network security major problems network security major problems why firewall? why firewall? problems...

24

Upload: theodora-blankenship

Post on 18-Jan-2016

237 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is
Page 2: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

Network Security Major ProblemsNetwork Security Major Problems Why Firewall?Why Firewall? Problems with FirewallsProblems with Firewalls What is an Intrusion Detector? What is an Intrusion Detector? Problems with Intrusion DetectorsProblems with Intrusion Detectors What is a Content Management Firewall?What is a Content Management Firewall? HACKTRAP FeaturesHACKTRAP Features Future TrendsFuture Trends DemoDemo

TopicsTopics

Page 3: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

Network Security Major ProblemsNetwork Security Major Problems

Providing information confidentiality.Providing information confidentiality.

Providing data integrity.Providing data integrity.

Protecting network services Protecting network services availability.availability.

Page 4: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

Why Firewall?Why Firewall?

Page 5: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

Problems with FirewallsProblems with Firewalls

Checks packet headers ONLYChecks packet headers ONLY

Does NOT detect header intrusionsDoes NOT detect header intrusions

Page 6: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is
Page 7: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

What is an Intrusion Detector?What is an Intrusion Detector?

A tool that detects intrusion A tool that detects intrusion attempts.attempts.

Alerts the network administrator with Alerts the network administrator with detected intrusions.detected intrusions.

Page 8: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

Problems with Intrusion DetectorsProblems with Intrusion Detectors

Does NOT take permanent actionsDoes NOT take permanent actions

Does NOT block specific IPs and Does NOT block specific IPs and PORTsPORTs

Page 9: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

Intrusion Detector

Page 10: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

What is a Content Management What is a Content Management Firewall? Firewall?

A new approach of firewalls.A new approach of firewalls.

Combines the features of BOTH Firewalls Combines the features of BOTH Firewalls and Intrusion Detectors.and Intrusion Detectors.

Checks NOT ONLY packet’s header but Checks NOT ONLY packet’s header but contents as well.contents as well.

Blocks the source of the detected Blocks the source of the detected intrusions.intrusions.

Page 11: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

HACKTRAPA content management firewall

IS OUR SOLUTION

Page 12: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

HACKTRAP

Page 13: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

HACKTRAP FeaturesHACKTRAP Features

Three Security LevelsThree Security Levels• FRA (FRA (Fast Response ActionFast Response Action) ) Firewall RulesFirewall Rules

• IDS (IDS (Intrusion Detection systemIntrusion Detection system) Alerts) Alerts

• ISS (Integrated security system) ISS (Integrated security system) feedback from IDS to FRAfeedback from IDS to FRA

Page 14: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

External Network

External Network

Internal NetworkInternal Network

ISSISS

FRAFRA IDSIDS

1

2

3

1 3

HACKTRAP ModelHACKTRAP Model

Generate FRA

Page 15: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

HACKTRAP FeaturesHACKTRAP Features

Dynamic Action GenerationDynamic Action Generation

FWRule

IDSPRule

IDMPRule

FRActions

Page 16: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

• Administrator point of viewAdministrator point of view Add and Remove types of attacks.Add and Remove types of attacks. Different types of alerts : popup messages, Data Different types of alerts : popup messages, Data

base, XML format ,TCP dump format.base, XML format ,TCP dump format. Restrict and unrestrict hosts accessing firewall .Restrict and unrestrict hosts accessing firewall . Close and open different services (ports) for outside Close and open different services (ports) for outside

hosts. hosts.

• Developer point of viewDeveloper point of view Intrusions can be easily implementedIntrusions can be easily implemented

HACKTRAP FeaturesHACKTRAP Features

Page 17: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

Future WorkFuture Work

Enhance for better performance.Enhance for better performance. Using iptables with the ipchains.Using iptables with the ipchains.

Using ACID to make a good analysis Using ACID to make a good analysis on the intrusion detection output to on the intrusion detection output to the data base and display neat the data base and display neat graphs representing it.graphs representing it.

Adding another output modules such Adding another output modules such as email & SMSas email & SMS..

Page 18: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

InternetInternetLANLAN

Hacker

Web Server

Unix Server

Page 19: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

InternetInternet

x y

yz

xy

Packet forwarding

And

NAT (Masquerading)

x y

x V

Z V

Page 20: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

rule4

rule3

rule2rule1

Input

chain rule4

rule3

rule2

Forward

chain

rule4

rule3

rule2

Output

chainrouter

d

e

m

a

s

q

log host

Local process

DENY ACCEPT

ACCEPTACCEPT

Page 21: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is
Page 22: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

+

preprocessor Attacks rules

Input chain

Forward chain

Output chain

Log file

Samba alert database Alert

file

Page 23: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

DemoDemo

Page 24: Network Security Major Problems Network Security Major Problems Why Firewall? Why Firewall? Problems with Firewalls Problems with Firewalls What is

InternetInternetLANLAN

Hacker

Windows

Lunix

HACKTRAP