Sunday, July 5, 2009

What is Port Scanning?

hat is port scanning? It is similar to a thief going through your neighborhood and checking every door and window on each house to see which ones are open and which ones are locked.
TCP (Transmission Control Protocol) and UDP (User Datagram Protocol) are two of the protocols that make up the TCP/IP protocol suite which is used universally to communicate on the Internet. Each of these has ports 0 through 65535 available so essentially there are more than 65,000 doors to lock.

The first 1024 TCP ports are called the Well-Known Ports and are associated with standard services such as FTP, HTTP, SMTP or DNS. Some of the addresses over 1023 also have commonly associated services, but the majority of these ports are not associated with any service and are available for a program or application to use to communicate on.

Port scanning software, in its most basic state, simply sends out a request to connect to the target computer on each port sequentially and makes a note of which ports responded or seem open to more in-depth probing.

If the port scan is being done with malicious intent, the intruder would generally prefer to go undetected. Network security applications can be configured to alert administrators if they detect connection requests across a broad range of ports from a single host. To get around this the intruder can do the port scan in strobe or stealth mode. Strobing limits the ports to a smaller target set rather than blanket scanning all 65536 ports. Stealth scanning uses techniques such as slowing the scan. By scanning the ports over a much longer period of time you reduce the chance that the target will trigger an alert.

By setting different TCP flags or sending different types of TCP packets the port scan can generate different results or locate open ports in different ways. A SYN scan will tell the port scanner which ports are listening and which are not depending on the type of response generated. A FIN scan will generate a response from closed ports- but ports that are open and listening will not send a response, so the port scanner will be able to determine which ports are open and which are not.

There are a number of different methods to perform the actual port scans as well as tricks to hide the true source of port scan. You can read more about some of these by visiting these web sites: Port Scanning or Network Probes Explained.

It is possible to monitor your network for port scans. The trick, as with most things in information security, is to find the right balance between network performance and network safety. You could monitor for SYN scans by logging any attempt to send a SYN packet to a port that isn't open or listening. However, rather than being alerted every time a single attempt occurs- and possibly being awakened in the middle of the night for an otherwise innocent mistake- you should decide on thresholds to trigger the alert. For instance you might say that if there are more than 10 SYN packet attempts to non-listening ports in a given minute that an alert should be triggered. You could design filters and traps to detect a variety of port scan methods- watching for a spike in FIN packets or just an anomylous number of connection attempts to a variety of ports and / or IP addresses from a single IP source.

To help ensure that your network is protected and secure you may wish to perform your own port scans. A MAJOR caveat here is to ensure you have the approval of all the powers that be before embarking on this project lest you find yourself on the wrong side of the law. To get accurate results it may be best to perform the port scan from a remote location using non-company equipment and a different ISP. Using software such as NMap you can scan a range of IP addresses and ports and find out what an attacker would see if they were to port scan your network. NMap in particular allows you to control almost every aspect of the scan and perform various types of port scans to fit your needs.

Once you find out what ports respond as being open by port scanning your own network you can begin to work on determining whether its actually necessary for those ports to be accessible from outside your network. If they're not necessary you should shut them down or block them. If they are necessary, you can begin to research what sorts of vulnerabilities and exploits your network is open to by having these ports accessible and work to apply the appropriate patches or mitigation to protect your network as much as possible.

The 7 Habits of Highlty Effective Network Professionals

In today’s business environment, the network IS the business. Without email, the Internet, IM VoIP, and dozens of other technologies, effective business communication simply can’t happen. For the people charged with selecting, implementing and maintaining the networks and applications that support business goals, the challenges have never been greater. Highly Effective Network Professionals have adopted the seven habits detailed below in order to build success for their careers and their companies. These seven habits are intended to be a useful guide to building your career. If you adopt them, the rewards can be high. You’ll play a prominent role in your company, working directly with business line and product managers, presenting to executives and the board of directors, and dealing with customers and partners. You’ll be contributing to the success of your company, not just operation a support function with little visibility and few rewards.

1. BE BUSINESS SAVVY

The savvy Network Professional is engaged with people at all levels and departments within the organization. It isn’t enough to simply interact with your fellow IT department members; you need to engage with business line managers, product managers, and executives. By interacting with a more diverse group of co-workers, you’ll get access to the business intelligence that’s as likely to be shared during a coffee break as it is during a formal business meeting. This intimate knowledge of what’s happening in your organization will be invaluable when you’re faced with the all too common scenario of deploying your resources to meet competing goals. By developing an understanding of who the players are- and who they aren’t- you can more easily make IT decisions that will positively impact your company. For example, if you know that sales and marketing organizations are planning to increase e-commerce initiatives, you can invest early in the research, acquisition, purchase, and management of the hardware and software this channel requires. All of your internal customers are looking to IT to help solve their business issues. But how do you decide whether to implement a new collection system or a new contact management system? You’ll likely start by evaluating the current solutions. Are they working as expected? Can small changes be made to improve performance? Are the systems effectively obsolete, making any further investment of questionable value? You also need to evaluate the business environment. Which system is more urgent? Which will have a greater impact on the company’s revenue and profitability? By understanding the business realities on the ground, you can position yourself to make smarter decisions. For instance, what if you knew that the business unit seeking a new contact management system was growing at 200 percent a year, and would be responsible for the company’s next product rollout? This information makes your decision an easier one, but you can’t always count on the intelligence being readily available. Only by playing an active and visible role in you company can you develop the business savvy that will help you succeed.

2. SET EXPECTATION APPROPRIATELY

Everybody’s an expert, right? How many times have business managers come to you and told you exactly what technology solutions the need to solve their business issues? It’s a critical part of you job not to only select the most appropriate solutions, but also to set expectations properly so that your users understand how much the solution will cost, how long it will take to deploy, and exactly what it can and can’t do. Often, it’s Network Professionals who take the hit when a solution doesn’t meet expectations. It’s in your best interests to close the gap between the business side of the house and it. When managers know up front what the can expect, your job is much easier. And when you deliver in line with expectations, you’ll be putting yourself in a better position to meet the expectations of your internal customers and fulfill the requirements of your service level agreement.

3. BE FINANCIALLY PRUDENT

In order to make effective decisions, Network Professionals must understand common financial terms like Return On Investment (ROI) and Total Cost of Ownership (TCO) and be ready to discuss them with business line managers. By understanding both the up front and long-term costs of technology solutions, you’ll be better able to guide you organization in making technology choices that will positively impact the business. Managing your budget involves looking not only at expenditures, but also at expected returns. By working with business line managers to understand how the manage P&L, you become a partner who helps them achieve their business goals as you spend your budget wisely.

4. BE A TECHNOLOGY REALIST.

It’s probably not a stretch to say that you love technology. But as a Network Professional, you also need to be a technology realist. While you may admire the elegance of a new technology solution, you’re realistic enough to know that what matters for your company is how that technology can be applied to solve business problems, improve processes, and increase sales. You have to be prepared to say no to shiny new software if it can’t solve the pain points your company is experiencing. By staying up-to-date on the latest technology as well as on those coming down the road, you can separate the must haves from the want-to-haves. And in doing this, you’ll be looked at as a credible source for technology advice and road-mapping, increasing you strategic value and enhancing you career.

5. BE CREDENTIAL READY PRACTICE PROVEN

You’re working in a global community, full of people with top-notch education and certifications. Employers are selecting candidates from the international talent pool, so you need to be ale to compete. In this environment, certifications really do matter. Be sure to make advantage of employer reimbursement programs for training opportunities, but don’t be afraid to invest in getting yourself certified – you’ll quickly realize the return of this investment on your career. It’s also important to have practical experience and not be afraid to get your hands dirty. Stay on top of emerging technologies, and seize every opportunity to get involved with a new implementation to keep your skills sharp and up-to-date. Network Professionals who understand both the theory and practice of technology will see their achievements reflected in their salary and benefits.

6. BE DIPLOMATIC

In your role as a Network Professional, you’ll find yourself working with a diverse group of people in a wide variety of situations. From IT management to product managers, you’ll need to develop diplomatic skills that will allow you to navigate smoothly through your organization. Keep in mind that you’ll be called upon to explain technology to nontechnical employees and you should learn how to explain pros and cons in language the can relate to.

7. CULTIVATE AN OPTIMISTIC OUTLOOK

The job of a Network Professional is a tough one. You’re forced to more dozens of demands, expectations, and realities from internal customers throughout your organization. You’re the first person they’ll call when something goes wrong, but you may never hear about it when thing right. When you come to work in the morning in a positive frame of now your day will fly by, and you’re more likely to have a fulfilling career.

NESSUS

In computer security, Nessus is a proprietary comprehensive vulnerability scanning software. It is free of charge for personal use in a non-enterprise environment. Its goal is to detect potential vulnerabilities on the tested systems. For example:
Vulnerabilities that allow a remote cracker to control or access sensitive data on a system.
Misconfiguration (e.g. open mail relay, missing patches, etc).
Default passwords, a few common passwords, and blank/absent passwords on some system accounts. Nessus can also call Hydra (an external tool) to launch a dictionary attack.
Denials of service against the TCP/IP stack by using mangled packets
On UNIX (including Mac OS X), it consists of nessusd, the Nessus daemon, which does the scanning, and nessus, the client, which controls scans and presents the vulnerability results to the user. For Windows, Nessus 3 installs as an executable and has a self-contained scanning, reporting and management system.
Nessus is the world's most popular vulnerability scanner, estimated to be used by over 75,000 organizations worldwide. It took first place in the 2000, 2003, and 2006 security tools survey from SecTools.Org.

Operation
In typical operation, Nessus begins by doing a port scan with one of its four internal portscanners (or it can optionally use Amap or Nmap) to determine which ports are open on the target and then tries various exploits on the open ports. The vulnerability tests, available as subscriptions, are written in NASL (Nessus Attack Scripting Language), a scripting language optimized for custom network interaction.
Tenable Network Security produces several dozen new vulnerability checks (called plugins) each week, usually on a daily basis. These checks are available for free to the general public seven days after they are initially published. Nessus users who require support and the latest vulnerability checks should contact Tenable Network Security for a Direct Feed subscription which is not free. Commercial customers are also allowed to access vulnerability checks without the seven-day delay.
Optionally, the results of the scan can be reported in various formats, such as plain text, XML, HTML and LaTeX. The results can also be saved in a knowledge base for reference against future vulnerability scans. On UNIX, scanning can be automated through the use of a command-line client. There exist many different commercial, free and open source tools for both UNIX and Windows to manage individual or distributed Nessus scanners.
If the user chooses to do so (by disabling the option 'safe checks'), some of Nessus's vulnerability tests may try to cause vulnerable services or operating systems to crash. This lets a user test the resistance of a device before putting it in production.
Nessus provides additional functionality beyond testing for known network vulnerabilities. For instance, it can use Windows credentials to examine patch levels on computers running the Windows operating system, and can perform password auditing using dictionary and brute force methods. Nessus 3 can also audit systems to make sure they have been configured per a specific policy, such as the NSA's guide for hardening Windows servers.

Limitations
While Nessus, through community participation, has a very extension list of known security vulnerabilities, it is not a substitution for anti-virus software. It is only able to detect viruses that open ports and listen.

History
The "Nessus" Project was started by Renaud Deraison in 1998 to provide to the Internet community a free remote security scanner. Nessus is currently rated among the top products of its type throughout the security industry and is endorsed by professional information security organizations such as the SANS Institute.
On October 5, 2005, Tenable Network Security, the company Renaud Deraison co-founded, changed Nessus 3 to a proprietary (closed source) license. The Nessus 3 engine is still free of charge, though Tenable charges $100/month per scanner for the ability to perform configuration audits for PCI, CIS, FDCC and other configuration standards, technical support, SCADA vulnerability audits, the latest network checks and patch audits, the ability to audit anti-virus configurations and the ability for Nessus to perform sensitive data searches to look for credit card, social security number and many other types of corporate data.
As of July 31, 2008, Tenable sent out a revision of the feed license which will allow home users full access to plugin feeds. A professional license is available for commercial use.
The Nessus 2 engine and a minority of the plugins are still GPL. Some developers have forked independent open source projects based on Nessus. Tenable Network Security has still maintained the Nessus 2 engine and has updated it several times since the release of Nessus 3.
Nessus 3 is available for many different UNIX and Windows systems, offers patch auditing of UNIX and Windows hosts without the need for an agent and is 2-5 times faster than Nessus 2.
There is a split-off project called OpenVAS that continues to develop a GPLed vulnerability scanner based on Nessus 2.
On April 9, 2009, Tenable released Nessus 4.0.0.

WIRESHARK

Wireshark is a free packet sniffer computer application. It is used for network troubleshooting, analysis, software and communications protocol development, and education. Originally named Ethereal, in May 2006 the project was renamed Wireshark due to trademark issues.

The functionality
Wireshark is very similar to tcpdump, but it has a graphical front-end, and many more information sorting and filtering options. It allows the user to see all traffic being passed over the network (usually an Ethernet network but support is being added for others) by putting the network interface into promiscuous mode.
Wireshark uses the cross-platform GTK+ widget toolkit, and is cross-platform, running on various computer operating systems including Linux, Mac OS X, and Microsoft Windows. Released under the terms of the GNU General Public License, Wireshark is free software.

History
Out of necessity, Gerald Combs (a computer science graduate of the University of Missouri-Kansas City) started writing a program called Ethereal so that he could have a tool to capture and analyze packets; he released the first version around 1998. As of now there are over 500 contributing authors while Gerald continues to maintain the overall code and issues releases of new versions; the entire list of authors is available from Wireshark's web-site.
The name was changed to Wireshark in May, 2006, because creator and lead developer Gerald Combs could not keep using the Ethereal trademark (which was then owned by his old employer, Network Integration Services) when he changed jobs. He still held copyright on most of the source code (and the rest was redistributable under the GNU GPL), so he took the Subversion repository for Ethereal and used it as the basis for the Subversion repository of Wireshark.
Ethereal development has ceased, and an Ethereal security advisory recommended switching to Wireshark.eWEEK Labs named Wireshark one of "The Most Important Open-Source Apps of All Time" as of May 2, 2007.

Features
Wireshark is software that "understands" the structure of different networking protocols. Thus, it is able to display the encapsulation and the fields along with their meanings of different packets specified by different networking protocols. Wireshark uses pcap to capture packets, so it can only capture the packets on the networks supported by pcap.
Data can be captured "from the wire" from a live network connection or read from a file that records the already-captured packets.
Live data can be read from a number of types of network, including Ethernet, IEEE 802.11, PPP, and loopback.
Captured network data can be browsed via a GUI, or via the terminal (command line) version of the utility, tshark.
Captured files can be programmatically edited or converted via command-line switches to the "editcap" program.
Data display can be refined using a display filter.
Plugins can be created for dissecting new protocols.
Wireshark's native network trace file format is the libpcap format supported by libpcap and WinPcap, so it can read capture files from applications such as tcpdump and CA NetMaster that use that format. It can also read captures from other network analyzers, such as snoop, Network General's Sniffer, and Microsoft Network Monitor.

Security
Capturing raw network traffic from an interface requires special privileges on some platforms. For this reason, older versions of Ethereal/Wireshark and tethereal/tshark often ran with superuser privileges. Taking into account the huge number of protocol dissectors, which are called when traffic for their protocol is captured, this can pose a serious security risk given a bug in a dissector. Due to the rather large number of vulnerabilities in the past (of which many have allowed remote code execution) and developers' doubts for better future development, OpenBSD removed Ethereal from its ports tree prior to its 3.6 release.[4]
One possible alternative is to run tcpdump, or the dumpcap utility that comes with Wireshark, with superuser privileges to capture packets into a file, and later analyze these packets by running Wireshark with restricted privileges on the packet capture dump file. On wireless networks, it is possible to use the Aircrack wireless security tools to capture IEEE 802.11 frames and read the resulting dump files with Wireshark.
As of Wireshark 0.99.7, Wireshark and tshark run dumpcap to do traffic capture. On platforms where special privileges are needed to capture traffic, only dumpcap needs to be set up to run with those special privileges - neither Wireshark nor tshark need to run with special privileges, and neither of them should be run with special privileges.

Ports
Wireshark runs on Unix and Unix-like systems, including Linux, Solaris, HP-UX, FreeBSD, NetBSD, OpenBSD and Mac OS X, and on Microsoft Windows.

Wednesday, June 3, 2009

SNORT

Snort is a free and open source network intrusion prevention system (NIPS) and network intrusion detection system (NIDS) capable of performing packet logging and real-time traffic analysis on IP networks. Snort was written by Martin Roesch and is now developed by Sourcefire, of which Roesch is the founder and CTO. Integrated enterprise versions with purpose built hardware and commercial support services are sold by Sourcefire.

Snort performs protocol analysis, content searching/matching, and is commonly used to actively block or passively detect a variety of attacks and probes, such as buffer overflows, stealth port scans, web application attacks, SMB probes, and OS fingerprinting attempts, amongst other features. The software is mostly used for intrusion prevention purposes, by dropping attacks as they are taking place. Snort can be combined with other software such as SnortSnarf, sguil, OSSIM, and the Basic Analysis and Security Engine (BASE) to provide a visual representation of intrusion data. With patches for the Snort source from Bleeding Edge Threats, support for packet stream antivirus scanning with ClamAV and network abnormality with SPADE in network layers 3 and 4 is possible with historical observation. ( These patches seem to be no longer maintained )


Monday, June 1, 2009

Network Vulnerability Assessment Using Data Mining Techniques

By Daminda Perera


The proposed framework would monitor the network traffic in details to analyze and classify the data connections to carry out the network vulnerability assessment of the hosts/networks.


Problem:

Due to the dynamic nature of the traffic characteristics, ever-changing network environment, the network vulnerability assessment has been proven to be complex, erroneous, costly and inefficient for many large-networked organizations.
This framework will compose a set of techniques and algorithms to assess the network vulnerabilities with the help of data mining techniques.
One of the main problems that to be addressed that how much the network vulnerability assessments are useful, up-to-dated, well-organized or efficient to reflect the current characteristics of network traffics.

Objective:

The main objective is to prepare a set of techniques and algorithms to analysis and assess the network vulnerabilities.
(1) Data mining technique to deduce network vulnerabilities by mining its network traffic log based on its frequency and the behaviors,
(2) A technique to identify the dominant vulnerabilities and any decaying vulnerabilities with the time
The secondary objective is to prepare a portable network vulnerability analyzer, which can be used to monitor/analyze vulnerabilities of the network traffic generated by networks/network nodes. This device is supposed to be connected to the network port of the computer/PC without changing the clients network topology configurations. The proposed toolkit may be able to sit between the LAN and the LAN's exit point, generally the WAN or Internet router, and all packets leaving and entering the network would go through them. In most cases the toolkit would operate as a bridge on the network so that it is undetectable by users.

Deliverables

1. A set of techniques and algorithms to deduce network vulnerabilities by mining its network traffic log based on its frequency and the behaviors.
2. A new software toolkit to analyze the network traffic for troubleshooting purposes while detecting unwanted traffic like worm/virus traffic etc. A portable toolkit that is capable to analyze and troubleshoot the problems may cause due to worm/virus attacks/intrusion attacks.
3. A detail study of the existing/common network traffic analysis and classification techniques.

Methodology

Various software tools are available to measure network traffic. Some tools measure traffic by sniffing and others use SNMP like methods to measure bandwidth use on servers and routers etc. However, for certain vulnerability assessment work may need to analyze the traffic in detail. Since it is required to position a traffic analyzer in different locations in the network to carry out the network vulnerability detections. So it is necessary to place a device with proper software toolkits, which doesn’t disturb the network topology and should be able to setup fairly fast.

Further, the packet sniffers are very useful for network experts tracking down tricky problems. But the volume of information they generate is enormous. A fast broadband connection can transmit thousands or millions of packets per second, and inspecting each one in detail is unlikely to help you make your network faster. In addition, understanding the output of these analyzers requires a detailed understanding of network protocols such as TCP/IP and HTTP. A protocol level broad overview would be useful, at least as a starting point for tracking down the network vulnerabilities of their networks.

In the research, I would like to introduce a new technique to the process of network vulnerability assessment using data mining techniques which consisting of anomaly detection, generalization and rules for data mining using frequency-based techniques. The steps are in summary, (1) to provide a capacity to reflect current trend of network traffic and thus to assess the network vulnerabilities if it contains in real time from traffic log data files, (2) to provide a tool to analyze its traffic patterns for the further analysis and anomaly detection including those hidden vulnerabilities, and for the decision making, (3) to apply various data mining techniques to handle both discrete and continuous attributes with operational efficiency and flexibility, and (4) to demonstrate the merit of data mining based algorithms not only feasible but also more accurate and effective (as traffic log dataset gets larger in size and variation in projection).

The anomaly detection based on the mining exposes many hidden vulnerabilities, not only those types of the anomalies detectable by analyzing the traffic logs for a long time periods but also those anomalies not detectable by analyzing the traffic logs for short periods. As a result, this analysis may conclude new types of the anomalies in the networks.

In conclusion, the data mining will be shown as one of the viable options but also a practical, effective and critical approach in network vulnerability assessment in the real time.

References


1. TANDI: Threat Assessment of Network Data and Information
By Jared Holsopple, Shanchieh Jay Yang, and Moises Sudit

2. A Graph-Based System for Network-Vulnerability Analysis
By Cynthia Phillips, Laura Painton Swiler

3. Scalable, Graph-Based Network Vulnerability Analysis∗
By Paul Ammann, Duminda Wijesekera, Saket Kaushik

4. Managing a Network Vulnerability Assessment
By Thomas R. Peltier, Justin Peltier and John A. Blackley
ISBN:0849312701
Auerbach Publications 2003

5. Network vulnerability assessment using Bayesian networks
By Yu Liu, Hong Man

6. Worm Traffic Analysis and Characterization
By Dainotti A, Pescap A, Ventre G.
Univ. of Napoli Federico II, Naples

Saturday, February 2, 2008

Daminda Perera's Profile


Profile:
Profession : Computer Engineer.
( Presently working for M-net Pvt Ltd as a computer engineer)
Education : BSc Eng Hons in Electrical & Electronic Engineering.
(at Faculty of Engineering, University of Peradeniya)
Nationality: Sri Lankan.
Marital Status: Married.

Contact :
Residence :  Battaramulla, Sri Lanka.
Electronic mail : info@daminda.com
Last updated 11th Nov 2008