Security Policy
PC Encryption Cards
PC encryption cards are available for USB, LPT, COM, RS232, PCMCIA, and (E)ISA. These cards can be attached as peripherals or integrated in almost any computer device. Figure 3-4 shows the setup for data encryption using PC cards. Encryption can be accomplished locally and remotely on the file server. PC cardbased solutions using encryption cards provide secure file storage and file transmission over a LAN segment, as seen in Figure 3-4. This option can also be used to protect data within...
Security Wheel
Cisco understands the importance of network security and its implications for the critical infrastructures on which developed nations depend. After setting appropriate policies, an organization must methodically consider security as part of normal network operations. This could be as simple as configuring routers not to accept unauthorized addresses or services, or as complex as installing firewalls, intrusion detection systems (IDSs), centralized authentication servers, and encrypted virtual...
IP Security
You cannot talk about VPNs without saying something about IP Security (IPSec). IPSec is a framework of open standards. It is not bound to any specific encryption or authentication algorithm keying technology. IPSec acts on the network layer, where it protects and authenticates IP packets between participating peers such as firewalls, routers, or concentrators. IPSec security provides four major functions Confidentiality The sender can encrypt the packets before transmitting them across the...
Countermeasures to WEP Protocol Vulnerabilities
Now that it is clear that many 802.11 networks employ the standard WEP protocol, which is known to have major faults, some 802.11 vendors have come up with proprietary solutions. Before the official IEEE 802.11i was released, Cisco created proprietary solutions to address WEP protocol vulnerabilities. The WEP protocol contains three components Data privacy or encryption algorithm The Cisco Wireless Security Suite contains an enhancement that exceeds the WEP functionality for each of the...
Different Types of Firewalls
Companies such as Cisco and other major vendors have introduced a multitude of firewall products that are capable of monitoring traffic using different techniques. Some of today's firewalls can inspect data packets up to Layer 4 (TCP layer). Others can inspect all layers (including the higher layers) and are referred to as deep packet firewalls. This section defines and explains these firewalls. The three types of inspection methodologies are as follows Packet filtering and stateless filtering...
Table 153 Commands to Monitor and Troubleshoot SNMP
Show snmp enginelD local remote Displays information on all local or remote engines that have been show snmp groups Displays information about each SNMP group on the network show snmp user Displays information about each SNMP username in the SNMP user table If you want to monitor SNMP traffic in real time for the purpose of troubleshooting, several debug commands are also available. For documentation of SNMP debug commands, see the Cisco IOS Debug command reference Configure SNMP Notifications...
Different WLAN Configurations
As you will see in the case study at the end of the chapter, wireless network connectivity is not limited to corporate enterprise buildings. WLANs also offer connectivity outside the traditional office environment. Numerous wireless Internet service providers are appearing in airports (hotspots), trains, hotels, and conference and convention centers. As with most technologies, the early wireless networks were nonstandard, and only vendor-proprietary technologies existed. This caused...
Hardware Firewalls PIX and Net Screen
This section covers two of the most common hardware-based firewalls in the marketplace today, namely the CiscoSecure Private Internet Exchange (PIX) Firewall and the NetScreen firewall. For more details on specific product lines, please visit www.cisco.com security and http www.juniper.net netscreen com.html. The PIX is a dedicated hardware-based networking device that is designed to ensure that only traffic that matches a set of criteria is permitted to access resources from networks defined...
Firewall Basics
A firewall is defined as a gateway or access server (hardware- or software-based) or several gateways or access servers that are designated as buffers between any connected public network and a private network. A firewall is a device that separates a trusted network from an untrusted network. It may be a router, a PC running specialized software, or a combination of devices. A Cisco firewall router primarily uses access lists to ensure the security of the private network. Figure 9-1 displays a...
Example 92 show ip wccp Commands
WCCP Cache-Engine information Web Cache ID Protocol Version State Hash Allotment Packets Redirected Connect Time 4d19h 1C.1C.1C.254 WCCP Cache Engines Visible 1C.1C.1C.3 WCCP Cache Engines NOT Visible -none- Global WCCP information Router information Router Identifier Protocol Version Service Identifier web-cache Number of Cache Engines Number of routers Total Packets Redirected Redirect access-list Total Packets Denied Redirect Total Packets Unassigned Group access-list Total Messages Denied...
Figure 113 ACS Setup for Tacacs Authentication
TACACS+ accounting provides an audit record of what commands were completed. When NAS sends a record of commands, the TACACS+ server sends a response acknowledging the accounting record. RADIUS is a client-server based system that secures a network. RADIUS is a protocol that is implemented in all Cisco devices that send authentication requests to a RADIUS server. RADIUS is defined in RFC 2138 2139. A RADIUS server is a device that has the RADIUS daemon or application installed. RADIUS must be...
Figure 1011 Network Based IDS Sensor Placement
Sensor 1, connected on the inside network, sees only traffic that is permitted by the firewall or internal traffic that does not traverse the firewall. All intrusions reported by Sensor 1 require immediate attention and response from the network administrator. Protecting all internal connections on the firewall with a network sensor is the best practice. Sensor 2, connected on the outside network, sees all traffic targeted for the organization, including the traffic that is blocked by the...
IP Fragment Attacks
The TCP IP protocol suite, or more specifically IP, allows the fragmentation of packets. As discussed in the previous sections, IP fragmentation offset is used to keep track of the different parts of a datagram. The information or content in this field is used at the destination to reassemble the datagrams. All such fragments have the same Identification field value, and the fragmentation offset indicates the position of the current fragment in the context of the original packet. Many access...
Appendix C Nsa Guidelines
Much of the material in this appendix is quoted directly from the relevant websites that are listed at the end of the appendix. According to its website, the National Security Agency (NSA) is the cryptologic organization in the U.S. It coordinates, directs, and performs highly specialized activities to protect American information systems and produce foreign intelligence information. NSA is a high technology organization, and as such it is on the frontier of communications and data processing....
Is It a Policy a Standard or a Guideline
What's in a name People frequently use the names policy, standard, and guideline to refer to documents that fall within the policy infrastructure. Although they all have different definitions, most people use these names synonymously, which is why the sections that follow define each term separately. A policy is typically a document that outlines specific requirements or rules that must be met. In the information and network security realm, policies are usually point-specific, covering a single...
Address Resolution Protocol Spoofing
The Address Resolution Protocol (ARP) provides a mechanism to resolve, or map, a known IP address to a MAC sublayer address. In Figure 2-two hosts are attempting to start a conversation across a multiaccess medium such as Ethernet. Host A wants to initiate the conversation with Host B but requires both the IP address and the MAC address. During the conversation setup, Host A is aware only of Hosts B's IP address, 132.12.25.2. To determine a destination MAC address for a datagram, the ARP cache...
Table 23 TCP Flags
The attacker's ultimate goal is to write special programs or pieces of code that are able to construct these illegal combinations resulting in an efficient DoS attack. The TCP IP protocol suite relies on the use of multiple timers during the lifetime of a session. These timers include the Connection Establishment timer, the FIN_WAIT timer, and the KEEP_ALIVE timer. The following list elaborates on the three-way handshake mechanism presented in Figure 2-7 Connection Establishment timer Starts...
War Driving and War Chalking
War-driving can be best described as a new form of hacking into the network. Crackers are equipped with an antenna either inside their cars or on the roof of their cars. The antenna is connected to a laptop in the car. Once installed in the car, the crackers start driving (or sometimes just park in garages) and log data as they go. Special software logs the latitude and longitude of the car's position as well as the signal strength and network name. It is important to be aware that companies...
Covert Channels
A covert or clandestine channel can be best described as a pipe or communication channel between two entities that can be exploited by a process or application transferring information in a manner that violates the system's security specifications. More specifically for TCP IP, in some instances, covert channels are established, and data can be secretly passed between two end systems. Let's take Internet Control Message Protocol (ICMP) as an example. In the following types of circumstances,...
IP Session Logging
After a sensor detects an attack, an alarm is generated by the sensor and sent to the management station. The information is saved in a memory-mapped file on both the sensor and the management platform. This memory-mapped file is in binary format file. As discussed in the next section, the sensor uses RDEP to communicate with the external world so does the IP logging feature. It is an HTTP communication that is client-server and two-way based, whereby the client (sensor) sends an RDEP request,...
Table 81 Banner Command
Banner exec Specifies a message to be displayed when an EXEC process is created (a line is activated or an incoming banner incoming Specifies a message used when you have an incoming connection to a line from a host on the network. Command banner login banner motd banner slip-ppp Specifies a message to be displayed before the username and password login prompts. Specifies and enables a message-of-the-day (MOTD) banner. Specifies and enables a banner to be displayed when a Serial Line Interface...
Figure 155 Inform Request Sent to SNMP Manager
Figure 15-4 displays a trap that is sent from an agent to a manager. As you can see in the figure, there is no difference between a successful and an unsuccessful notification. The manager doesn't know that a message was sent, and the agent doesn't know that the message was not received by the manager. Figure 15-5 shows a different story. If the inform request is sent to the manager and the manager receives it, the manager sends a response back to the agent. The agent knows that the inform...
SANS Initiatives and Programs
Some of the programs of the SANS Institute are as follows Information security training intensive This immersion training is designed to help you master the practical steps necessary for defending systems and networks against the most dangerous attacks. The GIAC certification program The Global Information Assurance Certification (GIAC) was founded in 1999 by SANS and offers certifications that address multiple specialty areas (security essentials, intrusion detection, incident handling, and...
Figure 716 Computer Management
Ij, Cow** M T49 ffWt (I Mil) - jgj, Syst en Tods K Jjj Event Wewer R jS Syrtom Wem ** h' g Peifor trunes Loqs ortd Werts K J hwedFcMere m Oev e Mw-jije S TJj Locd Users Jntf brixgw _J O* HjK fltrtM fe' DefcCiefrJCmetWer Lo k Cvives EB fteaovaWe 1 r > js Sen vui -CAdvrtvifr.v,y Djft-A woeuit f< v adpWvstems Sw mputer do Kl uBt 6jfc-r> i arccxt ftx guest ccc i to the ccnfxal _ Right-click Groups and select Add new. This brings you to the screen displayed in Figure 7-17. On that screen, you...











