Network Security Traceback Attack and React in the United States Department of Defense Network - Softcover

Machie, Edmond K.

 
9781466985735: Network Security Traceback Attack and React in the United States Department of Defense Network

Inhaltsangabe

Network Security and how to traceback, attack and react to network vulnerability and threats. Concentration on traceback techniques for attacks launched with single packets involving encrypted payloads, chaff and other obfuscation techniques. Due to the development of various tools and techniques to increase the source of network attacks, our interest will include network forensics, with the goal of identifying the specific host which launched the attack and cause denial of services (DoS). Also we will include tracing an attack that would compromise the confidentiality and integrity of information on the Intelligence Community (IC) network, which includes the NIPRNET, SIPRNET, JWICS, and IC enclaves. Deliverables will be technical reports, software, demonstrations, and results of experiments, which will provide evidence and metrics. The emergence of hybrid worm attacks utilizing multiple exploits to breach security infrastructures has forced enterprises to look into solutions that can defend their critical assets against constantly shifting threats.

Die Inhaltsangabe kann sich auf eine andere Ausgabe dieses Titels beziehen.

Auszug. © Genehmigter Nachdruck. Alle Rechte vorbehalten.

NETWORK SECURITY TRACEBACK ATTACK AND REACT IN THE UNITED STATES DEPARTMENT OF DEFENSE NETWORK

By EDMOND K. MACHIE

Trafford Publishing

Copyright © 2013 EDMOND K. MACHIE
All rights reserved.
ISBN: 978-1-4669-8573-5

Contents

Dedication.................................................................xi
Introduction...............................................................xiii
PART ONE: NETWORK SECURITY.................................................1
CHAPTER I: NETWORK ATTACK TRACEBACK........................................3
CHAPTER II: SECURITY ARCHITECTURE AND ANALYSIS.............................10
CHAPTER III: CISCO INTRUSION DETECTION SYSTEM (IDS) NETWORK MODULE FOR
CISCO ACCESS ROUTERS-INTERGRATES TRADITIONAL INTRUSION DETECTION INTO THE
ROUTER USING CISCO INTRUSION PREVENTION SYSTEM (IPS) SENSOR................
16
PART TWO: NETWORK VULNERABILITY ASSESSMENT.................................23
CHAPTER IV: NETWORK VULNERABILITY ASSESSMENT NETWORK SECURITY THREAT AND
VULNERABILITIES............................................................
25
CHAPTER V: DISTRIBUTED DENIAL OF SERVICE DETECT AND REACT IN THE UNITED
STATES DEPARTMENT OF DEFENSE NETWORK.......................................
31
PART THREE: SOFTWARE SECURITY AND WIRELESS NETWORKS........................43
CHAPTER VI: LIGHTWEIGHT MIDDLEWARE ENVIRONMENT FOR AD-HOC WIRELESS
NETWORKS...................................................................
45
CHAPTER VII: AUDITING SOFTWARE AND TOOLS—ARCHITECTURAL AND SOURCE-LEVEL....49
PART FOUR: INFORMATION SYSTEM FOR MANAGERS—LEGAL AND ETHICAL MANAGEMENT IN
INFORMATION SECURITY.......................................................
57
CHAPTER VIII: CYBERSECURITY AND THE TRUST ISSUES IN THE ONLINE
TRANSACTION................................................................
59
CHAPTER IX: THE SARBANES-OXLEY ACT of 2002—LITERATURE REVIEW...............64
CHAPTER X: THE SARBANES-OXLEY ACT of 2002—SECTION 404: MANAGEMENT
ASSESSMENT OF THE INTERNAL CONTROL OF ALL PUBLICLY-TRADE COMPANIES.........
70
CHAPTER XI: SARBANES-OXLEY ACT OF 2002.....................................79
CHAPTER XII: DATA PROTECTION LAW AND LEGISLATION IN THE UNITED STATES AND
THE EUROPEAN UNION.........................................................
84
CHAPTER XIII: INFORMATION ASSURANCE POLICY PLANNING & ANALYSIS.............89
PART FIVE: SECURITY FORENSICS..............................................97
CHAPTER XIV: COMPANIES SPECIALIZING IN COMPUTER FORENSICS SUMMARY REPORT...99
CHAPTER XV: AFFIDAVIT CRITIQUE—REVIEW OF THE HANSSEN AFFIDAVIT—CRITIQUE OF
ITS CONTENT AS IT PERTAINS TO COMPUTER EVIDENCE............................
105
PART SIX: GUIDING PRINCIPLES OF SECURITY OF WEB APPLICATION AND SAMPLES
TEST QUESTIONS AND ANSWERS.................................................
111
CHAPTER XVI: GUIDING PRINCIPLES OF SECURITY OF WEB APPLICATION.............113
CHAPTER XVII: SAMPLE TEST QUESTIONS AND ANSWERS............................123
Index......................................................................179

Excerpt

CHAPTER 1

NETWORK ATTACK TRACEBACK


I. INTRODUCTION

While increasing in number, sophistication, and severity, the networkattacks on governmental, business, academic, and critical infrastructurenetworks need immediate attention. In this research, prevention, detectionand reaction are the truism of the network security vulnerability andassessment. Variable aspects or processes are addressed with regardto attacks. Investigated attacks include, data collection, which refers tothe collection of data from multiple operating systems. Vatis states that,"Investigators also need tools to automate the collection of data files frommultiple operating systems in the victims' network or the network beingattacked."


II. ATTACK TRACEBACK IN A NETWORK ATTACK

The UNIX System is more complex than Windows, and is necessary for thedigital evidence examiner. Usually UNIX is configured to print, log, and storeuser data (e.g. files, e-mail, passwords) on remote location systems.

One of the options to trace back the attack in the network is MappingNetwork Topology. This provides a solution to automate the process ofdeveloping the map of the network quickly and accurately. It maps thevictim's network during the preliminary stage of a network-attack tracebackto assess the extent of the attack.

What follows are the specific network attack data recovery tools toautomate the digital evidence recovery process; capturing residentmemory data is also part of network attack traceback, as well as analyzingexcessively large media storage devices.

Michael A. Vatis described Log Analysis and Reporting as automated log fileanalysis and developing graphical reporting. Furthermore, he defined LogCompilation as recognizing and importing preliminary investigation data,recognizing and importing logs across a network, reconstructing alteredor damaged logs, placing log data into an organized timeline, organizeoutput to a common and portable format. Thus, Vitas presents IP Tracingand Real-Time Interception as critical for tracking cyber attackers. Accordingto the reporting, the distributed denial of service attacks or (DDoS) originand location of the attacker remain hidden. Non-technical issues such asunderemployed technologies to counter attacks utilizing spoofing and lackof record keeping by Internet Service Providers (ISP) hamper the tracing ofIP addresses. The real-time interception of digital data is a use of specializedforensic solutions for retrieving, storing, and analyzing very large mediastorage devices compromised by network attacks.

The other important point is that data collection from multiple operatingsystems is demonstrated because of computers' usage of several differentoperating systems to perform different tasks. Data collections from severalcomputers are relevant to understand how a network was compromised. Ithappens that Windows operating systems dominated their caseloads in theuse of the types of operating systems encountered in the traceback attack.

UNIX and Linux operating systems were encountered less frequently. MacOS (through version 9) and Mac OSX were seen the least during the lastthree years, but still on occasion by some investigators. Solutions that canautomate the collection of data from multiple operating systems are stillneeded, as well as solutions to identify and report system configurationsand file locations.

There is a need of tools that will help analyze the attack data across multipleplatforms, regardless of the platform that the investigator is working on.After data collection, this tool will reduce time and focus on analysis ratherthan collection.


III. DENIAL OF SERVICES IN THE NETWORK ATTACK—(DOS)

Symantec Security Response supports the thought that Denial of Service(DoS) attack is not a virus, but a method hackers use to prevent or...

„Über diesen Titel“ kann sich auf eine andere Ausgabe dieses Titels beziehen.

Weitere beliebte Ausgaben desselben Titels

9781466985759: Network Security Traceback Attack and React in the United States Department of Defense Network

Vorgestellte Ausgabe

ISBN 10:  1466985755 ISBN 13:  9781466985759
Verlag: Trafford Publishing, 2013
Hardcover