Sunday, July 5, 2009
What is Port Scanning?
TCP (Transmission Control Protocol) and UDP (User Datagram Protocol) are two of the protocols that make up the TCP/IP protocol suite which is used universally to communicate on the Internet. Each of these has ports 0 through 65535 available so essentially there are more than 65,000 doors to lock.
The first 1024 TCP ports are called the Well-Known Ports and are associated with standard services such as FTP, HTTP, SMTP or DNS. Some of the addresses over 1023 also have commonly associated services, but the majority of these ports are not associated with any service and are available for a program or application to use to communicate on.
Port scanning software, in its most basic state, simply sends out a request to connect to the target computer on each port sequentially and makes a note of which ports responded or seem open to more in-depth probing.
If the port scan is being done with malicious intent, the intruder would generally prefer to go undetected. Network security applications can be configured to alert administrators if they detect connection requests across a broad range of ports from a single host. To get around this the intruder can do the port scan in strobe or stealth mode. Strobing limits the ports to a smaller target set rather than blanket scanning all 65536 ports. Stealth scanning uses techniques such as slowing the scan. By scanning the ports over a much longer period of time you reduce the chance that the target will trigger an alert.
By setting different TCP flags or sending different types of TCP packets the port scan can generate different results or locate open ports in different ways. A SYN scan will tell the port scanner which ports are listening and which are not depending on the type of response generated. A FIN scan will generate a response from closed ports- but ports that are open and listening will not send a response, so the port scanner will be able to determine which ports are open and which are not.
There are a number of different methods to perform the actual port scans as well as tricks to hide the true source of port scan. You can read more about some of these by visiting these web sites: Port Scanning or Network Probes Explained.
It is possible to monitor your network for port scans. The trick, as with most things in information security, is to find the right balance between network performance and network safety. You could monitor for SYN scans by logging any attempt to send a SYN packet to a port that isn't open or listening. However, rather than being alerted every time a single attempt occurs- and possibly being awakened in the middle of the night for an otherwise innocent mistake- you should decide on thresholds to trigger the alert. For instance you might say that if there are more than 10 SYN packet attempts to non-listening ports in a given minute that an alert should be triggered. You could design filters and traps to detect a variety of port scan methods- watching for a spike in FIN packets or just an anomylous number of connection attempts to a variety of ports and / or IP addresses from a single IP source.
To help ensure that your network is protected and secure you may wish to perform your own port scans. A MAJOR caveat here is to ensure you have the approval of all the powers that be before embarking on this project lest you find yourself on the wrong side of the law. To get accurate results it may be best to perform the port scan from a remote location using non-company equipment and a different ISP. Using software such as NMap you can scan a range of IP addresses and ports and find out what an attacker would see if they were to port scan your network. NMap in particular allows you to control almost every aspect of the scan and perform various types of port scans to fit your needs.
Once you find out what ports respond as being open by port scanning your own network you can begin to work on determining whether its actually necessary for those ports to be accessible from outside your network. If they're not necessary you should shut them down or block them. If they are necessary, you can begin to research what sorts of vulnerabilities and exploits your network is open to by having these ports accessible and work to apply the appropriate patches or mitigation to protect your network as much as possible.
The 7 Habits of Highlty Effective Network Professionals
1. BE BUSINESS SAVVY
The savvy Network Professional is engaged with people at all levels and departments within the organization. It isn’t enough to simply interact with your fellow IT department members; you need to engage with business line managers, product managers, and executives. By interacting with a more diverse group of co-workers, you’ll get access to the business intelligence that’s as likely to be shared during a coffee break as it is during a formal business meeting. This intimate knowledge of what’s happening in your organization will be invaluable when you’re faced with the all too common scenario of deploying your resources to meet competing goals. By developing an understanding of who the players are- and who they aren’t- you can more easily make IT decisions that will positively impact your company. For example, if you know that sales and marketing organizations are planning to increase e-commerce initiatives, you can invest early in the research, acquisition, purchase, and management of the hardware and software this channel requires. All of your internal customers are looking to IT to help solve their business issues. But how do you decide whether to implement a new collection system or a new contact management system? You’ll likely start by evaluating the current solutions. Are they working as expected? Can small changes be made to improve performance? Are the systems effectively obsolete, making any further investment of questionable value? You also need to evaluate the business environment. Which system is more urgent? Which will have a greater impact on the company’s revenue and profitability? By understanding the business realities on the ground, you can position yourself to make smarter decisions. For instance, what if you knew that the business unit seeking a new contact management system was growing at 200 percent a year, and would be responsible for the company’s next product rollout? This information makes your decision an easier one, but you can’t always count on the intelligence being readily available. Only by playing an active and visible role in you company can you develop the business savvy that will help you succeed.
2. SET EXPECTATION APPROPRIATELY
Everybody’s an expert, right? How many times have business managers come to you and told you exactly what technology solutions the need to solve their business issues? It’s a critical part of you job not to only select the most appropriate solutions, but also to set expectations properly so that your users understand how much the solution will cost, how long it will take to deploy, and exactly what it can and can’t do. Often, it’s Network Professionals who take the hit when a solution doesn’t meet expectations. It’s in your best interests to close the gap between the business side of the house and it. When managers know up front what the can expect, your job is much easier. And when you deliver in line with expectations, you’ll be putting yourself in a better position to meet the expectations of your internal customers and fulfill the requirements of your service level agreement.
3. BE FINANCIALLY PRUDENT
In order to make effective decisions, Network Professionals must understand common financial terms like Return On Investment (ROI) and Total Cost of Ownership (TCO) and be ready to discuss them with business line managers. By understanding both the up front and long-term costs of technology solutions, you’ll be better able to guide you organization in making technology choices that will positively impact the business. Managing your budget involves looking not only at expenditures, but also at expected returns. By working with business line managers to understand how the manage P&L, you become a partner who helps them achieve their business goals as you spend your budget wisely.
4. BE A TECHNOLOGY REALIST.
It’s probably not a stretch to say that you love technology. But as a Network Professional, you also need to be a technology realist. While you may admire the elegance of a new technology solution, you’re realistic enough to know that what matters for your company is how that technology can be applied to solve business problems, improve processes, and increase sales. You have to be prepared to say no to shiny new software if it can’t solve the pain points your company is experiencing. By staying up-to-date on the latest technology as well as on those coming down the road, you can separate the must haves from the want-to-haves. And in doing this, you’ll be looked at as a credible source for technology advice and road-mapping, increasing you strategic value and enhancing you career.
5. BE CREDENTIAL READY PRACTICE PROVEN
You’re working in a global community, full of people with top-notch education and certifications. Employers are selecting candidates from the international talent pool, so you need to be ale to compete. In this environment, certifications really do matter. Be sure to make advantage of employer reimbursement programs for training opportunities, but don’t be afraid to invest in getting yourself certified – you’ll quickly realize the return of this investment on your career. It’s also important to have practical experience and not be afraid to get your hands dirty. Stay on top of emerging technologies, and seize every opportunity to get involved with a new implementation to keep your skills sharp and up-to-date. Network Professionals who understand both the theory and practice of technology will see their achievements reflected in their salary and benefits.
6. BE DIPLOMATIC
In your role as a Network Professional, you’ll find yourself working with a diverse group of people in a wide variety of situations. From IT management to product managers, you’ll need to develop diplomatic skills that will allow you to navigate smoothly through your organization. Keep in mind that you’ll be called upon to explain technology to nontechnical employees and you should learn how to explain pros and cons in language the can relate to.
7. CULTIVATE AN OPTIMISTIC OUTLOOK
The job of a Network Professional is a tough one. You’re forced to more dozens of demands, expectations, and realities from internal customers throughout your organization. You’re the first person they’ll call when something goes wrong, but you may never hear about it when thing right. When you come to work in the morning in a positive frame of now your day will fly by, and you’re more likely to have a fulfilling career.
NESSUS
WIRESHARK
Wednesday, June 3, 2009
SNORT
Snort is a free and open source network intrusion prevention system (NIPS) and network intrusion detection system (NIDS) capable of performing packet logging and real-time traffic analysis on IP networks. Snort was written by Martin Roesch and is now developed by Sourcefire, of which Roesch is the founder and CTO. Integrated enterprise versions with purpose built hardware and commercial support services are sold by Sourcefire.
Snort performs protocol analysis, content searching/matching, and is commonly used to actively block or passively detect a variety of attacks and probes, such as buffer overflows, stealth port scans, web application attacks, SMB probes, and OS fingerprinting attempts, amongst other features. The software is mostly used for intrusion prevention purposes, by dropping attacks as they are taking place. Snort can be combined with other software such as SnortSnarf, sguil, OSSIM, and the Basic Analysis and Security Engine (BASE) to provide a visual representation of intrusion data. With patches for the Snort source from Bleeding Edge Threats, support for packet stream antivirus scanning with ClamAV and network abnormality with SPADE in network layers 3 and 4 is possible with historical observation. ( These patches seem to be no longer maintained )
Monday, June 1, 2009
Network Vulnerability Assessment Using Data Mining Techniques
The proposed framework would monitor the network traffic in details to analyze and classify the data connections to carry out the network vulnerability assessment of the hosts/networks.
Problem:
Due to the dynamic nature of the traffic characteristics, ever-changing network environment, the network vulnerability assessment has been proven to be complex, erroneous, costly and inefficient for many large-networked organizations.
This framework will compose a set of techniques and algorithms to assess the network vulnerabilities with the help of data mining techniques.
One of the main problems that to be addressed that how much the network vulnerability assessments are useful, up-to-dated, well-organized or efficient to reflect the current characteristics of network traffics.
Objective:
The main objective is to prepare a set of techniques and algorithms to analysis and assess the network vulnerabilities.
(1) Data mining technique to deduce network vulnerabilities by mining its network traffic log based on its frequency and the behaviors,
(2) A technique to identify the dominant vulnerabilities and any decaying vulnerabilities with the time
The secondary objective is to prepare a portable network vulnerability analyzer, which can be used to monitor/analyze vulnerabilities of the network traffic generated by networks/network nodes. This device is supposed to be connected to the network port of the computer/PC without changing the clients network topology configurations. The proposed toolkit may be able to sit between the LAN and the LAN's exit point, generally the WAN or Internet router, and all packets leaving and entering the network would go through them. In most cases the toolkit would operate as a bridge on the network so that it is undetectable by users.
Deliverables
1. A set of techniques and algorithms to deduce network vulnerabilities by mining its network traffic log based on its frequency and the behaviors.
2. A new software toolkit to analyze the network traffic for troubleshooting purposes while detecting unwanted traffic like worm/virus traffic etc. A portable toolkit that is capable to analyze and troubleshoot the problems may cause due to worm/virus attacks/intrusion attacks.
3. A detail study of the existing/common network traffic analysis and classification techniques.
Methodology
Various software tools are available to measure network traffic. Some tools measure traffic by sniffing and others use SNMP like methods to measure bandwidth use on servers and routers etc. However, for certain vulnerability assessment work may need to analyze the traffic in detail. Since it is required to position a traffic analyzer in different locations in the network to carry out the network vulnerability detections. So it is necessary to place a device with proper software toolkits, which doesn’t disturb the network topology and should be able to setup fairly fast.
Further, the packet sniffers are very useful for network experts tracking down tricky problems. But the volume of information they generate is enormous. A fast broadband connection can transmit thousands or millions of packets per second, and inspecting each one in detail is unlikely to help you make your network faster. In addition, understanding the output of these analyzers requires a detailed understanding of network protocols such as TCP/IP and HTTP. A protocol level broad overview would be useful, at least as a starting point for tracking down the network vulnerabilities of their networks.
In the research, I would like to introduce a new technique to the process of network vulnerability assessment using data mining techniques which consisting of anomaly detection, generalization and rules for data mining using frequency-based techniques. The steps are in summary, (1) to provide a capacity to reflect current trend of network traffic and thus to assess the network vulnerabilities if it contains in real time from traffic log data files, (2) to provide a tool to analyze its traffic patterns for the further analysis and anomaly detection including those hidden vulnerabilities, and for the decision making, (3) to apply various data mining techniques to handle both discrete and continuous attributes with operational efficiency and flexibility, and (4) to demonstrate the merit of data mining based algorithms not only feasible but also more accurate and effective (as traffic log dataset gets larger in size and variation in projection).
The anomaly detection based on the mining exposes many hidden vulnerabilities, not only those types of the anomalies detectable by analyzing the traffic logs for a long time periods but also those anomalies not detectable by analyzing the traffic logs for short periods. As a result, this analysis may conclude new types of the anomalies in the networks.
In conclusion, the data mining will be shown as one of the viable options but also a practical, effective and critical approach in network vulnerability assessment in the real time.
References
1. TANDI: Threat Assessment of Network Data and Information
By Jared Holsopple, Shanchieh Jay Yang, and Moises Sudit
2. A Graph-Based System for Network-Vulnerability Analysis
By Cynthia Phillips, Laura Painton Swiler
3. Scalable, Graph-Based Network Vulnerability Analysis∗
By Paul Ammann, Duminda Wijesekera, Saket Kaushik
4. Managing a Network Vulnerability Assessment
By Thomas R. Peltier, Justin Peltier and John A. Blackley
ISBN:0849312701
Auerbach Publications 2003
5. Network vulnerability assessment using Bayesian networks
By Yu Liu, Hong Man
6. Worm Traffic Analysis and Characterization
By Dainotti A, Pescap A, Ventre G.
Univ. of Napoli Federico II, Naples
Saturday, February 2, 2008
Profile:
Profession : Computer Engineer.
( Presently working for M-net Pvt Ltd as a computer engineer)
Education : BSc Eng Hons in Electrical & Electronic Engineering.
(at Faculty of Engineering, University of Peradeniya)
Nationality: Sri Lankan.
Marital Status: Married.
Contact :
Residence : Battaramulla, Sri Lanka.
Electronic mail : info@daminda.com
Last updated 11th Nov 2008
