Add the rest of university notes
This commit is contained in:
366 files changed
+9844
-110
No files matched your search
@@ -0,0 +1,161 @@
|
||||
# Network Security
|
||||
|
||||
### TCP/IP
|
||||
|
||||
- Each protocol carries the protocol in the layer above by appending headers to it
|
||||
|
||||

|
||||
|
||||
- IP is connection-less and state-less
|
||||
- Best effort service
|
||||
- No delivery guarantee
|
||||
- No order guarantee
|
||||
- IPv4 No guaranteed security support
|
||||
- IPv6 security support is guaranteed - IPSec
|
||||
|
||||
#### IPSec
|
||||
|
||||
- Optional in IPv4, mandatory support in IPv6
|
||||
- Two major security mechanisms
|
||||
- IP Authentication Header (AH)
|
||||
- IP Encapsulation Security Payload (ESP)
|
||||
- Does not contain any mechanisms to prevent traffic analysis
|
||||
|
||||
##### Encapsulation Security Payload
|
||||
|
||||
- Includes an additional header within the IP packet that describes what encryption and authentication is in use
|
||||
|
||||

|
||||
|
||||
##### Security Parameter Index
|
||||
|
||||
- Stores security parameters e.g. crypto protocol and keys
|
||||
- Established by Internet Security association and key management protocol (ISAKMP) during the Internet Key Exchange (IKE) handshake
|
||||
- Uses Diffie-Hellman for key exchange
|
||||
- The SPI references the entry in a table that corresponds to this session’s parameters
|
||||
|
||||
- ESP uses either *transport* or *tunnel* modes
|
||||
|
||||
Transport mode
|
||||
|
||||

|
||||
|
||||
Tunnel mode
|
||||
|
||||

|
||||
|
||||
#### Transport vs Tunnel
|
||||
|
||||
- Transport mode simply encrypts packets, providing host-to-host encryption but using the original header
|
||||
- Prevents contents being read, but does not stop traffic analysis or manipulation of the header
|
||||
|
||||
- Tunnel mode (usually gateway-to-gateway) protects some segment of a channel with encryption
|
||||
- Provides some resistance to traffic analysis, and completely protects manipulation of the payload
|
||||
- VPNs are commonly implemented this way
|
||||
|
||||

|
||||
|
||||
### Network Attacks
|
||||
|
||||
#### ARP
|
||||
|
||||
- ARP is a protocol used to obtain physical MAC addresses for given IPs
|
||||
- It is used prior to constructing IP and TCP packets for communication
|
||||
- Network layer
|
||||
|
||||

|
||||
|
||||
##### ARP Cache Poisoning
|
||||
|
||||
- We can simply send an unrequested ARP reply, and overwrite the MAC address in a hosts ARP cache with our own
|
||||
|
||||

|
||||
|
||||
##### ARP Protection
|
||||
|
||||
- Some OSs ignore unsolicited ARP requests, or can be configured to use ARP differently
|
||||
- Some software, such as intrusion detection packages, will include ARP spoofing detection
|
||||
- Maintain a log of current MAC:IP assignments and ARP requests / replies
|
||||
|
||||
#### DNS
|
||||
|
||||
- DNS translates domain names into IP addresses
|
||||
- DNS packets are UDP
|
||||
- Stateless on the transport layer
|
||||
- DNS resolvers will cache the IP for awhile
|
||||
|
||||
##### DNS Spoofing
|
||||
|
||||
- If we poison the cache of a nameserver people are using, we can replace a website lookup with our IP
|
||||
- Can be achieved through prior ARP cache poisoning, a reply flood or a Kaminsky attack
|
||||
|
||||

|
||||
|
||||
###### DNS Protection
|
||||
|
||||
- *Random query numbers* help protect against spoof replies
|
||||
- Since the Kaminsky attack, most resolvers now *randomise the source port* too
|
||||
- DNSSEC aims to tackle DNS exploits by authenticating the name server and providing integrity for the messages
|
||||
|
||||
### Denial of Service
|
||||
|
||||
- A denial of service attack is an attempt to make a machine or network resource unavaliable to its authorised / intended users
|
||||
- This will usually involve flooding a machine with enough requests that it can’t server its legitimate purpose
|
||||
- ping flood
|
||||
- A distributed denial of service occurs where there is more than one attacking machine
|
||||
|
||||
#### TCP Syn Flooding
|
||||
|
||||
- Attacker initiates a genuine connection but then immediately breaks it
|
||||
- Attack never finishes 3-way handshake
|
||||
- Victim is busy with the timeout
|
||||
- Attack initiates large number of syn requests
|
||||
- Victim reaches it’s half-open connection limit
|
||||
|
||||

|
||||
|
||||
#### Amplification Attacks
|
||||
|
||||
- Regular attacks are your bandwidth vs your targets
|
||||
- Amplification attacks utilise some aspect of a network protocol to *increase the bandwidth* of an attack
|
||||
|
||||

|
||||
|
||||
##### Smurf and Fraggle Attacks
|
||||
|
||||
- Smurf attacks broadcast an ICMP ping request to a router, but with a spoofed IP belonging to the victim
|
||||
- A fraggle attack is identical in principle, using UDP echo packets
|
||||
|
||||

|
||||
|
||||
##### DNS Amplification
|
||||
|
||||
- Recursive resolvers respond to DNS queries then return a response
|
||||
- This response can be many times larger than the query
|
||||
|
||||

|
||||
|
||||
- In an ideal world, all DNS resolvers would:
|
||||
- Use an authorised list of requesters
|
||||
- e.g. ISPs allowing requests from only their customers
|
||||
- Egress filtering
|
||||
- Many DNS servers are set up incorrectly, and will happily amplify your traffic - **Open resolvers**
|
||||
- Botnets maintain lists of these open resolvers and there are projects attempting to shut these down
|
||||
|
||||
##### NTP Amplification
|
||||
|
||||
- NTP is a protocol for synchronsing time between machines
|
||||
- Extremely similar to DNS amplification
|
||||
- `MON_GETLIST` request returns the list of the last 600 contacts
|
||||
- Gives 200x amplification
|
||||
- `MON_GETLIST` is deprecated because of this attack
|
||||
|
||||
##### Slow Loris
|
||||
|
||||
- Opens numerous connections to a server
|
||||
- Begin an HTTP request
|
||||
- Send just enough traffic to stop the connection from closing
|
||||
- Apache2 creates a new thread for each connection
|
||||
- More connections slow the server down significantly
|
||||
- The attack only sends bytes of data at a time making it extremely easy to do
|
||||
|
||||
Reference in new issue
Block a user