-
CSE543 - Introduction to Computer and Network Security Page
CSE543 Computer and Network Security Module: Network Security
Professor Trent Jaeger
1
CSE543 Computer and Network Security Module: Network Security - - PowerPoint PPT Presentation
CSE543 - Introduction to Computer and Network Security Page
1
CSE543 - Introduction to Computer and Network Security Page
2
CSE543 - Introduction to Computer and Network Security Page
3
CSE543 - Introduction to Computer and Network Security Page
4
CSE543 - Introduction to Computer and Network Security Page
5
CSE543 - Introduction to Computer and Network Security Page
6
CSE543 - Introduction to Computer and Network Security Page
7
CSE543 - Introduction to Computer and Network Security Page
8
CSE543 - Introduction to Computer and Network Security Page
9
CSE543 - Introduction to Computer and Network Security Page
QS, then he can get S to accept whatever data it wants (useful if doing IP authentication, e.g., “rsh”)
10
CSE543 - Introduction to Computer and Network Security Page
11
CSE543 - Introduction to Computer and Network Security Page
In Proceedings of ACM Conference on Computer and Communications Security (CCS) 2012, Raleigh, NC.
In Proceedings of IEEE Security and Privacy (Oakland) 2012, San Francisco, CA.
12
CSE543 - Introduction to Computer and Network Security Page
without any authentication
13
CSE543 - Introduction to Computer and Network Security Page
14
CSE543 - Introduction to Computer and Network Security Page
15
CSE543 - Introduction to Computer and Network Security Page
16
CSE543 - Introduction to Computer and Network Security Page
17
root edu psu.edu cse.psu.edu Host Resolver
ada.cse.ps.edu? 216.10.243.112
CSE543 - Introduction to Computer and Network Security Page
18
a-root-servers.net a.gtld-servers.org ns-patrickmcdaniel.org ISP Nameserver User PC
www.patrickmcdaniel.org? redirect www.patrickmcdaniel.org? redirect www.patrickmcdaniel.org? 207.140.168.131 www.patrickmcdaniel.org? 207.140.168.131
2 3 4 5 6 7 1 8
www.patrickmcdaniel.org = 207.140.168.131
CSE543 - Introduction to Computer and Network Security Page
19
CSE543 - Introduction to Computer and Network Security Page
20
CSE543 - Introduction to Computer and Network Security Page
21
CSE543 - Introduction to Computer and Network Security Page
22
*the original attack exploited poor ID selection
CSE543 - Introduction to Computer and Network Security Page
responses, or are just plain patient, you can mount these attacks.
23
CSE543 - Introduction to Computer and Network Security Page
inside your network
24
CSE543 - Introduction to Computer and Network Security Page
25 Symptoms Best Current Practices Functions Attacks Dataset Open Recursive Resolvers BCP 140/RFC 5358 Naming Infrastructure DNS Amplification Global DNS Source Port Randomization RFC 5452 Naming Infrastructure DNS Cache Poisoning Global Consistent A and PTR records RFC 1912 Naming Infrastructure
BGP Misconfiguration RFC 1918, RFC 6598 Routing Infrastructure
Egress Filtering BCP 38/RFC 2827 Transit
Untrusted HTTPS Certificates RFC 5246, RFC 2459 Web Application Man-in-the-middle Global Open SMTP Mail Relays RFC 2505 Mail Application SPAM Global Publicly Available out-of-band Management Devices Manufacturer’s Guideline Server Compromising Hosts Global
TABLE I. SUMMARY OF MISMANAGEMENT METRICS AND THE THIRD-PARTY, PUBLIC DATA SOURCES USED FOR VALIDATION
CSE543 - Introduction to Computer and Network Security Page
26
CSE543 - Introduction to Computer and Network Security Page
27
CSE543 - Introduction to Computer and Network Security Page
28