COPYRIGHT This presentation is provided to specific parties on request. All slides must be shown in its entirety, including the D-Link’s logo and brand.

1 COPYRIGHT This presentation is provided to specific par...
Author: Ricardo Valdivia
0 downloads 2 Views

1 COPYRIGHT This presentation is provided to specific parties on request. All slides must be shown in its entirety, including the D-Link’s logo and brand name, without any modification or deletion, unless with the written consent of D-Link. Individual slides may be removed in its entirety. Background colour may be changed. Printed copies can be distributed freely for the specific purpose when this presentation slide is used. Failure to observe this violates the copyright agreement. D-Link reserves the right to withdraw from the party the right to use the presentation slide and/or any other actions deemed necessary by D-Link to prevent the slides or part of it being used.

2 CONCEPTOS BASICOS EN LA ADMINISTRACION DE REDES GESTION DE SEGURIDAD MSEE Ing. Héctor J. Simosa 22 Octubre 2004

3 Seguridad en Redes La seguridad en las Redes es mecanismo esencial. La Internet es una red de redes interconectadas sin fronteras…. Debido a este hecho, las redes de las organizaciones son vulnerables por su accesabilidad desde cualquier computador en el mundo.

4 Soluciones D-LINK ofrece soluciones de seguridad bastante completas además de FW para proteger su red, entre ellas tenemos: –Sistemas de Detección de Intrusión –Virtual Private Networks –Servicios de Identificación –Herramientas para Gerenciar la Seguridad.

5 Seguridad: Por qué es importante?

6 Computer Hackers Estos pueden ser divididos en tres categorias: –Los que rompen la seguridad de redes de computadores –Los que rompen la seguridad del software de aplicaciones –Los que crean programas maliciosos para vulnerar las debilidades de los S.O. Hecho: No existe una solución 100% segura!

7 Evolución de la Seguridad 1980 20001990 Password guessing Password Cracking Self Replicating code Exploit known vulnerabilities Disabling Audit DDoS Sniffers Hi jack sessions Stealth Diagnostics Sweepers BackdoorsPacket Forging/Spoofing Sophisticated Hacker Tools Internet Worm Technical Knowledge Required Low High

8 Ataques a Redes de Información Protección es un Reto! –La habilidad para atacar redes se ha vuelto más sofisticada –No es suficiente confiar en un Firewall –Al igual que proteje fisicamente sus instalaciones asi debe hacerlo con su Red. Qué preguntas debemos hacernos?

9 Qué preguntas debemos hacer? Tiene Usted: Intranet/Extranet/Internet? Tiene pensado/planeado implementar algún tipo de red? Tiene información crítica o estratégica disponible en su red? Cómo saber si ha sido victima de una falla de seguridad?

10 Qué és la Internet ? Internet Remote User Remote Office Corporate Network Remote Partner

11 Qué és la Intranet ? Internet Corporate Network Web Server E-Mail Server DMZ Network Remote Office Remote User

12 Qué és la Extranet? Qué és la Extranet ? Internet Remote User Partner Site Corporate Network Web Server E-Mail Server DMZ Network Partner Site

13 Qué necesitamos proteger? Routers are target Managed Switches target Hosts /Clients target Databases target Applications are target Information are target Web and email Servers Management tools are target

14 Más Preguntas …….. \Es su solución de seguridad completa? \Puede Ud. soportar una amplia gama de negocios sin comprometer la organización? \Es su solución de seguridad extensible a requerimientos de los usuarios que están en evolución?

15 Cómo surgen Problemas de Seguridad? Al conectar su computador a la Internet está amenazado……. La primera amenaza es que sus paquetes IP pueden ser escrutados al viajar por la Internet. La segunda amenaza es que alguien use su conectividad para atacar su OS. Hay una sola forma de proveer seguridad contra estas amenazas…….

16 Servicios de Seguridad Qué significan?. Por qué son necesarios?. Cómo se implementan?.

17 Qué significan Servicios de Seguridad? Privacidad…….? Autenticación..….? Control de Acceso….…….?

18 Propiedades Comunicación Alice Bob Comunicarse con seguridad ?? Secreto Autenticación Integridad Mensaje

19 Acceso Autenticado VLAN A VLAN B Auth. VLAN 1 1 Logon and establish access privileges 2 2 Instruct network to connect user to target VLAN(s) 3 3 User is connected to target VLAN(s) Authentication Server Target Resource A Target Resource B

20 Por qué son necesarios? Perpetrador tiene conocimientos sólidos de los protocolos usados. Puede interpretar el mensaje descubriendo passwords, o información sensible, etc.

21 Firewall Cómo se implementan? El reto de la Seguridad en una Red de Computadoras

22 Qué és un Firewall? Sistema diseñado para prevenir acceso no autorizado desde o hacia una red privada Se implementa tanto en hardware como en software, o una combinación de ambas Todo mensaje entrante/saliente de la red através del FW será examinado evitando aquellos que no cumplan con las políticas de seguridad.

23 Arquitecturas de Firewall 1. Packet Filters 2. Application Proxies 3. Circuit-level Gateways 4. Network Address Translation (NAT) Firewalls

24 Packet Filter Firewall Server Router with Packet Filter Application Presentation Session Data Link Transport Physical Network Layer User

25 Application Gateways / Proxies TelnetTelnetHTTPHTTPFTPFTP Gateway runs proxy applications for Network Data Link Transport Physical ApplicationLayer SMTPSMTP Presentation Application Session

26 Stateful Inspection Packets intercepted between Data Link and Network layers. Between Datalink and Network Layers Dynamic State Tables Application Presentation Session Transport Network Physical Data Link Information on all higher layers saved in dynamic state tables.

27 Proxy Server Gateways External Web Server Firewall Proxy Server Internal Client 1. Request 2. Repackage request 3. Response 4. Repackage response

28 Políticas de Seguridad Network Service Access Policy Firewall Design Policy

29 Políticas de Seguridad Network Service Access Policy Define los servicios que serán permitidos o negados explicitamente desde la red restringida y que cumplan con las propiedades de una comunicación segura.

30 Políticas de Seguridad Firewall Design Policy Describe como el firewall va ser configurado para aplicar las normas de restringir acceso o filtrado de servicios.

31 Enterprise Security - Internet Remote User Remote Office Partner Site Corporate Network DMZ Network Internet FW

32 Enterprise Security - Internet Remote User Remote Office Partner Site Corporate Network DMZ Network Internet FW

33 Enterprise Security - Intranet Policies for enterprise-wide communication Remote User Remote Office Partner Site Corporate Network DMZ Network Internet FW

34 Enterprise Security - Intranet Policies for enterprise-wide communication Remote User Remote Office Partner Site Corporate Network DMZ Network Internet FW

35 Enterprise Security - Extranet Secure communication between partners Remote User Remote Office Partner Site Corporate Network DMZ Network Internet FW

36 Elementos de Seguridad en Redes Inalámbricas

37  Control de Acceso By Network Name By MAC address  Tecnología transmisión DSSS es dificíl de interceptar.  DSSS permite ratas de transmisión altas al dividir la banda 2.4-GHz en 14 canales 22-MHz  Seguridad es debíl Seguridad en WLANs

38 Amenazas en WLANs Denial of Service Interception/Eavesdropping Manipulation Masquerading Repudiation Transitive Trust Infrastructure

39 Premisas Seguridad en 802.11b Service Set Identifier (SSID) Shared or Open Authentication MAC Filtering/FireWall Wired Equivalent Privacy (WEP) –Link Level –Poor security

40 SSID Mecanismo usado para segmentar WLANs Cada AP es programado con un SSID que corresponde a su Red Cliente presenta SSID correcto para accesar el AP Existen compromisos de seguridad –AP puede ser configurado para “broadcast” su SSID –SSID puede ser compartido entre varios usuarios de un segmento inalámbrico

41 Filtrado MAC Cada cliente identificado por su 802.11 NIC MAC Address El AP puede ser programado con un set de direcciones MAC para acceptarlas Combinar el filtrado con el SSID de AP Incurrimos en un “ Overhead ” manteniendo lista de direcciones MAC.

42  Criptografía usa el algoritmo RC4 definido en el estandard IEEE 802.11 WEP.  Hay productos disponibles con 40 y 128 bits de encriptamiento.  64 bit WEP es igual al de 40 bit WEP 40 bit (10 Hex caracter) "secret key" (definido por usuario), y un " Vector Initialization ” de 24 bits (que no esta bajo control del usuario). Criptografía

43 802.11 – Seguridad Enterprise/Home –Data Encryption (WEP, TKIP, AES): Prevent 3 rd parties from viewing the content of wireless data transmissions –User Authentication (802.1X): Prevent unauthorized users from connecting to the wireless network –Virtual LAN: Use VLAN-capable Access Points to tag “guest traffic” and other “non-secure” traffic so that it can be routed outside the firewall Across the Public Infrastructure –Virtual Private Network: Maintain end-to-end privacy through the use of Layer 3 tunneling protocols (independent of 802.11 devices)

44 Autenticación WEP Acceso requerido por el cliente AP envia reto al cliente con texto El texto es codificado por cliente usando la llave secreta enviada por la AP Si el texto es codificado adecuadamente el AP permite el acceso o lo niega.

45 WEP en Acción Supplicant Access Point Network resources Association Response Encrypted Data to Access Point WEP Key: 1234567890 WEP Key 1234567890 Authentication Response Authentication Request Association Request

46 Debilidades WEP Todos los clientes de un AP en una red inalámbrica comparten la misma llave de encriptamiento No existe un protocolo para la distribución de la llave de encriptamiento. Se mejora con WPA.

47 Client proves credential To authentication server WPA en Acción Supplicant Network resources Association Request AP sends authentication request Authenticator Client joins LAN with encrypted data Once authenticated, authentication server will distributes TKIP encryption key Authentication Server AP blocks request until user is authenticated

48 802.11 – Security Portfolio 802.11a and a/b Updated 802.11b Original 802.11b Different Ways a Network Needs to be Made Secure Application Authentication WEP Encryption Operation TKIP AES nothing “SSN” 802.1x LEAP PEAP TLS VPN VLAN “Is my data secure?” “How can I keep intruders from entering my network?” “Can I maintain the integrity of my link from end to end?” “How can I avoid breaking my own security mechanisms?”

49 End-User Station Password 802.1X Authentication 1 Using Extensible Authentication Protocol (EAP) an end-user contacts a wireless access point and requests to be authenticated. 2 The Access Point passes the request to the Radius Server. 3 The Radius Server challenges the end user for a password, and the end user responds with a password to the Radius server. 4 The Radius server authenticates the end user and the access points opens a port to accept data from the end user. DRS-200 Wireless AP Request EAPOL (EAP) RADIUS (EAP)

50 Muchas Gracias

51 D-Link Security Solution

52 Basic Definitions Confidentiality –Are you the only one who is viewing information specific to you or authorized users? Integrity –Are you communicating with whom you think? –Is the data you are looking at correct or has it been tampered with? Availability –Are the required services there when you need them? Authentication –Are you who you say you are?

53 Vocabulary in Security AS – Authentication Server EAP – Extensible Authentication Protocol EAPOL – EAP Over LAN IV – Initialization Vector MIC – Message Integrity Code PEAP – Protected EAP PKI – Public Key Infrastructure RADIUS – Remote Access Dial-In User Service TKIP – Temporal Key Integrity Protocol WEP – Wired Equivalent Privacy WLAN – Wireless Local Area Network AES – Advanced Encryption Standard

54 Hacker Prevention and Network Protection Network Intrusion Detection System (NIDS) is a real-time network intrusion detection sensor Identifies and takes action against suspicious network activity Uses intrusion signatures, stored in the attack database, to identify the most common attacks To notify system administrators of the attack, the NIDS records the attack and any suspicious traffic to the attack log

55 Hacker Prevention and Network Protection NIDS protects DFL-xxxx and the network connected to it by : –Dropping the connection –Blocking packets from the location of the attack –Blocking network ports, protocols or services being used by an attack

56 Hacker Prevention and Network Protection Using Virtual Private Networking (VPN), you can provide a secure connection between widely separated office networks or securely link telecommuters or travelers to an office network VPN features includeing –standard IPSec VPN (eg IPSec, DES, 3DES, etc) –PPTP –L2TP –IPSec and PPTP VPN pass through

57 Secure Installation, Configuration and Management Logging and Reporting –Report traffic that connects to the firewall interfaces –Report network services used –Report traffic permitted by firewall policies –Report events such as configuration changes and other management events, IPSec tunnel negotiation, virus detection, attacks and web page blocking Logs can be sent to a remote syslog server or to a WebTrends server using WebTrends enhanced log format

58 DFL-200 3,000 concurrent sessions Firewall performance: 60Mbps 3DES performance: 20Mbps 70 dedicated VPN tunnels 500 policies, 256 schedules 10/100BASE-TX port to connect to DSL/cable modem 10/100BASE-TX dedicated DMZ port 4 10/100BASE-TX LAN switch ports

59 DFL-700 Support 100 users 10,000 concurrent sessions Firewall performance: 100Mbps 3DES performance: 30Mbps 200 dedicated VPN tunnels 1,000 policies, 256 schedules 10/100BASE-TX port connect to DSL/cable modem or external LAN 10/100BASE-TX port connect to Internal LAN (Trusted) 10/100BASE-TX dedicated DMZ port

60 DFL-1100 200,000 concurrent sessions Firewall performance: 250Mbps 3DES performance: 60Mbps 1,000 dedicated VPN tunnels 10/100BASE-TX port connect to DSL/cable modem or External LAN 10/100BASE-TX dedicated DMZ port 10/100BASE-TX LAN port connect to Internal LAN (Trusted) 10/100BASE-TX backup port connect to backup firewall 2,000 policies, 256 schedules

61 Securing Your Network with DFL-1100 Internet ADSL Switches Backup Link DFL-1100 Active firewall DFL-1100 Backup firewall VPN Access HQ Network Branch Office ???? Mobile Users Tele worker 500 users Insurance Business Sector

62 DFL-500 & DFL-1000 Network Protection Gateway (NPG) A dedicated easily managed security device that delivers the following services :- –application-level services such as virus protection and content filtering –network-level services such as firewall, intrusion detection, VPN and traffic shaping

63 DFL-500 & DFL-1000 Accelerated Behaviour and Content Analysis System (ABACAS TM ) Unique ASIC-based architecture Analyse contents and behaviour in real-time Enable key applications to be deployed right at the network edge where they are most effective at protecting the network

64 DFL-500 vs DFL-1000 DFL-500DFL-1000 Product Category CPU RAM Flash Ports. SoHoSMB 133MHz300MHz 64MB256MB 32MB64MB 1 LAN, 1 WAN.1 LAN, 1 WAN, 1 DMZ

65 DFL-500 vs DFL-1000 (System Performance) Concurrent sessions DFL-1000DFL-500 25,0002,000 New session / speed10,000800 Firewall performance180Mbps30Mbps Triple-DES (168 bit)120Mbps15Mbps Policies1,000100 Schedules25630

66 DFL-500 vs DFL-1000 (Firewall Mode of Operation) Network Address Translation DFL-1000DFL-500 Yes Port Address TranslationYes Transparent modeYes Route modeYes Virtual IPYes

67 DFL-500 vs DFL-1000 (VPN) Dedicated tunnels DFL-1000DFL-500 10020 Manual key, IKE, PKIYes DES (56-bit) & 3DES (168-bit) encryptionYes. Perfect forward secrecy (DH Groups) Yes. Remote access VPNYes

68 DFL-500 vs DFL-1000 (Firewall Attacks) DDOS and DOS detected DFL-1000DFL-500 14 MAC address bind with IPYes

69 DFL-500 vs DFL-1000 (Logging / Monitoring) Internal log space DFL-1000DFL-500 YesNo E-mail notify3 addresses SyslogYes SNMPYes Device failure detectionYes Network notification on failoverYes

70 DFL-500 vs DFL-1000 (IPSec) Site-to-site VPN DFL-1000DFL-500 Yes AuthenticationYes SHA-1 / MD5Yes

71 DFL-500 vs DFL-1000 (Firewall & VPN User Authentication) Build-in database - user limit DFL-1000DFL-500 Yes RADIUS (external) databaseYesNo RSA SecureID (external) databaseYesNo LDAP (external) databaseYesNo

72 DFL-500 vs DFL-1000 (System Management) WebUI (HTTP and HTTPS) DFL-1000DFL-500 Yes Multi-language user interfaceYes Command line interface (telnet)Yes Wizard / Quick InstallationYes Secure command shell (ssh v1 compatible) Yes. All management via VPN tunnel on any interface Yes.

73 DFL-500 vs DFL-1000 (Traffic Management) Guaranteed bandwidth DFL-1000DFL-500 Yes Maximum bandwidthYes Priority-bandwidth utilizationYes

74 DFL-500 vs DFL-1000 (Administration) Multiple administrators DFL-1000DFL-500 Yes Root Admin, Admin & Read Only user levels Yes. Software upgrades & Configuration changesTFTP / WebUI Trust hostYes

75 DFL-500 vs DFL-1000 (Network Service) PPPoE DFL-1000DFL-500 Yes PPTPYes DHCP clientYes DHCP serverYes VPN client pass throughYes