,,,
:
,
-
..
: ..
2009
1. .
1.1
1.2
1.3 .
2.
2.1
2.2
2.3
2.4
2.5 (VPN)
3.
3.1
3.2 Intrusion Detection Systems (IDS)
3.3 IPv6
, , . , . . , , .
, . , , , , , . , , . , , . , , . , . .
. , , , , .
, (Computer Security Institute) , 70% , , 60% .
, , , , .
, " " .
, , . ,
. - - , .
. . ( , ..), .
, .
:
.
, . Gartner Dataquest . 2009 .
, ;
, , , . , , , , . . 70% , , script-kiddies, , . , , , , .
, , ;
70-90% , , .
;
, . - . , , . , , . , - , . , , Microsoft Windows Server 2003 14 , 6 . , Microsoft , , , . . , .
, .
, , , .
, , , , .
, 90% .
( ) - ( ), ( ), , , .
:
. , (), . ;
. ( , , ) - . . , ;
( ) ( ). , , . . , , , .., .
.
() - , , ( - ).
() , . . , , , , , , .
, . Gartner Group 4 ():
0 :
, ;
;
, ( , ).
, , , / . , . , .
1 :
"" , (, ) () ;
- ;
+ , , , VPN ( ).
2 3 :
, , ;
;
+ , web , IDS ( ), , SSO ( ), PKI ( ) ( , , , , , ).
3 2- :
, CISA ( );
, Datamonitor 5% ;
+ , CSIRT ( ), SLA ( ).
, 2- 3- . 1- 0- . . , , ..
. . . .
Gartner 85%.(0 30 %, 1 55%) 2005.
, 2- 3- Gartner, . , .
. , . , , , . .
, , . . , , . , , . .
, , , , . . , . , , ( ) ( , , , , . .).
, , , . , , , , . , . , , , . , , . . , , , , , , .
World Wide Web
WWW . , , , , .. World wide web HTTP- .
HTTP- . web- ( , HTML, gif jpeg, .), . , Microsoft Word, Microsoft Word. , , , , , . , , , Microsoft Word Microsoft Excel, .
(active content), Java-, Javascript, ActiveX .., , . , .
, , , www . , , , ..
. , , , .
, :
. SMTP, . . "social engineering". , .
. , , , . . . Santa.Claus@northpole.org, "" - , . , , . . , , , . . - , , , . .
. .
. . , , . : SMTP- , (open mail relay - ). , , . , , . , , . , . , . , , . , , , .
. (SMTP, POP3, IMAP) , . Sendmail, SMTP- "" , - . POP3- QUALCOMM qpopper IMAP- , (root) . CERT . .
FTP -
FTP . web- FTP. FTP-.
www , , .
DNS -
DNS - - . , , DNS-. , , IP-, web-, , FTP-, .. DNS. , DNS , .
DNS : (, IP- www.microsoft.com). , , , DNS- DNS- , . DNS- , , , .
DNS , . (primary) (secondary) . (). . " " (zone transfer) . , DNS- - (lookups) (zone transfers).
DNS- 53. UDP . UDP , TCP. TCP.
DNS:
. DNS , , .
DNS spoofing. DNS , . , : . , , . ( IP- ) , . IP- , , . : . , , , DNS IP-. , IP- , , . .
Cache Poisoning. : DNS- , , . , MX (mail exchanger) , MX A- mail exchanger' . : DNS-, - . , , . DNS- . , .
DNS-. 1998 DNS- BIND , (root) . .
- .
, , . , .
. (, ICQ, IRC) , , . , .
. (ICQ) , . , - , ..
. - .
. , . " ". , ( , ) , , , , .
:
, , , . , .
. , , .
, . , .
, " " . ( 80%), , , .
. . , . : , . , . , , . , , " ", ( ). . , IPX/SPX, - TCP/IP. , , Novell Netware, . . , , TCP/IP . , .
, " " . , . - - , . , , . . , , , , . , , . , , .
. , Microsoft Windows XP Windows NT Workstation, Microsoft Windows NT Server, Novell Netware / Unix-, , , , , , ..
, ( ) . Microsoft . , , .
() - (), , / , , .. () . , , , .
, . . .
,
, , . , .
, - , . , , - . .
, IP- .
, , . , FreeBSD, , (ipfw).
( -), , , . , -.
, - , , .
, , , -, .
- , . , -, - - , - .
, . , , TCP/IP. , . , , , . , . , , .
. OSI, - OSI . OSI . . 2.1 OSI.
.2.1. OSI
1 , Ethernet.
2 , (LAN). , , . MAC (Media Access Control) . Ethernet - , Ethernet-, - 2.
3 , WAN. 3 IP-; , , , (NAT) , IP- 3.
4 ; 4 . , TCP/IP, , : ; . (5, 6 7) .
, 2- OSI, (stealth), , .
. , .. (frame, ).
:
, .
. , . , .
. 2 OSI. , IP-. , . IP- . , ? , , .
(Packet - filtering firewall) - , , , , . , TCP- IP- ( , .)
3
,
( /, /)
, ( ),
20-
: (ACL, access control lists)
(Circuit-level gateway) , . , , . . 2.2 .
. 2.2.
, . (NAT, network address translation). , . IP- - IP-, . , , , . IP- IP-, .
4
TCP ,
, ,
: SOCKS
(Application-level gateways) - , , OSI. . 2.3 .
.2.3.
- , TCP/IP.
:
;
, , ;
;
, .
(Proxy).
HTTP-, FTP- .. TCP/IP , . , , , , -, . , , , . -, ), -, .
:
7 ;
;
, ;
;
: Web (http) proxy;
. 2.4. /I OSI
. . 2.4 TCP/IP OSI. ; . , , , . . , , , . , 2, 3 4, .
. (NAT), (DHCP) , VPN-, .
VPN-. , , , , VPN-; VPN-, . .
. , 7, . , , . web, Java, JavaScript ActiveX. . , , , ; , .
, , . . . , .
, :
1. (Keep It Simple)
, , . , . .
2.
, , , , . , ; , . : . (switch): , , . , .
3.
. . , , . , , . , .
4.
, , , , . , , - . , , web e-mail , DMZ-.
, . , , , .
DMZ
DMZ- . DMZ- , .
DMZ-
DMZ- , , , , , . , , . . DMZ . 2.5.
. 2.5. DMZ
DMZ- . VPN DMZ-. DMZ- , . , DMZ- , .
Service Leg
DMZ- Service Leg . 2.6. . , , DMZ-. DoS-, , DMZ-. DMZ- DoS- DMZ-, web-, . Service Leg DMZ- DoS-, , DMZ - . , web- DoS-.
. 2.6. Service Leg DMZ
DMZ-
DMZ . , DMZ , . DMZ, ; , , .
.2.7.
DMZ- , , - , .
VPN- ; VPN- .
SMTP- .
HTTP- , HTTP- -, DMZ.
stateful inspection . :
VPN-, ;
SMTP- -, ;
HTTP- HTTP- SMTP- SMTP-;
HTTP- SMTP-;
;
, HTTP- SMTP-. , SMTP- HTTP- , . , .
, :
DNS-, ;
NAT ;
, ;
;
.2.7. DMZ-
, , , , . , , TCP/IP, .
. () , . , , .
, , , , .
, : VPN. business-to-business . , , VPN.
, , , VPN . , . TCP/IP , . . 2.8 .
.2.8. VPN ,
:
, , (hubs) (switches). . , 1 OSI. , .
. , , , . DMZ- .
. 2, .
, , , ; DMZ- .
, - , DoS-, , .
:
1. ( )
2.
3.
4. :
5. :
6. :
7.
8.
9.
10.
11.
12. ()
.
.
1. .
:
. , , .
:
. :
, ;
;
.
:
.
:
. , , ;
. , , ;
/.
2.
. :
, / .
3.
. :
. , .
:
.
:
;
.
4. :
:
. () - .
:
.
:
. , . , .
5. :
:
() ( ) . ;
:
, ;
- ;
, .
:
.
(, ).
:
.
.
6. :
. :
, , , , .
7.
:
.
:
.
:
.
.
8.
:
, .
:
.
:
.
9.
:
:
;
;
;
;
.
:
:
;
;
;
;
;
.
:
;
;
;
;
;
;
.
10.
:
:
;
;
;
.
:
.
:
.
11.
:
, , .
:
, , .
:
, , .
12.
:
:
;
;
;
;
;
;
:
.
:
.
:
.
, , .
. . , . . .
90- - VPN. (Virtual Private Networks).
VPN
VPN : , , , . , () .
, , , , .
VPN
VPN , .
:
;
, .
:
;
() ;
.
. .
, , . . , , , .
, . , , .
, , . . () , . IP, , , , NetBEUI. IP, . .
, . . , , . , , .
, . , , .
VPN
. .
FireWall-1 Check Point Software Technologies. FairWall-1 VPN IPSec. , , , . FireWall-1 Solaris Windows NT 4.0.
, . . 2.9 VPN.
, .
. 2.9. VPN
, , . , , , .
, ( ) Windows Firewall, , . ? : .
.
. , , - .
. . , . , / , , . , . , ( ).
,
, . , , , (universal threat management, UTM). , Cisco Systems, Network Engines, Rimapp, SonicWall Symantec.
, . , . , , , , .
, Web-, , . Web Internet. Web-proxy .
, . , 3.2 3.3.
. . , . .
. , . HTTP, SMTP, Instant Messaging (IM).
. (, deep packet inspection) IETF (Internet Engineering Task Force) . DNS, FTP, POP3 SMTP. .
. . .
Windows. . .
Web Winsock. . Winsock , .
SSL (Secure Sockets Layer). SSL. , , SSL.
Microsoft Exchange Server. Exchange Internet Exchange, Outlook Web Access (OWA), Outlook Mobile Access (OMA), Exchange ActiveSync, Secure Exchange RPC RPC over HTTP. , RSA SecurID RSA Security.
VPN . VPN , PPTP, Layer Two Tunneling Protocol (L2TP)/IPsec IPsec . VPN , Blaster Sasser. , ISA Server 2004 Microsoft RPC (remote procedure call) Blaster .
. , TCP/IP . Intrusion Detection System (IDS)/Intrusion Prevention System (IPS) . IDS/IPS .
VPN VPN. VPN VPN . VPN VPN-.
VPN-. VPN ( SSL VPN ). PPTP L2TP/IPsec Windows VPN- Microsoft. () VPN, VPN, IPsec NAT (Network Address Translation). , .
10/100-/ . Ethernet, , . Ethernet, , Internet.
WAN. Internet. .
. . , .
. IP-, . , , .
. , . ( ), ( ) . , .
Internet- . Internet- , Internet. Internet- , . Internet.
. Web- SSL . , ISA Server RDP, FIPS (Federal Information Processing Standard).
. . .
Web- proxy-. Web-. Web- Internet Internet . Web-proxy , , HTTP.
, . . , , .
, . Internet DSL- T , . , NAT. VPN- VPN.
500 . , , Cisco, SonicWall Symantec, 3.1.
, . Internet. . .
, . . . .
SonicWall 170, . SonicWall 170 , . , SonicWall 170 , .
. . , , .
3.1.
SonicWall 170 | Cisco PIX 501 | Symantec Firewall/VPN | |
410 | 495 | 499 | |
() | () | () | |
Windows | |||
Web Winsock | |||
SSL | |||
Exchange | |||
VPN | |||
VPN VPN | |||
VPN- | |||
10/100-/ | 5 | 4 | 4 |
WAN | 1 | 1 | 1 |
10 | 10 | 15-25 | |
Internet- | |||
Web- | Web- | Web- | |
SonicWall Security Processor | AMD SC520 | ARM7 | |
Web- proxy- |
, , . , (, ) . , . , .
.
Internet. , , . .
, - , (P2P) (Instant Messaging - IM).
, , , VPN.
, , . , .
, , ; .
- , .
, , . 3000 . , 3-4 . ( 2 . ) , .
3.2 , . SonicWALL Pro 3060 Cisco PIX-515E-RDMZ Cisco Systems . NS6200 Network Engines Microsoft ISA Server 2004 SGS 5420 Symantec , ( ). NS6200 , , . SGS 5420 : , .
Network Engines Symantec, . , , SonicWALL Cisco.
(, , , , , Web-). - .
Network Engines Symantec , .
. . , Internet, . .
. , , , , .
SSL (Secure Sockets Layer - ). NS6200 ISA Server 2004 SSL . Microsoft Outlook Web Access (OWA) Microsoft SharePoint Portal Server. 3.2, NS6200 SSL- , , .
VPN-. VPN . VPN , VPN , , "" . Blaster , . , Blaster, , VPN- - . NS6200 VPN .
. 3.2 , NS6200.
, . , , / . , .
35 . ., . , .
, , . 10 . . . , , , 2500 . . 5000 6000 . .
3.3 , . SonicWALL PRO 4060 Cisco PIX 515E-UR-FE-BUN . , . , , .
, RoadBLOCK F302PLUS ISA Server 2004 RimApp . Web-, Internet . , RainWall RainConnect Rainfinity RoadBLOCK RoadBLOCK, Internet-. RoadBLOCK .
, , . . , .
3.2.
SonicWALL Pro 3060 | Cisco PIX-515E-R-DMZ | Network Engines NS6200 | Symantec SGS 5420 | |
2319 | 2699 | 2499 | 2999 | |
() | () | () | ||
Windows | ||||
Web Winsock | ||||
SSL | ||||
Exchange | ||||
VPN | ||||
VPN VPN | ||||
VPN- | ||||
10/100-/ | 5 | 2 | 3 | 5 |
WAN | 1 | 1 | 1 | 1 |
. | . | . | 50 | |
Internet- | ||||
Web- | Web- | Web FIPS- RDP | Web- | |
2- Intel | 1- Intel | 2- Intel | Intel | |
Web- proxy |
3.3.
SonicWALL Pro 4060 | Cisco PIX-515E UR-FE-BUN | RimApp RoadBLOCK F302PLUS | |
4995 | 5145 | 5580 | |
() | |||
Windows | |||
Web Winsock | |||
SSL | |||
Exchange | |||
VPN | |||
VPN VPN | |||
VPN- | |||
10/100-/ | 5 | 6 | 2-5 |
WAN | 1 | 1-4 | 1-5 |
Internet- | |||
Web- | Web- | Web FIPS- RDP | |
2- Intel | 433- Celeron | 2,8- Intel | |
Web - proxy |
IDS , , , . , IDS .
, , . , , . , , , , . IDS , , , .
IDS : , . , .
IDS
, . , , , , .
IDS, , ?
. , . ( ), .
, . . IDS , , . , , , , , .
IDS . . IDS , . IDS :
1. . : " , , , ". TCP/IP, . , .
2. . : " , , , , ". , .
, , , , .
, , , ICAT CERT, , . , , :
.
, , . , , .
, .
, .
. , .
, . , .
, . IDS , , . , IDS , , , . , .
3. , , .
, . . IDS . , .
IDS, , . , IDS , , , . .
4. .
. , .
5. , .
IDS , . , , , .
6. , , .
IDS , , . . , , .
7. IDS ( ), .
IDS
IDS, IDS. IDS , :
. network-based, host-based application-based.
. , , , , . (misuse detection) (anomaly detection).
. , IDS interval-based ( ) real-time.
IDS real-time network-based .
IDS :
. IDS , . , , .
: , . , , IDS, , .
IDS
. IDS , , , .
, , .
IDS
IDS, IDS. IDS , , . , , , , IDS.
network-based IDS host-based IDS. , network-based IDS, . host-based IDS. , IDS .
, Honey Pot , , . , .
network-based IDS
, network-based IDS, . network-based IDS, :
1.
2.
3. DMZ-
. 3.1. network-based IDS
DMZ- ( 1)
:
, , .
, , .
, ( web ftp), DMZ.
, IDS , .
( 2)
:
, , .
, , .
( 3)
:
; .
.
( 4)
:
, .
, .
host-based IDS
network-based IDS , host-based IDS. host-based IDS . , host-based IDS . , . host-based IDS , host-based IDS . host-based , . .
. host-based IDS .
( host-based IDS) IDS. , , - IDS , .
, IDS , IDS . IDS , , e-mail, , .
, IDS IDS . IDS .
, , - IP.
, IP ( IPv4) 20 , . IPv4 . . , , . , , IP (IPv6). IPv6 90-, 1994 RFC 1752 The Recommendation for the IP Next Generation Protocol.
IPv6 IPv4, IPv6 , .
IPv4 IPv6
IPv4 IPv6 ? . IPv6 , IPv4, IPv6. , , . IPv6 IPv4 IPv6 , IPv4.
IPv6
IP- 40 . , , . . 3.2 , , IPv4.
, IPv6 . 128 , . , , .
. 3.2. IPv6 40
IPv4 IPv6:
, , Fragment Offset ( ) Identification (), Don't Fragment ( ) More Fragments ( );
;
.
IPv6 . , , , . , ICMP (Packet Too Big - ) , .
IPv6 . , TTL . IP , TCP UDP, IP- .
ICMP
IP ICMP , PING, ICMP. IP, ICMP , . , IPv6, ICMP Internet Group Management Protocol (IGMP, Internet).
Options () . IP-, , , . Next Header ( ), , TCP UDP. , Next Header . ( ) IP- .
IPv6 :
Version () - 4- , , IPv4, IP. IPv6 6;
Traffic Class ( ) - 8- , , Type of Service ( ) IPv4, ;
Flow Label ( ) - (flows) . . . , - ;
Payload Length ( ) - 16- , , ;
Next Header ( ) - , IP . , IPv4;
Hop Limit ( ) - . , , . , ;
Source Address ( ) 128- ;
Destination Address ( ) - 128- .
Next Header 40- , IP-. , IP , TCP UDP, . IP- . , .
(extension headers), IP-. Next Header . :
Hop-by-Hop Options (, );
Fragmentation ();
Routing ();
Authentication ();
Security Encapsulation ( );
Encapsulation Security Payload ( );
Destination Options ( ).
( ) Next Header. , . - Jumbo Payload ( ), IP- 65535 . (. 3.3), , , IPv6, Next Header. , .
Fragmentation Next Header, 44, , , . IPv6 - IP-. , , .
. 3.3.
Routing ( Next Header 43) IPv4. , .
Destinations Options ( Next Header 60) , .
59 Next Header , , . , Payload Length, , , , .
IPv6
32 128 IPv6 IPv4.
IPv6 :
unicast () - ;
anycast () - . , anycast, ( ), ;
multicast () - . anycast, , multicast, , .
, unicast , unicast-. (broadcast) - multicast.
, , . . . . . .
CA | Certification Authority |
CGI | Common Gateway Interface |
DHCP | Dynamic Host Configuration Protocol |
DMZ | Demilitarized Zone |
DNS | Domain Name System |
DoS | Denial of Service |
DSA | Digital Signature Algorithm |
FTP | File Transport Protocol |
GUI | Graphical User Interface |
HTML | Hyper Text Markup Language |
HTTP | Hyper Text Transfer Protocol |
IDS | Intrusion Detection System |
IIS | Internet Information Services |
KSK | Key Signing Key |
MAC | Media Access Control |
MAC | Message Authentication Code |
MD5 | Message Digest v5 |
NAT | Network Address Translation |
NTP | Network Time Protocol |
NTP | Network Time Protocol |
OSI | Open System Interconnection |
PKI | Public Key Infrastructure |
RSA | Rivest, Shamir, Adleman |
SEP | Secure Entry Point |
SHA | Secure Hash Algorithm |
SMTP | Simple Mail Transfer Protocol |
SSH | Secure Shell |
SSL | Secure Socket Layer |
TOS | Trusted |
VPN | Virtual Private Network |
URL | Uniform Resource Locator |
REP | Robots Exclusion Standard |
IE | Internet Explorer |
SSI | Server Side Includes |
ASP | Active Server Pages |
ISP | Internet Service Provider |
1. .. . . һ, ., 2009;
2. .. . Firewalls. . ʻ, ., 2008;
3. , . Cisco Secure PIX. , ., 2009;
4. .. . . ., 2008;
5. .. . . һ, ., 2009;
6. . . Linux. , ., 2009;
7. Chip, 2007;
8. , 2008;
9. . 2009;
1. http://securitylab.ru
2. http://cisco.com
3. http://zonealarm.com
4. http://hub.ru
5. http://opennet.ru
6. http://infosecurity.ru
7. http://osp.ru
8. http://www.security-teams.net
9. http://www.oszone.ru
10. http://www.secure.com.ru
: ,
Copyright (c) 2025 Stud-Baza.ru , , , .