Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security...

66
Last revised 1-17-15

Transcript of Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security...

Page 1: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Last revised 1-17-15

Page 2: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

A.A. Degree

Page 3: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.
Page 4: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.
Page 5: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

CNIT 120: Network SecurityFundamentals of Network SecurityPreparation for Security+ CertificationEssential for any Information

Technology professional

Page 6: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

CNIT 40: DNS Security Configure and defend DNS

infrastructure

Page 7: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

CNIT 121: Computer Forensics

Analyze computers for evidence of crimes

Recover lost data

Page 8: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

CNIT 122: Firewalls Defend networks

Page 9: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Two Hacking ClassesPerform real cyberattacks and block themCNIT 123: Ethical Hacking and Network DefenseCNIT 124: Advanced Ethical Hacking

9

Page 10: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Supplemental Materials Projects from recent researchStudents get extra credit by attending conferences

10

Page 11: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Certified Ethical Hacker CNIT 123 and 124 help prepare students for CEH

Certification

11

Page 12: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

CNIT 125: Information Security Professional

CISSP – the most respected certificate in information security

Page 13: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

CNIT 126: Practical Malware Analysis

Incident response after intrusion

Page 14: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

CNIT 127: Exploit DevelopmentTo be offered in Fall 2015

Turning crashes into remote code execution

Buffer overflows Return-to-libc Return Oriented

Programming

Page 15: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

CNIT 128: Hacking Mobile DevicesFirst offered in Spring 2015

Rooting and jailbreaking Android security model Locking, remote location,

and remote wipe Mobile payment, including

Google Wallet

Page 16: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.
Page 17: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Student-run Not insanely difficult Fri, Sep 19 - Sun, Sep 21 Online

Page 18: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

NATIONAL CYBER LEAGUE Register by Sep. 20 Game happens Sep 27 – Oct 4

Page 19: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.
Page 20: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

First Tues. every month Free ad Microsoft, downtown San Francisco Free Pizza

Page 21: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Sat Oct 11 & Sun Oct 12, 2014 Foothill College Developers, not focused on security

Page 22: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Wardriving

Thu, Nov 20 6 PM SCIE 200

Page 23: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Security talks, lockpicking, contests, etc. Fri, Dec 5 & Sat, Dec 6 Mt. View Cost: approx. $35

Page 24: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Chapter 1Ethical Hacking Overview Last modified 8-21-14

Page 25: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 25

Describe the role of an ethical hackerDescribe what you can do legally as

an ethical hackerDescribe what you cannot do as an

ethical hacker

Page 26: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.
Page 27: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 27

Ethical hackers Employed by companies to perform penetration tests

Penetration test Legal attempt to break into a company’s network to

find its weakest link Tester only reports findings, does not solve problems

Security test More than an attempt to break in; also includes

analyzing company’s security policy and procedures Tester offers solutions to secure or protect the

network

Page 28: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 28

Hackers Access computer system or network without

authorization Breaks the law; can go to prison

Crackers Break into systems to steal or destroy data U.S. Department of Justice calls both hackers

Ethical hacker Performs most of the same activities but with owner’s

permission

Page 29: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 29

Script kiddies or packet monkeys Young inexperienced hackers Copy codes and techniques from knowledgeable

hackers Experienced penetration testers write programs

or scripts using these languages Practical Extraction and Report Language (Perl), C,

C++, Python, JavaScript, Visual Basic, SQL, and many others

Script Set of instructions that runs in sequence

Page 30: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

This class alone won’t make you a hacker, or an expert It might make you a script kiddie

It usually takes years of study and experience to earn respect in the hacker community

It’s a hobby, a lifestyle, and an attitude A drive to figure out how things work

Hands-On Ethical Hacking and Network Defense 30

Page 31: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 31

Tiger box Collection of OSs and hacking tools Usually on a laptop Helps penetration testers and security

testers conduct vulnerabilities assessments and attacks

Page 32: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 32

White box model Tester is told everything about the

network topology and technology Network diagram

Tester is authorized to interview IT personnel and company employees

Makes tester’s job a little easier

Page 33: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

From ratemynetworkdiagram.com (Link Ch 1g)

Hands-On Ethical Hacking and Network Defense 33

Page 34: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 34

Page 35: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 35

Black box model Company staff does not know about the

test Tester is not given details about the

network▪ Burden is on the tester to find these details

Tests if security personnel are able to detect an attack

Page 36: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 36

Gray box model Hybrid of the white and black box

models Company gives tester partial

information

Page 37: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.
Page 38: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 38

Basics: CompTIA Security+ (CNIT 120) Network+ (CNIT 106 or 201)

Page 39: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

39

CNIT 123: Ethical Hacking and Network Defense

CNIT 124: Advanced Ethical Hacking

Page 40: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

40

Designated by the Institute for Security and Open Methodologies (ISECOM) Uses the Open Source Security Testing

Methodology Manual (OSSTMM) Test is only offered in Connecticut and

outside the USA, as far as I can tell▪ See links Ch 1f and Ch 1h on my Web page

Page 41: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

41

Issued by the International Information Systems Security Certifications Consortium (ISC2) Usually more concerned with

policies and procedures than technical details

CNIT 125: Information Security Professional Practices

Web site: www.isc2.org

Page 42: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 42

SysAdmin, Audit, Network, Security (SANS) Offers certifications through Global

Information Assurance Certification (GIAC) Top 20 list

One of the most popular SANS Institute documents

Details the most common network exploits Suggests ways of correcting vulnerabilities

Web site www.sans.org (links Ch 1i & Ch 1j)

Page 43: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.
Page 44: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 44

Laws involving technology change as rapidly as technology itself

Find what is legal for you locally Laws change from place to place

Be aware of what is allowed and what is not allowed

Page 45: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 45

Tools on your computer might be illegal to possess

Contact local law enforcement agencies before installing hacking tools

Written words are open to interpretation Governments are getting more serious

about punishment for cybercrimes

Page 46: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 46

Some states deem it legal Not always the case Federal Government does not see it as

a violation Allows each state to address it separately

Read your ISP’s “Acceptable Use Policy” IRC “bots” may be forbidden

Program that sends automatic responses to users Gives the appearance of a person being present

Page 47: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 47

www.ccsf.edu/Policy/policy.shtml (link Ch 1k)

Page 48: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 48

Federal computer crime laws are getting more specific Cover cybercrimes and intellectual

property issues Computer Hacking and Intellectual

Property (CHIP) New government branch to address

cybercrimes and intellectual property issues

Page 49: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 49

Page 50: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 50

Accessing a computer without permission is illegal

Other illegal actions Installing worms or viruses Denial of Service attacks Denying users access to network resources

Be careful your actions do not prevent customers from doing their jobs

Page 51: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 51

Using a contract is just good business Contracts may be useful in court Books on working as an independent contractor

The Computer Consultant’s Guide by Janet Ruhl Getting Started in Computer Consulting by Peter

Meyer Internet can also be a useful resource Have an attorney read over your contract

before sending or signing it

Page 52: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Hands-On Ethical Hacking and Network Defense 52

What it takes to be a security tester Knowledge of network and computer

technology Ability to communicate with

management and IT personnel Understanding of the laws Ability to use necessary tools

Page 53: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.
Page 54: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Fake Antimalware Software

See Link Ch 1m

Page 55: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Anonymous

http://www.indybay.org/newsitems/2011/08/16/18687809.php

Page 56: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.
Page 57: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Social Engineering & SQLi

http://tinyurl.com/4gesrcj

Page 58: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Leaked HB Gary Emails

For Bank of AmericaDiscredit WikileaksIntimidate Journalist Glenn Greenwald

For the Chamber of Commerce Discredit the watchdog group US Chamber

Watch Using fake social media accounts

For the US Air Force Spread propaganda with fake accounts

http://tinyurl.com/4anofw8

Page 59: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Drupal Exploit

Page 60: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

OpBART Dumped thousands of commuter's emails

and passwords on the Webhttp://www.djmash.at/release/users.html

Defaced MyBart.orghttp://www.dailytech.com/Anonymous

%20Targets%20Californias%20Infamous%20BART%20Hurts%20Citizens%20in%20the%20Process/article22444.htm

Page 61: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

LulzSec The "skilled" group of Anons who

hackedUS Senate AZ PolicePron.com Booz HamiltonSony NATOInfragard The SunPBS Fox NewsH B Gary Federal Game websites

Page 62: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Ryan Cleary Arrested June 21, 2011 Accused of DDoSing the UK’s Serious Organised Crime

Agency Link Ch 1v

Page 63: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

T-Flow Arrested July 19, 2011

Link Ch 1u

Page 64: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Topiary (Jake Davis) Arrested on 7-27-11 Sentenced to 2 years, served

37 days in prison He's back on Twitter

@DoubleJake Links Ch 1s, 1t

Page 65: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Link Ch 1v

Page 66: Last revised 1-17-15. A.A. Degree CNIT 120: Network Security Fundamentals of Network Security Preparation for Security+ Certification Essential for.

Stay Out of Anonymous

Link Ch 1w