-
CSE543 - Introduction to Computer and Network Security Page
CSE543 Computer and Network Security Module: Network Security
Professor Trent Jaeger Fall 2010
1
CSE543 Computer and Network Security Module: Network Security - - PowerPoint PPT Presentation
CSE543 - Introduction to Computer and Network Security Page
1
CSE543 - Introduction to Computer and Network Security Page
2
CSE543 - Introduction to Computer and Network Security Page
3
CSE543 - Introduction to Computer and Network Security Page
4
CSE543 - Introduction to Computer and Network Security Page
5
CSE543 - Introduction to Computer and Network Security Page
6
CSE543 - Introduction to Computer and Network Security Page
7
CSE543 - Introduction to Computer and Network Security Page
8
CSE543 - Introduction to Computer and Network Security Page
9
CSE543 - Introduction to Computer and Network Security Page
10
CSE543 - Introduction to Computer and Network Security Page
11
CSE543 - Introduction to Computer and Network Security Page
networks within (a typically small) domain
propagated quickly
(a whole lot of people are trying)
12
CSE543 - Introduction to Computer and Network Security Page
13
CSE543 - Introduction to Computer and Network Security Page
14
CSE543 - Introduction to Computer and Network Security Page
15
CSE543 - Introduction to Computer and Network Security Page
16
CSE543 - Introduction to Computer and Network Security Page
PSU.local Presentations > finger megan Login: megan Name: Megan Smith Directory: /Users/megan Shell: /bin/bash Last login Mon 23 Aug 13:19 (EDT) on console No Mail. No Plan. PSU.local Presentations >
17
CSE543 - Introduction to Computer and Network Security Page
18
CSE543 - Introduction to Computer and Network Security Page
19
root edu psu.edu cse.psu.edu Host Resolver
ada.cse.ps.edu? 216.10.243.112
CSE543 - Introduction to Computer and Network Security Page
20
a-root-servers.net a.gtld-servers.org ns-patrickmcdaniel.org ISP Nameserver User PC
www.patrickmcdaniel.org? redirect www.patrickmcdaniel.org? redirect www.patrickmcdaniel.org? 207.140.168.131 www.patrickmcdaniel.org? 207.140.168.131
2 3 4 5 6 7 1 8
www.patrickmcdaniel.org = 207.140.168.131
CSE543 - Introduction to Computer and Network Security Page
21
CSE543 - Introduction to Computer and Network Security Page
22
CSE543 - Introduction to Computer and Network Security Page
23
CSE543 - Introduction to Computer and Network Security Page
24
CSE543 - Introduction to Computer and Network Security Page
25
CSE543 - Introduction to Computer and Network Security Page
26
CSE543 - Introduction to Computer and Network Security Page
27
CSE543 - Introduction to Computer and Network Security Page
28
CSE543 - Introduction to Computer and Network Security Page
29
CSE543 - Introduction to Computer and Network Security Page
30
CSE543 - Introduction to Computer and Network Security Page
31
CSE543 - Introduction to Computer and Network Security Page
SMTP FTP
HTTP
32
CSE543 - Introduction to Computer and Network Security Page
33
Header Payload Header Payload
encrypted MACed
Header
Header Payload Header Payload
encrypted MACed
CSE543 - Introduction to Computer and Network Security Page
34
CSE543 - Introduction to Computer and Network Security Page
35
CSE543 - Introduction to Computer and Network Security Page
36
CSE543 - Introduction to Computer and Network Security Page
37
CSE543 - Introduction to Computer and Network Security Page
38
CSE543 - Introduction to Computer and Network Security Page
39
IP Header AH Header MAC Payload
AH Packet Encrypted Authenticated
IP Header Payload
CSE543 - Introduction to Computer and Network Security Page
IPv4 Header
Next Header Length Reserved Security Parameter Index Authentication Data (variable number of 32-bit words)
40
Authentication Header Higher Level Protocol Data
CSE543 - Introduction to Computer and Network Security Page
– Type of crypto checksum, how large it is, and how it is computed – Really the policy for the packet
– Hash of packet contents include IP header as as specified by SPI – Treat transient fields (TTL, header checksum) as zero
Headers and data being sent Key Key Secret Key
MD5 Hash
41
CSE543 - Introduction to Computer and Network Security Page
42
CSE543 - Introduction to Computer and Network Security Page
43
IP Header ESP Header Payload ESP Trailer MAC
ESP Packet Encrypted Authenticated
IP Header Payload
CSE543 - Introduction to Computer and Network Security Page
IP Header Other IP Headers ESP Header Encrypted Data
Security Parameter Identifier (SPI) Opaque Transform Data, variable length Unencrypted Encrypted
Security Parameters Index (SPI) Initialization Vector (optional) Replay Prevention Field (incrementing count) Payload Data (with padding) Authentication checksum
44
CSE543 - Introduction to Computer and Network Security Page
45
CSE543 - Introduction to Computer and Network Security Page
46
CSE543 - Introduction to Computer and Network Security Page
Physical Link Logical Link (IPsec)
47
CSE543 - Introduction to Computer and Network Security Page
Physical Link Logical Link (IPsec)
48
CSE543 - Introduction to Computer and Network Security Page
Physical Link Logical Link (IPsec)
49
CSE543 - Introduction to Computer and Network Security Page
50
A B C D E A B C D E
VLAN 1: A,B VLAN 2: C,D,E