Network Security
Chapter 3
Panko and Panko
Business Data Networks and Security, 10th Edition, Global Edition
Copyright © 2015 Pearson Education, Ltd.
Copyright © 2015 Pearson Education, Ltd.
The Target Breach
Attacks and Attackers
Protecting Dialogs Cryptographically
Other Forms of Authentication
Firewalls
Antivirus Protection
The Target Breach
Copyright © 2015 Pearson Education, Ltd.
3.1 The Target Breach
Copyright © 2015 Pearson Education, Ltd.
BlackPOS
3.1 The Target Breach
Copyright © 2015 Pearson Education, Ltd.
E-Mail Spear Phishing Attack
Fazio Mechanical Services
3.1 The Target Breach
Copyright © 2015 Pearson Education, Ltd.
3.1 The Target Breach
Copyright © 2015 Pearson Education, Ltd.
Not shown:
Constant ongoing
command and control communication from the outside
3.1 The Target Breach
Copyright © 2015 Pearson Education, Ltd.
偽造者
Copyright © 2015 Pearson Education, Ltd.
The Target Breach
Attacks and Attackers
Protecting Dialogs Cryptographically
Other Forms of Authentication
Firewalls
Antivirus Protection
3.2 Malware and Vulnerabilities
Copyright © 2015 Pearson Education, Ltd.
3.2 Malware and Vulnerabilities
Copyright © 2015 Pearson Education, Ltd.
3.3 Viruses and Worms
Copyright © 2015 Pearson Education, Ltd.
3.3 Viruses and Worms
Copyright © 2015 Pearson Education, Ltd.
易受欺騙
3.3 Viruses and Worms
Copyright © 2015 Pearson Education, Ltd.
3.4 Other Types of Malware
Copyright © 2015 Pearson Education, Ltd.
良性的
3.4 Other Types of Malware
Copyright © 2015 Pearson Education, Ltd.
假扮,偽裝
3.4 Other Types of Malware
Copyright © 2015 Pearson Education, Ltd.
3.5 Payloads
Copyright © 2015 Pearson Education, Ltd.
3.6 Attacks on Human Judgment
Copyright © 2015 Pearson Education, Ltd.
3.6 Attacks on Human Judgment
Copyright © 2015 Pearson Education, Ltd.
誘使,慫恿
Copyright © 2015 Pearson Education, Ltd.
3.6 Attacks on Human Judgment
Copyright © 2015 Pearson Education, Ltd.
3.7 Human Break-Ins (Hacking)
Copyright © 2015 Pearson Education, Ltd.
3.8 Stages in an Attack
Copyright © 2015 Pearson Education, Ltd.
剝削
3.9 Distributed Denial-of-Service (DDoS) Attack with Bots
Copyright © 2015 Pearson Education, Ltd.
Denial-of-Service (DOS) attack: an attack to make a computer or entire network unavailable to its legitimate users.
Availability
3.9 Distributed Denial-of-Service (DDoS) Attack with Bots
Copyright © 2015 Pearson Education, Ltd.
The collection of compromised computers is called a botnet.
SYN Flood
Copyright © 2015 Pearson Education, Ltd.
Copyright © 2015 Pearson Education, Ltd.
TCP three-way handshake
SYN Flood
3.10 Advanced Persistent Threats
Copyright © 2015 Pearson Education, Ltd.
3.11 Types of Attackers
Copyright © 2015 Pearson Education, Ltd.
3.11 Types of Attackers
Copyright © 2015 Pearson Education, Ltd.
3.11 Types of Attackers
Copyright © 2015 Pearson Education, Ltd.
報復
Insiders
3.11 Types of Attackers
Copyright © 2015 Pearson Education, Ltd.
3.11 Types of Attackers
Copyright © 2015 Pearson Education, Ltd.
Copyright © 2015 Pearson Education, Ltd.
The Target Breach
Attacks and Attackers
Protecting Dialogs Cryptographically
Other Forms of Authentication
Firewalls
Antivirus Protection
Protecting Dialogs Cryptographically
Copyright © 2015 Pearson Education, Ltd.
3.12 Symmetric Key Encryption for Confidentiality
Copyright © 2015 Pearson Education, Ltd.
Symmetric Key Encryption: Two sides share a single key to encrypt and decrypt messages.
3.12 Symmetric Key Encryption for Confidentiality
Copyright © 2015 Pearson Education, Ltd.
3.12 Symmetric Key Encryption for Confidentiality
Copyright © 2015 Pearson Education, Ltd.
3.12 Symmetric Key Encryption for Confidentiality
Copyright © 2015 Pearson Education, Ltd.
128 bits
Public-Key Cryptography (Asymmetric Cryptography)� – Encryption for Confidentiality
Each party (entity) has a pair of keys:
Public key which may be distributed widely.
Private key which is known only to the owner.
Bob
Alice
Public-Key Cryptography - Authentication
* Either key can be used for encryption, the other for decryption.
Bob
Alice
3.13 Electronic Signature Authentication
Copyright © 2015 Pearson Education, Ltd.
Host-to-Host Virtual Private Networks (VPNs)
Copyright © 2015 Pearson Education, Ltd.
SSL: Secure Socket Layer (Netscape)
TLS: Transport Layer Security (IETF)
* SSL/TLS is supported widely in Web browsers.
Copyright © 2015 Pearson Education, Ltd.
The Target Breach
Attacks and Attackers
Protecting Dialogs Cryptographically
Other Forms of Authentication
Firewalls
Antivirus Protection
3.15 General Authentication Concepts
Copyright © 2015 Pearson Education, Ltd.
Credential: Proof of identity.
3.16 Reusable Password Authentication
Copyright © 2015 Pearson Education, Ltd.
3.16 Reusable Password Authentication
Copyright © 2015 Pearson Education, Ltd.
Processing1
3.16 Reusable Password Authentication
Copyright © 2015 Pearson Education, Ltd.
3.17 Other Forms of Authentication
Copyright © 2015 Pearson Education, Ltd.
3.17 Other Forms of Authentication
Copyright © 2015 Pearson Education, Ltd.
可欺騙的
3.17 Other Forms of Authentication
Copyright © 2015 Pearson Education, Ltd.
暗中地
爭論的
Social Credit System in China
Copyright © 2015 Pearson Education, Ltd.
3.18 Digital Certificate Authentication
Copyright © 2015 Pearson Education, Ltd.
Challenge and Response
3.18 Digital Certificate Authentication
Copyright © 2015 Pearson Education, Ltd.
Certificate Authority (CA): a trusted organization which distributes�the public key of a person in a document called a digital certificate.
3.18 Digital Certificate Authentication
Copyright © 2015 Pearson Education, Ltd.
自然人憑證
Copyright © 2015 Pearson Education, Ltd.
Copyright © 2015 Pearson Education, Ltd.
印鑑證明
3.18 Digital Certificate Authentication
Copyright © 2015 Pearson Education, Ltd.
True Party | Has a Public and Private Key |
Supplicant | Encrypts challenge message with supplicant’s private key |
Verifier | Decrypts response message with true party’s public key |
Choice | If decryption works, supplicant knows the true party’s private key so must be the true party |
3.19 Two-Factor Authentication
Copyright © 2015 Pearson Education, Ltd.
攔截
Copyright © 2015 Pearson Education, Ltd.
The Target Breach
Attacks and Attackers
Protecting Dialogs Cryptographically
Other Forms of Authentication
Firewalls
Antivirus Protection
3.20 General Firewall Operation
Copyright © 2015 Pearson Education, Ltd.
3.20 General Firewall Operation
Copyright © 2015 Pearson Education, Ltd.
3.20 General Firewall Operation
Copyright © 2015 Pearson Education, Ltd.
3.21 States in a Conversation
Copyright © 2015 Pearson Education, Ltd.
Stateful Inspection Firewalls use the concept of communication states
3.22 Stateful Packet Inspection (SPI)
Copyright © 2015 Pearson Education, Ltd.
What would the firewall do with
a packet containing a SYN segment?
3.22 Stateful Packet Inspection (SPI)
Copyright © 2015 Pearson Education, Ltd.
What would the firewall do with
a packet containing a FIN segment?
3.22 Stateful Packet Inspection (SPI)
Copyright © 2015 Pearson Education, Ltd.
What would the firewall do with
a packet containing a pure ACK segment?
3.22 Stateful Packet Inspection (SPI)
Copyright © 2015 Pearson Education, Ltd.
Yes (Trying to Open a Connection)
3.23 Access Control Lists (ACLs) for Attempts to Open a Connection
Copyright © 2015 Pearson Education, Ltd.
Rule | Destination IP Address or Range | Service | Action |
1 | ALL | 25 | Allow connection |
2 | 10.47.122.79 | 80 | Allow connection |
3 | ALL | ALL | Do not allow connection |
What will the SPI firewall do if the destination host is 10.47.122.79 and the service is 80?
3.23 Access Control Lists (ACLs) for Attempts to Open a Connection
Copyright © 2015 Pearson Education, Ltd.
What will the SPI firewall do if the destination host is 10.47.122.79 and the service is 25?
Rule | Destination IP Address or Range | Service | Action |
1 | ALL | 25 | Allow connection |
2 | 10.47.122.79 | 80 | Allow connection |
3 | ALL | ALL | Do not allow connection |
3.23 Access Control Lists (ACLs) for Attempts to Open a Connection
Copyright © 2015 Pearson Education, Ltd.
What packets will match the third row?
Rule | Destination IP Address or Range | Service | Action |
1 | ALL | 25 | Allow connection |
2 | 10.47.122.79 | 80 | Allow connection |
3 | ALL | ALL | Do not allow connection |
3.22 Stateful Packet Inspection (SPI)
Copyright © 2015 Pearson Education, Ltd.
No (Not Trying to Open a Connection)
3.22 Stateful Packet Inspection (SPI)
Copyright © 2015 Pearson Education, Ltd.
| Internal Host | External Host | ||
Connection | IP Address | Port | IP Address | Port |
1 | 128.171.17.13 | 3270 | 10.74.118.4 | 80 |
2 | 128.171.34.5 | 4747 | 60.3.5.75 | 25 |
Approved Connections Table
What if the internal IP address is 128.171.34.5, the external IP address is 60.3.5.75 and the source and destination ports are 4747 and 25?
3.22 Stateful Packet Inspection (SPI)
Copyright © 2015 Pearson Education, Ltd.
Approved Connections Table
What if the internal IP address is 128.171.34.9, the external IP address is 60.3.5.75 and the source and destination ports are 4747 and 25?
| Internal Host | External Host | ||
Connection | IP Address | Port | IP Address | Port |
1 | 128.171.17.13 | 3270 | 10.74.118.4 | 80 |
2 | 128.171.34.5 | 4747 | 60.3.5.75 | 25 |
3.25 Next-Generation Firewalls (NGFWs)
Copyright © 2015 Pearson Education, Ltd.
3.25 Next-Generation Firewalls (NGFWs)
Copyright © 2015 Pearson Education, Ltd.
3.25 Next-Generation Firewalls (NGFWs)
Copyright © 2015 Pearson Education, Ltd.
3.25 Next-Generation Firewalls (NGFWs)
Copyright © 2015 Pearson Education, Ltd.
3.25 Next-Generation Firewalls (NGFWs)
Copyright © 2015 Pearson Education, Ltd.
3.25 Next-Generation Firewalls (NGFWs)
Copyright © 2015 Pearson Education, Ltd.
3.25 Next-Generation Firewalls (NGFWs)
Copyright © 2015 Pearson Education, Ltd.
Copyright © 2015 Pearson Education, Ltd.
The Target Breach
Attacks and Attackers
Protecting Dialogs Cryptographically
Other Forms of Authentication
Firewalls
Antivirus Protection
3.26 Antivirus Protection
Copyright © 2015 Pearson Education, Ltd.
3.26 Antivirus Protection
Copyright © 2015 Pearson Education, Ltd.
突變
3.26 Antivirus Protection
Copyright © 2015 Pearson Education, Ltd.