Xây Dựng Hệ Thống Mạng Nguồn Mở Nghề: Công Nghệ Thông Tin Trình Độ: Cao Đẳng

Total Page:16

File Type:pdf, Size:1020Kb

Xây Dựng Hệ Thống Mạng Nguồn Mở Nghề: Công Nghệ Thông Tin Trình Độ: Cao Đẳng ỦY BAN NHÂN DÂN THÀNH PHỐ HỒ CHÍ MINH TRƯỜNG CAO ĐẲNG KINH TẾ - KỸ THUẬT THÀNH PHỐ HỒ CHÍ MINH GIÁO TRÌNH MÔN HỌC: XÂY DỰNG HỆ THỐNG MẠNG NGUỒN MỞ NGHỀ: CÔNG NGHỆ THÔNG TIN TRÌNH ĐỘ: CAO ĐẲNG LƯU HÀNH NỘI BỘ Tháng 12, năm 2017 ỦY BAN NHÂN DÂN THÀNH PHỐ HỒ CHÍ MINH TRƯỜNG CAO ĐẲNG KINH TẾ - KỸ THUẬT THÀNH PHỐ HỒ CHÍ MINH GIÁO TRÌNH MÔN HỌC: XÂY DỰNG HỆ THỐNG MẠNG NGUỒN MỞ NGHỀ: CÔNG NGHỆ THÔNG TIN TRÌNH ĐỘ: CAO ĐẲNG THÔNG TIN NGƯỜI BIÊN SOẠN Chủ biên: DƯƠNG ĐÌNH DŨNG Học vị: Thạc sĩ Đơn vị: Khoa Công nghệ thông tin Email: [email protected] TRƯỞNG KHOA TỔ TRƯỞNG CHỦ NHIỆM BỘ MÔN ĐỀ TÀI HIỆU TRƯỞNG DUYỆT Tháng 12, năm 2017 TUYÊN BỐ BẢN QUYỀN Tài liệu này thuộc loại sách giáo trình nên các nguồn thông tin có thể được phép dùng nguyên bản hoặc trích dùng cho các mục đích về đào tạo và tham khảo. Mọi mục đích khác mang tính lệch lạc hoặc sử dụng với mục đích kinh doanh thiếu lành mạnh sẽ bị nghiêm cấm. 1 LỜI NÓI ĐẦU Giáo trình này được biên soạn dựa trên chương trình chi tiết môn học bậc cao đẳng chuyên ngành quản trị mạng máy tính của Trường Cao đẳng Kinh tế - Kỹ thuật Thành Phố Hồ Chí Minh. Tài liệu được biên soạn nhằm cung cấp kiến thức nền tảng, giúp sinh viên nắm vững và vận dụng các kỹ thuật phổ biến với các dịch vụ mạng trong quá trình xây dựng hệ thống mạng trên hệ điều hành nguồn mở (Centos, Ubuntu). Từ đó, sinh viên có thể vận dụng vào công việc sau này.. Trong tài liệu này tác giả sử dụng phương pháp logic trình tự cho từng dịch vụ từ khái niệm, phân tích mô hình mạng, mô phỏng và bài tập áp dụng cho các dịch vụ được trình bày. Qua đó, giúp sinh viên nắm bắt kiến thức và kỹ năng thực hành cơ bản để vận dụng trong thực tiễn. Trong quá trình biên soạn chắc chắn giáo trình sẽ còn nhiều thiếu sót và hạn chế. Rất mong nhận được sự đóng góp ý kiến quý báu của sinh viên và các bạn đọc để giáo trình ngày một hoàn thiện hơn. TP. HCM, ngày……tháng 12 năm 2017 Tham gia biên soạn: 1. Chủ biên: Th.s Dương Đình Dũng 2 MỤC LỤC TUYÊN BỐ BẢN QUYỀN 1 LỜI NÓI ĐẦU 2 MỤC LỤC 3 Chương 1. Xây dựng mô hình mạng 8 1.1 Giới thiệu mô hình domain trên linux ................................................. 9 1.2 Triển khai hệ thống domain trên linux với samba 4.0 ........................ 9 1.3 Nâng cấp Active Directory Domain Controller ............................... 11 1.4 Xây dựng additional Domain Controller ........................................... 14 1.5 Join domain các máy client ............................................................... 18 1.5.1 Đối với Windows (7/8/10/2008/2012/2016) .......................... 18 1.5.2 Linux/Unix client (Ubuntu) ................................................... 19 1.6 Quản trị domain ................................................................................. 20 1.6.1 Quản lý user ........................................................................... 20 1.6.2 Quản lý group ......................................................................... 21 1.6.3 Home folder & User profile ................................................... 22 1.6.4 OU – Delegate ........................................................................ 23 1.6.5 Quản lý policy (Group Policies Management) ...................... 23 1.7 Share permission trên samba ............................................................. 26 1.7.1 Quyền thư mục/thư mục ........................................................ 27 1.7.2 Ký hiệu số .............................................................................. 27 1.8 Câu hỏi và Bài tập cuối chương ........................................................ 28 1.8.1 Câu hỏi lý thuyết .................................................................... 28 1.8.2 Thực hành ............................................................................... 28 Chương 2. Triển khai hạ tầng mạng 30 2.1 Xây dựng máy chủ phân giải tên miền .............................................. 31 2.1.1 DNS đơn ................................................................................. 31 2.1.2 Multi DNS .............................................................................. 35 2.2 Tạo bộ định tuyến động ..................................................................... 39 3 2.2.1 Khái niệm và định tuyến tĩnh ................................................. 39 2.2.2 Phương pháp định tuyến động trên Linux ............................. 43 2.3 Cấp phát IP động ............................................................................... 50 2.3.1 Single Subnet ......................................................................... 50 2.3.2 Multi Subnet ........................................................................... 57 2.3.3 IP reservation ......................................................................... 60 2.3.4 DHCP relay Agent ................................................................. 61 2.4 Bài tập áp dụng chương 2 .................................................................. 65 2.4.1 Câu hỏi lý thuyết .................................................................... 65 2.4.2 Bài tập thực hành ................................................................... 66 Chương 3. Web-Mail-FTP 68 3.1 Dịch vụ mail ...................................................................................... 69 3.1.1 Cài đặt và cấu hình Mail server Zimbra ................................ 69 3.1.2 Anti spam, anti virus .............................................................. 76 3.1.3 Tích hợp Zimbra vào Active Directory ................................. 77 3.2 Dịch vụ Web ...................................................................................... 83 3.2.1 Cài đặt và cấu hình apache ..................................................... 83 3.2.2 Cấu hình nhiều alias ............................................................... 87 3.2.3 Cấu hình máy chủ hosting ...................................................... 87 3.2.4 Cấu hình chứng thực web ...................................................... 88 3.3 Dịch vụ FTP Server ........................................................................... 91 3.3.1 Cài đặt và cấu hình dịch vụ ftp .............................................. 91 3.3.2 Cấu hình user truy xuất nhiều thư mục .................................. 95 3.3.3 Kiểm tra hoạt động ftp server và upload nội dung ................ 97 3.3.4 Bảo mật ftp ............................................................................. 98 3.3.5 Chú ý khi sử dụng ftp ............................................................. 99 3.4 Bài tập chương 3 ................................................................................ 99 3.4.1 Câu hỏi lý thuyết .................................................................... 99 3.4.2 Bài tập thực hành ................................................................. 100 4 Chương 4. Bảo mật và chia sẻ kết nối 101 4.1 Cài và cấu hình PFSense ................................................................. 102 4.1.1 Cài đặt PFSense lên máy chủ tường lửa .............................. 102 4.1.2 Tạo bô lọc nội dung trên tường lửa (Web proxy) ................ 108 4.1.3 Chống tấn công mạng bằng tường lửa PFSense .................. 112 4.2 Proxy: chia sẻ mạng ........................................................................ 121 4.2.1 Cài đặt squid ......................................................................... 121 4.2.2 Cấu hình chia sẻ internet trên mạng đơn ............................. 122 4.2.3 Cấu hình chia sẻ nhiều nhánh mạng và tạo bộ luật kiểm soát truy cập 126 4.3 Xuất bản dịch vụ nội bộ ra ngoài mạng .......................................... 130 4.3.1 Cài đặt và cấu hình iptables ................................................. 130 4.3.2 Xây dựng các luật (ACL) ..................................................... 132 4.3.3 NAT IN bằng iptables: chia sẻ dịch vụ web, mail, ftp ........ 136 4.4 Cấu hình VPN trên linux ................................................................. 138 4.5 Bài tập cuối chương 4 ...................................................................... 139 4.5.1 Cấu hình NAT bằng iptables ................................................ 139 4.5.2 BÀI TẬP SQUID - APACHE.............................................. 140 Chương 5. Mạng không đĩa cứng với máy chủ Linux (bootrom) 144 5.1 Chuẩn bị và cài đặt máy chủ bootrom ............................................. 145 5.1.1 Cấu hình máy tính ................................................................ 145 5.1.2 Chọn phần mềm CMS .......................................................... 146 5.1.3 Quy trình cài đặt phần mềm CMS ....................................... 147 5.2 Thiết lập các thông số trên server bootrom ..................................... 148 5.2.1 Cấu hình PXE ....................................................................... 148 5.2.2 Cấu hình cấp phát IP ............................................................ 153 5.2.3 Cấu hình đĩa ảo .................................................................... 156 5.2.4 Cấu hình user và danh mục máy client ................................ 156 5.3 Cài đặt máy Client và build imange lên server ............................... 157 5.3.1 Download phần mềm client ................................................. 157 5 5.3.2 Tạo ảnh đĩa ........................................................................... 159 5.3.3 Capture ảnh đĩa đưa lên Server ............................................ 161 5.3.4 Điều chỉnh chế độ protect .................................................... 163 5.3.5 Khởi động máy Client
Recommended publications
  • La Sécurité Informatique Edition Livres Pour Tous (
    La sécurité informatique Edition Livres pour tous (www.livrespourtous.com) PDF générés en utilisant l’atelier en source ouvert « mwlib ». Voir http://code.pediapress.com/ pour plus d’informations. PDF generated at: Sat, 13 Jul 2013 18:26:11 UTC Contenus Articles 1-Principes généraux 1 Sécurité de l'information 1 Sécurité des systèmes d'information 2 Insécurité du système d'information 12 Politique de sécurité du système d'information 17 Vulnérabilité (informatique) 21 Identité numérique (Internet) 24 2-Attaque, fraude, analyse et cryptanalyse 31 2.1-Application 32 Exploit (informatique) 32 Dépassement de tampon 34 Rétroingénierie 40 Shellcode 44 2.2-Réseau 47 Attaque de l'homme du milieu 47 Attaque de Mitnick 50 Attaque par rebond 54 Balayage de port 55 Attaque par déni de service 57 Empoisonnement du cache DNS 66 Pharming 69 Prise d'empreinte de la pile TCP/IP 70 Usurpation d'adresse IP 71 Wardriving 73 2.3-Système 74 Écran bleu de la mort 74 Fork bomb 82 2.4-Mot de passe 85 Attaque par dictionnaire 85 Attaque par force brute 87 2.5-Site web 90 Cross-site scripting 90 Défacement 93 2.6-Spam/Fishing 95 Bombardement Google 95 Fraude 4-1-9 99 Hameçonnage 102 2.7-Cloud Computing 106 Sécurité du cloud 106 3-Logiciel malveillant 114 Logiciel malveillant 114 Virus informatique 120 Ver informatique 125 Cheval de Troie (informatique) 129 Hacktool 131 Logiciel espion 132 Rootkit 134 Porte dérobée 145 Composeur (logiciel) 149 Charge utile 150 Fichier de test Eicar 151 Virus de boot 152 4-Concepts et mécanismes de sécurité 153 Authentification forte
    [Show full text]
  • Test-Beds and Guidelines for Securing Iot Products and for Secure Set-Up Production Environments
    IoT4CPS – Trustworthy IoT for CPS FFG - ICT of the Future Project No. 863129 Deliverable D7.4 Test-beds and guidelines for securing IoT products and for secure set-up production environments The IoT4CPS Consortium: AIT – Austrian Institute of Technology GmbH AVL – AVL List GmbH DUK – Donau-Universit t Krems I!AT – In"neon Technologies Austria AG #KU – JK Universit t Lin$ / Institute for &ervasive 'om(uting #) – Joanneum )esearch !orschungsgesellschaft mbH *+KIA – No,ia -olutions an. Net/or,s 0sterreich GmbH *1& – *1& -emicon.uctors Austria GmbH -2A – -2A )esearch GmbH -)!G – -al$burg )esearch !orschungsgesellschaft -''H – -oft/are 'om(etence 'enter Hagenberg GmbH -AG0 – -iemens AG 0sterreich TTTech – TTTech 'om(utertechni, AG IAIK – TU Gra$ / Institute for A((lie. Information &rocessing an. 'ommunications ITI – TU Gra$ / Institute for Technical Informatics TU3 – TU 3ien / Institute of 'om(uter 4ngineering 1*4T – 1-Net -ervices GmbH © Copyright 2020, the Members of the IoT4CPS Consortium !or more information on this .ocument or the IoT5'&- (ro6ect, (lease contact8 9ario Drobics7 AIT Austrian Institute of Technology7 mario:.robics@ait:ac:at IoT4C&- – <=>?@A Test-be.s an. guidelines for securing IoT (ro.ucts an. for secure set-up (ro.uction environments Dissemination level8 &U2LI' Document Control Title8 Test-be.s an. gui.elines for securing IoT (ro.ucts an. for secure set-u( (ro.uction environments Ty(e8 &ublic 4.itorBsC8 Katharina Kloiber 4-mail8 ,,;D-net:at AuthorBsC8 Katharina Kloiber, Ni,olaus DEr,, -ilvio -tern )evie/erBsC8 -te(hanie von )E.en, Violeta Dam6anovic, Leo Ha((-2otler Doc ID8 DF:5 Amendment History Version Date Author Description/Comments VG:? ?>:G?:@G@G -ilvio -tern Technology Analysis VG:@ ?G:G>:@G@G -ilvio -tern &ossible )esearch !iel.s for the -2I--ystem VG:> >?:G<:@G@G Katharina Kloiber Initial version (re(are.
    [Show full text]
  • NFV Decouples the Network Functions Such As NAT, Firewall, DPI, IPS/IDS, WAAS, SBC, RR Etc
    Virtualizing Enterprise Network Functions • BRKCRS-3447 Matt Falkner, Distinguished Engineer, Technical Marketing Agenda BRKCRS-3447 • Introduction & Motivation • Deployment Models and Characteristics • The Building Blocks of Virtualization (today) • Virtualization Trade-offs and Research Topics • Conclusion Abstract Network Function Virtualization (NfV) is gaining increasing traction in the industry based on the promise of reducing both CAPEX and OPEX using COTS hardware. This session introduces the use-cases for virtualizing Enterprise network architectures, such as virtualizing branch routers, LISP nodes, IWAN deployments, or enabling enterprise hybrid cloud deployments. The sessions also discusses the technology of Virtualization from both a system architecture as well as a network architecture perspective. Particular focus is given on understanding the impact of running routing functions on top of hypervisors, as well as the placement and chaining of network functions. Performance of virtualized functions is also discussed. BRKCRS-3447 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 Introduction and Motivation Network Functions Virtualization (NFV) Announced at SDN World Congress, Oct 2012 • AT&T • BT • CenturyLink • China Mobile • Colt • Deutsche Telekom • KDDI • NTT • Orange • Telecom Italia • Telstra • Verizon • Others TBA… BRKCRS-3447 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 10 What is NfV? A Definition … NFV decouples the network functions such as NAT, Firewall, DPI, IPS/IDS,
    [Show full text]
  • WP-MIRROR 0.7.4 Reference Manual
    WP-MIRROR 0.7.4 Reference Manual Dr. Kent L. Miller November 22, 2014 DRAFT 1 DRAFT 2 To Tylery DRAFT i WP-MIRROR 0.7.4 Reference Manual Legal Notices Copyright (C) 2012–2014 Dr. Kent L. Miller. All rights reserved. Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.3 or any later version published by the Free Software Foundation; with no Invariant Sections, no Front-Cover Texts, and no Back-Cover Texts. A copy of the license is included in the section entitled “GNU Free Documentation License”. THIS PUBLICATION AND THE INFORMATION HEREIN ARE FURNISHED AS IS, ARE FURNISHED FOR INFORMATIONAL USE ONLY, ARE SUBJECT TO CHANGE WITH- OUT NOTICE, AND SHOULD NOT BE CONSTRUED AS A COMMITMENT BY THE AU- THOR. THE AUTHOR ASSUMES NO RESPONSIBILITY OR LIABILITY FOR ANY ER- RORS OR INACCURACIES THAT MAY APPEAR IN THE INFORMATIONAL CONTENT CONTAINED IN THIS MANUAL, MAKES NO WARRANTY OF ANY KIND (EXPRESS, IMPLIED, OR STATUTORY) WITH RESPECT TO THIS PUBLICATION,AND EXPRESSLY DISCLAIMS ANY AND ALL WARRANTIES OF MERCHANTABILITY, FITNESS FOR PAR- TICULAR PURPOSES, AND NONINFRINGEMENT OF THIRD-PARTY RIGHTS. The WP-MIRROR logotype (see margin) was released by the author into the public domain on 2014-Apr-10. See https://www.mediawiki.org/wiki/File:Wp-mirror.png. This logotype fea- tures a sunflower that is derived from 119px-Mediawiki logo sunflower Tournesol 5x rev2.png, which is also in the public domain. See https://en.wikipedia.org/wiki/File:Mediawiki_logo_sunflower_Tournesol_5x.png.
    [Show full text]
  • Custom Equipment Monitoring with Openwrt and Carambola
    Custom Equipment Monitoring with OpenWRT and Carambola Sysadmin Miniconf Linux.conf.au Perth - 6 January 2014 Andrew McDonnell - Software Engineer & Tech Problem Solver [email protected] Twitter: @pastcompute http://blog.oldcomputerjunk.net https://launchpad.net/~andymc73 https://github.com/andymc73 Overview ● Equipment Monitoring with a Budget ● Introduction to Carambola ● Introduction to OpenWRT ● Monitoring with OpenWRT and Carambola Andrew McDonnell – LCA2014 Sysadmin Miniconf - Custom equipment monitoring with OpenWRT and Carambola – [email protected] 2 Use Case ● Everything has a computer in it these days ● And a connection: http://en.wikipedia.org/wiki/File:SolarpanelBp.JPG http://en.wikipedia.org/wiki/File:2008-07-11_Air_conditioners_at_UNC-CH.jpg http://en.wikipedia.org/wiki/File:Davis_VantagePro.jpg Andrew McDonnell – LCA2014 Sysadmin Miniconf - Custom equipment monitoring with OpenWRT and Carambola – [email protected] 3 Use Case Requirements ● So if you have a <insert widget here>? ● And a small physical space requirement? ● How do you have it talk to <insert toolkit here>? i2c rs485 http://openclipart.org/detail/182810/old-computer-by-jhnri4-182810 http://openclipart.org/detail/188441/sid-chip-by-arvin61r58-188441 Andrew McDonnell – LCA2014 Sysadmin Miniconf - Custom equipment monitoring with OpenWRT and Carambola – [email protected] 4 Potential Solutions ● Industrial COTS ● Embedded microcontrollers ● arduino ● Embedded Linux ● Raspberry Pi ● Beaglebone Black ● Carambola2 http://www.openelectrical.org/wiki/images/4/43/Programmable-logic-controller-plc-22971.jpg
    [Show full text]
  • D4.2: In-Vehicular Antitampering Security
    Ref. Ares(2021)2227326 - 31/03/2021 DIAS Smart Adaptive Remote Diagnostic Antitampering Systems EUROPEAN COMMISSION HORIZON 2020 LC-MG-1-4-2018 Grant agreement ID: 814951 Deliverable No. D4.2 Deliverable Title In-vehicular antitampering security techniques and integration Issue Date 31/03/2021 Dissemination level Public Main Author(s) Genge Béla (UMFST) Lenard Teri (UMFST) Obaid Ur-Rehman (FEV) Miao Zhang (FEV) Liu Cheng (BOSCH) Siegel Bjoern (BOSCH) Roland Bolboacă (UMFST) Haller Piroska (UMFST) DIAS D4.2-In-vehicular antitampering security techniques and integration, v1.0 Sofia Terzi (CERTH) Athanasios Sersemis (CERTH) Charalampos Savvaidis (CERTH) Konstantinos Votis (CERTH) Version v1.0 2 31/03/2021 DIAS D4.2-In-vehicular antitampering security techniques and integration, v1.0 DIAS Consortium This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 814951. This document reflects only the author's view and the Agency is not responsible for any use that may be made of the information it contains. 3 31/03/2021 DIAS D4.2-In-vehicular antitampering security techniques and integration, v1.0 Document log Distributed Version Description Assigned to Date for Draft structure of Structure Reviewer 1: FEV v0.1 20/11/2020 deliverable review Reviewer 2: UMFST Reviewer 1: Sofia Terzi v0.2- Draft content of Content (CERTH) 26/02/2021 v0.4 deliverable reviews Reviewer 2: Dominic Woerner (Bosch IoT) Final content of v0.5 GA check GA members 19/03/2021 deliverable v1.0 First final
    [Show full text]
  • Securing Complex Cyber-Physical Medical Device Landscapes
    April 2018 Volume 16 Issue 4 The Dangers in Perpetuating a Culture of Risk Acceptance Using PKI to Build a Secure Industrial Internet of Things The Two Faces of Innovation: From Safe and Dumb to Vulnerable Smart Products and Infrastructure Cyber-Physical Intelligence Securing Complex Cyber-Physical Medical Device Landscapes INTERNET OF THINGS DEVELOPING AND CONNECTING ISSA CYBERSECURITY LEADERS GLOBALLY Securing Complex Cyber-Physical Medical Device Landscapes By Ulrich Lang The author presents innovative approaches to cybersecurity that should be considered to securely integrate medical device landscapes (and many other IoT environments) in the coming years as IoT rapidly matures. Abstract comparison, in 2015 there were approximately 4.9 million things connected to the Internet). In this article we will present innovative approaches to cy- bersecurity that should be considered to securely integrate Importantly, IoT will also play a major role in achieving medical device landscapes (and many other IoT environ- “smart health care” to improve patient care/experience, effi- ments) in the coming years as IoT rapidly matures. The ar- ciency, and outcomes. Hospitals already use many medical ticle is based on the results of several government-funded devices today (e.g., numerous monitoring and pump devic- R&D projects, in particular a research project to secure a es, etc.) though mostly not in a very interconnected fashion. cyber-physical medical environment (for Defense Health Presently, in most cases, there is a human (e.g., nurse) in the Program, DHP), and a research project to automate access loop to ensure safety because the devices in use have not control policy testing (for National Institute of Standards been designed with the security in mind that is required for and Technology, NIST).
    [Show full text]
  • Cloud Security Guidelines for IBM Power Systems
    Front cover Cloud Security Guidelines for IBM Power Systems Turgut Aslan Peter G. Croes Liviu Rosca Max Stern Redbooks International Technical Support Organization Cloud Security Guidelines for IBM Power Systems February 2016 SG24-8242-01 Note: Before using this information and the product it supports, read the information in “Notices” on page ix. Second Edition (February 2016) This edition applies to IBM PowerVC 1.3.0 (5765-VCS), IBM PowerVM 2.2.4 (5765-PVS Standard Edition, 5765-PVE Enterprise Edition, 5765-PVL Linux Edition), IBM PowerKVM 3.1 (5765-KVM), IBM Cloud Manager with OpenStack 4.3 (5765-OSP), and the IBM Hardware Management Console 8.3.2 (7042-CR8). © Copyright International Business Machines Corporation 2015, 2016. All rights reserved. Note to U.S. Government Users Restricted Rights -- Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp. Contents Notices . ix Trademarks . .x IBM Redbooks promotions . xi Preface . xiii Authors. xiii Now you can become a published author, too! . .xv Comments welcome. .xv Stay connected to IBM Redbooks . xvi Part 1. Business context and architecture considerations. 1 Chapter 1. Business context . 3 1.1 Overview . 4 1.1.1 Cloud deployment models . 4 1.1.2 Cloud service models . 5 1.2 Business drivers for cloud computing . 6 1.3 IBM Power Systems and the cloud . 7 1.3.1 Hypervisors . 7 1.3.2 Platform management. 8 1.3.3 Advanced virtualization management . 8 1.3.4 Cloud management. 9 1.4 Conclusion . 11 Chapter 2. Cloud security reference architecture . 13 2.1 IBM Cloud Computing Reference Architecture .
    [Show full text]
  • Writing Netfilter Modules
    Writing Netfilter modules Jan Engelhardt, Nicolas Bouliane rev. July 3, 2012 The Netfilter/Xtables/iptables framework gives us the possibility to add features. To do so, we write kernel modules that register against this framework. Also, depending on the feature’s category, we write an iptables userspace module. By writing your new extension, you can match, mangle, track and give faith to a given packet or complete flows of interrelated connections. In fact, you can do almost everything you want in this world. Beware that a little error in a kernel module can crash the computer. We will explain the skeletal structures of Xtables and Netfilter modules with complete code examples and by this way, hope to make the interaction with the framework a little easier to understand. We assume you already know a bit about iptables and that you do have C programming skills. Copyright © 2005 Nicolas Bouliane <acidfu (at) people.netfilter.org>, Copyright © 2008–2012 Jan Engelhardt <jengelh (at) inai.de>. This work is made available under the Creative Commons Attribution-Noncom- mercial-Sharealike 3.0 (CC-BY-NC-SA) license. See http://creativecommons.org/ licenses/by-nc-sa/3.0/ for details. (Alternate arrangements can be made with the copyright holder(s).) Additionally, modifications to this work must clearly be indicated as such, and the title page needs to carry the words “Modified Version” if any such modifications have been made, unless the release was done by the designated maintainer(s). The Maintainers are members of the Netfilter Core Team, and any person(s) appointed as maintainer(s) by the coreteam.
    [Show full text]
  • Universidad Estatal Del Sur De Manabí 2018
    UNIVERSIDAD ESTATAL DEL SUR DE MANABÍ FACULTAD DE CIENCIAS TÉCNICAS CARRERA DE INGENIERÍA SISTEMAS COMPUTACIONALES TESIS DE GRADO PREVIO A LA OBTENCIÓN DEL TÍTULO DE: INGENIERO EN SISTEMAS COMPUTACIONALES TEMA “ESTUDIO DE COMPARACIÓN DE TÉCNICAS DE BALANCEO DE CARGA EN SERVICIOS WEB EN LA CARRERA DE INGENIERÍA EN SISTEMAS COMPUTACIONALES DE LA UNIVERSIDAD ESTATAL DEL SUR DE MANABI” AUTOR DIEGO ARMANDO MENDOZA BRAVO DIRECTOR DE TESIS ING. CRISTHIAN JOSÉ ÁLAVA MERO 2018 CERTIFICACIÓN Ing. Cristhian José Álava Mero docente de la Universidad Estatal del Sur de Manabí de la carrera de Ingeniería en Sistemas Computacionales. CERTIFICO: Que el señor Diego Armando Mendoza Bravo realizo la tesis de grado titulada: “ESTUDIO DE COMPARACIÓN DE TÉCNICAS DE BALANCEO DE CARGA EN SERVICIOS WEB EN LA CARRERA DE INGENIERÍA EN SISTEMAS COMPUTACIONALES DE LA UNIVERSIDAD ESTATAL DEL SUR DE MANABI” Bajo la dirección de quien suscribe; habiendo cumplido con las disposiciones reglamentarias establecidas para el efecto. Ing. Cristhian José Álava Mero DIRECTOR DE TESIS I AUTORÍA “La responsabilidad por los hechos, ideas y doctrinas expuestas en este trabajo de investigación me corresponden exclusivamente a su autor, y el patrimonio intelectual de la misma a la Universidad Estatal del Sur de Manabí” _______________________ Diego Armando Mendoza Bravo Autor de Tesis II APROBACIÓN DEL TRIBUNAL Sometida a la comisión de profesionalización de la carrera de Ingeniería en Sistemas Computacionales de la Universidad Estatal del Sur de Manabí: como requisito para obtener el título de Ingeniero en Sistemas Computacionales. Jipijapa…………………. 2018 Miembro del tribunal Miembro del tribunal ……………………….. ….…………………….. Miembro del tribunal …..………………. III DEDICATORIA Con infinito afecto y gratitud, a Dios y de quien formo parte como es mi familia mis padres, Rodrigo y Rocío quien siempre han sido mi guía y formación desde el momento de mi concepción, a mis hermanos y hermanas que gracias a su apoyo moral incentivan mis momentos más difíciles y duros en esta ocasión tan esperada y anhelada.
    [Show full text]
  • Deliverable D3.2
    Ref. Ares(2016)3479770 - 15/07/2016 Converged Heterogeneous Advanced 5G Cloud-RAN Architecture for Intelligent and Secure Media Access Project no. 671704 Research and Innovation Action Co-funded by the Horizon 2020 Framework Programme of the European Union Call identifier: H2020-ICT-2014-1 Topic: ICT-14-2014 - Advanced 5G Network Infrastructure for the Future Internet Start date of project: July 1st, 2015 Deliverable D3.2 Initial 5G multi-provider v-security realization: Orchestration and Management Due date: 30/06/2016 Submission date: 15/07/2016 Deliverable leader: I2CAT Editor: Shuaib Siddiqui (i2CAT) Reviewers: Konstantinos Filis (COSMOTE), Oriol Riba (APFUT), and Michael Parker (UESSEX) Dissemination Level PU: Public PP: Restricted to other programme participants (including the Commission Services) RE: Restricted to a group specified by the consortium (including the Commission Services) CO: Confidential, only for members of the consortium (including the Commission Services) CHARISMA – D3.2 – v1.0 Page 1 of 145 List of Contributors Participant Short Name Contributor Fundació i2CAT I2CAT Shuaib Siddiqui, Amaia Legarrea, Eduard Escalona Demokritos NCSRD NCSRD Eleni Trouva, Yanos Angelopoulos APFutura APFUT Oriol Riba Innoroute INNO Andreas Foglar, Marian Ulbricht JCP-Connect JCP-C Yaning Liu University of Essex UESSEX Mike Parker, Geza Koczian, Stuart Walker Intracom ICOM Spiros Spirou, Konstantinos Katsaros, Konstantinos Chartsias, Dimitrios Kritharidis Ethernity ETH Eugene Zetserov Ericsson Ericsson Carolina Canales Altice Labs Altice Victor Marques Fraunhofer HHI HHI Kai Habel CHARISMA – D3.2 – v1.0 Page 2 of 145 Table of Contents List of Contributors ................................................................................................................ 2 1. Introduction ...................................................................................................................... 7 1.1. 5G network challenges: Security and Multi-tenancy ......................................................................... 7 1.2.
    [Show full text]
  • Secured and Controlled Network Traffic with Load Balancing Using IP-Tables
    Volume 6, No. 7, September-October 2015 International Journal of Advanced Research in Computer Science REVIEW ARTICLE Available Online at www.ijarcs.info Secured and Controlled Network Traffic with Load Balancing using IP-Tables Talwinder kaur Mohita Garg M.tech(CSE) North west institute of engg.&tech., North west institute of engg. & tech. Dhudike(Moga) Dhudike (Moga) Abstract : There are two IP addresses for a typical home network: one for local devices to connect to across the local area network (LAN), another for the external or wide area network (WAN) Internet connection. A virtual private network (VPN) is a method for the extension of a private network across a public network, such as the Internet. It enables users to send and receive data across shared or public networks as if their computing devices were directly connected to the private network, and thus are benefiting from the functionality, security and management policies of the private network. The aim of this method of course is to balance the traffic so as to avoid the congestion. Keywords: Load balancing, IP network, VPN, NAT. (1) INTRODUCTION network and the Internet. Firewall prevents unauthorized use and access to your network. The job of a firewall is to carefully analyze data entering and exiting the network A default IP address is normally set to internal LAN, private based on your configuration. It ignores information that number for example, 192.168.1.1 for their internal IP comes from unsecured, unknown or suspicious locations. A address. No matter the brand of router, its default internal IP firewall plays an important role on any network as it address is listed in the manufacturer's documentation.
    [Show full text]