. , , ,

,,,

, — ,

:

,

-

..

: ..

2009


1. .

1.1

1.2

1.3 .

2.

2.1

2.2

2.3

2.4

2.5 (VPN)

3.

3.1

3.2 Intrusion Detection Systems (IDS)

3.3 IPv6


, , . , . . , , .

, . , , , , , . , , . , , . , , . , . .

. , , , , .

, (Computer Security Institute) , 70% , , 60% .

, , , , .

, " " .

, , . ,

. - - , .


1. .

1.1          

. . ( , ..), .

, .

:

                    .

                    , . Gartner Dataquest . 2009 .

                    , ;

, , , . , , , , . . 70% , , script-kiddies, , . , , , , .

                    , , ;

70-90% , , .

                    ;

, . - . , , . , , . , - , . , , Microsoft Windows Server 2003 14 , 6 . , Microsoft , , , . . , .

                    , .

, , , .

                    , , , , .

, 90% .

( ) - ( ), ( ), , , .

:

                    . , (), . ;

                    . ( , , ) - . . , ;

                    ( ) ( ). , , . . , , , .., .

.

() - , , ( - ).

() , . . , , , , , , .

, . Gartner Group 4 ():

0 :

, ;

;

, ( , ).

, , , / . , . , .


1 :

"" , (, ) () ;

- ;

+ , , , VPN ( ).

2 3 :

, , ;

;

+ , web , IDS ( ), , SSO ( ), PKI ( ) ( , , , , , ).

3 2- :

, CISA ( );

, Datamonitor 5% ;

+ , CSIRT ( ), SLA ( ).

, 2- 3- . 1- 0- . . , , ..

. . . .

Gartner 85%.(0 30 %, 1 55%) 2005.

, 2- 3- Gartner, . , .

. , . , , , . .

, , . . , , . , , . .

, , , , . . , . , , ( ) ( , , , , . .).

, , , . , , , , . , . , , , . , , . . , , , , , , .

1.2          

 

World Wide Web

WWW . , , , , .. World wide web HTTP- .

HTTP- . web- ( , HTML, gif jpeg, .), . , Microsoft Word, Microsoft Word. , , , , , . , , , Microsoft Word Microsoft Excel, .

(active content), Java-, Javascript, ActiveX .., , . , .

, , , www . , , , ..

. , , , .

, :

                    . SMTP, . . "social engineering". , .

                    . , , , . . . Santa.Claus@northpole.org, "" - , . , , . . , , , . . - , , , . .

                    . .

                    . . , , . : SMTP- , (open mail relay - ). , , . , , . , , . , . , . , , . , , , .

                    . (SMTP, POP3, IMAP) , . Sendmail, SMTP- "" , - . POP3- QUALCOMM qpopper IMAP- , (root) . CERT . .

FTP -

FTP . web- FTP. FTP-.

www , , .

DNS -

DNS - - . , , DNS-. , , IP-, web-, , FTP-, .. DNS. , DNS , .

DNS : (, IP- www.microsoft.com). , , , DNS- DNS- , . DNS- , , , .

DNS , . (primary) (secondary) . (). . " " (zone transfer) . , DNS- - (lookups) (zone transfers).

DNS- 53. UDP . UDP , TCP. TCP.

DNS:

                    . DNS , , .

                    DNS spoofing. DNS , . , : . , , . ( IP- ) , . IP- , , . : . , , , DNS IP-. , IP- , , . .

                    Cache Poisoning. : DNS- , , . , MX (mail exchanger) , MX A- mail exchanger' . : DNS-, - . , , . DNS- . , .

                    DNS-. 1998 DNS- BIND , (root) . .


- .

, , . , .

. (, ICQ, IRC) , , . , .

. (ICQ) , . , - , ..

. - .

1.3           .

. , . " ". , ( , ) , , , , .

:

                    , , , . , .

                    . , , .

                    , . , .

, " " . ( 80%), , , .

. . , . : , . , . , , . , , " ", ( ). . , IPX/SPX, - TCP/IP. , , Novell Netware, . . , , TCP/IP . , .

, " " . , . - - , . , , . . , , , , . , , . , , .

. , Microsoft Windows XP Windows NT Workstation, Microsoft Windows NT Server, Novell Netware / Unix-, , , , , , ..

, ( ) . Microsoft . , , .

() - (), , / , , .. () . , , , .


2.

 

2.1

, . . .

,

, , . , .

, - , . , , - . .

, IP- .

, , . , FreeBSD, , (ipfw).

( -), , , . , -.

, - , , .

, , , -, .

- , . , -, - - , - .

2.2

, . , , TCP/IP. , . , , , . , . , , .

. OSI, - OSI . OSI . . 2.1 OSI.



.2.1. OSI

1 , Ethernet.

2 , (LAN). , , . MAC (Media Access Control) . Ethernet - , Ethernet-, - 2.

3 , WAN. 3 IP-; , , , (NAT) , IP- 3.

4 ; 4 . , TCP/IP, , : ; . (5, 6 7) .

, 2- OSI, (stealth), , .

. , .. (frame, ).

:

, .

. , . , .

. 2 OSI. , IP-. , . IP- . , ? , , .

(Packet - filtering firewall) - , , , , . , TCP- IP- ( , .)

                    3

                    ,

                    ( /, /)

                    , ( ),

                    20-

                    : (ACL, access control lists)

(Circuit-level gateway) , . , , . . 2.2 .


. 2.2.

, . (NAT, network address translation). , . IP- - IP-, . , , , . IP- IP-, .

                    4

                    TCP ,

                    , ,

                   

                    : SOCKS

(Application-level gateways) - , , OSI. . 2.3 .

.2.3.

- , TCP/IP.

:

;

, , ;

;

, .

(Proxy).

HTTP-, FTP- .. TCP/IP , . , , , , -, . , , , . -, ), -, .

:

                    7 ;

                    ;

                    , ;

                    ;

                    : Web (http) proxy;


TCP/IP OSI :

. 2.4. /I OSI


. . 2.4 TCP/IP OSI. ; . , , , . . , , , . , 2, 3 4, .

. (NAT), (DHCP) , VPN-, .

VPN-. , , , , VPN-; VPN-, . .

. , 7, . , , . web, Java, JavaScript ActiveX. . , , , ; , .

2.3

, , . . . , .

, :

1.                (Keep It Simple)

, , . , . .

2.               

, , , , . , ; , . : . (switch): , , . , .

3.

. . , , . , , . , .

4.

, , , , . , , - . , , web e-mail , DMZ-.

, . , , , .

DMZ

DMZ- . DMZ- , .

DMZ-

DMZ- , , , , , . , , . . DMZ . 2.5.


. 2.5. DMZ

DMZ- . VPN DMZ-. DMZ- , . , DMZ- , .

Service Leg

DMZ- Service Leg . 2.6. . , , DMZ-. DoS-, , DMZ-. DMZ- DoS- DMZ-, web-, . Service Leg DMZ- DoS-, , DMZ - . , web- DoS-.


. 2.6. Service Leg DMZ

 

DMZ-

DMZ . , DMZ , . DMZ, ; , , .

.2.7.

                    DMZ- , , - , .

                    VPN- ; VPN- .

                    SMTP- .

                    HTTP- , HTTP- -, DMZ.

stateful inspection . :

                    VPN-, ;

                    SMTP- -, ;

                    HTTP- HTTP- SMTP- SMTP-;

                    HTTP- SMTP-;

                    ;

, HTTP- SMTP-. , SMTP- HTTP- , . , .

, :

                    DNS-, ;

                    NAT ;

                    , ;

                    ;

.2.7. DMZ-


, , , , . , , TCP/IP, .

. () , . , , .

, , , , .

, : VPN. business-to-business . , , VPN.

, , , VPN . , . TCP/IP , . . 2.8 .

.2.8. VPN ,

:

, , (hubs) (switches). . , 1 OSI. , .

. , , , . DMZ- .

. 2, .

, , , ; DMZ- .

, - , DoS-, , .

2.4

:

1.                ( )

2.               

3.               

4.                :

5.                :

6.                :

7.               

8.               

9.               

10.          

11.          

12.           ()

.

.

1.                .

:

. , , .

:

. :

                   , ;

                   ;

                   .

:

.

:

                   . , , ;

                   . , , ;

                   /.

2.               

. :

, / .

3.               

. :

. , .

:

.

:

                   ;

                   .

4.                :

:

. () - .

:

.

:

. , . , .

5.                :

:

() ( ) . ;

:

                   , ;

                   - ;

                   , .

:

.

(, ).

:

.

.

6.                :

. :

, , , , .

7.               

:

.

:

.

:

.

.

8.               

:

, .

:

.

:

.

9.               

:

:

                   ;

                   ;

                   ;

                   ;

                   .

:

:

                   ;

                   ;

                   ;

                   ;

                   ;

                   .

:

                   ;

                   ;

                   ;

                   ;

                   ;

                   ;

                   .

10.          

:

:

                   ;

                   ;

                   ;

                   .

:

.

:

.

11.          

:

, , .

:

, , .

:

, , .

12.          

:

:

                   ;

                   ;

                   ;

                   ;

                   ;

                   ;

:

.

:

.

:

                   .


2.5 (VPN)

, , .

. . , . . .

90- - VPN. (Virtual Private Networks).

VPN

VPN : , , , . , () .

, , , , .

VPN

VPN , .

:

                    ;

                    , .

:

                    ;

                    () ;

                    .

. .

, , . . , , , .

, . , , .

, , . . () , . IP, , , , NetBEUI. IP, . .

, . . , , . , , .

, . , , .

VPN

. .

FireWall-1 Check Point Software Technologies. FairWall-1 VPN IPSec. , , , . FireWall-1 Solaris Windows NT 4.0.

, . . 2.9 VPN.

, .


. 2.9. VPN


3.

 

3.1

 

, , . , , , .

, ( ) Windows Firewall, , . ? : .

.

. , , - .

. . , . , / , , . , . , ( ).

,

, . , , , (universal threat management, UTM). , Cisco Systems, Network Engines, Rimapp, SonicWall Symantec.

, . , . , , , , .

, Web-, , . Web Internet. Web-proxy .

, . , 3.2 3.3.

. . , . .

. , . HTTP, SMTP, Instant Messaging (IM).

. (, deep packet inspection) IETF (Internet Engineering Task Force) . DNS, FTP, POP3 SMTP. .

. . .

Windows. . .

Web Winsock. . Winsock , .

SSL (Secure Sockets Layer). SSL. , , SSL.

Microsoft Exchange Server. Exchange Internet Exchange, Outlook Web Access (OWA), Outlook Mobile Access (OMA), Exchange ActiveSync, Secure Exchange RPC RPC over HTTP. , RSA SecurID RSA Security.

VPN . VPN , PPTP, Layer Two Tunneling Protocol (L2TP)/IPsec IPsec . VPN , Blaster Sasser. , ISA Server 2004 Microsoft RPC (remote procedure call) Blaster .

. , TCP/IP . Intrusion Detection System (IDS)/Intrusion Prevention System (IPS) . IDS/IPS .

VPN VPN. VPN VPN . VPN VPN-.

VPN-. VPN ( SSL VPN ). PPTP L2TP/IPsec Windows VPN- Microsoft. () VPN, VPN, IPsec NAT (Network Address Translation). , .

10/100-/ . Ethernet, , . Ethernet, , Internet.

WAN. Internet. .

. . , .

. IP-, . , , .

. , . ( ), ( ) . , .

Internet- . Internet- , Internet. Internet- , . Internet.

. Web- SSL . , ISA Server RDP, FIPS (Federal Information Processing Standard).

. . .

Web- proxy-. Web-. Web- Internet Internet . Web-proxy , , HTTP.

, . . , , .

, . Internet DSL- T , . , NAT. VPN- VPN.

500 . , , Cisco, SonicWall Symantec, 3.1.

, . Internet. . .

, . . . .

SonicWall 170, . SonicWall 170 , . , SonicWall 170 , .

. . , , .

3.1.

SonicWall 170 Cisco PIX 501 Symantec Firewall/VPN
410 495 499
() () ()
Windows
Web Winsock
SSL
Exchange
VPN
VPN VPN
VPN-
10/100-/ 5 4 4
WAN 1 1 1
10 10 15-25
Internet-
Web- Web- Web-
SonicWall Security Processor AMD SC520 ARM7
Web- proxy-

, , . , (, ) . , . , .

.

                   Internet. , , . .

                   , - , (P2P) (Instant Messaging - IM).

                   , , , VPN.

                   , , . , .

                   , , ; .

                   - , .

, , . 3000 . , 3-4 . ( 2 . ) , .

3.2 , . SonicWALL Pro 3060 Cisco PIX-515E-RDMZ Cisco Systems . NS6200 Network Engines Microsoft ISA Server 2004 SGS 5420 Symantec , ( ). NS6200 , , . SGS 5420 : , .

Network Engines Symantec, . , , SonicWALL Cisco.

(, , , , , Web-). - .

Network Engines Symantec , .

                   . . , Internet, . .

                   . , , , , .

                   SSL (Secure Sockets Layer - ). NS6200 ISA Server 2004 SSL . Microsoft Outlook Web Access (OWA) Microsoft SharePoint Portal Server. 3.2, NS6200 SSL- , , .

                   VPN-. VPN . VPN , VPN , , "" . Blaster , . , Blaster, , VPN- - . NS6200 VPN .

. 3.2 , NS6200.

, . , , / . , .

35 . ., . , .

, , . 10 . . . , , , 2500 . . 5000 6000 . .

3.3 , . SonicWALL PRO 4060 Cisco PIX 515E-UR-FE-BUN . , . , , .

, RoadBLOCK F302PLUS ISA Server 2004 RimApp . Web-, Internet . , RainWall RainConnect Rainfinity RoadBLOCK RoadBLOCK, Internet-. RoadBLOCK .


, , . . , .

3.2.

SonicWALL Pro 3060 Cisco PIX-515E-R-DMZ Network Engines NS6200 Symantec SGS 5420
2319 2699 2499 2999
() () ()
Windows
Web Winsock
SSL
Exchange
VPN
VPN VPN
VPN-
10/100-/ 5 2 3 5
WAN 1 1 1 1
. . . 50
Internet-
Web- Web- Web FIPS- RDP Web-
2- Intel 1- Intel 2- Intel Intel
Web- proxy

3.3.

SonicWALL Pro 4060 Cisco PIX-515E UR-FE-BUN RimApp RoadBLOCK F302PLUS
4995 5145 5580
()
Windows
Web Winsock
SSL
Exchange
VPN
VPN VPN
VPN-
10/100-/ 5 6 2-5
WAN 1 1-4 1-5
Internet-
Web- Web- Web FIPS- RDP
2- Intel 433- Celeron 2,8- Intel
Web - proxy

3.2 Intrusion Detection Systems (IDS)

IDS , , , . , IDS .

, , . , , . , , , , . IDS , , , .

IDS : , . , .

IDS

, . , , , , .

IDS, , ?

. , . ( ), .

, . . IDS , , . , , , , , .

IDS . . IDS , . IDS :

1.                . : " , , , ". TCP/IP, . , .

2.                . : " , , , , ". , .

, , , , .

, , , ICAT CERT, , . , , :

                   .

                   , , . , , .

                   , .

                   , .

                   . , .

, . , .

, . IDS , , . , IDS , , , . , .

3.                , , .

, . . IDS . , .

IDS, , . , IDS , , , . .

4.                .

. , .

5.                , .

IDS , . , , , .

6.                , , .

IDS , , . . , , .

7.                IDS ( ), .

IDS

IDS, IDS. IDS , :

. network-based, host-based application-based.

. , , , , . (misuse detection) (anomaly detection).

. , IDS interval-based ( ) real-time.

IDS real-time network-based .

IDS :

. IDS , . , , .

: , . , , IDS, , .

IDS

. IDS , , , .

, , .

IDS

IDS, IDS. IDS , , . , , , , IDS.

network-based IDS host-based IDS. , network-based IDS, . host-based IDS. , IDS .

, Honey Pot , , . , .

network-based IDS

, network-based IDS, . network-based IDS, :

1.               

2.               

3.                DMZ-

. 3.1. network-based IDS

 

DMZ- ( 1)

:

                   , , .

                   , , .

                   , ( web ftp), DMZ.

                   , IDS , .

( 2)

:

                   , , .

                   , , .

( 3)

:

                   ; .

                   .

( 4)

:

                   , .

                   , .

host-based IDS

network-based IDS , host-based IDS. host-based IDS . , host-based IDS . , . host-based IDS , host-based IDS . host-based , . .

. host-based IDS .

( host-based IDS) IDS. , , - IDS , .

, IDS , IDS . IDS , , e-mail, , .

, IDS IDS . IDS .

3.3 IPv6

, , - IP.

, IP ( IPv4) 20 , . IPv4 . . , , . , , IP (IPv6). IPv6 90-, 1994 RFC 1752 The Recommendation for the IP Next Generation Protocol.

IPv6 IPv4, IPv6 , .

IPv4 IPv6

IPv4 IPv6 ? . IPv6 , IPv4, IPv6. , , . IPv6 IPv4 IPv6 , IPv4.

IPv6

IP- 40 . , , . . 3.2 , , IPv4.

, IPv6 . 128 , . , , .

. 3.2. IPv6 40

IPv4 IPv6:

                   , , Fragment Offset ( ) Identification (), Don't Fragment ( ) More Fragments ( );

                   ;

                   .

IPv6 . , , , . , ICMP (Packet Too Big - ) , .

IPv6 . , TTL . IP , TCP UDP, IP- .

ICMP

IP ICMP , PING, ICMP. IP, ICMP , . , IPv6, ICMP Internet Group Management Protocol (IGMP, Internet).

Options () . IP-, , , . Next Header ( ), , TCP UDP. , Next Header . ( ) IP- .

IPv6 :

                   Version () - 4- , , IPv4, IP. IPv6 6;

                   Traffic Class ( ) - 8- , , Type of Service ( ) IPv4, ;

                   Flow Label ( ) - (flows) . . . , - ;

                   Payload Length ( ) - 16- , , ;

                   Next Header ( ) - , IP . , IPv4;

                   Hop Limit ( ) - . , , . , ;

                   Source Address ( ) 128- ;

                   Destination Address ( ) - 128- .

Next Header 40- , IP-. , IP , TCP UDP, . IP- . , .

(extension headers), IP-. Next Header . :

                   Hop-by-Hop Options (, );

                   Fragmentation ();

                   Routing ();

                   Authentication ();

                   Security Encapsulation ( );

                   Encapsulation Security Payload ( );

                   Destination Options ( ).

( ) Next Header. , . - Jumbo Payload ( ), IP- 65535 . (. 3.3), , , IPv6, Next Header. , .

Fragmentation Next Header, 44, , , . IPv6 - IP-. , , .


. 3.3.

Routing ( Next Header 43) IPv4. , .

Destinations Options ( Next Header 60) , .

59 Next Header , , . , Payload Length, , , , .

IPv6

32 128 IPv6 IPv4.

IPv6 :

                   unicast () - ;

                   anycast () - . , anycast, ( ), ;

                   multicast () - . anycast, , multicast, , .

, unicast , unicast-. (broadcast) - multicast.


, , . . . . . .


CA Certification Authority
CGI Common Gateway Interface
DHCP Dynamic Host Configuration Protocol
DMZ Demilitarized Zone
DNS Domain Name System
DoS Denial of Service
DSA Digital Signature Algorithm
FTP File Transport Protocol
GUI Graphical User Interface
HTML Hyper Text Markup Language
HTTP Hyper Text Transfer Protocol
IDS Intrusion Detection System
IIS Internet Information Services
KSK Key Signing Key
MAC Media Access Control
MAC Message Authentication Code
MD5 Message Digest v5
NAT Network Address Translation
NTP Network Time Protocol
NTP Network Time Protocol
OSI Open System Interconnection
PKI Public Key Infrastructure
RSA Rivest, Shamir, Adleman
SEP Secure Entry Point
SHA Secure Hash Algorithm
SMTP Simple Mail Transfer Protocol
SSH Secure Shell
SSL Secure Socket Layer
TOS Trusted
VPN Virtual Private Network
URL Uniform Resource Locator
REP Robots Exclusion Standard
IE Internet Explorer
SSI Server Side Includes
ASP Active Server Pages
ISP Internet Service Provider
 

1.       .. . . һ, ., 2009;

2.       .. . Firewalls. . ʻ, ., 2008;

3.       , . Cisco Secure PIX. , ., 2009;

4.       .. . . ., 2008;

5.       .. . . һ, ., 2009;

6.       . . Linux. , ., 2009;

7.       Chip, 2007;

8.       , 2008;

9.       . 2009;

 

 

1.       http://securitylab.ru

2.       http://cisco.com

3.       http://zonealarm.com

4.       http://hub.ru

5.       http://opennet.ru

6.       http://infosecurity.ru

7.       http://osp.ru

8.       http://www.security-teams.net

9.       http://www.oszone.ru

10.  http://www.secure.com.ru

: ,

 

 

 

! , , , .
. , :