Network Security Traceback Attack and React in the United States Department of Defense Network
Machie, Edmond K.
New - Soft cover
Condition: New
Ships from Germany to U.S.A.
Quantity: Over 20 available
Add to basketCondition: New
Quantity: Over 20 available
Add to basketDieser Artikel ist ein Print on Demand Artikel und wird nach Ihrer Bestellung fuer Sie gedruckt. KlappentextrnrnNetwork Security and how to traceback, attack and react to network vulnerability and threats. Concentration on traceback techniques for attacks launched with single packets involving encrypted payloads, chaff and other obfuscation.
Seller Inventory # 447853998
| Dedication................................................................. | xi |
| Introduction............................................................... | xiii |
| PART ONE: NETWORK SECURITY................................................. | 1 |
| CHAPTER I: NETWORK ATTACK TRACEBACK........................................ | 3 |
| CHAPTER II: SECURITY ARCHITECTURE AND ANALYSIS............................. | 10 |
| CHAPTER III: CISCO INTRUSION DETECTION SYSTEM (IDS) NETWORK MODULE FOR CISCO ACCESS ROUTERS-INTERGRATES TRADITIONAL INTRUSION DETECTION INTO THE ROUTER USING CISCO INTRUSION PREVENTION SYSTEM (IPS) SENSOR................ | 16 |
| PART TWO: NETWORK VULNERABILITY ASSESSMENT................................. | 23 |
| CHAPTER IV: NETWORK VULNERABILITY ASSESSMENT NETWORK SECURITY THREAT AND VULNERABILITIES............................................................ | 25 |
| CHAPTER V: DISTRIBUTED DENIAL OF SERVICE DETECT AND REACT IN THE UNITED STATES DEPARTMENT OF DEFENSE NETWORK....................................... | 31 |
| PART THREE: SOFTWARE SECURITY AND WIRELESS NETWORKS........................ | 43 |
| CHAPTER VI: LIGHTWEIGHT MIDDLEWARE ENVIRONMENT FOR AD-HOC WIRELESS NETWORKS................................................................... | 45 |
| CHAPTER VII: AUDITING SOFTWARE AND TOOLS—ARCHITECTURAL AND SOURCE-LEVEL.... | 49 |
| PART FOUR: INFORMATION SYSTEM FOR MANAGERS—LEGAL AND ETHICAL MANAGEMENT IN INFORMATION SECURITY....................................................... | 57 |
| CHAPTER VIII: CYBERSECURITY AND THE TRUST ISSUES IN THE ONLINE TRANSACTION................................................................ | 59 |
| CHAPTER IX: THE SARBANES-OXLEY ACT of 2002—LITERATURE REVIEW............... | 64 |
| CHAPTER X: THE SARBANES-OXLEY ACT of 2002—SECTION 404: MANAGEMENT ASSESSMENT OF THE INTERNAL CONTROL OF ALL PUBLICLY-TRADE COMPANIES......... | 70 |
| CHAPTER XI: SARBANES-OXLEY ACT OF 2002..................................... | 79 |
| CHAPTER XII: DATA PROTECTION LAW AND LEGISLATION IN THE UNITED STATES AND THE EUROPEAN UNION......................................................... | 84 |
| CHAPTER XIII: INFORMATION ASSURANCE POLICY PLANNING & ANALYSIS............. | 89 |
| PART FIVE: SECURITY FORENSICS.............................................. | 97 |
| CHAPTER XIV: COMPANIES SPECIALIZING IN COMPUTER FORENSICS SUMMARY REPORT... | 99 |
| CHAPTER XV: AFFIDAVIT CRITIQUE—REVIEW OF THE HANSSEN AFFIDAVIT—CRITIQUE OF ITS CONTENT AS IT PERTAINS TO COMPUTER EVIDENCE............................ | 105 |
| PART SIX: GUIDING PRINCIPLES OF SECURITY OF WEB APPLICATION AND SAMPLES TEST QUESTIONS AND ANSWERS................................................. | 111 |
| CHAPTER XVI: GUIDING PRINCIPLES OF SECURITY OF WEB APPLICATION............. | 113 |
| CHAPTER XVII: SAMPLE TEST QUESTIONS AND ANSWERS............................ | 123 |
| Index...................................................................... | 179 |
NETWORK ATTACK TRACEBACK
I. INTRODUCTION
While increasing in number, sophistication, and severity, the networkattacks on governmental, business, academic, and critical infrastructurenetworks need immediate attention. In this research, prevention, detectionand reaction are the truism of the network security vulnerability andassessment. Variable aspects or processes are addressed with regardto attacks. Investigated attacks include, data collection, which refers tothe collection of data from multiple operating systems. Vatis states that,"Investigators also need tools to automate the collection of data files frommultiple operating systems in the victims' network or the network beingattacked."
II. ATTACK TRACEBACK IN A NETWORK ATTACK
The UNIX System is more complex than Windows, and is necessary for thedigital evidence examiner. Usually UNIX is configured to print, log, and storeuser data (e.g. files, e-mail, passwords) on remote location systems.
One of the options to trace back the attack in the network is MappingNetwork Topology. This provides a solution to automate the process ofdeveloping the map of the network quickly and accurately. It maps thevictim's network during the preliminary stage of a network-attack tracebackto assess the extent of the attack.
What follows are the specific network attack data recovery tools toautomate the digital evidence recovery process; capturing residentmemory data is also part of network attack traceback, as well as analyzingexcessively large media storage devices.
Michael A. Vatis described Log Analysis and Reporting as automated log fileanalysis and developing graphical reporting. Furthermore, he defined LogCompilation as recognizing and importing preliminary investigation data,recognizing and importing logs across a network, reconstructing alteredor damaged logs, placing log data into an organized timeline, organizeoutput to a common and portable format. Thus, Vitas presents IP Tracingand Real-Time Interception as critical for tracking cyber attackers. Accordingto the reporting, the distributed denial of service attacks or (DDoS) originand location of the attacker remain hidden. Non-technical issues such asunderemployed technologies to counter attacks utilizing spoofing and lackof record keeping by Internet Service Providers (ISP) hamper the tracing ofIP addresses. The real-time interception of digital data is a use of specializedforensic solutions for retrieving, storing, and analyzing very large mediastorage devices compromised by network attacks.
The other important point is that data collection from multiple operatingsystems is demonstrated because of computers' usage of several differentoperating systems to perform different tasks. Data collections from severalcomputers are relevant to understand how a network was compromised. Ithappens that Windows operating systems dominated their caseloads in theuse of the types of operating systems encountered in the traceback attack.
UNIX and Linux operating systems were encountered less frequently. MacOS (through version 9) and Mac OSX were seen the least during the lastthree years, but still on occasion by some investigators. Solutions that canautomate the collection of data from multiple operating systems are stillneeded, as well as solutions to identify and report system configurationsand file locations.
There is a need of tools that will help analyze the attack data across multipleplatforms, regardless of the platform that the investigator is working on.After data collection, this tool will reduce time and focus on analysis ratherthan collection.
III. DENIAL OF SERVICES IN THE NETWORK ATTACK—(DOS)
Symantec Security Response supports the thought that Denial of Service(DoS) attack is not a virus, but a method hackers use to prevent or denylegitimate users access to a computer. In order to traceback an attack inthe network better, we should know how the attack occurred. In so doing,Symantec Security Response indicates that DoS attacks are some type ofexecution using DoS tools that send many request packets to a targetedInternet server (usually Web, FTP, or Mail server), which floods the server'sresources, making the system useless. Therefore, any system that isconnected to the Internet and is equipped with TCP-based network servicesis subject to attack. It presents the capability of the many DoS attack toolsto executing a distributed (DoS), (DDoS) attack. DDoS tools are TFN, TFN2K,and Trinoo. The DoS tools can be secretly installed onto a large numberof innocent systems, which can be managed by the attacker centrally toinitiate DoS attacks at a target computer. Zombie agents, or Drones, are asystem that unknowingly has DoS. Smurf DoS attacks use a forged InternetControl Message Protocol (ICMP) echo request. TFN and Tribal FloodNetwork 2000 (TFN2K) use the SYN flooding technique, which creates half-openconnections. It can perform various attacks such as UDP flood attacks(similar to Trinoo), ICMP flood attack (similar to Smurf), and TCP SYN floodattacks. The systems affected are Linux, UNIX, Windows 2000, Windows NT,and Windows XP. The aftermath question is about how to prevent, or howto trace the origin of the request packets in a DoS attack, particularly whenthis is a distributed DoS attack.
It is impossible to prevent all DoS attacks; but there are simple precautionsthat server administrators can take to reduce the risk of being compromisedby a DoS attack. For example, disabling ICMP responses can protect from aSmurf-type attack; or configuring a router to filter and check if an IP comingfrom the outside has an external IP (or vice versa) can avoid a TFN-typeattack. But the query consists of the attack traceback, whereas the networkforensic part of this review will answer some questions about the DoSattacks.
IV. NETWORK FORENSICS
About the Network Forensic in the network attack traceback, I will just limitmy research over some Network Forensic tools and their capabilities. MarisaMack indicates that, "Hundreds of tools and applications address forensicincident response, but there's no single solution." Earlier in this research,we saw that network attack traceback needs a complete forensic incident-responsetoolkit, which must include data acquisition or digital evidencerecovery, text and file searching, Internet history analysis, Internet protocol(IP) tracing and real-time interception, and proprietary analysis of mail filesand data stores. Mack argues that three general investigation scenarios, orstages, are resuming products reviewed. Thus, the second-stage productsshould become the primary forensic-investigation tools.
You will find the Tools and theirs capabilities in the different stages asfollows:
• Stage 1: Network-capable initial analysis products for firstresponders. Guidance Software's EnCase Enterprise Edition andTechnology Pathway's ProDiscover are two products which canacquire drive images remotely in a live environment, and their useeliminates the need for the Stage 2 tools.
• Stage 2: Primary analysis and drive-image acquisition. This stageusually entails obtaining the hard disk of a suspect machine andinvestigating it in a controlled (not live) environment. AccessDataForensic Toolkit, Encase Forensic Edition and the open-sourceSleuth Kit fit this stage. Any one can be used as the primaryinvestigative tool in environments that don't require a network-capableacquisition application. All these products can acquire a fullsector-by-sector drive image of any hard disk under investigation;additional sleuthing functionality varies by application.
• Stage 3: Fine-grained keyword searches. Search through diskor partition contents, e-mail specific searches or Internet historyanalysis. Paraben's NetAnalysis, E-Mail Examiner and NetE-Mail Examiner, and dtSearch's dtSearch excel here. These toolsoperate on disk images created by any of the applications fromStages 1 or 2.
V. INTRUSION DETECTION SYSTEMS (IDS)
Intrusion detection systems (IDS) are increasingly important, as they helpmaintain proper network security. IDS often stores a database of knownattack signatures and can compare patterns of activity, traffic, or behaviorit sees in the logs it's monitoring against those signatures. It can recognizewhen a close match between a signature and current or recent behavioroccurs. Then IDS can issue alarms or alerts, take various automatic actionsranging from shutting down Internet links or specific servers to launchingtraceback, and make other active attempts to identify attackers and activelycollect evidence of their nefarious activities. In a nutshell, the simplest wayto define IDS might be to describe it as a specialized tool which can readand interpret the contents of log files from routers, firewalls, servers, andother network devices.
• DragonIDS: An IDS tool designed to meet the unique securityrequirements of the enterprise environment, the Dragon IntrusionDefense System offers comprehensive features that minimizenetwork vulnerabilities and bring improved security to theenterprise.
• RealSecure Network 10/100 software provides networkintrusion detection and response capabilities that monitor10/100Mbps network segments within a centralized operationaland management framework. RealSecure Network 10/100installations are centrally administered and maintained through theSiteProtector management system with tight integration with ISS'other enterprise protection products. Backed by X-Force securityintelligence, ongoing X-Press Update product enhancementsensure up-to-date protection so that customers can effectivelymonitor and protect their networks against both known andunknown attacks.
• RealSecure Network Gigabit software provides network intrusiondetection and response capabilities that monitor Gigabit networksegments within a centralized operational and managementframework.
• Cisco IPS 4200 Series sensors offer significant protection to thenetwork by helping to detect, classify, and stop threats, includingworms, spyware/adware, network viruses, and application abuse.
• IDS Sensor Software Version 4.x is the central element in theCisco® Intrusion Detection System (IDS) portfolio. Cisco IDS SensorSoftware Version 4.x provides unprecedented security againstknown and unknown threats targeting your network, includingworms, denial-of-service (DoS) attacks, and application attacks.
VI. CONCLUSION
No matter how much a network is hardened, network vulnerability andthreats are still obstinate. The network attacks on governmental, business,academic, and critical infrastructure networks, are increasing in number,sophistication, and severity. The technological impediments facingnetwork attack investigators need immediate attention. The networkattack traceback is a use of tools, but the attacker uses tools as well. Thedevelopment of new tools to prevent attacks is relevant. As in medicine,prevention is better than treatment. Network attack prevention is the mainpurpose of the development of firewalls, best policy, etc.
SECURITY ARCHITECTURE AND ANALYSIS
INTRUSION DETECTION SYSTEM INTEGRATED INTO THE ROUTERUSING CISCO INTRUSION PREVENTION SYSTEM (IPS) SENSOR
I. INTRODUCTION
In 2004, ninety-four percent of firms polled by Network World magazine hadexperienced some security-related downtime. Firms can lose significantrevenues as critical production systems like e-commerce, supply chain andplant management, or point-of-sale go offline due to devastating attackslike Sasser, Nimda, Blaster and SQL Slammer. The IT research and advisoryfirm Aberdeen Group has stated that the cost per security incident, onaverage, is $2 million. According to the 269 respondents of the 2004 CSI/FBI Computer Crime and Security Survey, denial-of-service (DoS) attacksaccounted for over $26 million in losses, while worms and virus attacksare among the most common security breaches of organizations today.These became very important at the point that called for the need offurther examination of Intrusion detection systems versus Intrusionprevention systems used in the network. Consider using both systems withthe network module for Cisco access routers. Furthermore, the intrusiondetection system is integrated into the router using Cisco preventionsystem (IPS) sensor.
II. INTRUSION DETECTION SYSTEM V INTRUSIONPREVENTION SYSTEM
Intrusion detection systems are used as traditional security solutions suchas firewalls and anti-virus software. They are necessary to identify andprevent many attacks that have plagued the network. Intrusion detectionsystem is used as a sentinel function, for alarming and alerting responsibleparties when activities of interest occur. They are defined as the processof monitoring the events occurring in a computer system or network,and analyzing them for signs of security problems. On a grander scale,civil defense and military early-warning systems fall into this functionalcategory.
According to Secure Computing Magazine, in 1999, the time between avulnerability disclosure and availability of a networking exploit was 288days. Furthermore, the article supports that in the last five years, thisduration of time has decreased to a shocking six days or less. Last year'sWitty Worm, which exploited the ICQ parsing process in ISS securityproducts, left system administrators and consumers scrambling after havingonly two days to prepare following the vulnerability announcement.Intrusion detection systems are proving less and less effective in thwartinghybrid worm attacks such as Code Red and Nimda. Malware writers arewreaking havoc on networks all over the world. Meanwhile, intrusionprevention is an emerging network security technology that is proving tohelp firms counter many of these new hybrid attacks. Carefully thoughtoutimplementation of an intrusion prevention system can, however, reappositive results if deployed to solve the right problems. While helpingmany firms block attacks rather than just alert users of their occurrence, asIntrusion detection system (IDS) does, Intrusion prevention systems (IPS)are proving to be a proactive defense mechanism.
III. NETWORK MODULE FOR CISCO ACCESS ROUTERS
The Cisco 3700 Series Application Service Router is a new family of modularrouters. Deployment of this application accelerates cost reduction benefitsof e-business applications, infrastructure and improves competitiveleverage of networks. This application supports the Cisco AVVID(Architecture for Voice, Video and Integrated Data), which is an enterprise-wide,standards-based network architecture. Complementing the existingCisco1700/2600/3600 modular multi-service routers, they are optimized tosupport the broadest array of connectivity options. This is ideal for sites andsolutions requiring the highest levels of integration at the edge, such as:
• Integration of flexible routing and low density switching
• Single platform solution for branch Office IP Telephony and VoiceGateway allowing flexible, incremental migration and serviceintegration
• Consolidation of service infrastructure and high service density ina compact form factor
It is important to note that the two Cisco 3700 platforms, the Cisco 3725and Cisco 3745, introduce a new, wider interface form factor. The high-densityservices module (HDSM) enables the NM slots to integrateadditional services, and offers increased Flash and DRAM default memoryto accelerate and simplify future service and feature additions. The Cisco3745 router offers additional availability features that may be requiredin high-density, multiple-services configurations. This helps deploy asingle, integrated platform that combines the industry-leading routingand switching technologies with the highest level of WAN flexibility toaccommodate the dynamic remote office environment. The 4 NM-slot Cisco3745 router can accept two HDSMs in place of four NMs by removing thecenter guides between each pair of adjacent NM slots. The 2 NM-slot Cisco3725 router can accept an HDSM in one of its two NM slots and still acceptan NM in the remaining slot.
Excerpted from NETWORK SECURITY TRACEBACK ATTACK AND REACT IN THE UNITED STATES DEPARTMENT OF DEFENSE NETWORK by EDMOND K. MACHIE. Copyright © 2013 by EDMOND K. MACHIE. Excerpted by permission of Trafford Publishing.
All rights reserved. No part of this excerpt may be reproduced or reprinted without permission in writing from the publisher.
Excerpts are provided by Dial-A-Book Inc. solely for the personal use of visitors to this web site.
"About this title" may belong to another edition of this title.
Instructions for revocation/
Standard Business Terms and customer information/ data protection declaration
Revocation right for consumers
(A ?consumer? is any natural person who concludes a legal transaction which, to an overwhelming extent, cannot be attributed to either his commercial or independent professional activities.)
Instructions for revocation
Revocation right
You have the right to revoke this contract within one month without specifying any reasons.
The revocation period is one month...
If you are a consumer you can withdraw from the contract in accordance with the following. Consumer means any natural person who is acting for purposes which are outside his trade, business, craft or profession.
Information regarding the right of withdrawal
Statutory right to withdraw
You have the right to withdraw from this contract within 14 days without giving any reason.
The withdrawal period will expire after 14 days from the day on which you acquire, or a third party other than the carrier and indicated by you acquires, physical possession of the last good or the last lot or piece.
To exercise the right of withdrawal, electronically fill in and submit a clear statement on our website, under "My Purchases" in "My Account". We will communicate to you an acknowledgement of receipt of such a withdrawal on a durable medium (e.g. by e-mail) without delay.
To meet the withdrawal deadline, it is sufficient for you to send your communication concerning your exercise of the right of withdrawal before the withdrawal period has expired.
Effects of withdrawal
If you withdraw from this contract, we will reimburse to you all payments received from you, including the costs of delivery (except for the supplementary costs arising if you chose a type of delivery other than the least expensive type of standard delivery offered by us).
We may make a deduction from the reimbursement for loss in value of any goods supplied, if the loss is the result of unnecessary handling by you.
We will make the reimbursement without undue delay, and not later than 14 days after the day on which we are informed about your decision to withdraw from this contract.
We will make the reimbursement using the same means of payment as you used for the initial transaction, unless you have expressly agreed otherwise; in any event, you will not incur any fees as a result of such reimbursement.
We may withhold reimbursement until we have received the goods back, or you have supplied evidence of having sent back the goods, whichever is the earliest.
You shall send back the goods or hand them over to moluna, Greven, Germany, without undue delay and in any event not later than 14 days from the day on which you communicate your withdrawal from this contract to us. The deadline is met if you send back the goods before the period of 14 days has expired. You will have to bear the direct cost of returning the goods. You are only liable for any diminished value of the goods resulting from the handling other than what is necessary to establish the nature, characteristics and functioning of the goods.
Exceptions to the right of withdrawal
The right of withdrawal does not apply to:
II. Kundeninformationen
Moluna GmbH
Engberdingdamm 27
48268 Greven
Deutschland
Telefon: 02571/5698933
E-Mail: abe@moluna.de
Wir sind nicht bereit und nicht verpflichtet, an Streitbeilegungsverfahren vor Verbraucherschlichtungsstellen teilzunehmen.
Die technischen Schritte zum Vertragsschluss, der Vertragsschluss selbst und die Korrekturmöglichkeiten erfolgen nach Maßgabe der Regelungen "Zustandekommen des Vertrages" unserer Allgemeinen Geschäftsbedingungen (Teil I.).
3.1. Vertragssprache ist deutsch .
3.2. Der vollständige Vertragstext wird von uns nicht gespeichert. Vor Absenden der Bestellung können die Vertragsdaten über die Druckfunktion des Browsers ausgedruckt oder elektronisch gesichert werden. Nach Zugang der Bestellung bei uns werden die Bestelldaten, die gesetzlich vorgeschriebenen Informationen bei Fernabsatzverträgen und die Allgemeinen Geschäftsbedingungen nochmals per E-Mail an Sie übersandt.
Die wesentlichen Merkmale der Ware und/oder Dienstleistung finden sich im jeweiligen Angebot.
5.1. Die in den jeweiligen Angeboten angeführten Preise sowie die Versandkosten stellen Gesamtpreise dar. Sie beinhalten alle Preisbestandteile einschließlich aller anfallenden Steuern.
5.2. Die anfallenden Versandkosten sind nicht im Kaufpreis enthalten. Sie sind über eine entsprechend bezeichnete Schaltfläche auf unserer Internetpräsenz oder im jeweiligen Angebot aufrufbar, werden im Laufe des Bestellvorganges gesondert ausgewiesen und sind von Ihnen zusätzlich zu tragen, soweit nicht die versandkostenfreie Lieferung zugesagt ist.
5.3. Die Ihnen zur Verfügung stehenden Zahlungsarten sind unter einer entsprechend bezeichneten Schaltfläche auf unserer Internetpräsenz oder im jeweiligen Angebot ausgewiesen.
5.4. Soweit bei den einzelnen Zahlungsarten nicht anders angegeben, sind die Zahlungsansprüche aus dem geschlossenen Vertrag sofort zur Zahlung fällig.
6.1. Die Lieferbedingungen, der Liefertermin sowie gegebenenfalls bestehende Lieferbeschränkungen finden sich unter einer entsprechend bezeichneten Schaltfläche auf unserer Internetpräsenz oder im jeweiligen Angebot.
Soweit im jeweiligen Angebot oder unter der entsprechend bezeichneten Schaltfläche keine andere Frist angegeben ist, erfolgt die Lieferung der Ware innerhalb von 3-5 Tagen nach Vertragsschluss (bei vereinbarter Vorauszahlung jedoch erst nach dem Zeitpunkt Ihrer Zahlungsanweisung).
6.2. Soweit Sie Verbraucher sind ist gesetzlich geregelt, dass die Gefahr des zufälligen Untergangs und der zufälligen Verschlechterung der verkauften Sache während der Versendung erst mit der Übergabe der Ware an Sie übergeht, unabhängig davon, ob die Versendung versichert oder unversichert erfolgt. Dies gilt nicht, wenn Sie eigenständig ein nicht vom Unternehmer benanntes Transportunternehmen oder eine sonst zur Ausführung der Versendung bestimmte Person beauftragt haben.
Sind Sie Unternehmer, erfolgt die Lieferung und Versendung auf Ihre Gefahr.
Die Mängelhaftung richtet sich nach der Regelung "Gewährleistung" in unseren Allgemeinen Geschäftsbedingungen (Teil I).
letzte Aktualisierung: 23.10.2019
| Order quantity | 16 to 45 business days | 16 to 45 business days |
|---|---|---|
| First item | £ 41.98 | £ 41.98 |
Delivery times are set by sellers and vary by carrier and location. Orders passing through Customs may face delays and buyers are responsible for any associated duties or fees. Sellers may contact you regarding additional charges to cover any increased costs to ship your items.