CHAPTER 17 NETWORK MANAGEMENT 17-4 Security Attacks Passive Threats Active Threats Release of Traffic Masquerade Replay Modification of Denial of message contents analy message contents service www.gxmu.edu.cn
www.gxmu.edu.cn 17-4 Security Attacks CHAPTER 17 NETWORK MANAGEMENT
CHAPTER 17 NETWORK MANAGEMENT 17-4 Passive Attacks art message from Bob messages from Bob Internet or other comms facility other comms facility (b)Traffic anal (a) release of message contents www.gxmu.edu.cn
www.gxmu.edu.cn 17-4 Passive Attacks CHAPTER 17 NETWORK MANAGEMENT
CHAPTER 17 NETWORK MANAGEMENT 17-4 Active Attacks Darth Message from Darth that appears to be Darth Bob to Alice: later from Bob replay message to Alice Internet or other comms f Alice (a) Masquerade (b)repla www.gxmu.edu.cn
www.gxmu.edu.cn 17-4 Active Attacks CHAPTER 17 NETWORK MANAGEMENT
CHAPTER 17 NETWORK MANAGEMENT 采用一切手段(主要指静态防护手段)保 检测本地网络的安全漏洞和存在的非 护信息系统的五大特性。 法信息流,从而有效阻止网络攻击 Protection Detection information Security Restore Reaction 及时恢复系统,使其尽快正常对外提供服 对危及网络安全的事件和行为做出反应,阻 务,是降低网络攻击造成损失的有效途径 止对信息系统的进一步破坏并使损失降到最 低 www.gxmu.edu.cn
17-4 Security Mechanism A mechanism that is designed to protect,detect, reaction, and restore from a security attack. www.gxmu.edu.cn Protection Detection Restore Reaction information Security 及时恢复系统,使其尽快正常对外提供 服务,是降低网络攻击造成损失的有效 途径 对危及网络安全的事件和行为做出反应,阻 止对信息系统的进一步破坏并使损失降到最 低 采用一切手段(主要指静态防护手段) 保护信息系统的五大特性。 检测本地网络的安全漏洞和存在的非 法信息流,从而有效阻止网络攻击 PDRR MODEL: Protection保护 Detection检测 Reaction响应 Restore恢复 Protection Detection Restore Reaction information Security 采用一切手段(主要指静态防护手段)保 护信息系统的五大特性。 及时恢复系统,使其尽快正常对外提供服 务,是降低网络攻击造成损失的有效途径 对危及网络安全的事件和行为做出反应,阻 止对信息系统的进一步破坏并使损失降到最 低 检测本地网络的安全漏洞和存在的非 法信息流,从而有效阻止网络攻击 CHAPTER 17 NETWORK MANAGEMENT
CHAPTER 17 NETWORK MANAGEMENT attack Protect failure Detect succeed React failure Recove failure www.gxmu.edu.cn
www.gxmu.edu.cn Protect Detect React Recove attack failure succeed failure succeed succeed failure CHAPTER 17 NETWORK MANAGEMENT