Communication security over the Internet The big picture Me - - PowerPoint PPT Presentation

communication security over the internet the big picture
SMART_READER_LITE
LIVE PREVIEW

Communication security over the Internet The big picture Me - - PowerPoint PPT Presentation

Communication security over the Internet The big picture Me Internet Resource Internet Server Client Attack vectors MAN DNS LAN Client Internet Back Bone Router Networking WWW overview MITM (Man In The Middle) 3 2 4 5 LAN


slide-1
SLIDE 1

Communication security

  • ver the Internet
slide-2
SLIDE 2

Me Internet Resource Attack vectors Server Client Internet

The big picture

slide-3
SLIDE 3

DNS WWW Router Client LAN MAN Internet Back Bone

Networking

  • verview
slide-4
SLIDE 4

Internet LAN Router 1 2 3 1 2 3 4 5 MITM (Man In The Middle)

AV: Spoofing

slide-5
SLIDE 5

Internet W-LAN Router Sniffer

AV: Sniffing Use WPA! Don't use WEP!

slide-6
SLIDE 6

HTTP network capture

slide-7
SLIDE 7

Enc ncryp ypt Decrypt

Encryption

slide-8
SLIDE 8

Internet %#$ %#$ a a b b c c %#$ a a b b c c ???!!!

Encrypted channel

slide-9
SLIDE 9

HTTPS Capture

slide-10
SLIDE 10
  • 1. requ

quest

  • 2. certificate
  • 3. keys
  • 4. da

data Client Server

HTTPS (TLS/SSL)

slide-11
SLIDE 11

AV: Phishing

my-bank.com my-bamk.com %#$ % % # # $ $

slide-12
SLIDE 12

AV: DNS

my-bank.com my-bank.com % % # # $ $ Root NS NS

  • 1. where is “m-b”

Resolver where? Other NS there! where? there! where? NS there!

slide-13
SLIDE 13
  • 1. requ

quest

  • 2. certificate
  • 4. keys
  • 5. da

data

  • 3. verify

delegate s s i i g g n n Client Server CA CA

SSL / Certificates

slide-14
SLIDE 14

SSL in action (1)

slide-15
SLIDE 15

SSL in action (2)

slide-16
SLIDE 16

SSL in action (3)

slide-17
SLIDE 17

SSL in action (4)

slide-18
SLIDE 18

SSL missing in action ???!!!

slide-19
SLIDE 19

??? Huh ???

slide-20
SLIDE 20

Check “SHA1 Fingerprint”!!! Don't rely on “MD5 Fingerprint”!!!

slide-21
SLIDE 21

The explanation!

slide-22
SLIDE 22

Email security

Browser Outlook HTTPS IMAPS My-Mail Extra-Mail ??? ;)

Use GnuPG!

slide-23
SLIDE 23

Keep focus!