Appendix B Answers to Applied Knowledge Questions

Chapter 1 Chapter 2 Chapter 3 Chapter 4 Chapter 5 Chapter 6 Chapter 7 Chapter 8 Chapter 9 Chapter 10 Chapter 11 Chapter 12 Chapter 13 Chapter 14 Chapter 15 Chapter 16

4 PREV

NEXT t

1 GeeWiz.com just released a patented remote process watchdog tool that allows you to govern the processes running on any server in your network. Should you find an excuse to buy it?

Al: Not right away. In addition to operational and financial questions, you must determine how this technology complements your current design. Buying security technology in an ad-hoc fashion does not build good systems; focus instead on building predictable systems.

2 You recently joined a company that uses an IPsec remote access product to allow employees who work from home and on the road to access the campus network. Because the product uses encryption and a one-time-password (OTP) authentication scheme (see Chapter 3) to validate each user's identity at logon, the company feels confident in its design. Should it be?

A2: Although the company has addressed the important issue of providing confidentiality in communications over public infrastructure, it might be ignoring threats that could be unaffected by this technology. Think about the axiom that confidentiality is not security, and make sure considerations about misuse, availability, and integrity are part of the planning process.

3: Every day you receive nearly a dozen requests to modify the configuration of your firewall to open and close services based on some department's or team's new online requirement. You are concerned that this process is going to lead to disaster someday soon. What should you do?

A3: Although you remember that business priorities come first, it is equally important that feedback must flow from the security team back to corporate planning. It is likely that those making the decisions to conduct business in this fashion do not understand the risk inherent in such an approach.

4 Your boss returns from a security convention and advises you that it is a good security practice to run all internal web servers on port TCP 8080 rather than TCP 80 to help secure access to them. How do you respond?

A4: Although "Yes, sir" is sometimes a necessary response, a better one is to suggest that security through obscurity is not overly valuable, especially when the effects will have an impact on every employee in the company on a day-to-day basis. It is not overly difficult for an attacker to learn the ports actually usedit's certainly much less effort than that required to maintain such an obscure environment.

5: Why isn't requiring user authentication for remote access to a network an axiom?

A5: Axioms apply to all areas of the network design and are pervasive in their applicability. This authentication requirement is really a design consideration that is important to keep in mind when focusing on the specific area of remote access.

6: Should you care about the security implemented by your service provider?

A6: Absolutely. Security is a system, and your networks are directly connected to others that you do not control. How your neighbors have constructed their security systems has a direct effect on the types of attacks you must plan to address. It also affects the reliability of some of the information you collect. For example, some providers guarantee IP spoof mitigation in their private clouds, which means you have a level of assurance as to the source environment from which malicious packets may be coming. Other providers implement various distributed denial of service (DDoS) detection and mitigation techniques within their cloud, and this is important to be aware of because you cannot control the traffic that enters your WAN link from the other end.

7: Consider two identical hosts connected to the network. Decide which one is better protected and why, based on the list of protections installed between the attacker and the host:

Attacker > Filtering Router > Firewall > Personal Firewall > Host 1 Attacker > Firewall > Host IDS > Host 2

A7: Because network security is a system, host 2 is better protected because, even though there are only two technologies protecting it, these technologies work in different ways (HIDS and firewall; see Chapter 3 for more information). This makes the protection provided somewhat additive, whereas even though you have three protection technologies for host 1, they are all firewall based; thus, if one is circumvented (such as with an application-layer attack, which most firewalls don't see), the attack will likely get through all three firewalls.

8: After reading the axioms, what do you think is the principal obstacle to deploying network security as an integral component throughout the network?

A8: Often the organizational challenges pose the most problems. Making two groups responsible for different aspects of the same device's configuration can be very problematic. Strategies to deal with this issue are discussed throughout the rest of the book.

9: In the section on the axiom "Everything is a target," you saw the various ways in which a web server could be compromised. Now run through the exercise yourself and list the potential methods an attacker could use to gain access to your internal LAN.

A9: Many potential attack vectors exist, including the following:

• Gain physical access to the building and connect to an unused port posing as a legitimate employee.

• Gain physical access to the building and install a WLAN AP in an unused port, then leave the building and attack over the air.

• War dial to find an insecure modem at an employee's desk that can provide access to the LAN.

• E-mail employees a Trojan application, which opens a connection to your attack machine and provides remote control.

• Attack remote WLAN teleworker connections and utilize their VPN connection to gain local access.

• Port scan the address range of the internal network (or its NAT equivalent) to learn hosts that might be open to attack.

• Compromise a perimeter system and then exploit the trust that system has with the internal network to gain access.

10: In the section on the axiom "Everything is a weapon," you saw how a DHCP server could be used as a weapon on the network. What are the potential attacks that could be launched against your company if your Internet edge router is compromised?

A10: Many potential attack vectors exist, including the following:

• Cause traffic destined for key servers on the Internet to be directed to the attacker's machine by using NAT.

• Take advantage of the network diagnosis tools on a router to learn more about the traffic types going through the router to probe for potential weaknesses.

• Cause intermittent connectivity problems to certain servers in the hopes that the administrator will open up the firewall policy in an effort to troubleshoot the problem.

• Inject false routing information into your ISP to attempt to disrupt the ISP's routing tables.

• Change the passwords on the device and shut down the internal interfaces, causing the administrator to go through password recovery. During the process, no Internet connectivity is available.

11: How can the axiom "Strive for operational simplicity" be applied when securing individual user workstations?

A11: First, it is important to involve the user as little as possible with any security component. As an example, personal firewalls that constantly prompt the user to make a decision, or that notify users of potential attacks, could dramatically increase your help desk calls, lead to users disabling the firewall to stop the annoying messages, or train the user to simply click OK at every popup message. The security you put on each user PC should be consistent and obvious in its application in the overall security system. Knowing the value that antivirus and personal firewalls provides keeps the security predictable.

4 PREV

1: What method of security policy enforcement would be most effective at ensuring that employees have the latest version of virus-scanning software?

A1: Although nontechnical compliance checking would be the easiest, it would likely yield results indicating that almost everyone is without an up-to-date virus signature file. More effective would be the deployment of virus signature file distribution by network login. This way, as users log on to the network, the latest virus definitions are automatically installed. Some newer antivirus software can do something similar by using the web as well.

2: What would be the best way to represent a policy for WLAN access in your organization? Should it be done through a policy, standard, or guideline?

A2: A policy is the best choice because you don't want to tie it too close to the technology, which might change. In this policy, you could describe minimum requirements, such as frame encryption and authentication, methods for detecting rogue access points (APs), and policies for user access when connected by wireless. A standard for WLAN can also be written. In it you could include methods for hardening the APs you have selected to use in your environment. Such a policy for WLAN should reference an acceptable encryption standard to define the cryptographic protections necessary for transmission over the air.

3: If you don't have the resources to track busy mailing lists such as BugTraq, is there an easier way to keep track of the high-profile attacks and vulnerabilities of which you should be aware?

A3: Although lists such as BugTraq and vuln-dev often discuss a vulnerability in the raw, any high-profile issue is also sent out as a advisory from the Computer Emergency Response Team (CERT). CERT can be found at http://www.cert.org, and subscribing to its notification list will ensure that you see any new high-profile issue.

4 What are some ways to keep track of security best practices as they evolve?

A4: Although this book contains many security best practices, over time new technologies and threats will likely subtly or dramatically alter certain best practices. On an ongoing basis, you should stay current with these new trends in some of the following ways:

• Attend ongoing training in new technologies (security related and security impacting).

• Participate in online discussions through mailing lists or discussion forums.

• Read industry trade journals.

• Network with your peers in other organizations and by attending industry conferences.

• Stay current with new technologies and security techniques that might someday become best practices.

5: Outline your organization's primary business needs. Are there any unique aspects of your organization that would require a different approach to security?

6: Put yourself in the shoes of a resourceful attacker. What damage could such a person with lots of free time and patience do to your organization's network? Would it matter where the attacker was located on the network?

7: Based on your answers to questions 5 and 6, what is your organization's greatest weakness in terms of network security? Is there something that should be changed right away?

8: Find and read your company's security policies (assuming they exist). Do they directly aid you in designing your security system? What policies are missing? When is the last time policies were updated? If you were in charge of rewriting the policies, would you make significant changes or only minor tweaks?

9: Is there an area in your own network where the user community is somehow avoiding the security decisions that have been made?

10: Role-play the scenario of your website being defaced. How would your organization respond to the incident? How would you resolve the desire to catch the attacker with your desire to get the website back up and running?

4 PREV

NEXT t

1: Drawing on what you learned in this chapter, in most cases, in which order would the following attacks be launched by an attacker: Probe/scan, buffer overflow, rootkit, web application, data scavenging?

A1: The attacks would likely be launched in this order: data scavenging, probe/scan, web application, buffer overflow, rootkit.

2 Looking at the top five attacks in Table 3-29, which one(s) would you expect to drop out of the top five category if the ratings were adapted specifically to an Internet edge design?

A2: War dialing and driving would not appear in the top five because most Internet edges do not make use of WLAN technology or have insecure modems.

3: Think about how virus, worm, and Trojan horse attacks propagate. Which kinds of attacks have the best chance of getting past traditional antivirus software?

A3: Attacks commonly called zero-day attacks have the best chance of getting past antivirus software. Because antivirus software uses pattern matching and a known signature database (which must be kept current), zero-day attacks, of which little is known, often slip past traditional antivirus systems. Also, since a Trojan horse can be almost anything, traditional antivirus software often does not detect the attack unless it is a known attack for which the software has a signature. The speed with which you can update signatures on your systems should be a critical factor in selecting an antivirus software.

4 If you discover that a rootkit has infected your system, what is the best course of action to take to secure your system?

A4: Since the rootkit could have infected nearly any application, your best bet is to rebuild your system from scratch. After installing the OS, follow the host-hardening guidelines appropriate for your OS and applications. Also, install the latest security fixes from your OS and application suppliers.

5 Even though DDoS is classified as a flooding attack, which other attack types does it use in launching the flood?

A5: Spoof Many DDoS attacks randomize their source IP address to make it harder to trace back the attack to the source.

Remote control software DDoS tools have a lot in common with remote control software. Their method of instructing systems to attack is just like the method remote control software uses to send instructions to victim PCs.

6: Download and run Nmap on your computer (assuming you aren't violating your organization's security policy by doing so). Was it able to detect your OS? Were you running any services you were not expecting to see?

7: In Table 3-29, find at least three places where you disagree with the assigned values. Consider building the table yourself and assigning your own values. Did the top five attacks change?

1: In Table 4-9, file system checking is listed as detecting both web application and buffer overflow attacks (the two elements of the application manipulation subclass). How does it do this?

A1: This is a case in which the categories don't fit quite perfectly. Remember from Chapter 3 that the attacks selected under application manipulation were just examples of a whole range of attacks. Because file system checking detects the modification of applications, it certainly can stop application manipulation in certain forms. Even though the two sample attacks listed can be stopped by file system checking (if the attack relies on first inserting the vulnerability into the application), file system checking is more geared toward detecting modified files and applications in general, which is not a listed attack element under application manipulation.

2: If you usually use OTP through TACACS+ when authenticating administrators to network devices, how would you deal with an automated script that checks configurations or upgraded software images?

A2: Because OTP requires the operator to manually enter a password, it is unsuitable for automated scripting. Instead, a reusable password is required and is sent, hopefully, over a secure medium such as SSH. This should be an appropriately random and long password that is impossible to brute force in a short period of time. Although these passwords should be changed often, if an insecure medium is used for the scripts (such as Telnet), the passwords should be changed very frequently. Thankfully, when using TACACS+ or RADIUS, a password can be changed in a single location that affects the authentication method for hundreds of devices.

3: When might SSL be used instead of IPsec for a VPN deployment?

A3: Using session layer crypto for a VPN has a few disadvantages, as discussed in this chapter. The biggest disadvantage is a lack of robust application support. If, however, your only goal is to provide internal web access and e-mail, SSL could be a fine alternative or addition to IPsec. IPsec could be used on company assets, providing robust application support. SSL could be used on employee home machines or public Internet terminals if limited access is all that is necessary.

4: If you don't need the level of user control that proxy servers offer for all your users, what kinds of users still might benefit from the technology?

A4: You might consider this level of control for several locations in your network, even if most users don't need it. Here are two examples:

• Guest machines are often used in public areas of a company. Contractors, customers, and other guests all might need to access the Internet at some time. This could also occur over a wireless LAN. Providing these users access to a limited set of protocols by proxy servers could be a good solution.

• Lab or test networks within your organization can have nonstandard applications that might not always be patched. This makes them more vulnerable to automated attacks. To prevent these systems from attacking hosts outside your network, forcing deliberate configuration of a proxy server on the part of the lab user will stop most of these attacks. For example, nonstandard systems were a huge source of attacks when Code Red hit. If these nonstandard systems were blocked from accessing the Internet directly and were forced to go through a proxy, much of the propagation of Code Red could have been stopped.

5: Besides running AV software, what else is equally important in stopping the spread of viruses?

A5: User education is very important in stopping the spread of viruses. Teach your users not to open attachments without carefully considering the likelihood of whether the file is a virus, Trojan horse, or worm. The configuration of mail clients matters as well. New attacks target popular e-mail clients and execute attacks without requiring the user to open an attachment.

6: Find at least three places in this chapter where you disagree with the rating values I've assigned to security technology. Consider building the included tables yourself and assigning your own values. Did the overall score of any technology significantly change? Did the top technology in any category change?

4 PREV

NEXT t

1: If you have limited resources, which kinds of devices should be hardened first?

A1: Since applications are the most common conduit for a network intrusion, securing critical hosts and their applications should be the top priority. Following that, the devices you rely on to perform security functions should be hardened.

2 Out of the box, are servers or desktop PCs more vulnerable to attack?

A2: There isn't a hard-and-fast rule here, but most often it is servers that are the most vulnerable. For example, installing a standard Linux system might leave lots of services running, all of which must be disabled or hardened. A desktop OS such as Microsoft Windows 98 isn't usually running any listeners that can be attacked directly. Most vulnerabilities in desktop OSs require the user to do something wrong (open an infected attachment, browse a malicious website, and so on).

3: How should the documentation for device hardening be tracked within an organization?

A3: Remember from Chapter 2, "Security Policy and Operations Life Cycle," that there are three elements to a security policy: policies, standards, and guidelines. Your device-hardening documents should be standards for all required steps and guidelines for any optional hardening tasks. Both of these can be contained within the same document by embedding the guidelines as optional elements within the standards.

4: Can you think of any ways in which proper host hardening might help identify rogue systems?

A4: If you are able to implement host hardening for IT-managed servers and hosts, it should be much easier to identify rogue systems on the network through automated scanning. Say, for example, one of your host-hardening techniques is to turn off the Telnet listener on all systems in favor of SSH. One easy way to find rogue systems is to search for Telnet listeners on the entire network. Any that respond will fall into one of three categories. First, it could be an IT-managed system you missed fixing. Second, it could be an IT-managed system that is a security policy exception. Third, it could be a rogue system.

5: As an exercise to learn more about the hardening process, go online and find information about hardening the OS you are running. Implement the hardening tasks. How difficult was the process? Are there any tools for your OS to make the hardening process easier? How secure was your system before you started the hardening process?

4 PREV

NEXT t

1: What would the inbound ACL look like on your router's serial interface connected to the Internet if you decided to block RFC 1918 addresses, the bogons listed in this chapter, and RFC 2827 filtering, assuming your local IP range is 96.0.20.0/24?

Continue reading here: A1

Was this article helpful?

0 0