Hacknotes : Network Security Portable Reference

Total Page:16

File Type:pdf, Size:1020Kb

Hacknotes : Network Security Portable Reference HackNote / HackNotes Network Security Portable Reference / Horton & Mugge / 222783-4 / Color profile: Generic CMYK printer profile Composite Default screen blind folio i HACKNOTES™ “Surprisingly complete. I have found this book to be quite useful and a great time-saver. There is nothing more irritating than thrashing in a search engine trying to remember some obscure tool or an obscure tool’s obscure feature. A great reference for the working security consultant.” —Simple Nomad, Renowned Security Researcher and Author of The Hack FAQ “While a little knowledge can be dangerous, no knowledge can be deadly. HackNotes: Network Security Portable Reference covers an immense amount of information readily available that is required for network and system administrators, who need the information quickly and concisely. This book is a must-have reference manual for any administrator.” —Ira Winkler, Chief Security Strategist at HP, security keynote speaker and panelist “HackNotes puts readers in the attacker’s shoes, perhaps a little too close. Security pros will find this reference a quick and easily digestible explanation of common vulnerabilities and how hackers exploit them. The step-by-step guides are almost too good and could be dangerous in the wrong hands. But for those wearing white hats, HackNotes is a great starting point for understanding how attackers enumerate, attack and escalate their digital intrusions.” —Lawrence M. Walsh, Managing Editor, Information Security Magazine “A comprehensive security cheat sheet for those short on time. This book is ideal for the consultant on a customer site in need of a robust reference manual in a concise and easy to parse format.” —Mike Schiffman, CISSP, Researcher, Critical Infrastructure Assurance Group, Cisco Systems, creator of the Firewalk tool and author of Hacker’s Challenge 1 & 2 “Heavy firepower for light infantry; Hack Notes delivers critical network security data where you need it most, in the field.” —Erik Pace Birkholz, Principal Consultant, Foundstone, and Author of Special Ops: Host and Network Security for Microsoft, UNIX, and Oracle. P:\010Comp\HackNote\783-4\fm.vp Monday, June 30, 2003 1:20:05 PM HackNote / HackNotes Network Security Portable Reference / Horton & Mugge / 222783-4 / Color profile: Generic CMYK printer profile Composite Default screen blind folio ii This page intentionally left blank P:\010Comp\HackNote\783-4\fm.vp Monday, June 30, 2003 1:20:05 PM HackNote / HackNotes Network Security Portable Reference / Horton & Mugge / 222783-4 / Color profile: Generic CMYK printer profile Composite Default screen blind folio iii HACKNOTES™ Network Security Portable Reference MIKE HORTON CLINTON MUGGE Enigma Sever McGraw-Hill/Osborne New York Chicago San Francisco Lisbon London Madrid Mexico City Milan New Delhi San Juan Seoul Singapore Sydney Toronto P:\010Comp\HackNote\783-4\fm.vp Monday, June 30, 2003 1:20:05 PM Color profile: GenericHackNote CMYK printer/ HackNotes profile Network Security Portable Reference / Horton & Mugge / 222783-4 / Composite Default screen blind folio 1 McGraw-Hill/Osborne 2100 Powell Street, 10th Floor Emeryville, California 94608 U.S.A. To arrange bulk purchase discounts for sales promotions, premiums, or fund-raisers, please contact McGraw-Hill/Osborne at the above address. For information on translations or book distributors outside the U.S.A., please see the International Contact Information page immediately following the index of this book. HackNotes™ Network Security Portable Reference Copyright © 2003 by The McGraw-Hill Companies. All rights reserved. Printed in the United States of America. Except as permitted under the Copyright Act of 1976, no part of this publication may be reproduced or distributed in any form or by any means, or stored in a database or retrieval system, without the prior written permission of publisher, with the exception that the program listings may be entered, stored, and executed in a computer system, but they may not be reproduced for publication. 1234567890 DOC DOC 019876543 ISBN 0-07-222783-4 Publisher Proofreader Brandon A. Nordin Claire Splan Vice President & Indexer Associate Publisher Irv Hershman Scott Rogers Composition Editorial Director Tara A. Davis Tracy Dunkelberger Elizabeth Jang Executive Editor Illustrators Jane K. Brownlow Kathleen Fay Edwards Project Editor Lyssa Wald Monika Faltiss Series Design Acquisitions Coordinator Dick Schwartz Athena Honore Peter F. Hancik Technical Editor Cover Series Design John Brock Dodie Shoemaker Copy Editor Judith Brown This book was composed with Corel VENTURA™ Publisher. Information has been obtained by McGraw-Hill/Osborne and the Authors from sources believed to be reliable. However, because of the possibility of human or mechanical error by our sources, McGraw-Hill/ Osborne, the Authors, or others, McGraw-Hill/Osborne and the Authors do not guarantee the accuracy, adequacy or completeness of any information and is not responsible for any errors or omissions or the results obtained from use of such information. P:\010Comp\HackNote\783-4\fm.vp Monday, June 30, 2003 1:20:06 PM HackNote / HackNotes Network Security Portable Reference / Horton & Mugge / 222783-4 / Color profile: Generic CMYK printer profile Composite Default screen blind folio 1 To my family, loved ones, and friends who encouraged me and put up with the seemingly endless long work days and weekends over the months. —Mike To Michelle and Jacob for supporting short weekends together and long nights apart. —Clinton P:\010Comp\HackNote\783-4\fm.vp Monday, June 30, 2003 1:20:06 PM HackNote / HackNotes Network Security Portable Reference / Horton & Mugge / 222783-4 / FM Color profile: Generic CMYK printer profile Composite Default screen vi HackNotes Network Security Portable Reference About the Authors Mike Horton A principal consultant with Foundstone, Inc., Mike Horton specializes in secure network architecture design, network penetration assess- ments, operational security program analysis, and physical security as- sessments. He is the creator of the HackNotes book series and the founder of Enigma Sever security research (www.enigmasever.com). His background includes over a decade of experience in corporate and industrial security, Fortune 500 security assessments, and Army counterintelligence. Before joining Foundstone, Mike held positions as a security inte- gration consultant for firewall and access control systems; a senior con- sultant with Ernst & Young e-Security Services, performing network penetration assessments; a chief technology officer with a start-up working on secure, real-time communication software; and a counterintelligence agent for the U.S. Army. Mike has a B.S. from City University in Seattle, Washington and has also held top secret/SCI clearances with the military. Clinton Mugge As director of consulting for Foundstone’s operations on the West Coast, Clinton Mugge defines and oversees delivery of strategic ser- vices, ranging from focused network assessments to complex enter- prise-wide risk management initiatives. Clinton’s career began as a counterintelligence agent assigned to the special projects group of the Army’s Information Warfare branch. His investigative days provided di- rect experience in physical, operational, and IT security measures. After leaving the Army he worked at Ernst & Young within the e-Security Solu- tions group, managing and performing network security assessments. Clinton has spoken at Blackhat, USENIX, CSI, and ISACA. He contributed to the Hacking Exposed series of books, Windows XP Profes- sional Security (McGraw-Hill/Osborne, 2002), and he is the technical editor on Incident Response, Investigating Computer Crime (McGraw-Hill/ Osborne, 2001). Clinton holds a B.S. from Southern Illinois University, an M.S. from the University of Maryland, and the designation of CISSP. P:\010Comp\HackNote\783-4\fm.vp Monday, June 30, 2003 1:20:06 PM HackNote / HackNotes Network Security Portable Reference / Horton & Mugge / 222783-4 / FM Color profile: Generic CMYK printer profile Composite Default screen vii About the Contributing Authors Vijay Akasapu As an information security consultant for Foundstone, Vijay Akasapu, CISSP, specializes in product reviews, web application assessments, and security architecture design. Vijay has previously worked on secu- rity architectures for international telecom providers, as well as secure application development with an emphasis on cryptography, and Internet security. He graduated with an M.S. from Michigan State Uni- versity and has an undergraduate degree from the Indian Institute of Technology, Madras. Nishchal Bhalla As an information security consultant for Foundstone, Nishchal Bhalla specializes in product testing, IDS architecture setup and design, and web application testing. Nish has performed numerous security re- views for many major software companies, banks, insurance, and other Fortune 500 companies. He is a contributing author to Windows XP Professional Security (McGraw-Hill/Osborne, 2002) and a lead instructor for Foundstone’s Ultimate Web Hacking and Ultimate Hacking courses. Nish has seven years of experience in systems and network admin- istration and has worked with securing a variety of systems including Solaris, AIX, Linux, and Windows NT. His prior experience includes network attack and penetration testing, host operating system harden- ing, implementation of host and network-based intrusion detection sys- tems, access control system design and deployment, as well as policy and procedure
Recommended publications
  • Hacking & Social Engineering
    Hacking & Social Engineering Steve Smith, President Innovative Network Solutions, Inc. Presentation Contents Hacking Crisis What is Hacking/Who is a Hacker History of Hacking Why do Hackers hack? Types of Hacking Statistics Infrastructure Trends What should you do after being hacked Proactive Steps Social Engineering Objective What is Social Engineering What are they looking for? Tactics Protecting yourself INS Approach Infrastructure Assessment Network Traffic Assessment Social Engineering Assessment Conclusion Security is Everyone’s Responsibility – See Something, Say Something! Hacking Crisis Internet has grown very fast and security has lagged behind It can be hard to trace a perpetrator of cyber attacks because most are able to camouflage their identities Large scale failures on the internet can have a catastrophic impact on: the economy which relies heavily on electronic transactions human life, when hospitals or government agencies, such as first responders are targeted What is Hacking? The Process of attempting to gain or successfully gaining, unauthorized access to computer resources Who is a Hacker? In the computer security context, a hacker is someone who seeks and exploits weaknesses in a computer system or computer network. History of Hacking Began as early as 1903: Magician and inventor Nevil Maskelyne disrupts John Ambrose Fleming's public demonstration of Guglielmo Marconi's purportedly secure wireless telegraphy technology, sending insulting Morse code messages through the auditorium's projector The term “Hacker” originated in the 1960’s at MIT A network known as ARPANET was founded by the Department of Defense as a means to link government offices. In time, ARPANET evolved into what is today known as the Internet.
    [Show full text]
  • Cheat Sheet – Common Ports (PDF)
    COMMON PORTS packetlife.net TCP/UDP Port Numbers 7 Echo 554 RTSP 2745 Bagle.H 6891-6901 Windows Live 19 Chargen 546-547 DHCPv6 2967 Symantec AV 6970 Quicktime 20-21 FTP 560 rmonitor 3050 Interbase DB 7212 GhostSurf 22 SSH/SCP 563 NNTP over SSL 3074 XBOX Live 7648-7649 CU-SeeMe 23 Telnet 587 SMTP 3124 HTTP Proxy 8000 Internet Radio 25 SMTP 591 FileMaker 3127 MyDoom 8080 HTTP Proxy 42 WINS Replication 593 Microsoft DCOM 3128 HTTP Proxy 8086-8087 Kaspersky AV 43 WHOIS 631 Internet Printing 3222 GLBP 8118 Privoxy 49 TACACS 636 LDAP over SSL 3260 iSCSI Target 8200 VMware Server 53 DNS 639 MSDP (PIM) 3306 MySQL 8500 Adobe ColdFusion 67-68 DHCP/BOOTP 646 LDP (MPLS) 3389 Terminal Server 8767 TeamSpeak 69 TFTP 691 MS Exchange 3689 iTunes 8866 Bagle.B 70 Gopher 860 iSCSI 3690 Subversion 9100 HP JetDirect 79 Finger 873 rsync 3724 World of Warcraft 9101-9103 Bacula 80 HTTP 902 VMware Server 3784-3785 Ventrilo 9119 MXit 88 Kerberos 989-990 FTP over SSL 4333 mSQL 9800 WebDAV 102 MS Exchange 993 IMAP4 over SSL 4444 Blaster 9898 Dabber 110 POP3 995 POP3 over SSL 4664 Google Desktop 9988 Rbot/Spybot 113 Ident 1025 Microsoft RPC 4672 eMule 9999 Urchin 119 NNTP (Usenet) 1026-1029 Windows Messenger 4899 Radmin 10000 Webmin 123 NTP 1080 SOCKS Proxy 5000 UPnP 10000 BackupExec 135 Microsoft RPC 1080 MyDoom 5001 Slingbox 10113-10116 NetIQ 137-139 NetBIOS 1194 OpenVPN 5001 iperf 11371 OpenPGP 143 IMAP4 1214 Kazaa 5004-5005 RTP 12035-12036 Second Life 161-162 SNMP 1241 Nessus 5050 Yahoo! Messenger 12345 NetBus 177 XDMCP 1311 Dell OpenManage 5060 SIP 13720-13721
    [Show full text]
  • Netcat and Trojans/Backdoors
    Netcat and Trojans/Backdoors ECE4883 – Internetwork Security 1 Agenda Overview • Netcat • Trojans/Backdoors ECE 4883 - Internetwork Security 2 Agenda Netcat • Netcat ! Overview ! Major Features ! Installation and Configuration ! Possible Uses • Netcat Defenses • Summary ECE 4883 - Internetwork Security 3 Netcat – TCP/IP Swiss Army Knife • Reads and Writes data across the network using TCP/UDP connections • Feature-rich network debugging and exploration tool • Part of the Red Hat Power Tools collection and comes standard on SuSE Linux, Debian Linux, NetBSD and OpenBSD distributions. • UNIX and Windows versions available at: http://www.atstake.com/research/tools/network_utilities/ ECE 4883 - Internetwork Security 4 Netcat • Designed to be a reliable “back-end” tool – to be used directly or easily driven by other programs/scripts • Very powerful in combination with scripting languages (eg. Perl) “If you were on a desert island, Netcat would be your tool of choice!” - Ed Skoudis ECE 4883 - Internetwork Security 5 Netcat – Major Features • Outbound or inbound connections • TCP or UDP, to or from any ports • Full DNS forward/reverse checking, with appropriate warnings • Ability to use any local source port • Ability to use any locally-configured network source address • Built-in port-scanning capabilities, with randomizer ECE 4883 - Internetwork Security 6 Netcat – Major Features (contd) • Built-in loose source-routing capability • Can read command line arguments from standard input • Slow-send mode, one line every N seconds • Hex dump of transmitted and received data • Optional ability to let another program service established connections • Optional telnet-options responder ECE 4883 - Internetwork Security 7 Netcat (called ‘nc’) • Can run in client/server mode • Default mode – client • Same executable for both modes • client mode nc [dest] [port_no_to_connect_to] • listen mode (-l option) nc –l –p [port_no_to_connect_to] ECE 4883 - Internetwork Security 8 Netcat – Client mode Computer with netcat in Client mode 1.
    [Show full text]
  • Secure Network Design
    NUREG/CR-7117 SAND2010-8222P Secure Network Design Office of Nuclear Regulatory Research AVAILABILITY OF REFERENCE MATERIALS IN NRC PUBLICATIONS NRC Reference Material Non-NRC Reference Material As of November 1999, you may electronically access Documents available from public and special technical NUREG-series publications and other NRC records at libraries include all open literature items, such as NRC’s Public Electronic Reading Room at books, journal articles, and transactions, Federal http://www.nrc.gov/reading-rm.html. Publicly released Register notices, Federal and State legislation, and records include, to name a few, NUREG-series congressional reports. Such documents as theses, publications; Federal Register notices; applicant, dissertations, foreign reports and translations, and licensee, and vendor documents and correspondence; non-NRC conference proceedings may be purchased NRC correspondence and internal memoranda; from their sponsoring organization. bulletins and information notices; inspection and investigative reports; licensee event reports; and Copies of industry codes and standards used in a Commission papers and their attachments. substantive manner in the NRC regulatory process are maintained at— NRC publications in the NUREG series, NRC The NRC Technical Library regulations, and Title 10, Energy, in the Code of Two White Flint North Federal Regulations may also be purchased from one 11545 Rockville Pike of these two sources. Rockville, MD 20852–2738 1. The Superintendent of Documents U.S. Government Printing Office These standards are available in the library for Mail Stop SSOP reference use by the public. Codes and standards are Washington, DC 20402–0001 usually copyrighted and may be purchased from the Internet: bookstore.gpo.gov originating organization or, if they are American Telephone: 202-512-1800 National Standards, from— Fax: 202-512-2250 American National Standards Institute 2.
    [Show full text]
  • Secure by Design, Secure by Default: Requirements and Guidance
    Biometrics and Surveillance Camera Commissioner Secure by Design, Secure by Default Video Surveillance Products Introduction This guidance is for any organisation manufacturing Video Surveillance Systems (VSS), or manufacturing or assembling components intended to be utilised as part of a VSS. It is intended to layout the Biometrics and Surveillance Camera Commissioners (BSCC) minimum requirements to ensure such systems are designed and manufactured in a manner that assures they are Secure by Design. It also contains certain component requirements that will ensure a configuration that is Secure by Default when the component is shipped, thereby making it more likely that the system will be installed and left in a secure state. This guidance forms part of a wider suite of documentation being developed as part of the SCC Strategy, in support of the SCC Code of Practice. Background and Context The nature of the Internet means that connected devices can be subjected to a cyber attack from anywhere in the world. Widespread attacks on connected products is a current and real threat, and a number of highly publicised attacks have already occurred. The Mirai malware targeted devices such as internet-enabled cameras (IP cameras). Mirai was successful because it exploited the use of common default credentials (such as a username and password being set by the manufacturer as ‘admin’) and poor security configuration of devices. Ultimately, this facilitated attacks on a range of commercial and social media services and included an outage of streaming services such as Netflix. An evolution of Mirai, called Reaper, has also been discovered. Reaper used publicly and easily available exploits that remained unfixed (patched) and highlighted the problem around non patching of known security vulnerabilities, allowing attackers to utilise them to cause harm.
    [Show full text]
  • Trojans and Malware on the Internet an Update
    Attitude Adjustment: Trojans and Malware on the Internet An Update Sarah Gordon and David Chess IBM Thomas J. Watson Research Center Yorktown Heights, NY Abstract This paper continues our examination of Trojan horses on the Internet; their prevalence, technical structure and impact. It explores the type and scope of threats encountered on the Internet - throughout history until today. It examines user attitudes and considers ways in which those attitudes can actively affect your organization’s vulnerability to Trojanizations of various types. It discusses the status of hostile active content on the Internet, including threats from Java and ActiveX, and re-examines the impact of these types of threats to Internet users in the real world. Observations related to the role of the antivirus industry in solving the problem are considered. Throughout the paper, technical and policy based strategies for minimizing the risk of damage from various types of Trojan horses on the Internet are presented This paper represents an update and summary of our research from Where There's Smoke There's Mirrors: The Truth About Trojan Horses on the Internet, presented at the Eighth International Virus Bulletin Conference in Munich Germany, October 1998, and Attitude Adjustment: Trojans and Malware on the Internet, presented at the European Institute for Computer Antivirus Research in Aalborg, Denmark, March 1999. Significant portions of those works are included here in original form. Descriptors: fidonet, internet, password stealing trojan, trojanized system, trojanized application, user behavior, java, activex, security policy, trojan horse, computer virus Attitude Adjustment: Trojans and Malware on the Internet Trojans On the Internet… Ever since the city of Troy was sacked by way of the apparently innocuous but ultimately deadly Trojan horse, the term has been used to talk about something that appears to be beneficial, but which hides an attack within.
    [Show full text]
  • 8 Ways to Protect Your Network Against Ransomware
    8 ways to protect your network against ransomware Steps to prevent ransomware attacks and save your money The ransomware threat Sometimes old becomes new again. Such is the case with ransomware attacks, which have become popular once more. First released in 1989, ransomware infects a system and “locks out” the user from accessing the device or files on it. Only when the victim agrees to pay a ransom, usually in the form of bitcoins, can the system be unlocked and accessed again. The following e-book provides eight ways you can protect your network against ransomware attacks and avoid giving your money to cybercriminals. Ransom amounts vary, but are often in the $200-$400 range.1 1. Educate your employees User education and awareness are critical when it comes to defeating ransomware. Treat suspicious emails with caution. Look at the domain name that sent the email. Check for spelling mistakes, review the signature and the legitimacy of the request. Hover over links to check where they lead to. 2. Use a multi-layered approach to network security Protection from ransomware and other forms of malware doesn’t begin and end at the gateway. Extending security through the use of anti-virus, anti-spyware, intrusion prevention and other technologies on devices at the network perimeter is critical. Adopt a layered approach to stop ransomware by avoiding a single point of failure in your security architecture. 2 3. Back up your files regularly Another safeguard against having to pay ransom is a robust backup and recovery strategy. Depending on how quickly the compromise is detected, how widely it has spread and the level of data loss that is acceptable, recovery from a backup could be a good option.
    [Show full text]
  • Secure Network Foundation 1.1 Design Guide for Single Site Deployments
    Secure Network Foundation 1.1 Design Guide for Single Site Deployments This document provides a simple vision for a smart and secure business where everyday communications are made easier, faster, and more efficient. Cisco partners and resellers can help small-to-medium size businesses leverage the full value of their data networks by deploying reliable secure routers and switches from Cisco Systems that are easily provisioned and managed via the use of simple graphical user interface (GUI) tools. The validated design guidance provided in this document and the validated implementation guidance covered in the Secure Network Foundation Implementation Guide for Single Site Deployments (EDCS-517888) provide a verified reference, ensuring that the individual components that the system is composed of work well together. Note The design described in this document is based on a simplified and cost-effective approach to establishing a secure network foundation as the initial phase of a network evolution. The redundancy in LAN and WAN design is a mandatory attribute of a resilient network. A resilient network is recommended for any network that transports mission-critical traffic. This aspect of LAN and WAN design will be documented in a subsequent release of the validated design. In the meantime, contact your Cisco representative if you have any questions. Contents Overview 1 Solution Components 2 Secure Network Foundation 3 Local Area Network Design 3 Virtual Local Area Networks (VLANs) 4 802.1Q Trunking 4 Spanning Tree 4 Smartports Roles 5 Wide Area Network Design 6 Corporate Headquarters: Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USA Copyright © 2004 Cisco Systems, Inc.
    [Show full text]
  • Study on Computer Trojan Horse Virus and Its Prevention ZHU Zhenfang
    International Journal of Engineering and Applied Sciences (IJEAS) ISSN: 2394-3661, Volume-2, Issue-8, August 2015 Study on Computer Trojan Horse Virus and Its Prevention ZHU Zhenfang to steal or viciously revise files, spy system information, steal various commands and passwords, and even format users’ Abstract— In recent years, the fast development of computer hardware. In addition, Trojan horse virus usually records network technology, has become an integral part of human’s life, keyboard operation by means of keyboard record, and then work and study. But with the popularity of the Internet, obtains the account and password of E-bank. Attackers can computer viruses, Trojans and other new terms have become some well-known network vocabularies. Studies have shown directly steal users’ wealth by obtaining accounts and that most users of computer are more or less suffered from passwords. On the other hand, Trojan horse can also cause the computer virus. So people must attach great importance to the native machine be affected by other vicious virus. network security problem. The paper studied Trojan virus. Paper first introduced the concept, characteristics and PREVENTION OF HORSE VIRUS categories of the Trojan virus and its harm, and then focused on the way and means of the Trojan’s spread. It introduced the According to the above introduction, we know that Trojan virus loading and hiding technology, too. Its last part Trojan horse virus is very dangerous. If we neglect the focused on the prevention measures, it put forward reasonable prevention, our computer may be easily attacked. For the suggestions to users, and paper also put forward prevention prevention of Trojan intrusion, Trojan intrusion should be advice to improve network security.
    [Show full text]
  • Pdf 2000 Check(Auth ) B [Fer03] Niels Ferguson, Bruce Schneier, „Practical Cryptography“, John Wiley & Sons, 2003 [Gar03] Jason Garman, “Kerberos
    Chair for Network Architectures and Services Overview Institute of Informatics TU München – Prof. Carle Part I: Introduction Network Security Part I: Introduction PartPart II: II: The The Secure Secure Channel Channel Part III: Authentication and Key Establishment Protocols Chapter 3 Part III: Authentication and Key Establishment Protocols KeyKey Distribution Distribution Centers Centers (KDC) (KDC) PublicPublic Key Key Infrastructures Infrastructures (PKI) (PKI) Cryptographic Protocols BuildingBuilding Blocks Blocks of of key key exchange exchange protocols protocols for Encryption, Authentication and Key Establishment Network Security, WS 2009/10, Chapter 3 2 Cryptographic Protocols Applications of Cryptographic Protocols Definition: Key establishment A cryptographic protocol is defined as a series of steps and message Authentication Data origin authentication exchanges between multiple entities in order to achieve a specific Entity authentication treated in security objective. Authenticated key establishment this course Properties of a protocol (in general): Data integrity Confidentiality Everyone involved in the protocol must know the protocol and all of the steps to follow in advance. Secret sharing Everyone involved in the protocol must agree to follow it. Key escrow (ensuring that only an authorized entity can recover keys) The protocol must be unambiguous, that is every step is well defined and Zero-Knowledge proofs (proof of knowledge of an information without revealing the there is no chance of misunderstanding. information) The protocol must be complete, i.e. there is a specified action for every Blind signatures (useful for privacy-preserving time-stamping services) possible situation. Secure elections Electronic money Additional property of a cryptographic protocol: It should not be possible to do or learn more than what is specified in the protocol.
    [Show full text]
  • Controlling Security Risk and Fraud in Payment Systems
    Controlling Security Risk and Fraud in Payment Systems By Richard J. Sullivan n late 2013, a breach of the cashier system at a major retailer ex- posed information on 40 million debit and credit cards. That Ifraudsters can use the payment card numbers harvested in this breach to create fraudulent payments underscores one of many security weaknesses that can lead to payment fraud. The direct cost of fraud on automated clearinghouse (ACH), debit card, and credit card payments reached $6.1 billion in 2012. Investments and ongoing expenses for preventing, detecting, monitoring, and responding to payment fraud add considerably to direct costs. Fraud and security weaknesses in pay- ments can have an indirect cost as well if they cause concerned con- sumers and businesses to choose less efficient forms of payment. More broadly, the public’s loss of confidence in payments has had significant negative economic consequences in the past. A constant stream of news reports on data breaches, phishing attacks, spoofed websites, payment card skimmers, fraudulent ATM withdrawals, computer malware, and infiltrated retail point-of-sale systems should concern policymakers be- cause it indicates weak payment security and undermines confidence in payments. Richard J. Sullivan is a senior economist at the Federal Reserve Bank of Kansas City. Emily Cuddy and Joshua Hanson, research associates at the bank, helped prepare this article. This article is on the bank’s website at www.KansasCityFed.org. 47 48 FEDERAL RESERVE BANK OF KANSAS CITY Payment participants—end-users who make payments, financial institutions and nonbanks that provide payment services, and networks and service providers that process payments—all have considerable in- centive to secure payments and deter fraud.
    [Show full text]
  • A Botnet Needle in a Virtual Haystack
    ANGLIA RUSKIN UNIVERSITY FACULTY OF SCIENCE AND TECHNOLOGY A BOTNET NEEDLE IN A VIRTUAL HAYSTACK MARK GRAHAM A thesis in partial fulfilment of the requirements of Anglia Ruskin University for the degree of Doctor of Philosophy Submitted: June 2017 Acknowledgements This dissertation was prepared in part fulfilment of the requirements of the degree of Doctor of Philosophy under the supervision of Adrian Winckles and Dr Erika Sanchez-Velazquez at Anglia Ruskin University. This Ph.D. journey would not have been possible without the support that I have received from many people. In particular, I express huge gratitude to my first supervisor Adrian Winckles for his inspiration and support. Adrian has been a mentor to me for many years. A huge thank you also to my second supervisor Dr. Erika Sanchez for her encouragement and motivation. I also extend my thanks to Chris Holmes for his friendship and companionship during my years spent at Anglia Ruskin University. I gratefully acknowledge the funding I received for my Ph.D. from Anglia Ruskin University. Sincere thanks goes to my head of department, Professor Marcian Cirstea for his guidance and advice. May I express my thanks to other members of the department, especially my fellow Ph.D. students; Mohamed Kettouch and Dr. Arooj Fatima. This work is dedicated to Samantha who is always there to listen. i ANGLIA RUSKIN UNIVERSITY ABSTRACT FACULTY OF SCIENCE AND TECHNOLOGY DOCTOR OF PHILOSOPHY Abstract A BOTNET NEEDLE IN A VIRTUAL HAYSTACK MARK GRAHAM JUNE 2017 The Cloud Security Alliance’s 2015 Cloud Adoption Practices and Priorities Survey reports that 73% of global IT professionals cite security as the top challenge holding back cloud services adoption.
    [Show full text]