You are on page 1of 103

FIS,2008 Network Security 1

Tng quan v bo mt
FIS,2008 Network Security 2
Ni dung
1. Network overview
2. Security overview
FIS,2008 Network Security 3
S cn thit phi c an ninh mng
Bn cn bo v nhng g
D liu
Ti nguyn
Danh ting
An ninh mng cn phi c gii php tng th
Khng c g gi l an ton tuyt i
FIS,2008 Network Security 4
Cc nguy c tn cng
C mc ch
Khng c mc ch
T bn ngoi
T bn trong
FIS,2008 Network Security 5
Nguy c tn cng - c mc ch



C mc tiu c th
c h tr: Thi gian, tin bc, cng c
C kin thc su v mt lnh vc no

FIS,2008 Network Security 6
Nguy c tn cng Khng c mc ch
Tn cng ch v thch
Khng c kin thc
su rng
i khi ch l nn nhn
k khc li dng tn
cng (DDoS)

FIS,2008 Network Security 7
Nguy c tn cng T bn ngoi





K tn cng l ngi khng c php truy
nhp
T bn ngoi h thng mng
FIS,2008 Network Security 8

Nguy c tn cng T bn trong




T bn trong h thng mng
K tn cng l nhng ngi dng c php
truy cp mng
70% nguy c tn cng l t bn trong
FIS,2008 Network Security 9
Network overview
FIS,2008 Network Security 10
Network overview
H tng mng
Dch v mng
FIS,2008 Network Security 11
H tng mng
M hnh mng
Router
Switch
....
FIS,2008 Network Security 12
M hnh mng OSI v TCP/IP
International Organization for
Standardization (ISO)
m bo s tng thch gia
cc h thng, thit b ca cc
nh sn xut khc nhau
L mt m hnh tham chiu
FIS,2008 Network Security 13
M hnh mng OSI v TCP/IP
US Department of
Defense.
Tr thnh m hnh
thc hin ph bin


TCP/IP (US DoD)
FIS,2008 Network Security 14
TCP/IP Layers & Protocols
Layers
Protocols
Network Access = Host-to-network = Data link + Physical
Network = Internet
FIS,2008 Network Security 15
Internet Data
application
transport
network
link
physical
application
transport
network
link
physical
application
transport
network
link
physical
application
transport
network
link
physical
network
link
physical
data
data
FIS,2008 Network Security 16
Network Data Flow Review
FIS,2008 Network Security 17
H tng mng
M hnh mng
Router
Switch
....
FIS,2008 Network Security 18
Cu to ca b nh tuyn
CPU : iu khin mi hot ng ca Router
ROM : Cha cc chng trnh t ng kim
tra
RAM : Gi cc bng nh tuyn, cc vng
m, tp tin cu hnh khi chy, cc thng s
m bo hot ng ca b nh tuyn khc.
NVRAM (None-volatile RAM): l ni cha
file cu hnh khi ng (Startup-Configure ),
khng b mt thng tin khi mt ngun.
Flash : l thit b nh / lu tr c kh nng
xo v ghi c, khng mt d liu khi ct
ngun. H iu hnh ca b nh tuyn c
cha y. Khi khi ng router s t c
ROM np IOS trc khi np file Startup-
Config trong NVRAM.
H iu hnh (IOS): m ng hot ng
ca b nh tuyn.
FIS,2008 Network Security 19
Router
FIS,2008 Network Security 20
Router vai tr ca b nh tuyn
Vai tr ca router trong mng ni b LAN (Local Area
Network):
Kt ni cc mng ni b
Gim kch thc qung b broadcast domain, gim cc lu
lng mng khng cn thit.

Router
` `
`
`
` `
`
`
FIS,2008 Network Security 21
Router vai tr ca b nh tuyn
Vai tr ca router trong mng din rng WAN (Wide
Area network): Kt ni mng LAN vi Internet.
internet
Router
` `
`
`
Modem
LAN
FIS,2008 Network Security 22
Router vai tr ca b nh tuyn
FIS,2008 Network Security 23
Switch nhu cu kt ni
Trao i d liu ?
`
`
`
FIS,2008 Network Security 24
Switch gii php ban u
`
`
FIS,2008 Network Security 25
Switch kh khn
`
`
`
Kt ni
...
FIS,2008 Network Security 26
Switch - Hub
FIS,2008 Network Security 27
Switch - Hub
FIS,2008 Network Security 28
Switch Hub, vn ?
ng
FIS,2008 Network Security 29
Switch - Switch
Star topology
Truyn vi tc ti a
(full-duplex, dedicated access):

+ A to A
+ B to B
+ C to C
FIS,2008 Network Security 30
Switch - Switch
FIS,2008 Network Security 31
Hub + switch + router
FIS,2008 Network Security 32
Qu trnh x l Packet ti
switch, router v host

FIS,2008 Network Security 33
Tng kt mt s c tnh ca hub,
router, switch
hubs routers switches
traffic
isolation
no yes yes
plug & play yes no yes
optimal
routing
no yes no
cut
through
yes no yes


FIS,2008 Network Security 34
Network Overview

Dch v
FIS,2008 Network Security 35
DNS nh ngha
DNS (Domain Name System)
L h thng dch tn min (d nh i vi con
ngi) sang a ch IP m my tnh lm vic.
Domain
i vi Internet min l tp hp cc my tnh c
chung v tr a l hay lnh vc kinh doanh
FIS,2008 Network Security 36
Cc thnh phn DNS
DNS Domain Name Space
Zones
Name Servers
DNS ca Internet
FIS,2008 Network Security 37
DNS Khng gian tn min
DNS root (topmost level) ca Internet Domain
namespace c qun l bi Internet
Corporation for Assigned Names and
Numbers (ICANN).
C 3 loi top-level domains tn ti
Organization domains
Geographical domains
Reverse domains: c nhng domain c bit, tn
l in-addr.arpa, s dng cho nh x t a ch IP
sang tn.
FIS,2008 Network Security 38
DNS Khng gian tn min Internet
11/2000, ICANN cng b thm 7 top-level
domain:
.biz
.coop
.info
.museum
.name
.pro
.aero
FIS,2008 Network Security 39
DNS Khng gian tn min Internet
H thng DNS l mt h thng c cu trc
phn cp.
Gc ca Domain Root Domain nm trn cng v
c k hiu .
Root Domain (root layer): Gm 13 siu my tnh c
tc cc cao.
Top layer: bao gm cc tn min .com, .vn,...
Second level: c th l subdomain (vd: .com.vn) hoc
hostname (vd: microsoft.com.)


FIS,2008 Network Security 40
DNS Khng gian tn min Internet
FIS,2008 Network Security 41
DNS Khng gian tn min Internet
Cng thc tng qut ca tn min
Hostname + Domain Name + Root
Domain Name = Subdomain. Second Level Domain. Top Level Domain. Root
FIS,2008 Network Security 42
DNS Khng gian tn min Internet
V d
Webserver.training.microsoft.com.
Trong :
Webserver l tn Host
Training l Subdomain
Microsoft l Second Level Domain
Com l Top Level Domain
Du chm l Root

FIS,2008 Network Security 43
DNS Khng gian tn min Internet
FIS,2008 Network Security 44
DNS Khng gian tn min ni b
Mt t chc c th c khng gian tn min
ni b c lp vi khng gian tn min ca
Internet.
Private name c th khng c phn gii
trn Internet.
V d: mycompany.local
FIS,2008 Network Security 45
Zone trong DNS
H thng tn min c chia ra cc phn
nh hn d qun l l cc Zone.
Primary Zone
Mt my ch cha d liu Primary Zone l my
ch c th ton quyn trong vic update d liu
Zone.
Secondary Zone
L mt bn copy ca Primary Zone
FIS,2008 Network Security 46
Name Server
my ch cha d liu Primary Zone
FIS,2008 Network Security 47
DNS Hot ng

FIS,2008
Network Security 48
DNS Cc kiu bn ghi
A (host name): a ch IP -> hostname
PTR (pointer): hostname -> a ch IP
SOA (Start Of Authority): DNS server, u tin c
quyn yu cu tr li DNS client
NS (Name Server): My ch qun l DNS Zone
CNAME: Tn thay th (b danh)
MX: Xc nh mail server nhn mail cho domain
tng ng
.......
FIS,2008 Network Security 49
Mail Khi nim
Electronic Mail (e-mail): Th in t.
L c ch gip gi nhn th qua mng my tnh.
Dng giao thc v (s hiu cng) SMTP (25),
POP3 (110), IMAP(143)
FIS,2008 Network Security 50
Mail hot ng
M hnh thng ip trc tip
Cc thng ip c gi trc tip, ngay lp tc ti
cc my ang hot ng trn mt mng ni b.




from: A
to: D
D
C
B
FIS,2008 Network Security 51
M hnh thng ip th lu

Cc thng ip c gi gin tip ti mt my phc v
ang hot ng trn mt mng ni b.




from: A
to: D
may phuc vu thu
Mail SERVER
B C
D
may nguoi dung
Mail CLIENT
FIS,2008 Network Security 52
M hnh Internet






VDC,
VIETNAM
TOYOTA,JAPAN
KMA-VNU
from: ha@vnu.edu.vn
to: asimo@toyo.com.jp
user name : asimo
password : it2kjp
SMTP
SMTP
POP3
from: hoang@hn.vnn.vn
to: asimo@toyo.com.jp

t ng
chuyn th
SMTP
FIS,2008 Network Security 53
mail SERVER
theo di v
qun l tin
trnh
theo doi quan ly
cac tai khoan thu

cac phan mem thong dung:MDAEMON, MS-EXCHANGE...

FIS,2008 Network Security 54
mail client
thu muc chua thu
danh sach thu
gui/nhan
cac nut chuc nang
so dia chi
hien thi noi dung
thu
cac phan mem thong dung: OUTLOOK EXPRESS, INCREDIT MAIL,...

FIS,2008 Network Security 55
Ti khon th in t
Ti khon ng nhp dch v th in t gm:
tn ngi s dng ng k (user name)
mt khu (password)
a ch th ca ngi s dng sau khi ng k
tn_ng_k@tn_min
V d: iti@kma.edu.vn
- iti l tn ngi s dng ng k,
- kma.edu.vn l tn min ca my phc v th ca hoc
Vin mat ma
- k hiu @ - c c theo ting Anh l at
Cc tn min thng gp: hn.vnn.vn, yahoo.com,...
FIS,2008 Network Security 56
Web M hnh hot ng
Giao thc hot ng l HTTP (HTTPs) cng
mc nh l 80 (443)
Hot ng theo m hnh client server.
Web client (web browse)
Web server l ni lu tr cc website web
client truy cp n.
FIS,2008 Network Security 57
Web M hnh hot ng
M hnh Web n gin

Thng tin
ca cc trang
Web
Internet
Trinh duyet may khach may chu web
HTML
Mo hinh web don gian
FIS,2008 Network Security 58
Web M hnh hot ng
M hnh Web hin nay
Internet
trinh duyet may khach My Host
mo hinh web hien nay
Web server
Database
Server
Application server
FIS,2008 Network Security 59
M hnh tng tc CSDL
thng qua giao din Web
du lieu cua
cac trang web
Internet
nguoi dung co so du lieu
cac giao dien Web
Mo hinh tuong tac csdl thong qua giao dien web
FIS,2008 Network Security 60
Security overview
FIS,2008 Network Security 61
Ni dung
1. M hnh bo mt theo quan nim c in
2. M hnh bo mt X.800
3. Cc nguy c bo mt h thng hin nay
FIS,2008 Network Security 62
Bo mt thng tin
Information security =
Computer security
Network security
+
FIS,2008 Network Security 63
M hnh CIA
C = Confidentiality
I = Integrity
A = Availability
FIS,2008 Network Security 64
Tnh b mt (C)
Gii hn cc i tng c php truy xut
n cc ti nguyn h thng.
Bao gm tnh b mt v ni dung thng tin v
b mt v s tn ti thng tin.
M ha (Encryption) v iu khin truy xut
(Access Control) l c ch m bo tnh b
mt ca h thng.
FIS,2008 Network Security 65
Tnh ton vn (I)
m bo thng tin khng b mt mt hoc
thay i ngoi mun.
Bao gm tnh ton vn v ni dung v ton
vn v ngun gc.
Cc c ch xc thc (peer authentication,
message authentication) c dng
m bo tnh ton vn thng tin.
FIS,2008 Network Security 66
Tnh Sn sng (A)
Tnh sn sng cho cc truy xut hp l.
L c trng c bn nht ca h thng thng
tin.
Cc m hnh bo mt hin i (v d X.800)
khng m bo tnh sn sng.
Tn cng dng DoS/DDoS nhm vo tnh
sn sng ca h thng.
FIS,2008 Network Security 67
Tnh hon thin ca CIA
Khng m bo tnh khng th t chi
hnh vi (non-repudiation).
Khng c s tng quan vi m hnh h
thng m OSI.
=> Cn xy dng m hnh mi.
FIS,2008 Network Security 68
Chin lc AAA
L tp cc c ch nhm xy dng h thng
bo mt theo m hnh CIA.
Access Control.
Authentication.
Auditing.
Phn bit vi thut ng AAA ca Cisco
(Authentication, Authorization, Accouting)
FIS,2008 Network Security 69
Chnh sch bo mt
Tp cc quy c nh ngha cc trng thi an ton
ca h thng.
P: tp hp tt c cc trng thi ca h thng
Q: tp hp cc trng thi an ton theo nh ngha ca policy.
R: tp hp cc trng thi ca h thng sau khi p dng cc
c ch bo mt.
:H thng tuyt i an ton.
Nu khng tn ti trng thi sao cho : h
thng khng an ton.

FIS,2008 Network Security 70
C ch bo mt
Tp hp cc bin php k thut hoc th tc
c trin khai m bo thc thi chnh
sch. V d:
Dng c ch cp quyn trn partition NTFS.
Dng c ch cp quyn h thng (user rights).
a ra cc quy nh mang tnh th tc.
..
FIS,2008 Network Security 71
Xy dng h thng bo mt
1. nh ngha chnh sch bo mt (security
policy).
2. Xy dng c ch bo mt (security
machanism)
FIS,2008 Network Security 72
M hnh bo mt X.800
Xem xt vn bo mt trong tng quan vi
m hnh h thng m OSI theo 3 phng
din:
Security attack
Security mechanism
Security service

FIS,2008 Network Security 73
Security attack
Passive attacks:
Tit l thng tin.
Phn tch lu lng
Ative attacks:
Thay i thng tin.
T chi dch v

FIS,2008 Network Security 74
Security service
Authentication.
Access Control.
Data Confidentiality.
Data Integrity.
Non-repudiation.
Availability????

FIS,2008 Network Security 75
Security mechanism
Encipherment.
Digital Signature.
Access Control.
Data Integrity.
Authentication Exchange.
Traffic padding.
.
FIS,2008 Network Security 76
Cc nguy c bo mt h thng
Cc tn cng c ch ch (attacks).
Cc phn mm ph hoi (malicious code).
FIS,2008 Network Security 77
Tn cng h thng mng
Da vo s h ca h thng.
Da vo cc l hng phn mm.
Da vo l hng ca giao thc.
Tn cng vo c ch bo mt.
Tn cng t chi dch v (DoS/DDoS)
FIS,2008 Network Security 78
Phn mm ph hoi
Virus.
Worm
Logic bomb.
Trojan horse.
Backdoor.
Spammer.
Zoombie.
FIS,2008 Network Security 79
Spyware
FIS,2008 Network Security 80
Case study

Cc hnh thc tn cng mng ph bin
FIS,2008 Network Security 81
Attack Methods
Tn cng thm d
Tn cng truy nhp
Tn cng t chi dch v

FIS,2008 Network Security 82
Attack Methods Thm d
Sniffing (nghe ln)
K tn cng tm cch nghe trm trn ng truyn
thu thp thng tin quan trng nh username/password.
Kh thc hin hn trong mng switch
Thch hp i vi cc thng tin khng c m ho
V d: Ethereal, Dsniff, Packet Inspector
FIS,2008 Network Security 83
Attack Methods Thm d
Ping sweep
Dng kim tra nhng
my tnh no ang tham
gia vo mng.
S dng ICMP echo
reply/request
V d: Superscan, Pinger

FIS,2008 Network Security 84
Attack Methods Thm d
Port sweep
Kim tra trn server
nhng cng no ang m
dch v ang chy l g.
Mt s cng thng dng
HTTP: 80
FTP: 20, 21
SMTP: 25
DNS: 53
V d: Nmap, SuperScan
FIS,2008 Network Security 85
Attack Methods Thm d
Xc nh h iu hnh
K tn cng gi thng tin
kim tra my ch ang
chy h iu hnh no.
Telnet vo h thng, cc
h iu hnh khc nhau
th c tr li khc nhau.
V d: Nmap
FIS,2008 Network Security 86
Attack Methods
Tn cng thm d
Tn cng truy nhp
Tn cng t chi dch v

FIS,2008 Network Security 87
Attack Mothods - Tn cng truy nhp
Relay (truyn li)
Hacker nghe ln trong mng
Mt khu, thng tin chng thc c hacker
ghi li
Hacker thay i thng tin xc thc v truyn
li c gng ng gi ngi dng
V d: Ngi dng gi cu lnh chuyn tin
(qua web) hacker bt c URL , c gng
gi li, khin ngi dng b mt ht tin.

FIS,2008 Network Security 88
Attack Methods - Tn cng truy nhp
Man-in-the-middle
Hacker ng gia lung
d liu gia hai my tnh
Thu thp d liu/Mt khu
Sau thng tin c tr
v my nn nhn
V d: Ethercap

FIS,2008 Network Security 89
Attack Methods - Tn cng truy nhp
Backdoor
L on m chn vo 1
chng trnh cho php
k tn cng c th li
dng cc k h truy
nhp vo h thng.
V d: Sobig, Mydoom li
dng l hng ca
windows, ci backdoor,
vi mc ch gi th
spam.

FIS,2008 Network Security 90
Attack Methods - Tn cng truy nhp
Social Engineering
K tn cng li dng yu t con ngi tn
cng.

FIS,2008 Network Security 91
Attack Methods - Tn cng truy nhp
Khai thc im yu cng ngh
Cng ngh c s pht trin quay vng
Ban u c to ra, a vo s dng, sau sa cha,
cp nht khi pht hin ra c li, im yu.

FIS,2008 Network Security 92
Attack Methods - Tn cng truy nhp
Khai thc im yu cng ngh - im yu ca giao thc
TCP/IP
Tn cng giao thc IP, ICMP tng 3
Tn cng giao thc TCP, UDP tng 4
Tn cng cc ng dng tng 7: SMTP, FTP...



FIS,2008 Network Security 93
Attack Methods - Tn cng truy nhp
Khai thc im yu cng ngh - im yu ca giao thc -
Application
V d: li ca oracle, khin c th b tn cng SQL injection.



FIS,2008 Network Security 94
Attack Methods - Tn cng truy nhp
Khai thc im yu cng ngh - im yu ca h iu hnh
V d: nng quyn user, khai thc li plug and play

FIS,2008 Network Security 95
Attack Methods - Tn cng truy nhp
Khai thc im yu cng ngh - buffer over flow

FIS,2008 Network Security 96
Attack Methods - Tn cng truy nhp
Tn cng ly mt
khu
K tn cng mun
chim ot mt khu
Window: administrator
Unix: root
C hai loi :
brute force
dictionary

FIS,2008 Network Security 97
Attack Methods - Tn cng truy nhp
Tn cng ly mt khu
v d
pwdump2
L0pht Crack
YDump
FIS,2008 Network Security 98
Attack Methods
Tn cng thm d
Tn cng truy nhp
Tn cng t chi dch v

FIS,2008 Network Security 99
Attack Methods - Tn cng t chi dch v
Denial of Service (DoS)
Tn cng t mt my n l
Mc tiu l phong to dch v
FIS,2008 Network Security 100
Attack Methods - Tn cng t chi dch v
Distribution Denial of Service (DDoS)
Tn cng t nhiu my
c s dng tn cng cc mc tiu cng cng
FIS,2008 Network Security 101
Attack Methods - Tn cng t chi dch v
Master
My tnh ca hacker iu khin cc my tnh
khc (Zombie) tn cng nn nhn
Slaver
Dch v chy trn my Zombie cho php hacker
c th iu khin
Victim
My nn nhn
FIS,2008 Network Security 102
Attack Methods - Tng kt
Tn cng thm d
Sniffing
Ping Sweep
Port Sweep
Tn cng truy nhp
Relay
Session Hijacking
MIMD
Backdoor
Social Engineering
Technology
Password
Tn cng t chi dch v
DOS
DDOS

FIS,2008 Network Security 103
Tm kim thng tin
Cc t chc CERT (Computer Emergency
Response Team)
Ti liu o to chng ch Security Plus
(CompTIA).
Ti liu CEH (Cirtified Ethical Hacker).
Tp ch an ton thng tin.
Cc din n bo mt.

You might also like