SIM314 Introduction Transport Layer Summary Network Layer.


Transcript of SIM314 Introduction Transport Layer Summary Network Layer.

Page 1: SIM314 Introduction Transport Layer Summary Network Layer.
Page 2: SIM314 Introduction Transport Layer Summary Network Layer.

Network Layers (in) Security

Paula JanuszkiewiczIT Security Auditor, MVP, [email protected]

Marcus MurraySecurity Team Manager, MVP, MCTTrueSec [email protected]


Page 3: SIM314 Introduction Transport Layer Summary Network Layer.



Transport Layer

Application Layer

Presentation Layer

Session Layer


Network Layer

Data-Link Layer

Physical Layer

Page 4: SIM314 Introduction Transport Layer Summary Network Layer.
Page 5: SIM314 Introduction Transport Layer Summary Network Layer.

The Issue

No matter how well we secure our hosts we are always “vulnerable” on some layers of the infrastructure

Security is a prime concern for networkingWhile access to the network is enough to break its integrity

Still tiny malicious actions can do a lot of damage

Usability stands in front of the securityInteroperability is based on protocols created more then 30 years ago!

So what is this “Network Security” about?

Page 6: SIM314 Introduction Transport Layer Summary Network Layer.

Physical Layer

IssuesLoss of power or environmental controlDisconnection, damage or theft of physical resourcesUnauthorized access: wired or wirelessKey loggers or other data interception method

Countermeasures Use appropriate physical access control f.e. electronic locks or retina scanningRecord video and audio in the company premisesEmployee trainingPhysical network isolation

Transport Layer

Application Layer

Presentation Layer

Session Layer

Network Layer

Data-Link Layer

Physical Layer

Page 7: SIM314 Introduction Transport Layer Summary Network Layer.

Sniff fiber

Page 8: SIM314 Introduction Transport Layer Summary Network Layer.


Page 9: SIM314 Introduction Transport Layer Summary Network Layer.


Wireless Attack BasicsThe scenario of physical access

Page 10: SIM314 Introduction Transport Layer Summary Network Layer.

Data-Link Layer

IssuesMAC address spoofing Wireless accessibilitySpanning tree malfunctionsTraffic flooding on the switch level

Countermeasures Segmentation (VLANs)Use corporate-level wireless solutionsDisable all unnecessary switch ports

Transport Layer

Application Layer

Presentation Layer

Session Layer

Network Layer

Data-Link Layer

Physical Layer

Page 11: SIM314 Introduction Transport Layer Summary Network Layer.


802.1x (IN)Security

Shadow Host Scenario

Page 12: SIM314 Introduction Transport Layer Summary Network Layer.






Page 13: SIM314 Introduction Transport Layer Summary Network Layer.

Network Layer

IssuesSpoofingIP AddressingRouting protocolsTunneling protocols

Countermeasures IPSecUse firewalls between different network segmentsUse route filtering on the edgePerform broadcast and multicast monitoringManaged IP Addressing

Transport Layer

Application Layer

Presentation Layer

Session Layer

Network Layer

Data-Link Layer

Physical Layer

Page 14: SIM314 Introduction Transport Layer Summary Network Layer.

demoPacket ModificationPlaying with protocols

Page 15: SIM314 Introduction Transport Layer Summary Network Layer.

demoDenial of ServiceIPv6 vulnerabilities and others

Evil Hacker







UntrustedComputerClient Untrusted



Page 16: SIM314 Introduction Transport Layer Summary Network Layer.

Transport Layer

IssuesConnectionless nature of UDPWeak TCP implementations

Predictable sequence numbers

May be disturbed by crafted packets Performance may impact traffic qualification and filtering

Countermeasures Host and network based firewallsIPS/IDSStrong session handling

Transport Layer

Application Layer

Presentation Layer

Session Layer

Network Layer

Data-Link Layer

Physical Layer

Page 17: SIM314 Introduction Transport Layer Summary Network Layer.

demoCommon TCP/UDP Attacks Network Trace Scenario

Page 18: SIM314 Introduction Transport Layer Summary Network Layer.

Session Layer

IssuesWeak or even lack of authenticationUnlimited number of failed authentication attemptsSession data may be spoofed and hijackedExposure of identification tokens

Countermeasures Rely on strong authentication


Use account and session expiration time Use timing to limit failed authentication attempts

Transport Layer

Application Layer

Presentation Layer

Session Layer

Network Layer

Data-Link Layer

Physical Layer

Page 19: SIM314 Introduction Transport Layer Summary Network Layer.

Presentation Layer

IssuesPoor handling of data types and structuresCryptographic flaws may be exploited to circumvent privacy protections

Countermeasures Sanitizing the input – user data should be separated from the control functionsCryptographic solutions must be up to date

Transport Layer

Application Layer

Presentation Layer

Session Layer

Network Layer

Data-Link Layer

Physical Layer

Page 20: SIM314 Introduction Transport Layer Summary Network Layer.


Null Byte Injection%00

Page 21: SIM314 Introduction Transport Layer Summary Network Layer.

Application Layer

IssuesThe most exposed layer todayBadly designed application may bypass security controlsComplex protocols and applicationError handling…

Countermeasures Application level access controlsUsing standards and testing application codeIDS/ Firewall to monitor application activity

Transport Layer

Application Layer

Presentation Layer

Session Layer

Network Layer

Data-Link Layer

Physical Layer

Page 22: SIM314 Introduction Transport Layer Summary Network Layer.

demoBinary Patching Over HTTPUnsecure protocol scenario

Poor ImplementationUser authentication scenario

Page 23: SIM314 Introduction Transport Layer Summary Network Layer.



Transport Layer

Application Layer

Presentation Layer

Session Layer


Network Layer

Data-Link Layer

Physical Layer

Page 24: SIM314 Introduction Transport Layer Summary Network Layer.


Do inventory of services and protocolsLower layers are not dependent on upper layersUse Network/Application layer for Integrity & ConfidentialitySecure all layers for accessibiliyTCP/IP is more than 30 years old

It is not idealBut has many security extensions

Page 25: SIM314 Introduction Transport Layer Summary Network Layer.

Safety and Security Center

Security Development Lifecycle

Security Intelligence Report

End to End Trust

Trustworthy Computing

Page 26: SIM314 Introduction Transport Layer Summary Network Layer.


Sessions On-Demand & Community Microsoft Certification & Training Resources

Resources for IT Professionals Resources for Developers


Connect. Share. Discuss.

Page 27: SIM314 Introduction Transport Layer Summary Network Layer.

Complete an evaluation on CommNet and enter to win!

Page 28: SIM314 Introduction Transport Layer Summary Network Layer.

Scan the Tag to evaluate this session now on myTech•Ed Mobile

Page 29: SIM314 Introduction Transport Layer Summary Network Layer.

Thank You!

Page 30: SIM314 Introduction Transport Layer Summary Network Layer.