Intrusion Detection

The Need for a Security Policy

It is important to understand that network security is an evolutionary process. No one product can make an organization secure. True network security comes from a combination of products and services, combined with a comprehensive security policy and a commitment to adhere to that policy from the top of the organization down. In fact, a properly implemented security policy without dedicated security hardware can be more effective at mitigating the threat to enterprise resources than a...

Figure 69 Csids Responds to the Attack

Need Intrusion Detection

After the attack is stopped, the cleanup process begins. The PIX and the mail server automatically drop the half-open connections after a timeout period expires. Similarly, the Sensor removes the dynamically created access control list from the perimeter router after a specified amount of time. The preceding example is meant to be purely illustrative in nature. Nearly all responses to signature detections, as well as the signatures themselves, are definable by the administrator. There is no...

Secure Management and Reporting

It is such a simple proposition that almost everyone familiar with network security has said it at least once. Yet logging and reading information from more than 100 devices can prove to be a challenging proposition. Which logs are most important How do I separate important messages from mere notifications How do I ensure that logs are not tampered with in transit How do I ensure my time stamps match each other when multiple devices report the same alarm...

Figure 19 IP Header Datagram Format

A list of the fields in Figure 1-9 and their functions follows A list of the fields in Figure 1-9 and their functions follows Version The version field is 4 bits and represents the IP version for this packet. Most systems use IP version 4. In the future, most systems will use IP version 6 (IPv6) or IP The Next Generation (IPng). IP Header Length (IHL) The IHL field defines the length of the IP header. The options field that is discussed later in this list is optional and can affect the length...

Finger Service

The finger service can be used to resolve usernames on remote systems. Specifically, finger was designed to show active users on a system. Although the prevalence of finger has been reduced in the last few years, several administrators still allow finger requests to traverse their networks. Because of the many known ways that finger can be abused, no router should ever run finger unless there is a very specific reason to do so. An administrator can (and should) stop finger services with the...

About the Technical Reviewers

Sean Convery is a network architect in Cisco's VPN and Security business unit. He has been at Cisco for three years. Prior to that he held positions in both IT and security consulting during his six years in the network security industry. Steve Gifkins is a CCIE and CCSI of four and five years, respectively. He is based in the United Kingdom, where he runs his own independent Cisco-only consulting and training business. He is married with no children, and his hobbies include anything to do with...

Cisco Secure PIX Firewall

The Cisco Secure PIX Firewall is the dedicated hardware firewall in the Cisco Secure product family. The PIX Firewall is the industry leader in both market share and performance within the firewall market. The Cisco PIX Firewall is built around a non-UNIX, secure, real-time, embedded operating system, which leads to excellent performance without comprising security. This high level of performance is the result of the hardware architecture of the PIX Firewall, compared with operating...

Network Based Intrusion Detection Systems

Network-based intrusion detection systems are physical devices that are connected to various network segments within the protected network. Network-based intrusion detection systems usually comprise two components that work together to provide the IDS service. These two components are an IDS sensor (Cisco's is the Intrusion Detection Sensor) and an IDS management platform (Cisco's is the Intrusion Detection Director). The IDS sensors are hardware devices that passively monitor and analyze the...

IP Spoofing

An IP spoofing attack occurs when a hacker inside or outside a network pretends to be a trusted computer. A hacker can do this in one of two ways. The hacker uses either an IP address that is within the range of trusted IP addresses for a network, or an authorized external IP address that is trusted and to which access is provided to specified resources on a network. IP spoofing attacks are often a launch point for other attacks.

Simple Network Management Protocol SNMP

Simple Network Management Protocol (SNMP) is used by a variety of programs involved with network management. The beauty of SNMP is intertwined with its dangers. Because SNMP is designed to allow an administrator to monitor and configure devices remotely, SNMP can also be used in attempts to penetrate the corporate network. This section explores how to minimize vulnerability while using SNMP. A few simple configuration changes, as well as a few logical choices that should be made by the...

Single DMZ Configuration

This configuration moves the FTP, Web, and e-mail servers to a DMZ. All traffic destined for these servers will not touch the LAN. When using a DMZ, it is critical that no connection between the LAN and the DMZ be maintained except through the PIX Firewall. Connecting the LAN to the DMZ in any way except through the firewall defeats the purpose of the DMZ. Figure 4-7 shows that a third interface has been added to the PIX. This interface will be used as a DMZ. Figure 4-7. Single DMZ...

VPN with Pointto Point Tunneling Protocol PPTP

Starting with Version 5.1 of the PIX IOS, Cisco provides support for Microsoft PPTP VPN clients as an alternative to IPSec. Although PPTP is a less secure technology than IPSec, PPTP is easier to configure and maintain. PPTP also enjoys a great deal of support, especially from Microsoft clients. The PPTP is an OSI Layer 2 tunneling protocol that allows a remote client to communicate securely through the Internet. PPTP is described by RFC 2637. The PIX Firewall only supports inbound PPTP, and...

Reflexive Access Lists

Reflexive access lists are a type of extended access list that allow two access lists to work together dynamically. When the outbound access list senses a connection to a remote site, the inbound access list is opened up to allow two-way communications to occur. Once this two-way session is completed, the inbound access list is again closed to the remote site. The characteristics of reflexive access lists are as follows There are no implied deny any statements at the end of the reflexive access...

Figure 411 VPN with IPSec

You need to configure both PIX Firewalls to enable a secure tunnel between them. The configurations that follow show only the items associated with setting up the IPSec tunnels. You will see both configurations and then a discussion of the ramifications of using the commands. Keep in mind that these are examplesl and, therefore, do not have routable IP addresses on the outside interfaces. In real life, the outside interfaces would need routable IP addresses inside the corporate LANs, the IP...

Crypto ipsec Command

You have also seen the crypto ipsec command used within the configurations. There are two major forms of this command, the crypto ipsec transform-set and the crypto ipsec security-association lifetime forms. Both of these can be removed with the no form of the command. These commands are explained in Table 4-7. crypto ipsec set security-association lifetime seconds seconds kilobytes If the keyword seconds is used, the seconds parameter specifies how many seconds before an SA will remain active...

Internet Protocol IP

IP, the network layer datagram service of the TCP IP suite, is used by all other protocols in the TCP IP suite except the address resolution protocol (ARP) and the reverse address resolution protocol (RARP) to transfer packets from host to host over an internetwork. This function isn't supported by any other protocols contained within the TCP IP suite. The other main feature of IP, congestion control, is found on nearly every layer of the OSI model. IP performs basic congestion control that is...

Solutions to the Threats to Web Servers

In theory, the Internet service that runs on TCP port 80 is intrinsically secure and does not really require protection. However, it is the Web server itself and the network operating system that causes the security concerns. Any service other than the HTTP service running on the server increases the risk associated to the server. The best way to protect against this, as with most other services, is to deploy a firewall that is situated between the public Internet and the Web server. The Web...

Figure 68 Csids Sensor Notices an Attack

As shown in Figure 6-8, a hacker on the Internet has decided to attempt a DoS attack against the internal e-mail server through the use of half-open TCP connections. Although the PIX Firewall is fully capable of resisting such an attack, the Sensor still notices the attack the moment it has been launched. The FloodGuard algorithm on the PIX Firewall will not start to drop half-open connections until the defined threshold has been exceeded. The Sensor sends a message to the Director stating that...

PIXtoPIX Configuration

One advantage of using the PIX Firewall is that it has become a standard within the industry. As time passes, your business might acquire or become acquired by another company. To provide connectivity, you are faced with two choices enabling VPNs over the Internet or using dedicated connections. Because one of the benefits of the PIX box is to allow secure VPNs, this section explores how to set up two PIX Firewalls between different locations through the Internet.

Cisco IOS Firewall IDS Configuration

The Internet connection point of nearly all companies is through some routing device. In this section, you will look at the configuration of the Cisco IOS Firewall IDS for a router that is acting as the Internet connection point for a large company. This company has other WAN links to other sites. All Internet-bound traffic is routed through the central site. The Internet connection is provided for Internet browsing and e-mail only. There are no Internet servers...

Intrusion Detection Post Office

The IDS Post Office is the communications backbone that allows Cisco Secure IDS services and hosts to communicate with each other. All communications between the Intrusion Detection Sensor and Director use a proprietary connection-based protocol that can switch between alternate routes to maintain point-to-point connections. Further information on the Cisco Secure Intrusion Detection System can be found at

Figure 111 Smurf Attack

ATho Victim now ncceivos an ICMP Echo Rcpty pacxet ffom every host on ihw insens (he IK address 01 me rcccivc Ow pacuct and send an ICMP Victim server as Uie source Eetw R&pfy is ihu souiee IP Ping of death The ping of death is a famous DoS attack that uses the ping ICMP Echo Request and Echo Reply to crash a remote system. It is classified as an elegant one-packet kill. This attack works by sending a large ICMP Echo Request packet that gets fragmented before sending. The receiving host, which...

Internet Control Message Protocol ICMP

ICMP messages are encapsulated within IP packets. Using a connectionless, unreliable transfer mechanism, ICMP is used to report errors within a network. Usually, only higher-level protocols are encapsulated within another protocol. However, ICMP is an integral part of the IP protocol suite that still is encapsulated within the data portion of an IP packet. RFCs 792 and 1700 define ICMP. Even though ICMP message formats vary based on which service is requested, all ICMP messages have the first...

Realistic Configuration

Although the basic configuration suffices to illustrate how simple it is to configure the PIX, there are a few more items that almost all systems need. Three examples are Web services, e-mail services, and FTP services. This configuration will show how access from the outside to the inside of the PIX can be allowed. The default configuration for the PIX Firewall is to prevent all access from an interface with a lower security level through an interface with a higher security level. The...

Figure 213 Ip Tcp Intercept

Hosl A initiales a connection to Hosl B Step 1 Slep 22 inls rapt roLrter answers as 1 it were Host B and (hen forwards a duplicate request to Hosl B wilh the imencept router as the requester Step 4 intercept router r Router duplicate Host A spooling Slep 22 inls rapt roLrter answers as 1 it were Host B and (hen forwards a duplicate request to Hosl B wilh the imencept router as the requester Step 4 intercept router r Router duplicate Host A spooling Step Host B Hosl B receives requ&sls from...

Differences Between Radius and TACACS

There are quite a few distinct differences between RADIUS and TACACS+. These differences can be vital in deciding which protocol to implement. The main differences are shown in Table 9-1. The main differences are shown in Table 9-1. Table 9-1. Differences Between RADIUS and TACACS+ Encrypts the entire body of the packet Combines authentication and authorization Uses the AAA architecture that separates authentication, authorization, and, accounting No support for ARA, NetBIOS, NASI, or X.25...

Crypto map Commands

The crypto map command is used extensively with IPSec. This section examines the forms of this command in Table 4-6 before examining exactly what has to be configured in the examples. The crypto map command's first parameter is always the mapname. The mapname parameter is an arbitrary name assigned to distinguish one map from another. Table 4-6 assumes that crypto map mapname precedes the command. As with most commands, the no form of a command removes the configuration. Table 4-6. crypto map...

Fixup Command

Some fixup commands appear in the configuration by default, others are added as needed. The fixup protocol commands allow changing, enabling, and disabling the use of a service or protocol through the PIX Firewall. The ports specified for each service are listened to by the PIX Firewall. The fixup protocol command causes the ASA to work on port numbers other than the defaults. The following fixup protocol commands are enabled by default fixup protocol ftp 21...

Signature Severity Levels

Each signature has an associated severity level that indicates the probability that the signature is an actual attack. The default security levels for all signatures are preset, and the administrator can change the setting at any time. The five signature severity levels are shown Table 6-2. IP Signature Severity Levels Table 6-2. IP Signature Severity Levels Informational events are logged only on Sensors. Simply someone pinging a server can cause this. An abnormal event is one that does not...

Packet Sniffers

A packet sniffer is a software application that uses a network adapter card in promiscuous mode to capture all network packets that are sent across a particular collision domain. (Promiscuous mode is when the network adapter card sends all packets received on the physical network wire to an application for processing.) Sniffers are used legitimately in networks today to aid in troubleshooting and traffic analysis. However, because several network applications send data in clear text (Telnet,...

IDS Monitoring

Once intrusion detection has been configured, you can monitor the syslog information to identify any attempted security issues. The following log data are extracts from an actual Internet-facing PIX Firewall. You can see that the IDS on the PIX has intercepted quite a few items of suspicious activity 400027 IDS 3041 TCP interface outside 400027 IDS 3041 TCP interface outside 400027 IDS 3041 TCP interface outside 400027 IDS 3041 TCP interface outside 400027 IDS 3041 TCP interface outside 400027...

Ip local pool Command

An IP local pool is used with VPNs to reserve a range of IP addresses that will be assigned to hosts using VPNs. The addresses in this range must not be in use by any other hosts and should not be used in any other commands. Use the show form of the command to display all of the IP addresses within a pool. The command, reserving IP addresses of 10.1.1.50 through 10.1.1.75 and using the name thelocalpool follows. ip local pool thelocalpool 10.1.1.50-10.1.1.75 vpdn Command The vpdn command takes...

Cisco Secure ACS Configuration

This section covers the configuration of Cisco Secure ACS, including information on the client configuration and the server configuration. In this section, the client is a Cisco router running IOS 12 and supporting both RADIUS and TACACS+. The server is a Windows NT server that is authenticated against the Windows NT domain and also a remote ODBC data source. The section shows the configuration of RADIUS and TACACS+ for authentication and accounting both for EXEC and network connections. This...

Threats Posed to Internet eMail Servers

Internet e-mail systems can be attacked to deny service, or they can be misused if they are incorrectly configured. One common misuse of Internet e-mail systems is spam. Spam is unsolicited bulk e-mail the people who send it are known as spammers. Spammers usually send bulk e-mails about get-rich-quick schemes or advertising pornographic web sites. Spam is enabled if the Web server is running as an open relay. Various Internet groups, such as the Open Relay Behavior-modification System (ORBS,...