System and Network Administration lecture in color

Security basics

Security Illusions

All security decisions are tradeoffs between:

Some guiding principles:

Parts of Security

Policy

Role of policy

Without policy

True story

Real policies

Scope of a real policy

What are we protecting?

Policy realities

Legal limits upon system administrators

Ethical limits upon system administrators

Parts of System Administrator Ethics

What to do when policies go wrong

Example: sketch of EECS policies

The double edge:

Know the enemy

Social Engineering

Reverse Social Engineering

General security principles

Security activities

Prevention

Mitigation

Detection

Recovery

Detection includes State Monitoring

Detection includes Event Monitoring

Mitigation means some form of filtering

Examples of security tools in action:

Firewalls

References

Setting up a firewall

Chains

Using chains:

Chaining concepts:

Ipchains doesn't use files

Filtering

Caveat:

Proxies

Transparent Proxy

Masquerading

Principles of gate design

Patterns

Rule modifiers

Packet chain actions

Editing chains

Ipchains commands

where

A quick note on laziness

Other techniques:

Tunnelling (a.k.a. encapsulation)

Tunnelling example: PPP

Advanced tunnelling: ssh

Practical SSH example:

Tunnelling application: VPN

The Practice of Firewalling

Network Security Risks

Case study: illusion of security

Case study: illusion of insecurity

Algebra of insecurity:

Case study:


lecture in color

/comp/150NET/notes/security.php
downloaded on Mar-15-2010 01:48:27 PM,
was last modified on Feb-17-2004 10:49:49 PM.

All lecture note content is copyright 2004 by
Alva L. Couch, Computer Science, Tufts University