|
|
TCP/IP Message Routing
TCP/IP is routable protocol that enables computers on different
networks to communicate as if on same network
IP part of protocol provides routing capability
Sent message divided into packets
TCP/IP determines travel path and transmits packets
When packet reaches destination, confirmation sent to source
Confirmation is why TCP/IP is considered to be so reliable
U.S. Department of
Homeland Security
United States
Secret Service
TCP/IP Suite Protocols
Simple Mail Transfer Protocol (SMTP) - Used to send email
File Transfer Protocol (FTP) - Used to transfer files
Simple Network Management Protocol (SNMP) - Used to
monitor network activities
Telnet - Allows logon to remote computer to run program
Domain Name Service (DNS) - Matches domain names of
host computers with corresponding IP addresses
U.S. Department of
Homeland Security
United States
Secret Service
TCP/IP Model
Application layer
Transport layer
Network layer
Link layer
U.S. Department of
Homeland Security
United States
Secret Service
Encapsulation
A TCP/IP process for handling data packets
As data travel down TCP/IP model when a device transmits
packets, each layer adds leading information, or headers
U.S. Department of
Homeland Security
United States
Secret Service
De-capsulation
The process of removing headers as data travels up TCP/IP
model on receiving network device
U.S. Department of
Homeland Security
United States
Secret Service
TCP/IP vs. OSI Model
OSI considered conceptual model of how communications
should flow from one network to another
OSI Provides standard for other protocols to use
TCP/IP represents actual implementation of how internetwork
communications occur
TCP/IP Application layer absorbs functions of OSI Model’s
Presentation and Session layers
TCP/IP combines functions of Data Link and Physical layers of
OSI Model
U.S. Department of
Homeland Security
United States
Secret Service
TCP/IP vs. OSI Model Illustration
TCP/IP Protocol
OSI
Stack
Application Layer
Presentation Layer
Application Layer
Session Layer
Transport Layer
Transport Layer
Network Layer
Network Layer
Data Link Layer
Link Layer
Physical Layer
U.S. Department of
Homeland Security
United States
Secret Service
Internetwork Packet Exchange (IPX)
Novell Netware protocol
Easy to configure for small networks and compatible with other
network operating systems
IPX is connectionless network protocol operates on Network
Layer
IPX data packets sent without prior knowledge of current state
of recipient system
Packet delivery not guaranteed
U.S. Department of
Homeland Security
United States
Secret Service
Sequenced Packet Exchange (SPX)
Novell Netware protocol
Easy to configure for small networks and compatible with other
network operating systems
Connection-oriented, ensures proper delivery of packets by
establishing virtual connection between sender and receiver
before packets sent
Guarantees delivery of packets and provides error correction
and packet sequencing
U.S. Department of
Homeland Security
United States
Secret Service
NetBIOS
Standard networking protocol for Windows networks
Provides programming interface for applications on Session
Layer
Combined with NetBIOS Extended User Interface (NetBEUI),
which serves as default transport protocol for Windows
networks
U.S. Department of
Homeland Security
United States
Secret Service
NetBEUI
Each computer on NetBEUI network has unique NetBIOS
name (no more than 15 characters)
Non-routable, cannot pass data through router to leave LAN
Broadcasts many packets which makes it difficult to scale
Easy to configure with low overhead
Fast, self-tuning
Best suited for small LANs
U.S. Department of
Homeland Security
United States
Secret Service
Point-to-Point Protocol (PPP)
Designed for simple links between two peers
Offers full-duplex operation to both peers
Packets delivered in order (circuit-switched)
Used to link PC to Internet
Creates session between PC and ISP
Works well with many protocols including IPX
U.S. Department of
Homeland Security
United States
Secret Service
Point-to-Point Tunneling Protocol
(PPTP)
Enables other protocols to transmit over IP network
For example, used to encapsulate NetWare IPX packets and
send them over Internet
Also used to carry TCP/IP, IPX/SPX, and NetBEUI traffic
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 4 - Wireless Networks
What is a Wireless Network?
Types of Wireless Networks
Hardware Components
Security Concerns
Vulnerabilities
U.S. Department of
Homeland Security
United States
Secret Service
Wireless Network
Does not require cables to connect computers and peripherals
Network communications transmitted across airwaves using
infrared and various forms of radio technology
Uses radio frequencies between 2 and 5 gigahertz
Growing in popularity
Effective range between 300 and 1,500 feet
U.S. Department of
Homeland Security
United States
Secret Service
802.11
Established global rules for wireless networking at speed of
2Mb/sec
802.11b, extension of original standard, increased throughput
from to 11Mb/sec
802.11b operates at frequency of 2.4 gigahertz, backward
compatible with original standard
U.S. Department of
Homeland Security
United States
Secret Service
802.11
Extensions 802.11a and 802.11g, both offer throughput as
high as 54Mb/sec
802.11g, backward compatible with 802.11b, both operate at
2.4 gigahertz
802.11n claims to be twice as fast as 802.11g,
802.11i addresses security concerns over current 802.11
standards
802.11n incorporates Multiple Input Multiple Output (MIMO)
antennas
U.S. Department of
Homeland Security
United States
Secret Service
Hot Spots
802.11 networking feature often packaged under label Wi-Fi
and Centrino, an Intel trademark
Intel partnered with companies like Hilton Hotels & Resorts,
Borders Group, and McDonalds to develop concept called hot
spots
Enables user of wireless-enabled notebooks and PDAs to
connect to Internet while using other services business offers
Strategy is two-fold: wireless hardware sales increase, and
hosting businesses attract more customers
U.S. Department of
Homeland Security
United States
Secret Service
Types of Wireless Networks
In general, two types of wireless networks: ad-hoc and
infrastructure
Type of network simply indicates how wireless devices are
configured to communicate
Configuration can be easily changed from one type to other
making wireless networking flexible and easy to use
U.S. Department of
Homeland Security
United States
Secret Service
Ad-Hoc Wireless Network
When group of wireless computers configured to communicate
with each other in peer-to-peer configuration, result is
independent wireless network
Combination of wireless computers and modern operating
systems allow enough flexibility for wireless computers to join
network with ease
Provides easy setup, ideal for groups who wish to collaborate
on project
Ad-hoc nature of network provides wireless network its name
U.S. Department of
Homeland Security
United States
Secret Service
Ad-Hoc Wireless Network
U.S. Department of
Homeland Security
United States
Secret Service
Infrastructure Wireless Network
Computers configured in infrastructure wireless network look
for other wireless devices attached to wired network
Devices, called access points, usually attached directly to hub
or switch in wired network
Primary function is to provide wireless computers with access
to wired network
Once connected to wired network, wireless devices can use
resources available to wired network including Internet access
U.S. Department of
Homeland Security
United States
Secret Service
Infrastructure Wireless Network
U.S. Department of
Homeland Security
United States
Secret Service
Hardware Components
A wireless local area network (WLAN) is rarely wireless
Shared resources, such as Internet gateway, printers, file
servers, etc., are typically all interconnected with cables
U.S. Department of
Homeland Security
United States
Secret Service
Wireless NIC
Network interface card (NIC) is essential part of any wireless
network
Wireless NIC functions as interface between PC and media
used to connect PC to network
NICs typically have visible antennae as shown in examples on
following slide
U.S. Department of
Homeland Security
United States
Secret Service
Wireless NIC Illustration
U.S. Department of
Homeland Security
United States
Secret Service
Wireless Access Points (WAP)
Provides connection for Wireless NIC to wired network
Generally small hardware device connected by cable to hub or
switch on wired network
Can also be wireless cable/DSL router that provides routing
protection and functionality to broadband Internet service
U.S. Department of
Homeland Security
United States
Secret Service
Wireless Access Points (WAP)
Usually equipped with one or two visible antenna
Antennae receive signals from wireless NIC and converts to
format compatible with cable that connects WAP to network
Single WAP can support connections from multiple wireless
devices
U.S. Department of
Homeland Security
United States
Secret Service
WAP Illustrations
U.S. Department of
Homeland Security
United States
Secret Service
Security Concerns
Wireless network communications extremely vulnerable to
eavesdropping and attack
In broadcast network, data transmissions are sectioned into
packets broadcast to all devices attached to network
Packets broadcast over wireless connections can easily be
intercepted and examined
Data being transmitted can be viewed and reassembled by
intercepting party
U.S. Department of
Homeland Security
United States
Secret Service
WEP
Networking devices manufactured under 802.11 standards
employ method of encryption called wired equivalent privacy or
WEP
Provides encryption of communications based on 64 or 128 bit
key
Wireless computer and WAP must use same key to
communicate
Wireless devices have ability to turn WEP on or off
Default state of WEP for most devices is off
U.S. Department of
Homeland Security
United States
Secret Service
WEP
WEP intended to secure wireless networks
Flaws well documented
Slightly better than no security at all
With right combination of hardware and software WEP key can
be cracked within minutes
U.S. Department of
Homeland Security
United States
Secret Service
WPA
Wi-Fi Alliance, in cooperation with several members of IEEE
802.11i task group, developed Wi-Fi Protected Access (WPA)
to address wireless security
WPA uses dynamic keys so same encryption key never used
twice
WPA encryption key derived from up to 500 trillion possibilities
Key virtually uncrackable if strong password used
U.S. Department of
Homeland Security
United States
Secret Service
LEAP
Lightweight Extensible Authentication Protocol (LEAP)
provides authentication services on wireless network
When wireless client attempts to access network, wireless
access point (WAP) blocks all ports except for authentication
ports to allow input of authentication credentials
Once received, WAP forwards credentials to special
authentication server for validation
If credentials valid, unique key generated for session and
access to network through WAP is granted
U.S. Department of
Homeland Security
United States
Secret Service
LEAP
Key generated is per-user and per-session, complicating and
hopefully frustrating hacking attempts
Time-out settings of key can be adjusted to force devices to re-
authenticate frequently
Re-authentication results in new session, new key
Keys change frequently and sessions become short
Packet sniffing becomes useless as means of deriving session
keys
U.S. Department of
Homeland Security
United States
Secret Service
Service Set Identifier (SSID)
Unique, user configurable name used to communicate with
WAP
Most wireless access points have SSID indicative of
manufacturer or model of device
Example, Linksys brand of WAP uses name LINKSYS as
default SSID
SSID can be any combination of alpha and numeric characters
with maximum length of 32 characters
U.S. Department of
Homeland Security
United States
Secret Service
Service Set Identifier (SSID)
When WAP powered on, begins broadcasting SSID to any
wireless device within range
Feature intended to simplify connectivity by mobile devices
Can be disabled in some WAPs eliminating necessity for
notebook PC or PDA users to know SSID before connecting
U.S. Department of
Homeland Security
United States
Secret Service
MAC Filtering
Enabling WPA and MAC filtering are methods that can harden
wireless network against attack
If MAC filtering enabled, (disabled by default), list of MAC
addresses is created for devices allowed to join network
As connection attempts made, MAC address of each device
validated against list
Device denied access if device’s MAC not on filter list
Can be circumvented through MAC spoofing
U.S. Department of
Homeland Security
United States
Secret Service
Wireless Detection Systems
Wireless detectors developed as result of security concerns
Among solutions are small inexpensive detectors like
examples shown on next slide
Both devices cost less than $25 and only detect presence of
802.11 wireless signals and signal strength
Devices not well suited for determining WAP SSID, MAC
address of WAP, or other information that can be detected
using more sophisticated and expensive solutions
U.S. Department of
Homeland Security
United States
Secret Service
Wireless Detection Devices
U.S. Department of
Homeland Security
United States
Secret Service
Wireless Detection Systems
Unauthorized or rogue wireless devices can appear on
network for short durations, making them hard to detect
Solution providers have developed detection systems
comprised of specialized software and customized sensors to
address issue
Sensors placed strategically throughout network, constantly
monitoring for rogue devices
When device detected, location triangulated using strategically
placed sensors
U.S. Department of
Homeland Security
United States
Secret Service
Wireless Detection Systems
Once identified and approximate position determined,
notebook computer or PDA equipped with directional antenna
used to pinpoint device
Can be accomplished by sweeping antenna in a 360-degree
rotation while monitoring signal strength
Number of freeware applications available to perform function
Net Stumbler for MS Windows and Pocket PC, Kismet for
Linux
U.S. Department of
Homeland Security
United States
Secret Service
War Driving Roots
Hacker groups collaborated, developed software configured to
search for BBS or modem-enabled mainframe computer by
sequentially dialing telephone numbers within given area code
and exchange
As number dialed, hacker’s computer waited for carrier signal
of modem on other end
No carrier detected, call ended and next number in sequence
dialed
If carrier detected, calling computer saved telephone number
to log file, disconnect, moved to next number in sequence
U.S. Department of
Homeland Security
United States
Secret Service
War Driving
Process called war dialing and became foundation for many
hacking applications
Concept was applied to wireless networks, but without
modems
Just as modems sat waiting for someone to connect, in
wireless network, WAP waits
Airwaves can be scanned for 802.11 signals, and SSIDs
U.S. Department of
Homeland Security
United States
Secret Service
War Driving
Tools can be used with notebook computer to scan for and
identify wireless networks
Data these programs collect include:
SSID (if broadcasted)
Which of 14 wireless channels or frequencies used (only 11
used in U.S.)
Whether or not WEP or WPA is enabled
MAC address of WAP
U.S. Department of
Homeland Security
United States
Secret Service
War Driving
Hackers have developed software similar to war dialer that
attempts to connect to computers or WAPs
Name War Driving derived from running programs on laptop
with wireless NIC and external antenna while driving along
major traffic routes in effort to locate wireless networks
Common for War Drivers to record GPS coordinates of
wireless networks for use with mapping software and for
publication to various sites on Internet
U.S. Department of
Homeland Security
United States
Secret Service
Overlapping Signals
Wireless network signals typically radiate in elliptical pattern
Can vary depending upon physical structure in which WAP
deployed
Walls, floors, ceilings, and other obstacles affect radio waves
U.S. Department of
Homeland Security
United States
Secret Service
Overlapping Signals
U.S. Department of
Homeland Security
United States
Secret Service
Overlapping Signals
Four buildings with wireless networks in illustration on previous
slide
Building C far enough away from other buildings, overlapping
signals not an issue
Building D has two wireless access points deployed with
minimal signal overlap
If two signals in building D are owned by different businesses,
could pose a significant problem
Buildings A and B wireless access points generate overlapping
signals
U.S. Department of
Homeland Security
United States
Secret Service
Overlapping Corrective Action
Relocation of the WAP
Reducing power output of the WAP
U.S. Department of
Homeland Security
United States
Secret Service
Accidental Access
Wireless end user operating in overlapping signal area could
possibly connect to wrong network accidentally
If wireless networks configured to use WEP, possibility of
accidental access eliminated
U.S. Department of
Homeland Security
United States
Secret Service
Known Attacks
Wireless network technology constantly improving
There are known vulnerabilities that lead to attack
Wireless network attacks usually result from improperly
managed or improperly secured wireless technology
U.S. Department of
Homeland Security
United States
Secret Service
Session Hijacking
Attacker monitors active sessions, connections between WAP
and remote station, identifying information used to facilitate
attack
Once enough information collected, attacker sends spoofed
message to target workstation to disconnect
Workstation responds by ending session allowing attacker to
masquerade as disconnected workstation
U.S. Department of
Homeland Security
United States
Secret Service
Man-in-the-Middle
Exploits one-way authentication of 802.11 design, allows
attacker to configure computer to act as wireless access point
Attacker waits for users to connect to wireless network
Remote computers pass WEP key to attacker’s computer
Attacker’s computer connects to real WAP and passes remote
computers packets transparently between user and WAP
Result is captured WEP key that will allow attacker access to
wireless network
U.S. Department of
Homeland Security
United States
Secret Service
WEP Key Cracking
When WEP enabled, encrypted key used to connect to, and
transfer data across wireless network
Only computers with WEP key allowed to communicate
Software tools, such as Airsnort and WEPcrack, simplify job of
cracking WEP key
By monitoring packets transmitted across airwaves, attacker
can save packets to log file
After several thousand packets have been collected, cracking
tools can analyze collected packets to determine WEP key
U.S. Department of
Homeland Security
United States
Secret Service
WPA-PSK Cracking
WPA-PSK uses pre-shared key for its encryption algorithm
Method much more secure than using WEP, but still
susceptible to cracking
Attack method used to crack WPA-PSK is dictionary attack
Captured data between transmitting access point and user can
be run through dictionary to find correct key to unlock data
Countered by use of long key not found in dictionary, such as
complete phrase with additional special characters, etc
U.S. Department of
Homeland Security
United States
Secret Service
U.S. Department of
Homeland Security
United States
Secret Service
Module 7 - IP Addresses and Subnets
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
IP Addresses
Ports
Subnets
Network Security
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - IP Addresses
IP Address Basics
IP Address Classes
More about IP Addresses
U.S. Department of
Homeland Security
United States
Secret Service
Network Addressing Overview
In TCP/IP network, IP (Internet Protocol) addressing essential
to physical routing of network communications
Every device on LAN must have unique IP address
Addresses essential for internetworking over WANs
U.S. Department of
Homeland Security
United States
Secret Service
Network Addressing Overview
Media Access Control (MAC) address is unique hardware
identification number specific for each network device
To send data packet to host on LAN, sending device must first
know receiver’s MAC address
MAC addresses exist at Data Link Layer 2 of OSI model
U.S. Department of
Homeland Security
United States
Secret Service
Network Addressing Overview
IP addresses identify every device attached to TCP/IP
network, including PCs, servers, switches, printers, and any
other networked device
Each device has unique IP address so it can be identified for
internetwork data packet routing
IP addresses exist at Network Layer 3 of OSI model
U.S. Department of
Homeland Security
United States
Secret Service
Network Addressing Overview
Workstations can have permanent (static) IP address, or
dynamically assigned address each time network connection
established
For clients on isolated LAN, administrator can assign unique
static IP addresses
To communicate with Internet, hosts must have unique
registered Internet routable IP address
U.S. Department of
Homeland Security
United States
Secret Service
What’s in an IP Address
IP address, 32-bit numeric address written as four sets of
numbers, called octets, separated by periods
For example, 131.160.10.240 is example of class B IP address
Each octet can range from 0 to maximum of 255
Valid IP addresses cannot consist of all zeros or all ones
U.S. Department of
Homeland Security
United States
Secret Service
What’s in an IP Address
For each networked device, IP address consists of network
address (netid) and host address (hostid)
Each octet of IP address contains eight bits or one byte
Address has total of four bytes
U.S. Department of
Homeland Security
United States
Secret Service
Example Class B IP Address
131.107.10.7
U.S. Department of
Homeland Security
United States
Secret Service
Binary IP Addressing
IP addresses read as set of four decimals
Computer only reads ones and zeros
IP addresses are binary, each of four decimals translated into
eight binary numbers consisting of ones and zeros
Binary numbering system used in IP addresses based on
number 2, called Base2
Each octet in address limited to eight bits, corresponding
binary numbers range from 20 to 27 (1 to 255)
U.S. Department of
Homeland Security
United States
Secret Service
Converting Decimal 131 to Binary
Binary Conversion of Decimal 131
Base2
27
26
25
24
23
22
21
20
Decimal
128
64
32
16
8
4
2
1
Binary Number is
1
0
0
0
0
0
1
1
10000011
U.S. Department of
Homeland Security
United States
Secret Service
Classes of IP Addresses
IP addresses divided into several class types
Class A, B, and C used for government and commercial
addresses
Class D and E reserved for multicasting, transmission of data
to many recipients simultaneously
Class D and E not commonly used
Each class allows for specific maximum number of subnets
and end nodes
U.S. Department of
Homeland Security
United States
Secret Service
Class A
Classes of IP Addresses Defined
Class
First
Maximum
Maximum
Other
Octet
Networks
Hosts
Characteristics
A
1 -
126
16,777,214
Most often
126
allocated to
government and
large institutions;
Address Range:
1.X.X.X to
126.X.X.X
U.S. Department of
Homeland Security
United States
Secret Service
Class B
Classes of IP Addresses Defined
Class
First
Maximum
Maximum
Other
Octet
Networks
Hosts
Characteristics
B
128 -
16,384
65,534
Most often
191
allocated for
commercial use
and ISPs;
Address Range:
128.X.X.X to
191.X.X.X
U.S. Department of
Homeland Security
United States
Secret Service
Class C
Classes of IP Addresses Defined
Class
First
Maximum
Maximum
Other
Octet
Networks
Hosts
Characteristics
C
192 -
2,097,152
254
Most often
223
allocated for
commercial use
and ISPs;
Address Range:
192.X.X.X to
223.X.X.X
U.S. Department of
Homeland Security
United States
Secret Service
Class D
Classes of IP Addresses Defined
Class
First
Maximum
Maximum
Other
Octet
Networks
Hosts
Characteristics
D
224 -
N/A
N/A
Reserved class
239
used for
multicasting;
does not contain
network or host
IDs
U.S. Department of
Homeland Security
United States
Secret Service
Class E
Classes of IP Addresses Defined
Class
First
Maximum
Maximum
Other
Octet
Networks
Hosts
Characteristics
E
240 -
N/A
N/A
Reserved class
247
used for
experimentation;
does not contain
network or host
IDs
U.S. Department of
Homeland Security
United States
Secret Service
Reserved IP Addresses
Description
IP Address Range
Reserved for non-
• 10.0.0.0 to 10.255.255.255
routable networks
• 172.16.0.0 to 172.31.255.255
• 192.168.0.0 to 192.168.255.255
Reserved for loopback
127.0.0.1
NIC testing
U.S. Department of
Homeland Security
United States
Secret Service
Reserved IP Addresses
Description
IP Address Range
Reserved for routing
128.5.0.0
tables; refers to entire
network
IDs an entire network
X.0.0.0 (Class A)
X.X.0.0 (Class B)
X.X.X.0 (Class C)
Broadcast
X.255.255.255 (Class A)
X.X.255.255 (Class B)
X.X.X.255 (Class C)
U.S. Department of
Homeland Security
United States
Secret Service
New Methods for IP Addressing
Class system provides a finite number of IP addresses
Number of unassigned Internet addresses running out
New scheme called Classless Inter-Domain Routing (CIDR)
introduced as replacement for system based on classes A, B,
and C
U.S. Department of
Homeland Security
United States
Secret Service
Classless Inter-Domain Routing
With CIDR, IP addresses assigned in blocks
Single IP address can be used to identify many unique IP
addresses
CIDR IP address looks like normal IP address except it ends
with a slash followed by a number
End number is called IP prefix length, represents how many
bits used for network partition of address
An example of a CIDR address is 162.200.0.0/12
U.S. Department of
Homeland Security
United States
Secret Service
Classless Inter-Domain Routing
Prefix length designates how many addresses available for
network and hosts in CIDR address
In example 162.200.0.0/12, first 12 bits of address identify
network and remaining 20 bits identify host
10100010.1100|1000.00000000.00000000
212 = 4098 Networks
220 = 1,048,576 Hosts per Network
CIDR addresses also reduce size of routing tables and allows
more IP addresses for subnetting and supernetting
U.S. Department of
Homeland Security
United States
Secret Service
IPv6
Internet Protocol version 6 (IPv6), new method for IP
addressing, significantly increases amount of available IP
addresses
Expands IP address from 32 bits to 128 bits
Will provide over 3.4x10**38 power new addresses
Enough IP addresses that every cell of human body could be
assigned one with addresses to spare
U.S. Department of
Homeland Security
United States
Secret Service
IPv6
Addresses presented in hexadecimal format, such as:
FE80:325B:134C:5555:678D:9C4D:3EEE:2D5F
Format consists of eight groups of hexadecimal digits
Initially, many addresses will have zeros in groups
U.S. Department of
Homeland Security
United States
Secret Service
IPv6
Shorthand notation exists to expresses groups of zeros, :: (the
colon-colon operator)
All groups in colons are zeros
For example, IPv6 address, FE80::3E4F
First group is FE80
Second through 7th groups are all zeros
Eighth group is 3E4
U.S. Department of
Homeland Security
United States
Secret Service
IPv6 Special Addresses and Prefixes
Address
Description
::FFFF:0:0/96
Used for IPv4 mapped addresses
FC00::/7
Unique local IPv6 unicast addresses.
Routable only within set of cooperating
sites. Replaced “site-local” used in
earlier implementation of IPv6.
U.S. Department of
Homeland Security
United States
Secret Service
IPv6 Special Addresses and Prefixes
Address
Description
FE80::/10
Local link for use within a LAN. Similar
to 169.254.x.x, the autoconfig IP
address in IPv4.
FF00::/8
Multicast prefix. No address ranges
reserved for broadcast. Applications are
to use multicast.
U.S. Department of
Homeland Security
United States
Secret Service
IPv6 Special Addresses and Prefixes
Address
Description
::1 /128
Loopback or “localhost” address. Similar
to 127.0.0.1 IPv4 loopback address.
FE80::/10 through
Private address ranges. Similar to IPv4
FEB0::/10
private LAN addresses. Local link
addresses. Stateless and
autoconfigured for use within LAN
segment.
U.S. Department of
Homeland Security
United States
Secret Service
IPv6 Special Addresses and Prefixes
Address
Description
FEC0::/10 through
Private address ranges. Similar to IPv4
FEF0::/10
private LAN addresses. Local site
addresses.
FF00::/8 prefix
Multi-cast prefix
( 2000 to 3FFF )::/16
Global unicast prefix
prefix
U.S. Department of
Homeland Security
United States
Secret Service
IPv6 Special Addresses and Prefixes
Address
Description
2001::/16
Assigned to Regional Internet Registrar
(RIR)
2002::/16
Assigned to 6to4 Transition Methods
3FFE::/16
Temporary address assigned to 6bone
U.S. Department of
Homeland Security
United States
Secret Service
Dual Stacks
Routers and computers can be configured to use both IPv4
and IPv6
Routers that route both IPv4 and IPv6 packets called dual-
stack
No need for subnet mask address or NAT (Network Address
Translation) with IPv6, although NAT can be implemented
U.S. Department of
Homeland Security
United States
Secret Service
Pseudo-Interfaces
Network card can be configured with multiple IPv6 addresses
For example, one address can be for just a segment, another
for the site, and third can be for Internet
IPv6 protocol assigns pseudo-interfaces or zone IDs for each
of these
An address may look like ABCD::1234:B2C3 %4
%4 would be its zone ID
U.S. Department of
Homeland Security
United States
Secret Service
Domain Name Service
Most networks and Web sites have text-based domain names
people can remember, such as www.google.com
Internet based on numerical IP addresses
Domain name service (DNS) translates text domain names
into numerical IP addresses before Internet connection made
Type Web address to favorite site, DNS server receives site
request and translates into corresponding IP address
U.S. Department of
Homeland Security
United States
Secret Service
Dynamic Host Configuration
Protocol
Dynamic Host Configuration Protocol (DHCP) used to assign
dynamic IP addresses to devices on network
Addresses are assigned from pool of pre-registered addresses
Eliminates need and time to manually assign IP addresses to
new network equipment
Tracks all assigned addresses automatically
U.S. Department of
Homeland Security
United States
Secret Service
Dynamic Host Configuration
Protocol
Computer or other device can be assigned different IP address
every time it accesses network
Device can change IP address between logon and logoff
ISPs frequently use DHCP for dial-up and broadband users
DHCP6 will run in networks that have implemented IPv6
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - Ports
Overview of Ports
How Ports are Used
Configuring TCP/IP
U.S. Department of
Homeland Security
United States
Secret Service
Ports
Communications over computer networks similar to telephone
system in sense that thousands of conversations between
computers occur every second
For computers and applications to communicate, need means
of channeling communications, called service ports, or simply
ports
U.S. Department of
Homeland Security
United States
Secret Service
Ports
When computer receives data from network, TCP/IP protocol
stack must know data’s user application destination
For example, Web server sends Web page to computer,
TCP/IP must know Web page data goes to Web browser to
display page
U.S. Department of
Homeland Security
United States
Secret Service
Ports
TCP/IP maps data to an application using a port, number that
represents an application
Each transmission is labeled with source and destination port
The source port identifies application sending data
Destination port identifies application to process data
U.S. Department of
Homeland Security
United States
Secret Service
Well-Known Ports
Over 65,000 ports available to network applications
Ports 1 - 1023 usually map to specific applications, regardless
of computers involved
For this reason, they are often called well-known ports
U.S. Department of
Homeland Security
United States
Secret Service
Well-Known Ports
Service
Protocol
Port Number
World Wide Web
TCP
80
(HTTP)
Telnet
TCP
23
Simple Mail Transfer
TCP
25
Protocol (SMTP)
File Transfer Protocol
UDP
21
(FTP) Control
U.S. Department of
Homeland Security
United States
Secret Service
Communication Through Ports
U.S. Department of
Homeland Security
United States
Secret Service
Port Use
Network hardware devices such as firewalls, routers and
gateways offer ability to close or open certain ports
Provides or denies access to specific types of information
Some network devices can open port, but restrict packets
traveling through port
For example, port 21 (File Transfer Protocol) can be opened,
but monitored to disallow packets carrying the put command
Conversely, the get command would not be blocked
U.S. Department of
Homeland Security
United States
Secret Service
Port Management
Computer’s ports can be enabled or disabled using features of
operating system
Windows XP, for example, provides built-in software firewall
that automatically restricts port access
Terminating an active service on server can also disable ports
Example, FTP service can be disabled using features of
operating system, disabling port 21
U.S. Department of
Homeland Security
United States
Secret Service
Port Management
Often, ports managed through configuration of hardware
firewalls
Hardware firewalls can be managed locally by attaching
special cable from PC to network device and running standard
communications software, such as Telnet or HyperTerminal
Devices can be managed remotely with Telnet
Can be managed through Web browser, such as Internet
Explorer, pointing browser to device’s IP address
U.S. Department of
Homeland Security
United States
Secret Service
Port Management
Regardless of management technique, device will most likely
have administration account requiring login ID and password to
configure device
Windows XP firewall has rules that block inbound
communication attempts
Windows Vista firewall includes rules that block both inbound
and outbound communication attempts
U.S. Department of
Homeland Security
United States
Secret Service
Port Misuse
Most government agencies and corporations publish policies
specifying port configurations for network devices
Blocking certain ports mandatory in many instances
Policies intend to minimize risk of intrusion standard
Technical personnel might “bend the rules” to accomplish
specific task and open unauthorized port on network device
long enough to accomplish task
Policies protecting network violated and network becomes
vulnerable
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Create a TCP/IP LAN via a
Router with Microsoft Vista
This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Subnets
Subnet Overview
Subnet Masks
Virtual LAN
U.S. Department of
Homeland Security
United States
Secret Service
Subnets
Class A, B, and C networks can be subdivided into subnets
Subnet is segment of network that shares common IP network
address component with other devices on same subnet
Devices with same IP address prefix belong to same subnet on
TCP/IP network
Networks on Internet view other networks as single entities
No way of viewing another network’s subnet structure, helps
reduce size of routing tables
U.S. Department of
Homeland Security
United States
Secret Service
Subnets
When data packet is sent over Internet, it goes to router of
destination network
Router determines destination node by deciphering packet’s
subnet address
U.S. Department of
Homeland Security
United States
Secret Service
Advantages of Subnetting
Enhances security by creating subnets that have restricted
access
Extends capabilities of network
Enhances network performance, eliminating traffic on other
segments
U.S. Department of
Homeland Security
United States
Secret Service
Advantages of Subnetting
Allows subnets to be invisible to outside world
Provides flexibility to deploy additional subnets without
registering new network numbers
Allows data route changes within network without affecting
Internet routing table
U.S. Department of
Homeland Security
United States
Secret Service
Subnet Addressing
Like IP addresses, each subnet address is unique
Recall each IP address has four octets, address divided into
two major segments: network and host
By comparison, subnet address contains three segments:
network address, subnet address, host address
U.S. Department of
Homeland Security
United States
Secret Service
IP Address vs. Subnet Address
U.S. Department of
Homeland Security
United States
Secret Service
Creating Subnets
Subnets created as extensions of network number
To create, take bits from host number and reassign to subnet
field
The more bits taken from host number, the fewer host
addresses that can be assigned to subnet
U.S. Department of
Homeland Security
United States
Secret Service
Subnet Masks
A subnet mask conceals a subnet from outside networks
Two main functions of a subnet mask:
Identify subnet of an IP address
Notify communicating devices which part of IP address is
network ID (including subnet) and which part is host ID
U.S. Department of
Homeland Security
United States
Secret Service
Default Classes of Subnet Masks
Class A - 255.0.0.0
Class B - 255.255.0.0
Class C - 255.255.255.0
U.S. Department of
Homeland Security
United States
Secret Service
Subnet Masks Components
Subnet masks use same 32-bit, four-octet structure as IP
addresses
Subnet mask addresses have three parts: network address,
subnet address, host address
Subnet mask has all ones in network and subnet segments of
address and contains all zeros in host segment
With subnetting, part of host address used to identify subnet
Subnet mask is network address plus bits reserved to identify
subnet
U.S. Department of
Homeland Security
United States
Secret Service
Virtual LAN
Virtual LAN (VLAN), another way to divide local area network
into logical subgroups
VLAN uses software to connect group of computers and
devices instead of manually moving cables and wiring
Can be used to combine workstations and other devices into
single group regardless of physical location
Improves traffic flow within workgroup
U.S. Department of
Homeland Security
United States
Secret Service
Virtual LAN
VLANs used in LAN switches
Network changes and additions quickly implemented with
VLAN software making group solutions easy to create
VLANs operate at Data Link Layer 2 and Network Layer 3 of
OSI model
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 4 - Network Security
Data Encryption
Anti-Virus Software
Firewalls
IDS
Logs
Network Security Summary
U.S. Department of
Homeland Security
United States
Secret Service
Data Encryption
Conversion of data into form that cannot be easily deciphered
Encrypted text called cipher text
Decryption converts encrypted data into plain text
Encryption provides highly effective method for data protection
U.S. Department of
Homeland Security
United States
Secret Service
Two Types of Encryption
Asymmetric encryption uses two types of cryptographic keys to
encode messages
Public key is known to everyone
Private key is only known to recipient
Method works because public key relates to private key so
that messages can be decrypted upon receipt
Symmetric encryption uses same key to encode and decode
messages
U.S. Department of
Homeland Security
United States
Secret Service
Virus
Small piece of code that executes when opening a real
program or file
Example, virus might attach itself to word processing file
When file opened, virus code attaches itself to word
processing program
Each time program runs, virus runs
Has chance to replicate by attaching to other programs or
wreak havoc, such as deleting entire contents of hard drive
U.S. Department of
Homeland Security
United States
Secret Service
E-mail Viruses
Spreads in e-mail messages
Usually automatically mails itself to every address in victim's e-
mail address book
U.S. Department of
Homeland Security
United States
Secret Service
Worms
Small piece of code uses computer networks and
vulnerabilities, known as security holes, to replicate itself
Worm scans network for any machine that has specific security
hole
Copies itself to new machine using security hole, and starts
replicating from there
U.S. Department of
Homeland Security
United States
Secret Service
Trojan Horses
A computer program, not a virus
Program claims to do one thing, instead could do deliberate
damage when run
For example, Trojan horse may claim to be a game, but
instead may erase hard disk or create “back door”
Trojan horses have no way to replicate automatically
U.S. Department of
Homeland Security
United States
Secret Service
Boot Sector Viruses
Boot sector viruses spread by infecting boot sector of boot
media, usually hard drive or floppy diskette
Once infected, every time computer boots, virus is loaded
automatically into memory
Thereafter, attempts to infect every other program and file
opened
U.S. Department of
Homeland Security
United States
Secret Service
Firewalls
Method of securing a network from unauthorized access
Most often, protect against intruders who seek access via
Internet
Enterprises install firewalls to secure Internet access for
employees, separate and protect intranet from unauthorized
public Web site traffic
Also installed to protect organization’s internal departments or
domains, such as firewall that secures accounting department
U.S. Department of
Homeland Security
United States
Secret Service
Firewalls
Protection can be software, hardware, or combination of both
Each performs specific security activities
Firewalls are access control devices that only detect failed
attempts at access
If intruder defeats corporate firewall, intrusion may or may not
be logged, depending on firewall configurations
U.S. Department of
Homeland Security
United States
Secret Service
Intranet Protected by Firewall
U.S. Department of
Homeland Security
United States
Secret Service
How Firewalls Work
All messages going in or out of the network pass through
firewall
Messages checked using specified security criteria
Firewall blocks those that do not meet criteria
Different types of firewalls work at various layers of OSI model
or TCP/IP protocol
U.S. Department of
Homeland Security
United States
Secret Service
Network Address Translation (NAT)
NAT allows use of internal non-routable IP addresses on
intranet to connect to Internet with one registered IP address
Registered IP address assigned to software or hardware
device running NAT
Process allows any computer behind NAT device to be
invisible to Internet
Only NAT device’s registered IP address is used
U.S. Department of
Homeland Security
United States
Secret Service
How NAT Works
Intranet computer sends data packet to NAT device
NAT device examines packet header and records intranet
computer making request
NAT device replaces IP address with its own registered IP
address and sends request to Internet
When packet returns, it goes to IP address of NAT device
NAT device examines packet, places appropriate IP address
for intranet computer in packet, and sends to computer
U.S. Department of
Homeland Security
United States
Secret Service
Stateful Inspection
Stateful inspection firewall architecture has ability to look into
packet and allow only certain types of application commands
while rejecting others
For example, stateful packet-filtering firewall allows FTP
command Get and rejects Put command
U.S. Department of
Homeland Security
United States
Secret Service
Stateful Inspection
Stateful inspection firewalls record User Datagram Protocol
(UDP) packet requests permitted to cross firewall in state table
Incoming UDP packets examined and verified against ones
waiting for response in state table
If information matches, request is permitted to enter network,
otherwise packet rejected
U.S. Department of
Homeland Security
United States
Secret Service
Packet-filtering Firewalls
Packet-filtering firewalls check header of packets for specific
information and accepts or rejects packets based on user-
defined rules
Checks are made for:
Source and destination IP address
Source and destination port numbers
Protocol type
Direction of the packet (inbound or outbound)
U.S. Department of
Homeland Security
United States
Secret Service
Packet-filtering Firewall Advantages
Good performance
NAT shields internal addresses from external users
No code modifications are needed
Closes ports when not in use
Stateful inspection checks packets and only allows those
through that were requested
U.S. Department of
Homeland Security
United States
Secret Service
Packet-filtering Firewalls
Disadvantage
Subject to IP spoofing or port spoofing
Cannot filter or authenticate URL information
Little or no auditing or alert mechanisms
Rules need to be entered for stateful inspection type firewalls
and then changed
U.S. Department of
Homeland Security
United States
Secret Service
Circuit-level Firewall
Validates TCP and UDP sessions before opening connection
After validation, passes everything through until session ends
Establishes a virtual circuit between client and host on
session-by-session basis
Maintains table of connections including session and
sequencing information
When session ends, table information removed and virtual
connection is closed
U.S. Department of
Homeland Security
United States
Secret Service
Circuit-level Firewall
Only packets associated with session are allowed through
If packet is valid according to session table, packet is passed
through without any further security checks
Session consists of two connections: one between client and
firewall and one between firewall and server
All outgoing packets appear to have originated from firewall in
method similar to NAT
U.S. Department of
Homeland Security
United States
Secret Service
Circuit-level Firewall Advantages
Good performance because packets are not examined after
initial connection is allowed
No direct connection between client and application server
Similar to NAT’s method of shielding internal IP address
U.S. Department of
Homeland Security
United States
Secret Service
Circuit-level Firewall Disadvantages
Client programs need to be recompiled and relinked to a
special library containing set of rules for sessions
Does not examine application level information in packets
allowing them to be subverted by inside user or outside hacker
U.S. Department of
Homeland Security
United States
Secret Service
Application-Gateway Firewall
Runs on proxy server application that acts as intermediary
between two systems
Evaluates all requests from internal computers to connect to
external service, such as FTP
Determines whether to permit or deny request based on rules
defined for individual network
U.S. Department of
Homeland Security
United States
Secret Service
Application-Gateway Firewall
Application-gateway running on proxy server understands
protocols of service it is evaluating
Can deny packets that do not comply with protocol for service
Provides detailed audit records or session information, user
authentication, URL filtering, and caching
U.S. Department of
Homeland Security
United States
Secret Service
Application-Gateway Firewall
Application-gateway firewalls are application specific and
require proxy addresses for FTP, HTTP, SMTP, etc
These firewalls operate at Application Layer of OSI model
Able to look down through packets to application layer
information to determine if packet is altered or not complying
with appropriate protocol rules
Additional steps cause application-gateway firewall to be
slower than other types of firewalls
U.S. Department of
Homeland Security
United States
Secret Service
Application-Gateway Firewall
Advantages
No direct connection between internal client and external
server
Can deny packets that do not comply with protocol for service,
such as FTP, HTTP, SMTP, etc
Ability to screen data streams for potential threats, such as
send mail attacks, and Java or ActiveX scripts riding on top of
HTTP services
Provide NAT services
U.S. Department of
Homeland Security
United States
Secret Service
Application-Gateway Firewall
Advantages
Transparent to individual user
Can implement features such as HTTP object caching, URL
filtering and user authentication
Provide audit logs for administrators to monitor for violations of
security policy
U.S. Department of
Homeland Security
United States
Secret Service
Application-Gateway Firewall
Disadvantages
Slower than other firewall methods
Vulnerable to operating system and application level bugs
because highly dependant on operating system, TCP/IP
stacks, and runtime libraries
New services require new proxy servers
U.S. Department of
Homeland Security
United States
Secret Service
Intrusion Detection Systems (IDS)
Monitor network for attacks
Two basic types of IDSs:
Network-based IDS monitors entire network for signs of
intrusion
Host-based IDS monitors individual computer
IDS must be installed consistent with network’s type and
topology
U.S. Department of
Homeland Security
United States
Secret Service
Network-based IDS
Monitors entire network and uses information in data packets
to detect intrusion
Analyzes packets for attack signature, known pattern in packet
or packets that match specific attack type
Analyzes packets in real time using recognition files
Most common method used by IDS pattern expression is byte
code matching, also known as signature analysis or misuse
detection
U.S. Department of
Homeland Security
United States
Secret Service
Network-based IDS
When attack identified, IDS can be programmed to perform
any of following actions:
Send alert to console
Log event and send email
Initiate connection kill (TCP reset)
Reconfigure firewall or router, or use SNMP trap
Important to keep list of known attack signatures current
U.S. Department of
Homeland Security
United States
Secret Service
Host-based IDS
Host-based IDS installed on individual computer to monitor
only that computer
Host-based IDSs are used to:
Monitor logs
Detect file access
Detect attempts to install executables
Monitor remote user activities
U.S. Department of
Homeland Security
United States
Secret Service
Host-based IDS
Specific to OS installed on computer
On host with NT OS, IDS will monitor system, event, and
security logs
On host with Unix OS, IDS will monitor syslog
Host-based IDS examines each log’s entry to see if it matches
any known attack pattern
Some can monitor ports on computer
Can also detect attacks initiated from local keyboard
U.S. Department of
Homeland Security
United States
Secret Service
Host-based IDS Actions
Log event
Alert console and send an e-mail
Initiate a SNMP trap
Terminate user login and disable user account
U.S. Department of
Homeland Security
United States
Secret Service
Logs
Record of network activity that provide details of transactions
and traffic
Routinely used for backup, recovery, and statistical purposes
Also used to detect failed and successful intrusions, abnormal
network activity, and system activities
Many different types of logs generated by both software and
hardware devices
Can be integral part of computer forensic investigations
U.S. Department of
Homeland Security
United States
Secret Service
Common Logs
System logs
Firewall logs
Router logs
IDS logs
U.S. Department of
Homeland Security
United States
Secret Service
System Logs
Most networking operating systems able to maintain log files
Can include system activities, application activities, and
security activities
Most systems can be configured to maintain logs for Internet
access, FTP sessions, etc
U.S. Department of
Homeland Security
United States
Secret Service
System Logs
Example, Windows NT/2000/XP maintains three main logs that
can be accessed through Event Viewer
System log
Security log
Application log
U.S. Department of
Homeland Security
United States
Secret Service
Firewall Logs
Type of attempted access (Web access, FTP access, Telnet
access etc.)
Port that attempted access
Date and time of attempted access
IP address from which attempt came
Application-level firewall logs can also provide detailed
information of session information, user authentication, and
security policy violations
U.S. Department of
Homeland Security
United States
Secret Service
Router Logs
Can log information about network traffic and potential network
problems
Can be configured to log abnormal activity that contains host
information of possible intruder and what was accessed on
network during attempt
Dial-up-access routers, can log dial-up connection information
including username, IP address assigned, date, time, duration
of connection
Can be very beneficial during an intrusion investigation
U.S. Department of
Homeland Security
United States
Secret Service
IDS Logs
Intrusions
Intrusion attempts
Unauthorized access to a computer
Attempts to access unauthorized data
Attempts to manipulate privileged files
Attempts to render a network system inoperable
U.S. Department of
Homeland Security
United States
Secret Service
Network Security Summary
Layered approach commonly used
Intrusion Detection to provide real-time monitoring of network
Firewalls to restrict unauthorized access to network
Anti-virus protection to reduce risk of infection
Encryption to prevent stolen data packets from being read
Logs to record activity and provide documentation should a
breach of security occur
U.S. Department of
Homeland Security
United States
Secret Service
U.S. Department of
Homeland Security
United States
Secret Service
Module 8 - Common Network Crimes
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
E-Mail Scams
On-line Fraud
Identity Theft
Social Threats
Internal Threats
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
Malicious Code
Denial of Service Attacks
Extortion
Network Attacks
Terrorism
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - E-Mail Scams
Overview
Attack Methodologies
Investigative Response
U.S. Department of
Homeland Security
United States
Secret Service
E-Mail Scams
Scam defined as a dishonest act or fraud
Postal system used for fraudulent means since the 1660’s
Simple step for surface-mail scammers to make leap to
Internet E-mail
U.S. Department of
Homeland Security
United States
Secret Service
Why E-mail Scams Works
People do not look closely at e-mail header information
Few notice or question origin of messages
Some scams use HTML encoded E-mail to display logos and
other items to give impression of respectability
Easy to hide code in HTML formatted E-mail that launches
Trojans or other malicious code when E-mail viewed
Chain E-mails and solicitations for money using every
imaginable story and trick are prevalent on Internet
U.S. Department of
Homeland Security
United States
Secret Service
Nigerian, or 419 Scam
Legendary among E-mail frauds
Virtually all originate from foreign countries that have no
agreement with U.S. pertaining to prosecution of fraud
Person making request claims to be government official, or
relative of deposed leader or potentate
Requests involve large, usually multi-million dollar, sums of
money
Tap into greed of recipient
U.S. Department of
Homeland Security
United States
Secret Service
Nigerian, or 419 Scam
Reason person making request can’t get money themselves,
but recipient, being an upstanding American can
Will ask sum of money be deposited in account in other
country
Transfers of money to foreign account
Requestor absconds with money
Perpetrator outside reach of U.S. Law Enforcement
U.S. Department of
Homeland Security
United States
Secret Service
Where 419 Comes From
Nigerian government has taken hard line against frauds
Section 419 of Nigerian Criminal Code outlaws activity
Nigerian Government also considers anyone trying to remove
funds from their country a criminal
Victims who have gone to Nigeria to try get money back have
been imprisoned
U.S. Department of
Homeland Security
United States
Secret Service
Phishing
Perpetrator sends out legitimate looking E-mail in attempt to
gain financial or personal information
Compromised information used for other network crimes
E-Bay/PayPal
Banks
Cross Site Scripting
U.S. Department of
Homeland Security
United States
Secret Service
Spam
Unsolicited advertisement or bulk E-mail
Use of network bandwidth consumed
Storage space on mail servers
Estimated cost to companies in U.S. is over $12 billion dollars
a year
U.S. Department of
Homeland Security
United States
Secret Service
E-mail Scam Investigative Response
Capture
Preservation
Warrants
Reporting
Education
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - Online Fraud
Overview
Attack Methodologies
Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Online Fraud
Any form of trickery or deceptive gain practiced on Internet
U.S. Department of
Homeland Security
United States
Secret Service
Common Attack Vectors
Price to good to be true
Short time to decide
Fine print
Hijacked sites
Box-of-rocks
Stall tactics
U.S. Department of
Homeland Security
United States
Secret Service
Attack Methodologies
Bogus web sites
Auctions
Bogus Charities
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
Capture
Preservation
Warrants
Reporting
Education
Recording Observations
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Identity Theft
Overview
Attack Methodologies
Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Identity Theft
In 2007 estimated 8.4 million reported cases of identity theft in
U.S.
Number down from reported 10.1 million in 2003
Even with decline identity theft problem is major problem
U.S. Department of
Homeland Security
United States
Secret Service
Gathering Personal Information
Search Engines
Public information sites
Group sites
Commercial sites
Membership sites
U.S. Department of
Homeland Security
United States
Secret Service
Attack Methodologies
Name
Phone
Social Security Number
Address
License plate
U.S. Department of
Homeland Security
United States
Secret Service
Attack Methodologies
Pretexting - using small bits of information about subject to
gather more details from businesses and vendors
Attacker calls business or service that victim is member of and
pretends to be victim
Using information already gathered, attacker persuades
business to disclose further information, or change information
in account of victim to allow attacker full control of account
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
Capture
Preservation
Warrants
Reporting
Education
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 4 - Social Threats
Overview
Attack Methodologies
Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Social Threats
Predators
Stalkers
Cyberbullying
U.S. Department of
Homeland Security
United States
Secret Service
Attack Methodologies
E-mail
Chat
Texting
Impersonation
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
Capture
Preservation
Warrants
Reporting
Education
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 5 - Internal Threats
Overview
Attack Methodologies
Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Internal Threats
Inappropriate Usage
Embezzlement
Extortion
Espionage
Sabotage
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
Capture
Preservation
Warrants
Reporting
Education
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 6 - Malicious Code
Overview
Attack Methodologies
Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Malicious Code Attacks
Viruses
Trojans
Worms
Spyware
Adware
Rootkits
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
Capture
Preservation
Warrants
Reporting
Education
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 7 - Denial of Service Attacks
Overview
Attack Methodologies
Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Denial of Service
Flooding target with more information than it can handle,
causing system crash or reset
Interfering with communications channel in such a way that
others can’t access system
Starting so many processes on target system that available
resources are used and system cannot respond to requests
Changing access codes so that normal users can no longer
access system
U.S. Department of
Homeland Security
United States
Secret Service
Distributed Denial of Service Attack
When multiple systems attack target system
Multiple systems usually compromised systems over which
attacker has control
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
Capture
Preservation
Warrants
Reporting
Education
U.S. Department of
Homeland Security
United States
Secret Service
|
||
|
|
|