TL;DR: Three classes of attacks which exploit fundamentally problems with the reliability of passive protocol analysis are defined--insertion, evasion and denial of service attacks--and how to apply these three types of attacks to IP and TCP protocol analysis is described.
Abstract: : All currently available network intrusion detection (ID) systems rely upon a mechanism of data collection passive protocol analysis-which is fundamentally flawed In passive protocol analysis, the intrusion detection system (IDS) unobtrusively watches all traffic on the network, and scrutinizes it for patterns of suspicious activity We outline in this paper two basic problems with the reliability of passive protocol analysis: (1) there isn't enough information on the wire on which to base conclusions about what is actually happening on networked machines, and (2) the fact that the system is passive makes it inherently "fail-open," meaning that a compromise in the availability of the IDS doesn't compromise the availability of the network We define three classes of attacks which exploit these fundamentally problems---insertion, evasion and denial of service attacks--and describe how to apply these three types of attacks to IP and TCP protocol analysis We present the results of tests of the efficacy of our attacks against four of the most popular network intrusion detection systems on the market All of the ID systems tested were found to be vulnerable to each of our attacks This indicates that network ID systems cannot be fully trusted until they are fundamentally redesigned
TL;DR: In this article, a signature-based dynamic network intrusion detection system (IDS) includes attack signature profiles which are descriptive of characteristics of known network security violations and are organized into sets of attack profile profiles according to security requirements of network objects on a network.
Abstract: A signature based dynamic network intrusion detection system (IDS) includes attack signature profiles which are descriptive of characteristics of known network security violations. The attack signature profiles are organized into sets of attack signature profiles according to security requirements of network objects on a network. Each network object is assigned a set of attack signature profiles which is stored in a signature profile memory together with association data indicative of which sets of attack signature profiles correspond to which network objects. A monitoring device monitors network traffic for data addressed to the network objects. Upon detecting a data packet addressed to one of the network objects, packet information is extracted from the data packet. The extracted information is utilized to obtain a set of attack signature profiles corresponding to the network object based on the association data. A virtual processor executes instructions associated with attack signature profiles to determine if the packet is associated with a known network security violation. An attack signature profile generator is utilized to generate additional attack signature profiles configured for processing by the virtual processor in the absence of any corresponding modification of the virtual processor.
TL;DR: In this paper, the authors propose a firewall for isolating network elements from a publicly accessible network to which such network elements are attached by assigning a variety of proxy agents that are specifically assigned to an incoming request in accordance with the service protocol (i.e., port number) indicated in the incoming access request.
Abstract: Providing a firewall for isolating network elements from a publicly accessible network to which such network elements are attached. The firewall operates on a stand alone computer connected between the public network and the network elements to be protected such that all access to the protected network elements must go through the firewall. The firewall application running on the stand alone computer is preferably the only application running on that machine. The application includes a variety of proxy agents that are specifically assigned to an incoming request in accordance with the service protocol (i.e., port number) indicated in the incoming access request. An assigned proxy agent verifies the authority of an incoming request to access a network element indicated in the request. Once verified, the proxy agent completes the connection to the protected network element on behalf of the source of the incoming request.
TL;DR: In this article, a method of establishing a representation of an abstract network security policy is disclosed, which is established in the form of a decision tree that is constructed by assembling graphical symbols representing policy actions and policy conditions.
Abstract: A method of establishing a representation of an abstract network security policy is disclosed. The representation is established in the form of a decision tree that is constructed by assembling graphical symbols representing policy actions and policy conditions. A user modifies properties of the graphical symbols to create a logical representation of the policy. Concurrently, the logical representation is transformed into a textual script that represents the policy, and the script is displayed as the user works with the logical representation. When the policy representation is saved, the script is translated into machine instructions that govern the operation of a network gateway or firewall. The policy representation is named. The policy representation may be applied to other network devices or objects by moving an icon identifying the representation over an icon representing the network device. Policies, network objects, and network services are stored in the form of trees.
TL;DR: In this article, a method and system for adaptive network security using network vulnerability assessment is disclosed, which comprises directing a request onto a network, a response to the request is assessed to discover network information, and a plurality of analysis tasks are prioritized based upon the network information.
Abstract: A method and system for adaptive network security using network vulnerability assessment is disclosed The method comprises directing a request onto a network A response to the request is assessed to discover network information A plurality of analysis tasks are prioritized based upon the network information The plurality of analysis tasks are to be performed on monitored network data traffic in order to identify attacks upon the network
TL;DR: In this paper, a dynamic network security system (20) responds to a security attack (92) on a computer network (22) having a multiplicity of computer nodes (24), including a plurality of security agents (36) that concurrently detect occurrences of security events (50) on associated computer nodes.
Abstract: A dynamic network security system (20) responds to a security attack (92) on a computer network (22) having a multiplicity of computer nodes (24). The security system (20) includes a plurality of security agents (36) that concurrently detect occurrences of security events (50) on associated computer nodes (24). A processor (40) processes the security events (50) that are received from the security agents (36) to form an attack signature (94) of the attack (92). A network status display (42) displays multi-dimensional attack status information representing the attack (92) in a two dimensional image to indicate the overall nature and severity of the attack (92). The network status display (42) also includes a list of recommended actions (112) for mitigating the attack. The security system (20) is adapted to respond to a subsequent attack that has a subsequent signature most closely resembling the attack signature (94).
TL;DR: In this article, a method and system for adaptive network security using intelligent packet analysis is presented, which comprises monitoring network data traffic to assess network information and a plurality of analysis tasks are prioritized based upon the network information.
Abstract: A method and system for adaptive network security using intelligent packet analysis are provided. The method comprises monitoring network data traffic. The network data traffic is analyzed to assess network information. A plurality of analysis tasks are prioritized based upon the network information. The analysis tasks are to be performed on the monitored network data traffic in order to identify attacks upon the network.
TL;DR: By using a formal model of both the network and the attacks, NetSTAT is able to determine which network events have to be monitored and where they can be monitored.
Abstract: Network-based attacks have become common and sophisticated. For this reason, intrusion detection systems are now shifting their focus from the hosts and their operating systems to the network itself. Network-based intrusion detection is challenging because network auditing produces large amounts of data, and different events related to a single intrusion may be visible in different places on the network. This paper presents NetSTAT, a new approach to network intrusion detection. By using a formal model of both the network and the attacks, NetSTAT is able to determine which network events have to be monitored and where they can be monitored.
TL;DR: The security gateway as discussed by the authors is a hardware component of one embodiment of the security gateway which in a typical configuration simply adds new security functions to the programmable controllers that are typically used for an I/O controller or hard drive controller, although this is not always necessary.
Abstract: Apparatus and process are disclosed by which to disable a computer's access to all or a part of the computer's memory system or associated peripherals, so as to protect the computer from accidental or malicious damage of data files or programs that may result from the activity of computer users or computer viruses. This result is achieved by providing the authorized user with a token whereby the user can configure the security gateway to completely or partially disable the peripheral device without disrupting the operation of the computer or other peripherals. The principal hardware component of one embodiment of the invention is the security gateway which in a typical configuration simply adds new security functions to the programmable controllers that are typically used for an I/O controller or hard drive controller, although this is not always necessary. The process can just as easily be incorporated into a local network controller, a communications controller, or a main processor board for a system. The speed of the security gateway can be further enhanced by adding additional computational or encryption hardware to the chip sets used in said I/O or hard drive controllers.
TL;DR: In this article, a computer based system and method of providing security when receiving digital data at a client computer from one or more Web sites is disclosed, which includes receiving security configuration information that specifies multiple security zones, each zone corresponding to a set of Web sites.
Abstract: A computer based system and method of providing security when receiving digital data at a client computer from one or more Web sites is disclosed The method includes receiving security configuration information that specifies multiple security zones, each zone corresponding to a set of Web sites The security configuration information also includes information specifying a set of security settings corresponding to each security zone A security setting is a specification indicating an action to perform when a Web page from one of the security zones requests a protected operation to be performed During a Web browsing session, the mechanism of the invention determines the security zone corresponding to the Web site currently being browsed Prior to performing the protected operation, the mechanism of the invention determines the action to perform, based on the current Web site's security zone, the requested operation, and the security setting corresponding to the requested operation and the Web site's zone Depending upon the security setting, the Web browser may perform the requested operation, prevent the requested operation from being performed, or prompt the user of whether to perform the requested operation During the browsing of a Web site, the Web browser visually indicates the security zone corresponding to the current Web site
TL;DR: In this article, a network security system (10) that has a single point of access control (24) to a source computer system (20) is described. But the security system does not provide a single-use encryption key.
Abstract: A method of the present invention includes a network security system (10) that has a single point of access control (24) to a source computer system (20). The network security system (10) provides various mechanisms for securing access to source computer systems (20) that includes generating single-use encryption keys, generating random port assignments for communication between devices, an asynchronous message protocol used in the security system and utilizing various levels of transaction tables to help secure and manage security parameters of the system. More particularly, the present invention provides a method for securing access to a plurality of computers (20) connected via a network (26, or 22). An indication is received that a first user of a first computer program module of a first computer (16) desires to communicate with a destination computer system (20). When this indication is received, a message is directed to a security computer system (24). The security computer system (24) determines whether the first user of the first computer (16) is authorized to access the destination computer program module of the destination computer system (20). If the security computer system (24) determines that the first user is authorized to access the destination computer system (20), the security computer system (24) sets up a communication protocol between the first computer program module and the destination computer program module.
TL;DR: In this paper, the authors present a method and an apparatus for establishing a virtual private network that operates over a public data network, which includes a system that selects a plurality of entities coupled to the public data networks to include in the virtual private networks.
Abstract: The present invention provides a method and an apparatus for establishing a virtual private network that operates over a public data network. One embodiment of the present invention includes a system that selects a plurality of entities coupled to the public data network to include in the virtual private network. The system next assembles a plurality of identifiers for the plurality of entities. These identifiers are used to identify communications between the plurality of entities, so that these communications can be transferred securely over the public data network. A variation on this embodiment includes defining encryption, authentication and compression parameters for the virtual private network. In another variation, selecting the plurality of entities includes, assembling entities coupled to the public data network into groups, and selecting groups of entities to include in the virtual private network. Another variation includes defining access control rules specifying types of communications that are allowed to pass through virtual private network units. These virtual private network units are typically used to couple local area networks to the public network so that secure communications on the public network pass through the virtual private network units. Yet another variation on this embodiment includes defining address translation rules for virtual private network units coupled to the public data network. These address translation rules are used to translate local network addresses to public network addresses.
TL;DR: This article describes the architecture and implementation of a secure active network environment (SANE), which it is believed provides a basis for implementing secure network-level solutions and guarantees that a node begins operation in a trusted state with the AEGIS secure bootstrap architecture.
Abstract: An active network is a network infrastructure which is programmable on a per-user or even per-packet basis. Increasing the flexibility of such network infrastructures invites new security risks. Coping with these security risks represents the most fundamental contribution of active network research. The security concerns can be divided into those which affect the network as a whole and those which affect individual elements. It is clear that the element problems must be solved first, since the integrity of network-level solutions will be based on trust in the network elements. In this article we describe the architecture and implementation of a secure active network environment (SANE), which we believe provides a basis for implementing secure network-level solutions. We guarantee that a node begins operation in a trusted state with the AEGIS secure bootstrap architecture. We guarantee that the system remains in a trusted state by applying dynamic integrity checks in the network element's runtime system, using a novel naming system, and applying node-to-node authentication when needed. The construction of an extended LAN is discussed.
TL;DR: A network resource security services control system comprises an integrated arrangement of security services that are operative to control the ability of an information storage and retrieval network user to have access to and communicate with one or more information resources within the network as discussed by the authors.
Abstract: A network resource security services control system comprises an integrated arrangement of security services, that are operative to control the ability of an information storage and retrieval network user to have access to and communicate with one or more information resources within the network. The security access control mechanism monitors activity associated with a user's attempt to and actual conducting of data communications with respect to a system resource, and controllably modifies one or more security relationships of a security association that has been established among the users and resources of the system, in dependence upon one or more characteristics of the monitored activity, in such a manner that affects the ability of the system user to conduct data communications with respect to a system resource.
TL;DR: In this paper, a method for securely adding a new end station to a local area network (LAN) segmented into a number of virtual local area networks (VLANs) is presented.
Abstract: The present invention discloses a method for securely adding a new end station to a local area network (LAN) segmented into a number of virtual local area networks (VLANs). The invention is applicable to various types of LANs such as Ethernet and token ring. The LAN comprises an authentication server (AS) which interacts with each new end station before connection to a VLAN is allowed. The method involves the AS administering a test to the new end station, which may involve prompting the new end station for a password or asking it to encrypt a given number using a secret algorithm known only to the new end station and to the AS. The AS examines the results of this test and determines whether the new end station is permitted to join the VLAN. For added security, the new end station can verify authenticity of the AS by administering a test of its own, which may consist of prompting the AS for a password of its own or asking it to encrypt a new number, the new end station subsequently determining whether the AS is indeed genuine before beginning to transmit any further information. In this way, an end station cannot join a VLAN without authentication by the AS and a legitimate end station can verify whether the test it is asked to pass comes from a legitimate source, thereby avoiding network security breaches.
TL;DR: In this article, the authors present a computer system for processing communications in a virtual private network in a selective mode, in which only communications passing between a public network and a private network are processed according to the algorithms, while other communications bypass the computer system.
Abstract: One embodiment of the present invention provides a computer system for processing communications in a virtual private network. The computer system operates in a selective mode, in which only communications transiting the virtual private network are processed according to specified virtual private network parameters, such as encryption, compression and authentication algorithms. Virtual private network communications passing between a public network and a private network are thus received and processed according to the algorithms, while other communications bypass the computer system. Multiple private networks may be served by a single computer system.
TL;DR: In this paper, the biometrics account manager changes the current password associated with the user to a new password and overwrites the previous password with the new password at some point during or after the log-on process.
Abstract: A computer network includes at least one client computer coupled to a server computer that dynamically changes a user's password each time the user logs on to the computer network. By changing the password during the log on process, network security is increased. The server computer includes a users databases that contains a password, a username (if desired) and a biometrics template value associated with each user registered to access the computer network. A biometrics sensing device, such as a fingerprint sensor, is connected to each client computer. The user attempts to log on the server by entering a username which is optional and activating the biometrics sensing device. Appropriate software and/or hardware in the client and server computers capture a sample from the biometrics sensing device and create a template value from the captured sample. The template value thus is representative of a bodily characteristic of the user who activated the biometrics sensing device in an attempt to log on to the server computer. The client computer then transmits the template value to the server which compares the template value received from the client computer with template values previously stored in the users database. If a match is found, the log on process completes. At some point during or after the log on process, the biometrics account manager changes the current password associated with the user to a new password and overwrites the previous password with the new password.
TL;DR: In this article, an apparatus, method and system are disclosed for providing network security for executable code in computer and communications networks, such as providing networks security for downloadable and executable Java programming language bytecode.
Abstract: An apparatus, method and system are disclosed for providing network security for executable code in computer and communications networks, such as providing network security for downloadable and executable Java programming language bytecode. The preferred apparatus embodiment includes a network interface for the reception and transmission of network information, such as an interactive world wide web page; and includes a processor having program instructions to determine whether network information includes a network language keyword, such as a Java applet. When the network information includes such a network language keyword, the processor includes further instructions is further responsive to generate the network language keyword having a distinctive reference to corresponding executable code, such as a distinctive Java class name, and to provide, for transmission by the network interface, the network information in which the network language keyword incorporates the distinctive reference. When the network language keyword incorporating the distinctive reference is invoked, the processor includes further instructions to provide, for downloading by the network interface, the corresponding executable code. The preferred apparatus embodiment is within a network server, and may also include a memory system for storage of the corresponding executable code.
TL;DR: This book discusses Intrusion Detection and the Classic Security Model, the Role of Identification and Authentication in Your Environment, and Vulnerability Scanners.
Abstract: BEFORE INTRUSION DETECTION: TRADITIONAL COMPUTER SECURITY. Intrusion Detection and the Classic Security Model. The Role of Identification and Authentication in Your Environment. The Role of Access Control in Your Environment. Traditional Network Security Approaches. INTRUSION DETECTION: BEYOND TRADITIONAL SECURITY. Intrusion Detection and Why You Need It. Detecting Intruders on Your System Is Fun and Easy. Vulnerability Scanners. UNIX System-Level IDSs. Sniffing for Intruders. Intrusion Detection for NT. ROUNDING OUT YOUR ENVIRONMENT. You've Been Hit!. Intrusion Detection: Not the Last Chapter When It Comes To Security. Appendix. References. Index.
TL;DR: A comprehensive network security plan must encompass all the elements that make up the network and provide five important services: access-providing users with the means to transmit and receive data to and from any network resources with which they are authorized to communicate; confidentiality-ensures that the information in the network remains private (usually through encryption); authentication-ensured that the sender of a message is who he claims to be; integrity-ensure that a message has not been modified in transit; non-repudiation-enforces that the originator of the message cannot deny that he
Abstract: "Network security is the most important thing on the planet". We have heard these words uttered with great conviction many times. However, the first time it causes any inconvenience to system owners, administrators, or users, the same people hasten to add "except when it impacts performance, system complexity, or cost". Let's face it. Security is usually discarded when it contends with performance. The reason is simple, and at one time it may have even been valid: performance directly contributes to the bottom line while security provides only indirect benefits. But as the world becomes more tightly interconnected, organizations are feeling a greater need to rediscover network security. A thread that spans most definitions of network security is the intent to consider the security of the network as a whole, rather than as an endpoint issue. A comprehensive network security plan must encompass all the elements that make up the network and provide five important services: access-provides users with the means to transmit and receive data to and from any network resources with which they are authorized to communicate; confidentiality-ensures that the information in the network remains private (usually through encryption); authentication-ensures that the sender of a message is who he claims to be; integrity-ensures that a message has not been modified in transit; nonrepudiation-ensures that the originator of the message cannot deny that he sent the message and this is useful for both commercial and legal reasons.
TL;DR: The International Cryptography Framework (ICF) as discussed by the authors is a set of service elements which allow applications to exercise cryptographic functions under the control of a policy, and it includes the host system, cryptographic unit, policy activation token, and network security server.
Abstract: An international cryptography framework (ICF) is provided that allows manufacturers to comply with varying national laws governing the distribution of cryptographic capabilities. In particular, such a framework makes it possible to ship worldwide cryptographic capabilities in all types of information processing devices (e.g. printers, palm-tops). The ICF comprises a set of service elements which allow applications to exercise cryptographic functions under the control of a policy. The four core elements of the ICF architecture, i.e. the host system, cryptographic unit, policy activation token, and network security server, comprise an infrastructure that provides cryptographic services to applications. Applications that request cryptographic services from various service elements within the ICF are identified through a certificate to protect against misuse of a granted level of cryptography. The host system comprises a set of system programs and services which provide the application with an execution environment. The host system's role within the ICF is twofold. First, the host system provides services to the application in the form of programming interfaces to access the functions offered by the cryptographic unit. Second, the host system provides support for the cryptographic unit in building trust relationships to the host system elements, such as the cryptographic programming interfaces, operating systems drivers, and memory management subsystems.
TL;DR: In this paper, a technique for determining whether particular clients within a computer network are universally configured in accordance with the desired network security features of the computer network is presented, where a probe is randomly inserted within incoming files, e.g., at a firewall in the computer networks.
Abstract: A technique for determining whether particular clients within a computer network are universally configured in accordance with the desired network security features of the computer network. A probe is randomly inserted within incoming files, e.g., at a firewall in the computer network. The probe is configured as a function of a particular execution task, e.g. a known virus, such that in a properly configured client the probe will not execute and the firewall does not detect a security breach. However, if the client is misconfigured, i.e., not in compliance with the standard network security features, the probe will execute and trigger an alarm in the firewall indicating that the client is vulnerable to a security breach. Advantageously, a network security administrator can take appropriate action to correct those clients which are misconfigured.
TL;DR: In this paper, a keyboard with an activating module and an encrypting module is presented, which converts a memorable (insecure) password which is typed on the keyboard into a secure password which can be used to gain access to a computer network system.
Abstract: A keyboard which performs a password encryption function, i.e., converting a memorable (insecure) password which is typed on the keyboard, into a secure password which is used to gain access to a computer network system. A preferred embodiment of the present invention comprises a user designated keyboard having an activating module and an encrypting module, both of which are disposed within the keyboard. To gain access to a computer network, the user will press an activating key of the keyboard which sends an activating signal to the activator. The activating module will direct all subsequent keystroke signals (i.e. password) to the encrypting module, which performs an encrypting function and generates an encrypted password. When the user is finished typing the password, a deactivating key is pressed, which send the encrypted password to the computer network and which signals the activating module to divert (pass through) all subsequent keystroke signals.
TL;DR: The explosive growth of networking technology continues to redefine the rules for maintaining the privacy and integrity of electronic data.
Abstract: The explosive growth of networking technology continues to redefine the rules for maintaining the privacy and integrity of electronic data. There is a staggering amount of personal, commercial, gov...
TL;DR: This article explains the impact the network service model and architecture have on safety and security, and provides a model with which policies can be translated into restrictions of a general system, which is illustrated with the Secure Active Network Environment (SANE) architecture.
Abstract: Safety and security are two reliability properties of a system. A "safe" system provides protection against errors of trusted users, while a "secure" system protects against errors introduced by untrusted users. There is considerable overlap between mechanisms to support each property. Requirements for rapid service creation have stimulated the development of programmable network infrastructures, where end users or service providers can customize the properties of a network infrastructure while it continues to operate. A central concern of potential users of such systems is their reliability and, most specifically, their safety and security. In this article we explain the impact the network service model and architecture have on safety and security, and provide a model with which policies can be translated into restrictions of a general system. We illustrate these ideas with the Secure Active Network Environment (SANE) architecture, which provides a means of controlling access to the functions provided by any programmable infrastructure.
TL;DR: A new algorithm for attack localization in networks is presented that can localize attacks for a variety of network applications and is particularly well suited to the requirements of All-Optical Networks because it provides fast, reliable response to attacks.
Abstract: All-Optical Networks provide ultra-fast data rates, but present a new set of challenges for network security. We present a new algorithm for attack localization in networks. The algorithm is distributed and requires only local information. The algorithm can localize attacks for a variety of network applications. This algorithm is particularly well suited to the requirements of All-Optical Networks because it provides fast, reliable response to attacks. In particular we apply it to two common forms of rapid optical network restoration: automatic protection switching and loopback.
TL;DR: A run-time security methodology and apparatus for supporting complete access to the security features of a network computer by a network administrator is presented in this article. But it does not specify a set of user passwords.
Abstract: A run-time security methodology and apparatus for supporting complete access to the security features of a network computer by a network administrator. In a network computer according to the invention, various resources are secured by a security device. The resources are accessible by a computer user with knowledge of one or more user passwords stored in the security device. An administrator password is also stored in the security device. In addition to control access to specified resources, the administrator password also functions as a surrogate for the other passwords stored in the security device. An administrator password implemented according to the invention thereby allows a network administrator to remotely override any activated user security settings and receive complete access to a secured network computer.
TL;DR: The Network Flight Recorder (NFR) as mentioned in this paper uses a promiscuous packet interface to pass visible traffic into an internally meta-programmed decision engine which routes information about packets and their contents into statistical or logging backends.
TL;DR: This paper presents the study, design and implementation of a firewall, in particular a major component of awall: the dynamic packet filter, which is currently no dynamic packet filters on the Linux operating system.
Abstract: This paper presents the study, design and implementation of a firewall, in particular a major component of a firewall: the dynamic packet filter. A packet filter may be static or dynamic. A dynamic packet filter checks, on the fly, the outgoing IP packets from a computer and then allows incoming packets to get through the packet filter if the packets are from the same computer as the outgoing packets were sent to. There are currently no dynamic packet filters on the Linux operating system which has been chosen to be the development and test environment due to the source code availability. Some performance measurements have also been obtained to show that a safe system does not necessarily have to be very slow. This might otherwise be of some concern, as there is a trade-off between the security and the performance of the system.
TL;DR: Some of the current techniques and tools employed by the hacker underground in breaching the security of networked computers are described, focusing primarily on UNIX®-based hosts connected to TCP/IP networks.
Abstract: For years, “hackers” have broken into computer systems, and now an entire industry is dedicated to computer network security. Both hackers and computer security professionals have developed software tools for either breaking into systems or identifying potential security problems within computer networks. This software can be found on compromised systems as well as within the toolkits of legitimate “tiger” teams that operate with the consent of the network owners. This paper describes some of the current techniques and tools employed by the hacker underground in breaching the security of networked computers, focusing primarily on UNIX®-based hosts connected to TCP/IP networks.