-
CSE543 - Introduction to Computer and Network Security Page
CSE543 - Introduction to Computer and Network Security Module: Network Security
Professor Patrick McDaniel Fall 2008
1
CSE543 - Introduction to Computer and Network Security Module: - - PowerPoint PPT Presentation
CSE543 - Introduction to Computer and Network Security Page
1
CSE543 - Introduction to Computer and Network Security Page
2
CSE543 - Introduction to Computer and Network Security Page
3
CSE543 - Introduction to Computer and Network Security Page
4
CSE543 - Introduction to Computer and Network Security Page
5
CSE543 - Introduction to Computer and Network Security Page
6
CSE543 - Introduction to Computer and Network Security Page
7
CSE543 - Introduction to Computer and Network Security Page
8
CSE543 - Introduction to Computer and Network Security Page
9
CSE543 - Introduction to Computer and Network Security Page
10
CSE543 - Introduction to Computer and Network Security Page
11
CSE543 - Introduction to Computer and Network Security Page
12
CSE543 - Introduction to Computer and Network Security Page
13
CSE543 - Introduction to Computer and Network Security Page
PSU.local Presentations > finger megan Login: megan Name: Megan Smith Directory: /Users/megan Shell: /bin/bash Last login Mon 23 Aug 13:19 (EDT) on console No Mail. No Plan. PSU.local Presentations >
14
CSE543 - Introduction to Computer and Network Security Page
15
CSE543 - Introduction to Computer and Network Security Page
Host (resolver)
16
CSE543 - Introduction to Computer and Network Security Page
17
CSE543 - Introduction to Computer and Network Security Page
18
CSE543 - Introduction to Computer and Network Security Page
19
CSE543 - Introduction to Computer and Network Security Page
20
CSE543 - Introduction to Computer and Network Security Page
21
CSE543 - Introduction to Computer and Network Security Page
22
http://artfiles.art.com/images/-/Philip-Gendreau/Jolly-Roger-the-Pirates-Flag-Giclee-Print-C10274009.jpeg
CSE543 - Introduction to Computer and Network Security Page
23
CSE543 - Introduction to Computer and Network Security Page
24
CSE543 - Introduction to Computer and Network Security Page
SMTP FTP
HTTP
25
CSE543 - Introduction to Computer and Network Security Page
26
CSE543 - Introduction to Computer and Network Security Page
27
CSE543 - Introduction to Computer and Network Security Page
28
CSE543 - Introduction to Computer and Network Security Page
29
CSE543 - Introduction to Computer and Network Security Page
30
CSE543 - Introduction to Computer and Network Security Page
IPv4 Header
Next Header Length Reserved Security Parameter Index Authentication Data (variable number of 32-bit words)
31
Authentication Header Higher Level Protocol Data
CSE543 - Introduction to Computer and Network Security Page
32
IP Header AH Header MAC Payload
AH Packet Encrypted Authenticated
IP Header Payload
CSE543 - Introduction to Computer and Network Security Page
– Type of crypto checksum, how large it is, and how it is computed – Really the policy for the packet
– Hash of packet contents include IP header as as specified by SPI – Treat transient fields (TTL, header checksum) as zero
Headers and data being sent Key Key Secret Key
MD5 Hash
33
CSE543 - Introduction to Computer and Network Security Page
34
CSE543 - Introduction to Computer and Network Security Page
IP Header Other IP Headers ESP Header Encrypted Data
Security Parameter Identifier (SPI) Opaque Transform Data, variable length Unencrypted Encrypted
Security Parameters Index (SPI) Initialization Vector (optional) Replay Prevention Field (incrementing count) Payload Data (with padding) Authentication checksum
35
CSE543 - Introduction to Computer and Network Security Page
36
IP Header ESP Header Payload ESP Trailer MAC
ESP Packet Encrypted Authenticated
IP Header Payload
CSE543 - Introduction to Computer and Network Security Page
37
CSE543 - Introduction to Computer and Network Security Page
38
CSE543 - Introduction to Computer and Network Security Page
39
CSE543 - Introduction to Computer and Network Security Page
Physical Link Logical Link (IPsec)
40
CSE543 - Introduction to Computer and Network Security Page
Physical Link Logical Link (IPsec)
41
CSE543 - Introduction to Computer and Network Security Page
Physical Link Logical Link (IPsec)
42
CSE543 - Introduction to Computer and Network Security Page
43
CSE543 - Introduction to Computer and Network Security Page
44
CSE543 - Introduction to Computer and Network Security Page
45
CSE543 - Introduction to Computer and Network Security Page
46
CSE543 - Introduction to Computer and Network Security Page
47
CSE543 - Introduction to Computer and Network Security Page
500,000,000 1,000,000,000 1,500,000,000 2,000,000,000 2,500,000,000 3,000,000,000 3,500,000,000 4,000,000,000 4,500,000,000 5,000,000,000
48
CSE543 - Introduction to Computer and Network Security Page
49
CSE543 - Introduction to Computer and Network Security Page
50
CSE543 - Introduction to Computer and Network Security Page
51
CSE543 - Introduction to Computer and Network Security Page
52
500,000,000 1,000,000,000 1,500,000,000 2,000,000,000 2,500,000,000 3,000,000,000 3,500,000,000 4,000,000,000 4,500,000,000 5,000,000,000CSE543 - Introduction to Computer and Network Security Page
Shield
Network Traffic
53
CSE543 - Introduction to Computer and Network Security Page
54
CSE543 - Introduction to Computer and Network Security Page
55
CSE543 - Introduction to Computer and Network Security Page
addresses (e.g., 192.168.27.254)
Host Host Host Host Host Host Host Host Host
adversary Broadcast victim
56
CSE543 - Introduction to Computer and Network Security Page
57
CSE543 - Introduction to Computer and Network Security Page
58
CSE543 - Introduction to Computer and Network Security Page
59
CSE543 - Introduction to Computer and Network Security Page
60
CSE543 - Introduction to Computer and Network Security Page
61
CSE543 - Introduction to Computer and Network Security Page
62
CSE543 - Introduction to Computer and Network Security Page
63
CSE543 - Introduction to Computer and Network Security Page
64
CSE543 - Introduction to Computer and Network Security Page
65
CSE543 - Introduction to Computer and Network Security Page
66
CSE543 - Introduction to Computer and Network Security Page
67
CSE543 - Introduction to Computer and Network Security Page
68
CSE543 - Introduction to Computer and Network Security Page
R1 R2 R3
69
CSE543 - Introduction to Computer and Network Security Page
70