1 of 86

Network Security

Chapter 3

Panko and Panko

Business Data Networks and Security, 10th Edition, Global Edition

Copyright © 2015 Pearson Education, Ltd.

2 of 86

Copyright © 2015 Pearson Education, Ltd.

The Target Breach

Attacks and Attackers

Protecting Dialogs Cryptographically

Other Forms of Authentication

Firewalls

Antivirus Protection

3 of 86

The Target Breach

  • Christmas Season 2013
  • BlackPOS malware “scrapes” transaction data
  • Debit/credit transactions of 40 million customers
  • In separate attack, information stolen on 70 million Target customers
  • Sales losses, stock decline, technology officer fired, CEO fired

Copyright © 2015 Pearson Education, Ltd.

4 of 86

3.1 The Target Breach

Copyright © 2015 Pearson Education, Ltd.

BlackPOS

5 of 86

3.1 The Target Breach

Copyright © 2015 Pearson Education, Ltd.

E-Mail Spear Phishing Attack

Fazio Mechanical Services

6 of 86

3.1 The Target Breach

Copyright © 2015 Pearson Education, Ltd.

7 of 86

3.1 The Target Breach

Copyright © 2015 Pearson Education, Ltd.

Not shown:

Constant ongoing

command and control communication from the outside

8 of 86

3.1 The Target Breach

Copyright © 2015 Pearson Education, Ltd.

偽造者

9 of 86

Copyright © 2015 Pearson Education, Ltd.

The Target Breach

Attacks and Attackers

Protecting Dialogs Cryptographically

Other Forms of Authentication

Firewalls

Antivirus Protection

10 of 86

3.2 Malware and Vulnerabilities

  • Malware
    • A general name for evil software
  • Malware attacks

Copyright © 2015 Pearson Education, Ltd.

11 of 86

3.2 Malware and Vulnerabilities

  • Vulnerabilities (安全漏洞/弱點)
    • Security flaws in specific programs
    • Enable specific attacks against these programs
    • Vendors release patches to close vulnerabilities
    • However, users do not always install patches promptly or at all, so continue to be vulnerable
    • Also, zero-day attacks occur before the patch is released for the vulnerability

Copyright © 2015 Pearson Education, Ltd.

12 of 86

3.3 Viruses and Worms

  • Viruses
    • Pieces of code that attach themselves to other programs
  • Worms
    • Stand-alone programs that do not need to attach to other programs

Copyright © 2015 Pearson Education, Ltd.

13 of 86

3.3 Viruses and Worms

  • Typical Propagation Vectors
    • E-mail attachments
    • Visits to websites (even legitimate ones)
    • Social networking sites
    • Many others (USB RAM sticks, peer-to-peer file sharing, etc.)
    • These requires human gullibility, which is slow

Copyright © 2015 Pearson Education, Ltd.

易受欺騙

14 of 86

3.3 Viruses and Worms

  • Directly propagating worms
    • Jump to victim hosts directly
    • Target hosts must have a specific vulnerability for this to succeed
    • No action is necessary on the part of the victim
    • Directly propagating worms can spread with amazing speed
    • In 2003, SQL Slammer infected most of its 75,000 victims within ten minutes.

Copyright © 2015 Pearson Education, Ltd.

15 of 86

3.4 Other Types of Malware

  • Mobile Code on Webpages
    • HTML webpages can contain scripts
    • Commands in a simplified programming language
    • Scripts are called mobile code because they are downloaded with the webpage
    • Scripts are normally benign but may be damaging if the browser has a vulnerability

Copyright © 2015 Pearson Education, Ltd.

良性的

16 of 86

3.4 Other Types of Malware

  • Trojan Horses
    • Trojan horses are programs that disguise themselves as system files.
    • Spyware Trojans collect sensitive data and send the data to an attacker

Copyright © 2015 Pearson Education, Ltd.

假扮,偽裝

17 of 86

3.4 Other Types of Malware

  • Downloaders
    • Malware that downloads a larger malware program onto the infected computer
  • Spam
    • Unsolicited Commercial E-Mail

Copyright © 2015 Pearson Education, Ltd.

18 of 86

3.5 Payloads

  • After propagation, viruses and worms execute their payloads
  • Malicious payloads do damage
    • Payloads can erase hard disks
    • Payloads can send users to pornography sites if they mistype URLs
  • Even malware without payloads can do damage
    • Not all malware has payloads—malicious or otherwise
    • Can still cause computer to run slowly or crash

Copyright © 2015 Pearson Education, Ltd.

19 of 86

3.6 Attacks on Human Judgment

  • Social Engineering
    • Tricking the victim into doing something against personal or organizational security interests
    • Open E-Mail Attachments, visit websites, etc.

Copyright © 2015 Pearson Education, Ltd.

20 of 86

3.6 Attacks on Human Judgment

  • Phishing Attacks
    • A sophisticated social engineering attack in which an authentic-looking e-mail or website entices the user to enter his or her username, password, or other sensitive information
  • Spear phishing attacks
    • Spear phishing attacks are directed at a particular individual.

Copyright © 2015 Pearson Education, Ltd.

誘使,慫恿

21 of 86

Copyright © 2015 Pearson Education, Ltd.

22 of 86

3.6 Attacks on Human Judgment

  • Credit Card Number Theft
    • Uses stolen credit card numbers to make unauthorized transactions
  • Identity Theft
    • Involves collecting enough data to impersonate the victim in large financial transactions
    • Can result in much greater financial harm to the victim than credit card theft
    • May take a long time to restore the victim’s credit rating

Copyright © 2015 Pearson Education, Ltd.

23 of 86

3.7 Human Break-Ins (Hacking)

  • Hacking
    • Intentionally using a computer resource without authorization or in excess of authorization.
    • The key issue is authorization.

Copyright © 2015 Pearson Education, Ltd.

24 of 86

3.8 Stages in an Attack

  • Exploit
    • The actual break-in
    • The tool used is also called an exploit
  • After the Break-In
    • Manually exploits the resource
    • Leaves a Trojan horse behind for continuous automated exploitation

Copyright © 2015 Pearson Education, Ltd.

剝削

25 of 86

3.9 Distributed Denial-of-Service (DDoS) Attack with Bots

Copyright © 2015 Pearson Education, Ltd.

Denial-of-Service (DOS) attack: an attack to make a computer or entire network unavailable to its legitimate users.

Availability

26 of 86

3.9 Distributed Denial-of-Service (DDoS) Attack with Bots

Copyright © 2015 Pearson Education, Ltd.

The collection of compromised computers is called a botnet.

27 of 86

SYN Flood

  • https://en.wikipedia.org/wiki/SYN_flood
  • A SYN flood is a form of denial-of-service attack in which an attacker sends a succession of SYN requests to a target's system in an attempt to consume enough server resources to make the system unresponsive to legitimate traffic.

Copyright © 2015 Pearson Education, Ltd.

28 of 86

Copyright © 2015 Pearson Education, Ltd.

TCP three-way handshake

SYN Flood

29 of 86

3.10 Advanced Persistent Threats

  • Long-term attack on an organization
    • Can last months or even years
  • Uses extremely advanced techniques
    • Often begins with a spear phishing attack
  • Difficult and expensive to do
    • So usually done by national governments
    • Although well-funded criminal groups can do it

Copyright © 2015 Pearson Education, Ltd.

30 of 86

3.11 Types of Attackers

  • Hackers
    • Old-school hackers driven by curiosity, a desire for power, and peer reputation
    • Today, most hackers are career criminal hackers who hack for money
    • Criminal attackers are well-funded and have an online criminal infrastructure
      • Purchase malware
      • Hire expertise when needed
      • Credit card “fences, “etc.

Copyright © 2015 Pearson Education, Ltd.

31 of 86

3.11 Types of Attackers

  • Malware Attackers
    • It is not illegal to write malware.
    • It is illegal to release malware against a company.

Copyright © 2015 Pearson Education, Ltd.

32 of 86

3.11 Types of Attackers

  • Employees, Ex-Employees, and Other Insiders
    • Current employees: revenge or theft
    • Extremely dangerous
      • Already have access
      • Know the systems
      • Know how to avoid detection
      • Are trusted by the organization

Copyright © 2015 Pearson Education, Ltd.

報復

Insiders

33 of 86

3.11 Types of Attackers

  • Employees, Ex-Employees, and Other Insiders
    • IT and security employees are the most dangerous
    • Ex-employees are Dangerous, so all access must be terminated before Leaving
    • Contractors with access permissions are also “insiders”

Copyright © 2015 Pearson Education, Ltd.

34 of 86

3.11 Types of Attackers

  • Cyberterrorists
    • Cyberterror attacks by terrorists
    • Cyberwar by nations
    • Dangerous because tend to be sophisticated
    • Dangerous because focus on doing widespread damage instead of committing isolated crimes

Copyright © 2015 Pearson Education, Ltd.

35 of 86

Copyright © 2015 Pearson Education, Ltd.

The Target Breach

Attacks and Attackers

Protecting Dialogs Cryptographically

Other Forms of Authentication

Firewalls

Antivirus Protection

36 of 86

Protecting Dialogs Cryptographically

  • Cryptography is the use of mathematics to protect information.
  • Confidentiality
    • Symmetric Key Encryption
  • Message Authentication and Integrity
    • Electronic Signature (Digital Signature)

Copyright © 2015 Pearson Education, Ltd.

37 of 86

3.12 Symmetric Key Encryption for Confidentiality

Copyright © 2015 Pearson Education, Ltd.

Symmetric Key Encryption: Two sides share a single key to encrypt and decrypt messages.

38 of 86

3.12 Symmetric Key Encryption for Confidentiality

Copyright © 2015 Pearson Education, Ltd.

39 of 86

3.12 Symmetric Key Encryption for Confidentiality

Copyright © 2015 Pearson Education, Ltd.

40 of 86

3.12 Symmetric Key Encryption for Confidentiality

Copyright © 2015 Pearson Education, Ltd.

128 bits

41 of 86

Public-Key Cryptography (Asymmetric Cryptography)� – Encryption for Confidentiality

Each party (entity) has a pair of keys: 

Public key  which may be distributed widely.

Private key  which is known only to the owner.

Bob

Alice

42 of 86

Public-Key Cryptography - Authentication

* Either key can be used for encryption, the other for decryption.

Bob

Alice

43 of 86

3.13 Electronic Signature Authentication

Copyright © 2015 Pearson Education, Ltd.

  • Authentication means proving a sender's identity.
  • Message integrity: the receiver is able to detect if the packet is altered by an attacker while the packet is in transit.

44 of 86

Host-to-Host Virtual Private Networks (VPNs)

Copyright © 2015 Pearson Education, Ltd.

SSL: Secure Socket Layer (Netscape)

TLS: Transport Layer Security (IETF)

* SSL/TLS is supported widely in Web browsers.

45 of 86

Copyright © 2015 Pearson Education, Ltd.

The Target Breach

Attacks and Attackers

Protecting Dialogs Cryptographically

Other Forms of Authentication

Firewalls

Antivirus Protection

46 of 86

3.15 General Authentication Concepts

Copyright © 2015 Pearson Education, Ltd.

Credential: Proof of identity.

47 of 86

3.16 Reusable Password Authentication

  • Reusable Passwords
    • Passwords are strings of characters
    • They are typed to authenticate the use of a username (account) on a computer
    • They are used repeatedly and so are called reusable passwords.
  • Benefits
    • Ease of use for users (familiar)
    • Inexpensive (often free) because they are built into operating systems.

Copyright © 2015 Pearson Education, Ltd.

48 of 86

3.16 Reusable Password Authentication

  • Often Weak (Easy to Crack)
    • Hackers use password dictionaries that include common passwords, names, and simple variations such as capitalizing the first letter and adding a number at the end
  • Dictionary attacks can crack almost all passwords in seconds or minutes.
    • A password that can be cracked using a dictionary can never be adequately strong-no matter how long it is.

Copyright © 2015 Pearson Education, Ltd.

Processing1

49 of 86

3.16 Reusable Password Authentication

  • Passwords Should Be Long and Complex
    • Should have a minimum of eight to twelve characters
    • Should mix case, digits, and other keyboard characters ($, #, etc.)
    • Example: r8pWm#4D*&2B
    • Can only be cracked with brute force attacks (trying all combinations of characters)
    • This is very difficult and often impossible
    • However, long, complex passwords are often written down

Copyright © 2015 Pearson Education, Ltd.

50 of 86

3.17 Other Forms of Authentication

  • Perspective
    • Goal is to replace reusable passwords
  • Access Cards
    • Permit door access
    • Can be used for computer access
    • Proximity access cards do not require physical contact

Copyright © 2015 Pearson Education, Ltd.

51 of 86

3.17 Other Forms of Authentication

  • Biometrics
    • Biometrics uses body measurements to authenticate you
    • Vary in cost, precision, and susceptibility to deception
    • Fingerprint recognition
      • Inexpensive but poor precision, deceivable
      • Sufficient for low-risk uses
      • On a notebook, may be better than requiring a reusable password

Copyright © 2015 Pearson Education, Ltd.

可欺騙的

52 of 86

3.17 Other Forms of Authentication

  • Iris recognition
    • Based on patterns in the colored part of your eye
    • Expensive but precise and difficult to deceive
  • Facial recognition
    • Based on facial features
    • Controversial because can be done surreptitiously—without the supplicant’s knowledge

Copyright © 2015 Pearson Education, Ltd.

暗中地

爭論的

53 of 86

Social Credit System in China

Copyright © 2015 Pearson Education, Ltd.

54 of 86

3.18 Digital Certificate Authentication

Copyright © 2015 Pearson Education, Ltd.

Challenge and Response

55 of 86

3.18 Digital Certificate Authentication

Copyright © 2015 Pearson Education, Ltd.

Certificate Authority (CA): a trusted organization which distributes�the public key of a person in a document called a digital certificate.

56 of 86

3.18 Digital Certificate Authentication

Copyright © 2015 Pearson Education, Ltd.

57 of 86

自然人憑證

Copyright © 2015 Pearson Education, Ltd.

58 of 86

Copyright © 2015 Pearson Education, Ltd.

印鑑證明

59 of 86

3.18 Digital Certificate Authentication

Copyright © 2015 Pearson Education, Ltd.

True Party

Has a Public and Private Key

Supplicant

Encrypts challenge message with supplicant’s private key

Verifier

Decrypts response message with true party’s public key

Choice

If decryption works, supplicant knows the true party’s private key so must be the true party

60 of 86

3.19 Two-Factor Authentication

  • Supplicant needs two forms of credentials
  • Example: debit card and PIN
  • Strengthens authentication
  • Fails if
    • Attacker controls user’s computer
    • Attacker can intercept authentication communication

Copyright © 2015 Pearson Education, Ltd.

攔截

61 of 86

Copyright © 2015 Pearson Education, Ltd.

The Target Breach

Attacks and Attackers

Protecting Dialogs Cryptographically

Other Forms of Authentication

Firewalls

Antivirus Protection

62 of 86

3.20 General Firewall Operation

Copyright © 2015 Pearson Education, Ltd.

63 of 86

3.20 General Firewall Operation

Copyright © 2015 Pearson Education, Ltd.

64 of 86

3.20 General Firewall Operation

  • What happens if a provable attack packet arrives?
  • What happens if a legitimate packet arrives?
  • What happens if a packet that is probably an attack packet arrives?
    • What are the implications of the answer?

Copyright © 2015 Pearson Education, Ltd.

65 of 86

3.21 States in a Conversation

Copyright © 2015 Pearson Education, Ltd.

Stateful Inspection Firewalls use the concept of communication states

66 of 86

3.22 Stateful Packet Inspection (SPI)

Copyright © 2015 Pearson Education, Ltd.

What would the firewall do with

a packet containing a SYN segment?

67 of 86

3.22 Stateful Packet Inspection (SPI)

Copyright © 2015 Pearson Education, Ltd.

What would the firewall do with

a packet containing a FIN segment?

68 of 86

3.22 Stateful Packet Inspection (SPI)

Copyright © 2015 Pearson Education, Ltd.

What would the firewall do with

a packet containing a pure ACK segment?

69 of 86

3.22 Stateful Packet Inspection (SPI)

Copyright © 2015 Pearson Education, Ltd.

Yes (Trying to Open a Connection)

70 of 86

3.23 Access Control Lists (ACLs) for Attempts to Open a Connection

Copyright © 2015 Pearson Education, Ltd.

Rule

Destination IP Address or Range

Service

Action

1

ALL

25

Allow connection

2

10.47.122.79

80

Allow connection

3

ALL

ALL

Do not allow connection

What will the SPI firewall do if the destination host is 10.47.122.79 and the service is 80?

71 of 86

3.23 Access Control Lists (ACLs) for Attempts to Open a Connection

Copyright © 2015 Pearson Education, Ltd.

What will the SPI firewall do if the destination host is 10.47.122.79 and the service is 25?

Rule

Destination IP Address or Range

Service

Action

1

ALL

25

Allow connection

2

10.47.122.79

80

Allow connection

3

ALL

ALL

Do not allow connection

72 of 86

3.23 Access Control Lists (ACLs) for Attempts to Open a Connection

Copyright © 2015 Pearson Education, Ltd.

What packets will match the third row?

Rule

Destination IP Address or Range

Service

Action

1

ALL

25

Allow connection

2

10.47.122.79

80

Allow connection

3

ALL

ALL

Do not allow connection

73 of 86

3.22 Stateful Packet Inspection (SPI)

Copyright © 2015 Pearson Education, Ltd.

No (Not Trying to Open a Connection)

74 of 86

3.22 Stateful Packet Inspection (SPI)

Copyright © 2015 Pearson Education, Ltd.

 

Internal Host

External Host

Connection

IP Address

Port

IP Address

Port

1

128.171.17.13

3270

10.74.118.4

80

2

128.171.34.5

4747

60.3.5.75

25

Approved Connections Table

What if the internal IP address is 128.171.34.5, the external IP address is 60.3.5.75 and the source and destination ports are 4747 and 25?

75 of 86

3.22 Stateful Packet Inspection (SPI)

Copyright © 2015 Pearson Education, Ltd.

Approved Connections Table

What if the internal IP address is 128.171.34.9, the external IP address is 60.3.5.75 and the source and destination ports are 4747 and 25?

 

Internal Host

External Host

Connection

IP Address

Port

IP Address

Port

1

128.171.17.13

3270

10.74.118.4

80

2

128.171.34.5

4747

60.3.5.75

25

76 of 86

3.25 Next-Generation Firewalls (NGFWs)

  • Limitations of Stateful Packet Inspection (SPI) Firewalls
    • Limited primarily to examining socket data
    • Cannot detect what applications are actually using Port 80
    • Cannot identify problems in streams of packets

Copyright © 2015 Pearson Education, Ltd.

77 of 86

3.25 Next-Generation Firewalls (NGFWs)

  • Next-Generation Firewall (NGFW) Operation
    • Uses deep Inspection
      • Examines all fields in the internet and transport layer
      • Examines application layer content as well
    • Requires reassembling application messages from multiple segments

Copyright © 2015 Pearson Education, Ltd.

78 of 86

3.25 Next-Generation Firewalls (NGFWs)

  • Application Awareness
    • Can identify what application created traffic
    • Can base rules on application policies for specific applications
    • Even understands malware applications

Copyright © 2015 Pearson Education, Ltd.

79 of 86

3.25 Next-Generation Firewalls (NGFWs)

  • Intrusion Detection System (IDS) Functionality
    • Can detect suspicious traffic
    • Log suspicious traffic
    • Notify the security administrator of high-threat suspicious traffic
    • Produce many false alarms that can dull vigilance

Copyright © 2015 Pearson Education, Ltd.

80 of 86

3.25 Next-Generation Firewalls (NGFWs)

  • Intrusion Prevention Systems (IPS) Functionality
    • IPSs are IDSs that drop packets that are suspicious but for which there is high confidence that they are attacks.

Copyright © 2015 Pearson Education, Ltd.

81 of 86

3.25 Next-Generation Firewalls (NGFWs)

  • Reputation Management
    • Whitelists and blacklists in external reputation management databases
    • Use to inform decisions about packets to and from listed sites
  • NAT and VPN Traversal
    • Traditional firewall functionality
    • VPN traversal passes encrypted traffic without inspection

Copyright © 2015 Pearson Education, Ltd.

82 of 86

3.25 Next-Generation Firewalls (NGFWs)

  • Need Wire-Speed Operation
    • Processing work per packet is heavy
    • Yet must be able to process at the highest speed of incoming transmission lines
    • Traditional firewalls are general-purpose computers that do processing with step-by-step software
    • NGFWs use purpose-built hardware than can do processing in hardware
      • Much faster than doing the same processing in software

Copyright © 2015 Pearson Education, Ltd.

83 of 86

Copyright © 2015 Pearson Education, Ltd.

The Target Breach

Attacks and Attackers

Protecting Dialogs Cryptographically

Other Forms of Authentication

Firewalls

Antivirus Protection

84 of 86

3.26 Antivirus Protection

  • Firewalls versus Antivirus Filtering
    • Firewalls work on packets and groups of packets
    • Antivirus filtering works on files
  • Antivirus Filtering
    • Not limited to viruses
    • Looks for all forms of malware

Copyright © 2015 Pearson Education, Ltd.

85 of 86

3.26 Antivirus Protection

  • Signature Detection
    • Looks for byte patterns that characterize individual malware programs
    • There are now too many malware programs to test for all malware program signatures
    • Also, many malware programs mutate, changing their signatures

Copyright © 2015 Pearson Education, Ltd.

突變

86 of 86

3.26 Antivirus Protection

  • Behavioral Detection
    • Analysis of what the program is attempting to do
    • Reformat the hard drive, etc.
    • If appropriate, delete the program
    • May run programs in a sandbox (environment it cannot escape from) to study it

Copyright © 2015 Pearson Education, Ltd.