Types of Attacks
The types of cyber attackers and their motivations are too numerous and varied to list. They
range from the novice hacker who is attracted by the challenge, to the highly skilled
Vulnerabilities, Threats, and Attacks 9
professional who targets an organization for a specific purpose (such as organized crime,
industrial espionage, or state-sponsored intelligence gathering). Threats can originate from
outside the organization or from inside. External threats originate outside an organization
and attempt to breach a network either from the Internet or via dialup access. Internal
threats originate from within an organization and are usually the result of employees or other
personnel who have some authorized access to internal network resources. Studies indicate
that internal attacks perpetrated by disgruntled employees or former employees are
responsible for the majority of network security incidents within most organizations.
There are three major types of network attacks, each with its own specific goal:
■ Reconnaissance attack—An attack designed not to gain access to a system or network
but only to search for and track vulnerabilities that can be exploited later.
■ Access attack—An attack designed to exploit vulnerability and to gain access to a system
on a network. After gaining access, the goal of the user is to
— Retrieve, alter, or destroy data.
— Add, remove, or change network resources, including user access.
— Install other exploits that can be used later to gain access to the network.
■ Denial of service (DoS) attack—An attack designed solely to cause an interruption on a
computer or network.
Reconnaissance Attacks
The goal of this type of attack is to perform reconnaissance on a computer or network. The
goal of this reconnaissance is to determine the makeup of the targeted computer or network
and to search for and map any vulnerability. A reconnaissance attack can indicate the
potential for other, more-invasive attacks. Many reconnaissance attacks are written into
scripts that allow novice hackers or script kiddies to launch attacks on networks with a few
mouse clicks. Here are some of the more common reconnaissance attacks:
■ Domain Name Service (DNS) query—Provides the unauthorized user with such
information as what address space is assigned to a particular domain and who owns that
domain.
■ Ping sweep—Tells the unauthorized user how many hosts are active on the network. It
is possible to drop ICMP packets at the perimeter devices, but this occurs at the expense
of network troubleshooting.
■ Vertical scan—Scans the service ports of a single host and requests different services at
each port. This method enables the unauthorized user to determine what type of
operating system and services are running on the computer.
10 Chapter 1: Network Security
■ Horizontal scan—Scans an address range for a specific port or service. A very common
horizontal scan is the FTP sweep. This is done by scanning a network segment to look
for replies to connection attempts on port 21.
■ Block scan—A combination of the vertical scan and the horizontal scan. In other words,
it scans a network segment and attempts connections on multiple ports of each host on
that segment.
IT Certification CCIE,CCNP,CCIP,CCNA,CCSP,Cisco Network Optimization and Security Tips
Vulnerabilities, Threats, and Attacks
Vulnerabilities, Threats, and Attacks
Attackers who attempt to access a system or network use various methods to find and exploit
specific targets. This section discusses the basic concepts of a cyber attack.
Vulnerabilities
To understand cyber attacks, you must remember that computers, no matter how advanced,
are still just machines that operate based on predetermined instruction sets. Operating
systems and other software packages are simply compiled instruction sets that the computer
uses to transform input into output. A computer cannot determine the difference between
authorized input and unauthorized input unless this information is written into the
instruction sets. Any point in a software package at which a user can alter the software or
gain access to a system (that was not specifically designed into the software) is called a
vulnerability. In most cases, a hacker gains access to a network or computer by exploiting a
vulnerability. It is possible to remotely connect to a computer on any of 65,535 ports.
Different applications configure a system to listen on specific ports. It is possible to scan a
computer to determine which ports are listening, and what applications are running on that
system. By knowing what vulnerabilities are associated with which applications, you can
determine what vulnerabilities exist and how to exploit them. As hardware and software
technology continue to advance, the “other side” continues to search for and discover new
vulnerabilities. For this reason, most software manufacturers continue to produce patches
for their products as vulnerabilities are discovered.
Threats
Potential threats are broken into the following two categories:
■ Structured threats—Threats that are preplanned and focus on a specific target. A
structured threat is an organized effort to breach a specific network or organization.
■ Unstructured threats—Threats that are random and tend to be the result of hackers
looking for a target of opportunity. These threats are the most common because an
abundance of script files are available on the Internet to users who want to scan
unprotected networks for vulnerabilities. Because the scripts are free and run with
minimal input from the user, they are widely used across the Internet. Many unstructured
threats are not of a malicious nature or for any specific purpose. The people who carry
them out are usually just novice hackers looking to see what they can do.
Attackers who attempt to access a system or network use various methods to find and exploit
specific targets. This section discusses the basic concepts of a cyber attack.
Vulnerabilities
To understand cyber attacks, you must remember that computers, no matter how advanced,
are still just machines that operate based on predetermined instruction sets. Operating
systems and other software packages are simply compiled instruction sets that the computer
uses to transform input into output. A computer cannot determine the difference between
authorized input and unauthorized input unless this information is written into the
instruction sets. Any point in a software package at which a user can alter the software or
gain access to a system (that was not specifically designed into the software) is called a
vulnerability. In most cases, a hacker gains access to a network or computer by exploiting a
vulnerability. It is possible to remotely connect to a computer on any of 65,535 ports.
Different applications configure a system to listen on specific ports. It is possible to scan a
computer to determine which ports are listening, and what applications are running on that
system. By knowing what vulnerabilities are associated with which applications, you can
determine what vulnerabilities exist and how to exploit them. As hardware and software
technology continue to advance, the “other side” continues to search for and discover new
vulnerabilities. For this reason, most software manufacturers continue to produce patches
for their products as vulnerabilities are discovered.
Threats
Potential threats are broken into the following two categories:
■ Structured threats—Threats that are preplanned and focus on a specific target. A
structured threat is an organized effort to breach a specific network or organization.
■ Unstructured threats—Threats that are random and tend to be the result of hackers
looking for a target of opportunity. These threats are the most common because an
abundance of script files are available on the Internet to users who want to scan
unprotected networks for vulnerabilities. Because the scripts are free and run with
minimal input from the user, they are widely used across the Internet. Many unstructured
threats are not of a malicious nature or for any specific purpose. The people who carry
them out are usually just novice hackers looking to see what they can do.
Overview of Network Security
Overview of Network Security
In the past, the term information security was used to describe the physical security measures
used to keep vital government or business information from being accessed by the public and
to protect it against alteration or destruction. These measures included storing valuable
documents in locked filing cabinets or safes and restricting physical access to areas where
those documents were kept. With the proliferation of computers and electronic media, the
old way of accessing data changed. As technology continued to advance, computer systems
were interconnected to form computer networks, allowing systems to share resources,
including data.
The ultimate computer network, which interconnects almost every publicly accessible
computer network, is the Internet. Although the methods of securing data have changed
dramatically, the concept of network security remains the same as that of information
security.
Because computers can warehouse, retrieve, and process tremendous amounts of data, they
are used in nearly every facet of our lives. Computers, networks, and the Internet are integral
parts of many businesses. Our dependence on computers continues to increase as businesses
and individuals become more comfortable with technology and as technology advances
make systems more user-friendly and easier to interconnect.
A single computer system requires automated tools to protect data on that system from users
who have local system access. A computer system that is on a network (a distributed system)
requires that the data on that system be protected not only from local access but also from
unauthorized remote access and from interception or alteration of data during transmission
between systems. Network security is not a single product, process, or policy, but rather a
combination of products and processes that support a defined policy. Network security is the
implementation of security devices, policies, and processes to prevent unauthorized access to
network resources or alteration or destruction of resources or data.
In the past, the term information security was used to describe the physical security measures
used to keep vital government or business information from being accessed by the public and
to protect it against alteration or destruction. These measures included storing valuable
documents in locked filing cabinets or safes and restricting physical access to areas where
those documents were kept. With the proliferation of computers and electronic media, the
old way of accessing data changed. As technology continued to advance, computer systems
were interconnected to form computer networks, allowing systems to share resources,
including data.
The ultimate computer network, which interconnects almost every publicly accessible
computer network, is the Internet. Although the methods of securing data have changed
dramatically, the concept of network security remains the same as that of information
security.
Because computers can warehouse, retrieve, and process tremendous amounts of data, they
are used in nearly every facet of our lives. Computers, networks, and the Internet are integral
parts of many businesses. Our dependence on computers continues to increase as businesses
and individuals become more comfortable with technology and as technology advances
make systems more user-friendly and easier to interconnect.
A single computer system requires automated tools to protect data on that system from users
who have local system access. A computer system that is on a network (a distributed system)
requires that the data on that system be protected not only from local access but also from
unauthorized remote access and from interception or alteration of data during transmission
between systems. Network security is not a single product, process, or policy, but rather a
combination of products and processes that support a defined policy. Network security is the
implementation of security devices, policies, and processes to prevent unauthorized access to
network resources or alteration or destruction of resources or data.
Network Security
Network Security
Rather than jump directly into what you need to know for the Cisco Securing Networks
with PIX and ASA (642-522) examination, this chapter presents some background
information about network security and its integral role in business today. You need to
understand this information because it is the basis for CCSP Certification and is a
common theme throughout the five CCSP certification exams.
The term network security defines an extremely broad range of very complex subjects.
To understand the individual subjects and how they relate to each other, it is important
for you first to look at the “big picture” and get an understanding of the importance of
the entire concept. Much of an organization’s assets consist of data and computer
resources that are interconnected and must be protected from unauthorized access. There
are many different ways to ensure that network assets are adequately protected. The key
is to correctly balance the business need with the requirement for security.
How to Best Use This Chapter
This chapter will give you an understanding of the general principles of network security.
It will give you the foundation to understand the specifics of how the Cisco Security
Appliance family of firewalls is incorporated into a network architecture.
“Do I Know This Already?” Quiz
The purpose of the “Do I Know This Already?” quiz is to help you decide if you really
need to read the entire chapter. If you already intend to read the entire chapter, you do
not necessarily need to answer these questions now.
The ten-question quiz, derived from the major sections in the “Foundation and
Supplemental Topics” portion of the chapter, helps you determine how to spend your
limited study time.
Table 1-1 outlines the major topics discussed in this chapter and the “Do I Know This
Already?” quiz questions that correspond to those topics.
Rather than jump directly into what you need to know for the Cisco Securing Networks
with PIX and ASA (642-522) examination, this chapter presents some background
information about network security and its integral role in business today. You need to
understand this information because it is the basis for CCSP Certification and is a
common theme throughout the five CCSP certification exams.
The term network security defines an extremely broad range of very complex subjects.
To understand the individual subjects and how they relate to each other, it is important
for you first to look at the “big picture” and get an understanding of the importance of
the entire concept. Much of an organization’s assets consist of data and computer
resources that are interconnected and must be protected from unauthorized access. There
are many different ways to ensure that network assets are adequately protected. The key
is to correctly balance the business need with the requirement for security.
How to Best Use This Chapter
This chapter will give you an understanding of the general principles of network security.
It will give you the foundation to understand the specifics of how the Cisco Security
Appliance family of firewalls is incorporated into a network architecture.
“Do I Know This Already?” Quiz
The purpose of the “Do I Know This Already?” quiz is to help you decide if you really
need to read the entire chapter. If you already intend to read the entire chapter, you do
not necessarily need to answer these questions now.
The ten-question quiz, derived from the major sections in the “Foundation and
Supplemental Topics” portion of the chapter, helps you determine how to spend your
limited study time.
Table 1-1 outlines the major topics discussed in this chapter and the “Do I Know This
Already?” quiz questions that correspond to those topics.
Conclusions
Conclusions
Wired Equivalent Privacy (WEP) isn't. The protocol's problems are a result of misunderstanding of some cryptographic primitives and therefore combining them in insecure ways. These attacks point to the importance of inviting public review from people with expertise in cryptographic protocol design; had this been done, the problems stated here would have surely been avoided.
Wired Equivalent Privacy (WEP) isn't. The protocol's problems are a result of misunderstanding of some cryptographic primitives and therefore combining them in insecure ways. These attacks point to the importance of inviting public review from people with expertise in cryptographic protocol design; had this been done, the problems stated here would have surely been avoided.
Subscribe to:
Posts (Atom)