antivirus)
  • Encryption (VPN)
  • Monitoring (IDS/IPS)
  • Policies and training (human layer)
  • Key idea:
  • If one layer fails, other layers still provide protection.

26

1/29/26

27 of 33

27

1/29/26

28 of 33

What is AAA in network security?�

  • AAA is a standard framework used to control who can enter a network, what they can do, and how their actions are recorded. It’s widely used in real networks via RADIUS and TACACS+ with network devices like routers, switches, VPN gateways, Wi-Fi controllers, and firewalls.
  • Think of AAA as a security checkpoint system:
  • Authenticate → prove identity
  • Authorize → grant the right permissions
  • Account → record and review what happened

28

1/29/26

29 of 33

  • Authentication — “Who are you?”
  • Definition:Authentication is the process of verifying identity (user/device/service). It answers: Is this entity really who it claims to be?
  • How authentication is done (common methods)
  • Passwords/PINs (something you know)
  • MFA/2FA (combine two or more factors)
  • Certificates (digital identity, common in Wi-Fi enterprise, VPN, and device-to-device trust)
  • Biometrics (fingerprint/face—more common in user authentication)
  • Why authentication matters
  • Without authentication:
  • anyone can pretend to be “admin”
  • attackers can use stolen credentials
  • rogue devices can join the network
  • Common failure examples
  • shared accounts (“admin/admin”)
  • weak passwords
  • no MFA on VPN/Wi-Fi admin portals

29

1/29/26

30 of 33

  • Authorization — “What are you allowed to do?”
  • Definition:Authorization happens after authentication. It decides what actions and resources the authenticated identity is permitted to access.
  • Typical authorization models (simple but correct)
  • RBAC (Role-Based Access Control): permissions based on role (student, teacher, admin)
  • ABAC (Attribute-Based): permissions based on attributes/context (department, location, device type)
  • Least privilege: give only the minimum access needed
  • Authorization tools in networks
  • Roles & permissions (admin levels, service permissions)
  • ACLs (Access Control Lists) (permit/deny traffic, management access)
  • Firewall policies (who can reach what)
  • Network segmentation rules (user zone cannot access database zone)
  • Key point
  • Authentication says “you are AxborotX.”�Authorization says “AxborotX may access only these services.”

30

1/29/26

31 of 33

  • Accounting — “What did you do?”
  • Definition:Accounting (also called auditing) is recording who did what, when, from where, and to which resource.
  • What accounting records usually contain
  • login time, logout time, session duration
  • source IP/device, location (if available)
  • commands executed (especially for admins)
  • resources accessed (files, servers, databases)
  • data volume (upload/download), failed attempts
  • Where accounting comes from (network examples)
  • VPN logs (who connected, from where, duration)
  • Wi-Fi controller logs (device MAC/user identity, AP used)
  • Firewall logs (connections allowed/blocked)
  • Admin command logs via TACACS+ (who ran “show run”, “conf t”, etc.)
  • Central SIEM storage (collecting logs from many sources)

31

1/29/26

32 of 33

Modern network security concepts

  • “Modern network security concepts” basically means the newer ways we protect networks today, because the old idea (“strong firewall at the edge, everything inside is trusted”) doesn’t work anymore with cloud, remote users, mobile devices, SaaS, IoT, and constant credential theft.
  • Zero Trust
  • Zero Trust is a model where no user/device is trusted automatically—even if it is inside the network. Every access request must be verified and allowed by policy.
  • Key principles
  • Never trust, always verify
  • Least privilege (minimum access needed)
  • Assume breach (design as if an attacker is already inside)

32

1/29/26

33 of 33

Network security requirements:

  • Control of the protection system;
  • Control of access to files;
  • Control of data transmission in the network;
  • Control of access to information repositories;
  • Control of data dissemination to other devices connected to the network.

To protect data being transmitted between network elements, the following measures must be taken:

  • Do not allow data interception;
  • Do not allow analysis of information exchange;
  • Do not allow alteration of messages;
  • Do not allow unauthorized connections and detect such cases quickly.