| Summary of this unit The network is the entry point of the application. It provides the first layer of gateway guard to control access to various servers in the environment. For example, a server uses its own operating system gateway guard for protection, but it is very important to prevent the server from being damaged by attacks from the network layer. This module describes network security by device, so that you can focus on the configuration points. To comply with the consistent philosophy of this guidance, this module will use methods for analyzing potential threats. Without threat analysis, security cannot be correctly applied. This module focuses on the software of the drive network hardware (which is responsible for delivering ASP. NET applications. The end of this unit is "snapshot of the security network", which provides readers with a benchmark for evaluating their own solutions. TargetYou can use this Unit:
| • |
Improve the security of network components (routers, firewalls, and switches. |
| • |
Reinforce router configurations to make it easier to recover from attacks. |
| • |
Measure the test taker's knowledge about the application's firewall filters and policies. |
| • |
Understand the advantages and disadvantages of creating a peripheral network. |
| • |
Use the provided snapshots to list security network features. |
| • |
Measure the test taker's knowledge about the countermeasures to deal with common network threats, including information collection, sniffing, spoofing, session hijacking, and denial of service. |
ApplicabilityThis module applies to the following products and technologies:
| • |
Vro |
| • |
Firewall |
| • |
Vswitch |
How to use this unitThis module provides methods and steps to protect network security. The methods can be adjusted based on the reader's own situation. The steps are used to put the methods into practice. Maximum benefit from this unit:
| • |
Read"Threats and Countermeasures"Unit.This allows you to better understand the potential threats to Web applications. |
| • |
Use snapshots. Table 3 ending with this unitProvides a snapshot of the security network. You can use this table as a reference when configuring the network. |
| • |
Use Checklist. Use the checklist: protect network security to quickly evaluate and determine the required steps. The checklist also helps you complete each step. |
| • |
Use the detailed technical information provided by the vendor to implement this Guide. This unit guide is not specific to a specific network hardware or software vendor. Please refer to the vendor's documentation for specific instructions on how to implement the countermeasures provided by this unit. |
OverviewThe network is the entry point of the application. It provides the first layer of gateway guard to control access to various servers in the environment. The server uses its own operating system gateway guard for protection, but it is very important to prevent the server from being damaged by attacks from the network layer. It is equally important to make sure that the gateway guard of the network is not replaced by the counterfeiter or reconfigured. In short, network security includes protecting the data transmitted by network devices and devices. The basic network components that act as front-line gateway Guard include routers, firewalls, and switches. Figure 1 shows these core components.
Figure 1. network components: routers, firewalls, and switches Threats and CountermeasuresAttackers often search for poorly configured network devices for exploitation. Common Vulnerabilities include vulnerable default installation settings, open portal access control, and unpatched devices. The following are high-level network threats:
| • |
Information Collection |
| • |
Sniffing |
| • |
Spoofing |
| • |
Session hijacking |
| • |
Denial of Service |
Understanding the threats that can affect the network helps apply effective countermeasures. Information Collection Information collection attacks can expose detailed information about network topologies, system configurations, and network devices. Attackers can use this information to conduct concentrated attacks on discovered vulnerabilities. Vulnerabilities Common vulnerabilities that make the network vulnerable include:
| • |
Insecure nature of TCP/IP protocol groups |
| • |
Configuration Information provided by the title |
| • |
Public services that should be blocked |
Attack Common Information Collection attacks include:
| • |
UseTracertNetwork Topology Detection |
| • |
UseTelnetOpen the port to obtain the title |
| • |
Use port scan to detect opened ports |
| • |
Use broadcast requests to enumerate hosts on the subnet |
Countermeasure The following countermeasures can be taken:
| • |
Use a General Service title to avoid leakage of configuration information such as the software version or name. |
| • |
Use a firewall to shield services that should not be made public. |
Sniffing Sniffing, Also knownListenIs a behavior that monitors network traffic to obtain various data (such as plaintext passwords or configuration information. Through simple Packet sniffing, all plaintext traffic can be easily read. Likewise, lightweight hash algorithms may be cracked, and considered safe loads may be decrypted. Vulnerabilities Common vulnerabilities that make the network vulnerable to data sniffing include:
|