SCND

Types of IDS and IPS Sensors

No detection of unknown signatures Initially a lot of false positives Signatures must be created, updated, and tuned Difficult to profile typical activity in large networks Traffic profile must be constant Distract and confuse attackers Slow down and avert attacks Collect information about attack Honey pot server must not be trusted The table in the figure summarizes the advantages and disadvantages of the various types of IDS and IPS sensors available. The list here describes these IDS and...

VLAN Hopping by Double Tagging

Vlan Hopping Attacks

The first switch strips off the first tag and sends it The first switch strips off the first tag and sends it Note This attack works only if the trunk has the same native VLAN as the attacker. Note This attack works only if the trunk has the same native VLAN as the attacker. The attacker sends double-encapsulated 802.1Q frames. The switch performs only one level of decapsulation. Only unidirectional traffic is passed. The attack works even if the trunk ports are set to off. Note There is no way...

ARP Spoofing Maninthe Middle Attacks

Legitimate ARP reply 10.1.1.1 MAC B.B.B.B 3. Subsequent gratuitous ARP replies overwrite legitimate replies ARP spoofing attacks, or ARP cache poisoning, occurs when ARP allows a gratuitous reply from a host even if an ARP request is not received. After the attack, all traffic from the device under attack flows through the attacker computer and then to the router, switch, or host. An ARP spoofing attack can target hosts, switches, and routers connected to your Layer 2 network by poisoning the...

Wired Equivalent Privacy

This topic describes the WEP protocol, including its purpose, its evolution, and the weaknesses that have limited its effectiveness as a standalone WLAN security protocol. The 802.11 standard defines a type of security WEP using 40-bit keys. WEP is based on a stream cipher called RC4. The RC4 method allows encryption up to 128 bits however, IEEE 802.11 has chosen to use 40-bit keys. WEP requires a wireless client and an access point to compare static 40-bit keys during the authentication...

Application Layer Proxy Firewall

Proxy Firewall Figure

An application layer firewall operates on OSI Layers 3, 4, 5, and 7. Advantages of application layer proxy firewalls - This firewall authenticates individuals, not devices. - Hackers have a harder time with spoofing and implementing DoS attacks. - This firewall can monitor and filter application data. - This firewall can provide detailed logging. Application layer firewalls filter information at Layers 3, 4, 5, and 7 of the OSI reference model. Because application layer firewalls process...

Network Address Translation

NAT translates the source address of a device inside a network to a public source address (SA in the figure). NAT allows a host on your private network that does not have a valid registered IP address to communicate with other hosts through the Internet. There are three types of NAT to consider Static NAT In static NAT, a private IP address is mapped to a public IP address, where the public address is always the same IP address (that is, a static address). A static address allows an internal...

Symmetric vs Asymmetric Encryption Algorithms Cont

Comparing security levels of cryptographic algorithms The table in the figure shows the security level and the amount of computational work that it takes to crack a variety of symmetric encryption algorithms. The Work Factor column lists estimates of the number of hash computations that a computer would need to make to decipher the symmetric key. For example, a work factor of 269 hash computations takes a computer with 10,000 custom application-specific integration circuits, each performing two...

Symmetric vs Asymmetric Encryption Algorithms

Symmetric Asymmetric Encryption

This topic explains the difference between and the functionality of symmetric and asymmetric encryption algorithms. The figure shows the differences between symmetric and asymmetric encryption. In symmetric encryption, the sender and the receiver are using the same secret key to encrypt and decrypt the message. The weakness in symmetric encryption is the secret key. Any user can obtain the secret key to crack the code. In asymmetric encryption, one key is used for encryption and another key is...

ACL name Cisco IOS Releases 112 and later You provide the name of the ACL

- Names contain alphanumeric characters. - Names cannot contain spaces or punctuation and must begin with an alphabetic character. - You can add or delete entries within the ACL. Prior to Cisco IOS Release 11.2, you had to assign a number to each ACL as you created it. Since then, either a number or a name can identify Cisco ACLs and the protocols that they filter. Using numbered ACLs is an effective method on smaller networks with more homogeneously defined traffic. Because each ACL type is...

Rogue Trunk Port

An attacker tricks a network switch into believing that it is a legitimate switch on the network needing trunking. Auto trunking allows the rogue station to become a member of all VLANs. Note There is no way to execute switch spoofing attacks unless the switch is misconfigured. VLAN architecture simplifies network maintenance and improves performance. However, VLAN operation opens the door to abuse. VLAN hopping allows traffic from one VLAN to be seen by another VLAN without first crossing a...

IPS Signature Characteristics Cont

Cisco Ios Encoding Types List

There are four types of signatures The type of signature used depends on these factors The number of signatures available depends on the IPS sensor platform type. Here are the four categories of signatures Exploit Exploit-specific signatures seek to identify network activity or upper-layer protocol transactions that are unique to a specific exploit or attack tool. Consequently, each new exploit may require its own signature. Because a successful exploit can be created by slightly modifying the...

When you need more stringent controls over security than stateful filtering provides

Layered Defense Strategy

Application inspection firewalls are more stringent than stateful firewalls but do not add significant cost to your implementation. Application inspection firewalls also provide more control than stateful filtering firewalls do, still at a minimal increase in cost. 4-34 Securing Cisco Network Devices (SND) v2.0 2006 Cisco Systems, Inc. 2. Cisco IOS firewall forwards the request to the web server and sends a look up request of the requested URL to the 2. Cisco IOS firewall forwards the request...

Dynamic or Stateful Packet Filtering Firewalls

Statefull Packet Filtiring

This topic explains how dynamic or stateful inspection packet filtering provides improved network security and performance. Stateful packet filters, or stateful firewalls, are the most versatile and therefore the most common firewall technologies in use. Stateful filtering provides dynamic packet filtering capabilities to firewalls. Stateful inspection is firewall architecture that works at the network layer. Unlike static packet filtering, which examines a packet based on the information in...

Stateful firewalls do not support user authentication of connections

Use stateful packet filtering firewalls in these applications As a primary means of defense In most situations, a stateful firewall is used as a primary means of defense by filtering unwanted, unnecessary, or undesirable traffic. As an intelligent first line of defense Networks use routing devices supporting a stateful function as a primary line of defense or as an additional security boost on perimeter routers. As a means of strengthening packet filtering Stateful filtering provides more...

Configuring IPsec Transform Sets

Easy VPN Server Wizard - 35 Complete Atransform set specifies the encryption and authentication s data in the VPN tunnel. W Dala integrity and encryption ESP I ntegritj Algorithm ESP_SHA_HMAC Atransform set specifies the encryption and authentication s data in the VPN tunnel. W Dala integrity and encryption ESP I ntegritj Algorithm ESP_SHA_HMAC Click the Add button to add a new transform set and the Edit Encryption Algorithm ESP_AES_256 3 Data and address integrity without encryption (AH) Click...

Port Security Configuration Script

Enable port security on Fast Ethernet port 1 Set the maximum number of secure addresses to 50 Set violation mode to default No static secure MAC addresses needed Switch(config) interface fastethernet0 1 Switch(config-if) switchport mode access Switch(config-if) switchport port-security Switch(config-if) switchport port-security maximum 50 Switch(config-if) switchport port-security mac-address sticky Switch(config-if) switchport port-security aging time 20 Switch(config-if) end MAC addresses...

EAP Deployment Comparison

Single login using Microsoft Windows login Dynamic WEP key and mutual authentication Static password support One-time password support Capability to tie login with non-Microsoft user databases (LDAP, Novell Directory Services, and so on) Layer 3 roaming support Works with WPA * Microsoft PEAP (EAP-Microsoft Challenge Handshake Authentication Protocol Version 2) supports single sign-on. ** WPA testing is done with EAP-TLS, but all EAP types can be used with WPA. * Microsoft PEAP (EAP-Microsoft...

Normal traffic or a benign action does not cause an alarm

The ability of IDS and IPS sensors to accurately detect an attack or a policy violation and generate an alarm is critical to the functionality of the sensors. Attacks can generate these types of alarms False positive A false positive is an alarm triggered by normal traffic or a benign action. Consider this scenario A signature exists that generates alarms if the enable password of any network devices is entered incorrectly. A network administrator attempts to log in to a Cisco router but enters...

Configuring Port Security on a Cisco Catalyst Switch

Enter interface configuration mode for the port that you want to secure. 3. Enable basic port security on the interface. 4. Set the maximum number of MAC addresses allowed on this interface. 5. Set the interface security violation mode. The default is shutdown. For mode, select one of these keywords 6. Return to privileged EXEC mode. The figure lists the tasks required to configure port security on a Cisco Catalyst switch. The Enabling Port Security with...

Throughput on Cisco Routers That Support Cisco Ios Ips

Cisco 1841 Integrated Services Router Cisco 2801 Integrated Services Router Cisco 2811 Integrated Services Router Cisco 2821 Integrated Services Router Cisco 2851 Integrated Services Router Cisco 3825 Integrated Services Router Cisco 3845 Integrated Services Router The table in the figure lists the maximum throughput obtained for various router platforms with Cisco IOS IPS enabled. Maximum throughput numbers change often. The numbers presented in the table provide a good comparison of the...

Authentication dictionary attacks

These attacks are described in Security of the WEP Algorithm Passive attacks to decrypt traffic based on statistical analysis Active attacks to inject new traffic from unauthorized mobile stations, based on known plain text Active attacks to decrypt traffic, based on tricking the access point Dictionary-building attacks, which, after analysis of traffic for about a day, allow real-time automated decryption of all traffic Passive or Weak Initialization Vector Attack An initialization vector (IV)...

Use ACLs to disable and limit services ports and protocols

To review, always apply these general rules when deciding how to handle router services, ports, and protocols Disable unused services, ports, or protocols In the case where no one, including the router itself, needs to use an enabled service, port, or protocol, disable that service, port, or protocol. Limit access to services, ports, or protocols In the case where a limited number of users or systems require access to an enabled router service, port, or protocol, limit access to that service,...

IKE Communication Negotiation Phases

IKE uses these phases to secure a communication channel between two peers IKE Phase 1 Transform sets, hash methods, and other parameters are determined. IKE Phase 1.5 (optional) XAUTH protocol can be used to provide user authentication of IPsec tunnels within the IKE protocol to provide additional authentication of the VPN clients. IKE Phase 2 SAs are negotiated by ISAKMP, where quick mode is used. In this phase, the IPsec SAs are unidirectional. To establish a secure communication channel...

Three prebuilt SDFs come with Cisco integrated services routers

An SDF contains all or a subset of the signatures supported by a sensor. The sensor reads the SDF, parses the file, and populates the internal tables of the sensor with the information necessary to detect each signature. The SDF can be saved on the router flash memory (recommended), or users can specify the location of the SDF on the router using a security management tool such as Cisco SDM. The option of where to save the SDF gives customers the flexibility to choose from a broad set of...

Cisco IPS 4200 Series Sensors

Cisco IPS solutions run on a variety of platforms. Here is a brief description of the available Cisco ASA 5500 Series Adaptive Security Appliances The Cisco ASA 500 Series Adaptive Security Appliances offer a purpose-built, high-performance security solution. These appliances integrate the technologies from Cisco PIX 500 Series Security Appliances, Cisco IPS 4200 Series Sensors, and Cisco VPN 3000 Series Concentrators. The Cisco ASA 5500 Series Adaptive Security Appliances are a key component...

Benefits of DTM with Cisco Ios Ips Software

Attempts to use the resources of the router for IPS only occur when needed. This solution provides (optionally) automated tuning of IPS signatures. Customers that turn on and use the IPS feature on their branch routers will not have to deal with too many (sometimes false) alarms. This solution increases the value of a company investment in network-based intrusion detection products. This solution helps the operator to quickly locate the source of the attacks. The Cisco IOS IPS system evaluates...

Cisco ASA 5500 Series Adaptive Security Appliance Platforms

Simultaneo us Web VPN (clientless) users Site-to-site tunnels and remote access server (RAS) VPN peers The table shows how the performance of Cisco ASA 5500 Series Adaptive Security Appliances depends on the platform feature license used. Here are the available licenses Cisco ASA 5510 Adaptive Security Appliance Base license and Security Plus license Cisco ASA 5520 Adaptive Security Appliance Base license with VPN Plus add-on license Cisco ASA 5540 Adaptive Security Appliance Base license with...

DHCP Snooping

DHCP snooping allows the configuration of ports as trusted or untrusted. - Trusted ports can send DHCP requests and acknowledgements. - Untrusted ports can forward only DHCP requests. DHCP snooping enables the switch to build a DHCP binding table that maps a client MAC address, IP address, VLAN, and port ID. DHCP snooping is a Cisco Catalyst feature that determines which switch ports can respond to DHCP requests. Ports are identified as trusted and untrusted. Trusted ports can source all DHCP...

Introducing the Cisco Security Appliance Product Family

This topic describes the main components of the Cisco security appliance product family. The Cisco security appliances family includes these products Cisco IOS Firewall The Cisco IOS Firewall provides robust, integrated firewall and intrusion detection functionality for every perimeter of the network. The Cisco IOS Firewall is available for a wide range of Cisco IOS software-based routers and offers sophisticated security and policy enforcement for connections within an organization (intranet)...

Mitigates STP manipulation with guard root command

To mitigate STP root bridge manipulation, use the spanning-tree guard root interface configuration command. The root guard feature provides a way to enforce the root bridge placement in the network. Root guard must be enabled on all ports where the root bridge should not appear. If the bridge receives superior STP BPDUs on a root guard-enabled port, this port is moved to a root-inconsistent STP state (effectively equal to listening state), and no traffic is forwarded across this port. To...

Recommended approaches to implementing multiple IDS management consoles

- Hierarchical monitoring structure Event monitoring and management can be divided into the need for real-time event monitoring and management and the need to perform analysis based on archived information (reporting). These functions can be handled by a single server, or the functions can be placed on separate servers to scale deployment. The number of sensors that should be forwarding alarms to a single IDS management console is a function of the aggregate number of alarms per second...

Shared Key Authentication

Steps 1 through 3 are the same as for open authentication. < < < > 4. Client sends an authentication request to access point (A). rf packet 4. Client sends an authentication request to access point (A). rf packet 5. Access point (A) send authentication response containing the unencrypted challenge text. rf 6. Client encrypts the challenge text using one of its WEP keys and sends it to access point (A). rf packet 7. Access point (A) compares the encrypted challenge text with its copy of...

Circuit Level Firewalls

This topic describes the operation of a circuit level firewall. This topic describes the operation of a circuit level firewall. Requires reprogramming of transport handling A circuit level firewall, also called a circuit level gateway, is second-generation firewall technology that validates that a packet is either a connection request or a data packet belonging to a connection or virtual circuit between two peer transport layers. In addition to allowing or disallowing packets, the circuit level...

MAC B is unknown so the switch will flood the frame

The CAM table in a switch contains the MAC addresses available on a given physical port of a switch and the associated VLAN parameters for each. When a Layer 2 switch receives a frame, the switch looks in the CAM table for the destination MAC address. If an entry exists for the MAC address in the CAM table, the switch forwards the frame to the MAC address port designated in the CAM table. If the MAC address does not exist in the CAM table, the switch acts like a hub...

Switched Port Analyzer

- SPAN port used to mirror traffic to another port where a probe or IDS sensor is connected - Stops hackers before they can do damage Otherwise, there is no easy way to shut down hackers after they have entered the network. An IDS has the ability to detect misuse, abuse, and unauthorized access to networked resources. SPAN can be used to mirror traffic to another port where a probe or an IDS sensor is connected. When an IDS sensor detects an intruder, the sensor can send out a TCP reset that...

IDS and IPS technologies look for these patterns of misuse

IDS and IPS technologies share these characteristics IDS and IPS technologies are deployed as sensors. An IDS or an IPS sensor can be any of these devices A router configured with Cisco IPS An appliance specifically designed to provide dedicated IDS or IPS services A network module installed in an adaptive security appliance, switch, or router IDS and IPS technologies typically monitor for malicious activities in these two spots Malicious activity is monitored at the network detecting attacks...

Cisco PIX 500 Series Security Appliances Hardware acceleration

Here are more details on the Cisco VPN product family Cisco VPN-enabled routers and switches Cisco VPN security routers and switches represent the best options for customers of all sizes looking to take advantage of their existing network infrastructures to deploy VPNs and security while integrating all services in a single device with the widest selection of WAN and LAN interfaces. Cisco VPN 3000 Series Concentrators Cisco VPN 3000 Series Concentrators are the most feature-rich remote-access...

VPN Product Placement

Leverage existing infrastructure Broad choice of interfaces Feature-rich Cisco IOS software (routing, QoS, and so on) Cisco PIX 500 Series Security Appliances Purpose-built application inspection firewall Clear demarcation between security and network operation Cisco ASA 5500 Series Security Appliances All-in-one security appliance IPsec and SSL VPN capabilities Feature-rich remote-access platform IPsec and SSL VPN capabilities No individual feature licensing This figure shows the product...

Cut Through Proxy Firewall Communication Process

Step 1 Authentication Inbound Step 2 Add Filtering Rule Step 1 Authentication Inbound Step 2 Add Filtering Rule Cisco's firewall technology performs dramatically better than competing firewalls. A proprietary process called cut-through proxy is the fastest way for a firewall to authenticate a user. Using the cut-through proxy feature of the Cisco PIX Security Appliance or Cisco IOS Firewall helps alleviate performance issues inherent in proxy server design. Firewalls using a cut-through proxy...

HIPS is behaviorbased

Recall that HIPS operates by detecting attacks occurring on a host on which it is installed. HIPS works by intercepting operating system and application calls, securing the operating system and application configurations, validating incoming service requests, and analyzing local log files for after-the-fact suspicious activity. HIPS uses rules based on a combination of known attack signatures and a detailed knowledge of the operating system and specific applications running on the host. These...

Cisco NIPS Deployment

The figure shows a typical network IPS deployment. The key difference between this Network IPS deployment example and the previous HIPS deployment example is that there are no CSA agents on the various platforms. In this topology, the network IPS sensors are deployed at network entry points that protect critical network segments. The network segments have internal and external corporate resources. The sensors report to a central management and monitoring server located inside the corporate...

Using Cisco Sdm Gui to Edit Existing IPS Rules

Eksisting Sdm

The Edit IPS tab provides access to the main Cisco IOS IPS management and tuning functions buttons, including IPS Policies, Global Settings, SDEE Messages, and Signatures. All interfaces on the router or security device are prominently displayed in a list that includes an IPS status report. 5-52 Securing Cisco Network Devices (SND) v2.0 2006 Cisco Systems, Inc. This topic explains how to configure Cisco IPS rules using the Cisco SDM GUI. Using the Cisco SDM GUI to create a new rule on a Cisco...

Cisco VPN Client Software

Simple to deploy and operate, the Cisco VPN Client allows organizations to establish end-to-end, encrypted VPN tunnels for secure connectivity for mobile employees or teleworkers. This thin design, IPsec implementation is compatible with all Cisco VPN products. The Cisco VPN Client supports Microsoft Windows 98, Me, NT 4.0, 2000, and XP Linux (Intel) Solaris (UltraSPARC 32- and 64-bit) and Mac OS X 10.2, 10.3, and 10.4. The Cisco VPN Client is compatible with these Cisco products Cisco VPN 3000...

Cisco ASA 5500 Series Adaptive Security Appliances

VPN Technology Cisco VPN 3000 Series Concentrator Network Intelligence Cisco Network Services VPN Technology Cisco VPN 3000 Series Concentrator Network Intelligence Cisco Network Services Adaptive Threat Defense and Secure Connectivity Secure Connectivity IPsec and SSL VPN Adaptive Threat Defense and Secure Connectivity Application Inspection, Use Enforcement, Web Control, Application Security Traffic-Admission Control, Proactive Response, Network Containment and Control Secure Connectivity...

Examining Signature Micro Engine and SDF Build Failures

Signature micro-engine build failure Unsupported signature or signature parameter There are times when building a signature micro-engine it will fail. The signature micro-engine can fail for reasons such as attempting to load a corrupted SDF file or the signature micro-engine exceeding memory limitations of the router. The Signature Micro-Engine Failure Types table lists types of SDF and signature micro-engine failures, the default sensor responses, and a description of suggested responses and...

Configuring NAT with Cisco SDM

Choose the NAT wizard on the task bar. You can use the Cisco Router and Security Device Manager (SDM) NAT wizard to guide you in creating a NAT rule. Choose the Basic NAT wizard if you want to connect your network to the Internet (or the outside) and your network has hosts but no servers. If your network is made up only of PCs that require access to the Internet, choose Basic NAT and click the Launch the Selected Task button. Choose the Advanced NAT wizard if you want to connect your network to...