Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 1/41
Remote Network Analysis
- I know what you know -
Torsten Höfler
htor@cs.tu-chemnitz.de
Remote Network Analysis - I know what you know - Torsten Hfler - - PowerPoint PPT Presentation
Remote Network Analysis - I know what you know - Torsten Hfler htor@cs.tu-chemnitz.de Torsten Hfler, 21. November 2004 Remote Network Analysis - p. 1/41 Outline Outline 1. Introduction Introduction 2. Passive Analysis Passive
Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 1/41
htor@cs.tu-chemnitz.de
Introduction Passive Analysis Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 2/41
Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 3/41
Introduction
Passive Analysis Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 4/41
Introduction
Passive Analysis Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 5/41
Introduction
Passive Analysis Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 6/41
Introduction
Passive Analysis Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 7/41
Introduction
Passive Analysis Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 8/41
Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 9/41
Introduction Passive Analysis
Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 10/41
⇒ different possibilities:
Introduction Passive Analysis
Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 11/41
Introduction Passive Analysis
Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 12/41
Introduction Passive Analysis
Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 13/41
Introduction Passive Analysis
Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 14/41
Introduction Passive Analysis
Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 15/41
Introduction Passive Analysis
Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 16/41
Introduction Passive Analysis
Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 17/41
Introduction Passive Analysis
Active Analysis Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 18/41
Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 19/41
Introduction Passive Analysis Active Analysis
Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 20/41
Introduction Passive Analysis Active Analysis
Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 21/41
Introduction Passive Analysis Active Analysis
Advanced Methods Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 22/41
Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 23/41
Introduction Passive Analysis Active Analysis Advanced Methods
Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 24/41
Introduction Passive Analysis Active Analysis Advanced Methods
Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 25/41
Introduction Passive Analysis Active Analysis Advanced Methods
Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 26/41
Introduction Passive Analysis Active Analysis Advanced Methods
Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 27/41
Introduction Passive Analysis Active Analysis Advanced Methods
Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 28/41
Introduction Passive Analysis Active Analysis Advanced Methods
Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 29/41
Introduction Passive Analysis Active Analysis Advanced Methods
Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 30/41
→ IP-ID counts up globally!
Introduction Passive Analysis Active Analysis Advanced Methods
Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 31/41
Introduction Passive Analysis Active Analysis Advanced Methods
Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 32/41
e.g. portscan of wald.informatik.tu-chemnitz.de (134.109.184.40): archimedes: # hping2 wald.informatik.tu-chemnitz.de -p 22 -A HPING wald.informatik.tu-chemnitz.de (eth0 134.109.184.40): A set ... len=46 ip=134.109.184.40 ttl=55 DF id=0 sport=22 fl ags=R seq=0 win=0 rtt=64.3 ms len=46 ip=134.109.184.40 ttl=55 DF id=0 sport=22 fl ags=R seq=1 win=0 rtt=64.8 ms
⇒ port 22 (ssh) open
archimedes: # hping2 wald.informatik.tu-chemnitz.de -p 81 -A HPING wald.informatik.tu-chemnitz.de (eth0 134.109.184.40): A set ... ICMP Port Unreachable from ip=134.109.184.40 name=wald ICMP Port Unreachable from ip=134.109.184.40 name=wald
⇒ port 81 closed
are the pool-computers switched on during the weekend? HPING donau.hrz.tu-chemnitz.de (eth0 134.109.72.177): SA set ... len=46 ip=134.109.72.177 ttl=55 DF id=0 sport=82 fl ags=R seq=0 win=0 rtt=62.5 ms len=46 ip=134.109.72.177 ttl=55 DF id=0 sport=82 fl ags=R seq=1 win=0 rtt=65.4 ms
⇒ yes ;o)
Introduction Passive Analysis Active Analysis Advanced Methods
Prevention Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 33/41
Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 34/41
Introduction Passive Analysis Active Analysis Advanced Methods Prevention
Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 35/41
⇒ appropriate values on other Operating Systems (e.g.
Introduction Passive Analysis Active Analysis Advanced Methods Prevention
Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 36/41
⇒ Grsecurity
⇒ IP Personality
⇒ own modifi cations in kernel sources
Introduction Passive Analysis Active Analysis Advanced Methods Prevention
Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 37/41
Introduction Passive Analysis Active Analysis Advanced Methods Prevention
Questions Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 38/41
Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 39/41
Introduction Passive Analysis Active Analysis Advanced Methods Prevention Questions
Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 40/41
Introduction Passive Analysis Active Analysis Advanced Methods Prevention Questions
Torsten Höfler, 21. November 2004 Remote Network Analysis - p. 41/41