0% found this document useful (0 votes)
5 views37 pages

Network Security Class

The document outlines the key concepts and threats associated with network security, including network vulnerabilities, types of attacks, and the motivations behind attackers. It emphasizes the importance of understanding network characteristics that increase security risks and discusses various attack methods such as impersonation, spoofing, and denial of service. Additionally, it highlights the significance of threat precursors and the need for effective security measures to protect networks from potential breaches.

Uploaded by

Dzame Ashley
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views37 pages

Network Security Class

The document outlines the key concepts and threats associated with network security, including network vulnerabilities, types of attacks, and the motivations behind attackers. It emphasizes the importance of understanding network characteristics that increase security risks and discusses various attack methods such as impersonation, spoofing, and denial of service. Additionally, it highlights the significance of threat precursors and the need for effective security measures to protect networks from potential breaches.

Uploaded by

Dzame Ashley
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Security in Networks – (Part 1)

Security in Networks – Part 1 – Outline (1)


2. Security in Networks
2.1. Network Concepts
a) Introduction
b) The network
c) Media
d) Protocols
e) Types of networks
f) Topologies
g) Distributed systems
h) APIs
i) Advantages of computing networks

2.2. Threats in Networks


a) Introduction
b) Network vulnerabilities
c) Who attacks networks?
d) Threat precursors
e) Threats in transit: eavesdropping and wiretapping
f) Protocol flaws
Security in Networks – Part 1 – Outline (2)
2.2. Threats in Networks - ctd
g) Types of attacks
g-1) Impersonation
g-2) Spoofing
g-3) Message confidentiality threats
g-4) Message integrity threats
g-5) Web site attacks
g-6) Denial of service
g-7) Distributed denial of service
g-8) Threats to active or mobile code
g-9) Scripted and complex attacks
h) Summary of network vulnerabilities
2. Security in Networks
▪ Network attacks are critical problems due to:
▪ Widespread use of networks
▪ Fast changes in network technology
▪ We’ll discuss security issues in network
▪ Design / Development / Usage
▪ Outline for Part 1 of Security in Networks (this Section)
2.1. Network Concepts
2.2. Threats in Networks
▪ Note: Part 2 of Security in Networks will be covered in
lecture Section 5:
• Network Security Controls
• Network Security Tools
2.1. Network Concepts
▪ Outline
a) Introduction
b) The network
c) Media
d) Protocols
e) Types of networks
f) Topologies
g) Distributed systems
h) APIs
i) Advantages of computing networks
2.2. Threats in Networks (1)
▪ Outline
a) Introduction
b) Network vulnerabilities
c) Who attacks networks?
d) Threat precursors
e) Threats in transit: eavesdropping and wiretapping
f) Protocol flaws
g) Types of attacks:
g-1) Impersonation
g-2) Spoofing
g-3) Message confidentiality threats
g-4) Message integrity threats
g-5) Web site attacks
Threats in Networks (2)

▪ Outline—cont.
g) Types of attacks-cont.:
g-6) Denial of service
g-7) Distributed denial of service
g-8) Threats to active or mobile code
g-9) Scripted and complex attacks
h) Summary of network vulnerabilities
a. Introduction (1)
▪ We will consider
threats aimed to compromise C-I-A
applied against data, software, or hardware
by nature, accidents, nonmalicious humans, or malicious
attackers
Introduction (2)

▪ From CSI/FBI Report 2002 (survey of ~500 com/gov/edu/org)


▪ 90% detected computer security breaches
▪ 80% acknowledged financial losses
▪ 44% (223) were willing/able to quantify losses: $455M
▪ Most serious losses: theft of proprietary info and fraud
▪ 26 respondents: $170M
▪ 25 respondents: $115M
▪ 74% cited Internet connection as a frequent point of
attack
▪ 33% cited internal systems as a frequent point of attack
▪ 34% reported intrusions to law enforcement (up from
16%-1996)

[cf.: D. Frincke]
Introduction (3)

▪ More from CSI/FBI Report 2002


◼ 40% detected external penetration
◼ 40% detected DoS attacks
◼ 78% detected employee abuse of Internet
◼ 85% detected computer viruses
◼ 38% suffered unauthorized access on Web sites
◼ 21% didn’t know
◼ 12% reported theft of information
◼ 6% reported financial fraud (up from 3%-- 2000)

[cf.: D. Frincke]
b. Network vulnerabilities (1)
▪ Network characteristics significantly increase security risks
▪ These vulnerability-causing characteristics include:
1) Attacker anonymity
▪ Attacker can be far away
▪ Can disguise attack origin (pass through long chain of
hosts)
▪ Weak link: computer-to-computer authentication

2) Many points of origin and target for attacks


▪ Data and interactions pass through many systems on
their way between user and her server
▪ Each system can be origin of an attack or target for
attack
▪ Systems might have widely different security
policies/mechanisms
Network vulnerabilities (2)

3) Resource and workload sharing


▪ More users have access to networks than to stand-
alone systems
▪ More systems have access to networks
4) Network complexity
▪ Complexity much higher in networks than in single
OSs
5) Unknown or dynamic network perimeter
▪ Dynamic in any network, unknown in network w/o
single administrative control
▪ Any new host can be untrustworthy
▪ Administrator might not known that some of hosts of
his network are also hosts in another network
▪ Hosts are free to join other networks
Network vulnerabilities (3)

6) Uknown paths between hosts and users


▪ Many paths
▪ Network decides which one chosen
▪ Network might change path any time

7) Nonuniform security policies/mechanisms for hosts


belonging to multiple networks
▪ If Host H belongs to N1 and N2, does it follow:
▪ N1’s rules?
▪ N2’s rules?
▪ Both?
▪ What if they conflict?
c. Who attacks networks? (1)
▪ Who are the attackers?
▪ We don’t have a name list
▪ Who the attackers might be?
▪ MOM will help to answer this
▪ MOM = Method/Opportunity/Motive

▪ Motives of attackers:
1) Challenge/Power
2) Fame
3) Money/Espionage
4) Ideology
Who attacks networks? (2)

1) Attacking for challenge/power


▪ Some enjoy intellectual challenge of defeating
supposedly undefeatable
▪ Successful attacks give them sense of power
▪ Not much challenge for vast majority of hackers
▪ Just replay well-known attacks using scripts
2) Attacking for fame
▪ Some not satisfied with challenge only
▪ Want recognition – even if by pseudonym only
▪ Thrilled to see their pseudonym in media
3) Attacking for money/espionage
▪ Attacking for direct financial gains
▪ Attacking to improve competitiveness of ones com/org
▪ 7/2002: Princeton admissions officers broke into Yale’s system
▪ Attacking to improve competitiveness of ones country
▪ Some countries support industrial espionage to aid their own
industries (cont.)
Who attacks networks? (3)
▪ Attacking to spy on/harm another country
▪ Espionage and information warfare
▪ Steal secrets, harm defense infrastructure, etc.
▪ Few reliable statistics – mostly perceptions of attacks
▪ 1997-2002 surveys of com/gov/edu/org: ~500 responses/yr
▪ 38-53% believed they were attacked by US competitor
▪ 23-32% believed they were attacked by foreign competitor

4) Attacking to promote ideology


▪ Two types of ideological attacks:
▪ Hactivism
▪ Disrupting normal operation w/o causing serious
damage
▪ Cyberterrorism
▪ Intent to seriously harm
▪ Including loss of life, serious economic damage
Who attacks networks? (4)

Recall: Threat Spectrum

[cf.: D. Frincke]
d. Threat precursors (1)
◼ How attackers prepare for attacks?
◼ Investigate and plan
These are threat prescursors
◼ If we detect threat precursors, we might be able to block
attacks before they’re launched
◼ Threat prescursors techniques include:
1) Port scan
2) Social engineering
3) Reconnaissance
4) OS and application fingerprinting
5) Using bulletin boards and chats
6) Getting available documentation
Threat precursors (2)

1) Port scan
Port scanner - pgm that scans port indicated by IP address
▪ Reports about:
a) Standard ports/services running and responding
▪ Recall (ex.): port 80–HTTP, 25-SMTP(e-mail), 23-Telnet
b) OS installed on target system
c) Apps and app versions on target system
 Can infer which known vulnerabilities present

Threat precursors (3)


2) Social engineering
= using social skills and personal interaction to get someone to reveal
security-releveant info or do sth that permits an attack
◼ Impersonates sb inside an organization
◼ Person in a high position (works best – by intimidation), co-worker, ...
◼ Relies on human tendency to help others when asked politely
Threat precursors (6)

3) Reconnaissance
= collecting discrete bits of security information from various sources and putting them together

◼ Reconnaissance techniques include:


a) Dumpster diving
b) Eavesdropping
▪ E.g., follow employees to lunch, listen in
c) Befriending key personnel (social engg!)

◼ Reconnaissance requires little training, minimal investment, limited time


BUT can give big payoff in gaining background info

4) OS and application fingerprinting


= finding out OS/app name, manufacturer and version by using pecularities in OS/app
responses
◼ Example: Attacker’s approach
◼ Earlier port scan (e.g., nmap) reveals that port 80 – HTTP is running
◼ Attacker uses Telnet to send meaningless msg to port 80
◼ Attacker uses response (or a lackof it) to infer which of many possible OS/app
it is
◼ Each version of OS/app has its fingerprint (pecularities) that reveals its
identity (manufacturer, name, version)
Threat precursors (8)

5) Using bulletin boards / chats


◼ Attackers use them to help each other
◼ Exchange info on their exploits, tricks, etc.

6) Getting available documentation


◼ Vendor documentation can help attackers
e. Threats in transit: eavesdropping
and wiretapping (1)
▪ Threats to data in transit:
1) Eavesdropping
= overhearing without any extra effort
E.g., admin anyway uses s/w to monitor network traffic to manage the
network - in this way she effortlessly eavesdrops on the traffic
2) Wiretapping
= overhearing with some extra effort
a) Passive wiretapping
Pretty similar to eavesdropping but some extra effort
E.g., starting monitoring s/w usually not used
b) Active wiretapping – injecting msgs
▪ Wiretapping technique depends on the communication medium
f. Protocol flaws
◼ Protocol flaws:
◼ Design flaws
◼ Proposed Internet protocols posted for public
scrutiny
◼ Does not prevent protocol design flaws
◼ Implementation flaws
g. Types of attacks
g-1. Impersonation (1)
◼ Impersonation = attacker foils authentication and assumes
identity of a valid entity in a communication
◼ Impersonation attack may be easier than wiretapping
◼ Types of impersonation attacks (IA):
1) IA by guessing
2) IA by eavesdropping/wiretaping
3) IA by circumventing authentication
4) IA by using lack of authentication
5) IA by exploiting well-known authentication
6) IA by exploiting trusted authentication
g-2. Spoofing (1)
◼ Spoofing — attacker (or attacker’s agent) pretends to be a
valid entity without foiling authentication
◼ Spoof - 1. To deceive. [...]
The American Heritage® Dictionary of the English Language: Fourth Edition. 2000

◼ Don’t confuse spoofing with impersonation


◼ Impersonation — attacker foils authentication and
assumes identity of a valid entity
◼ Three types of spoofing:
1) Masquerading
2) Session hijacking
3) Man-in-the middle (MITM)
Spoofing (2)
1) Masquerading = a host pretends to be another
◼ Really: attacker sets up the host (host is attacker’s agent)
◼ Masquerading - Example 1:
◼ Real web site: [Link] for Blue Bank Corp.
◼ Attacker puts a masquerading host at: [Link]
◼ It mimics the look of original site as closely as possible
◼ A mistyping user (who just missed „-”) is asked to login,
to give password => sensitive info disclosure
◼ Can get users to masquerading site by other means
◼ E.g., advertise masquerading host with banners on other
web sites (banners would just say „Blue Bank”-no „-” there)
◼ Similar typical masquerades:
◼ [Link] and [Link] masquerade as [Link]
◼ [Link] masquerades as [Link] (1-I, 0-O)
◼ [Link] masquerades as [Link]
Section 2/1 (Ch.7) – Computer Security and Information Assurance © 2006-2008 by Leszek T. Lilien
Spoofing (4)

2) Session hijacking = attacker intercepting and carrying on a


session begun by a legitimate entity

◼ Session hijacking - Example


◼ Sysadmin starts Telnet session by remotely logging in
to his privileged acct
◼ Attacker uses hijacking utility to intrude in the
session
◼ Can send his own commands between admin’s commands
◼ System treats commands as coming from sysadmin
Spoofing (5)

3) Man-in-the middle (MITM)


◼ Similar to hijacking
◼ Difference: MITM participates in a session from its start
g-3. Message confidentiality threats (1)
◼ Message confidentiality threats include:
1) Eavesdropping – above
2) Impersonation – above
3) Misdelivery
◼ Msg delivered to a wrong person due to:
◼ Network flaw
◼ Human error
◼ Email addresses should not be cryptic
iwalkey@[Link] better than iw@[Link]
iwalker@[Link] better than 10064,30652@[Link]
Message confidentiality threats (2)
4) Exposure
◼ Msg can be exposed at any moment between its
creation and disposal
◼ Some points of msg exposure:
◼ Temporary buffers
◼ Switches / routers / gateways / intermediate hosts
◼ Workspaces of processes that build / format / present msg
(including OS and app pgms)
◼ Many ways of msg exposure:
◼ Passive wiretapping
◼ Interception by impersonator at source / in transit / at
destination

5) Traffic flow analysis


◼ Mere existence of msg (even if content unknown) can
reveal sth important
◼ E.g., heavy msg traffic form one node in a military network
might indicate it’s headquarters
g-4. Message integrity threats (1)
◼ Message integrity threats include:
1) Msg fabrication
2) Noise
1) Msg fabrication
◼ Receiver of fabricated msg may be misled to do what
fabricated msg requests or demands
◼ Some types of msg fabrication:
◼ Changing part of/entire msg body
◼ Completely replacing whole msg (body & header)
◼ Replay old msg
◼ Combine pieces of old msgs
◼ Change apparent msg source
◼ Destroy/delete msg
Message integrity threats (2)

◼ Means of msg fabrication:


◼ Active wiretap
◼ Trojan horse
◼ Impersonation
◼ Taking over host/workstation
2) Noise = unintentional interference
◼ Noise can distort msg
◼ Communication protocols designed to detect/correct
transmission errors
◼ Corrected by:
◼ error correcting codes
◼ retransmission
g-5. Denial of service (attack on avail.) (1)
▪ Service can be denied:
A) due to (nonmalicious) failures
▪ Examples:
▪ Line cut accidentally (e.g., by a construction crew)
▪ Noise on a line
▪ Node/device failure (s/w or h/w failure)
▪ Device saturation (due to nonmalicious excessive workload/ or
traffic)
▪ Some of the above service denials are short-lived and/or
go away automatically (e.g., noise, some device saturations)
B) due to denial-of-service (DoS) attacks = attacks on availab.
▪ DoS attacks include:
1) Physical DoS attacks
2) Electronic DoS attacks
Denial of service (2)
1) Physical DoS attacks – examples:
▪ Line cut deliberately
▪ Noise injected on a line
▪ Bringing down a node/device via h/w manipulation
2) Electronic DoS attacks – examples:
(2a) Crashing nodes/devices via s/w manipulation
(2b) Saturating devices (due to malicious injection of excessive
workload/ or traffic)
Includes:
(i) Connection flooding
(ii) SYN flood
(2c) Redirecting traffic
Includes:
(i) Packet-dropping attacks (incl. black hole attacks)
(ii) DNS attacks
g-6. Distributed denial of service

[Fig. courtesy of B. Endicott-Popovsky]


(attack on availability)
▪ DDoS = distributed denial of service
▪ Attack scenario:
1) Stage 1:
▪ Attacker plants Trojans on many target machines
▪ Target machines controlled by Trojans become
zombies
2) Stage 2:
▪ Attacker chooses victim V, orders zombies to attack V
▪ Each zombie launches a separate DoS attack
▪ Different zombies can use different DoS attacks
▪ E.g., some use syn floods, other smurf attacks
▪ This probes different weak points
▪ All attacks together constitute a DDoS
▪ V becomes overwhelmed and unavailable
=> DDoS succeeds
g-9. Scripted and complex attacks

[Fig. courtesy of B. Endicott-Popovsky]


1) Scripted attacks = attacks using attack scripts
▪ Attack scripts created by knowledgeable crackers
BUT
▪ Can be run even by ignorant script kiddies
▪ Just download and run script code
▪ Script selects victims, launches attack

▪ Scripted attacks can cause serious damage


▪ Even when run by script kiddies

2) Complex attacks = multi-component attacks using


miscellanous forms of attacks as its building blocks
▪ Bldng block example: wiretap for reconaissance,
ActiveX attack to install a Trojan, the Trojan spies on
sensitive data
▪ Complex attacks can expand target set
For more go through chapter 7 of the book by
Charles P. Pfleeger, Security in computing,
fourth edition, Prentice Hall

You might also like