What is Network Security?
Define Security, Security Threat and Security Attack
Security:
- the state of being free from danger or threat
Security Threat:
- a potential violation of security
Security Attack:
- Attempt to gain unauthorized access to a service, resource, or information, or to compromise integrity, availability, or confidentiality
(Note that success is not necessary! )
Passive vs Active attacks
Passive attacks
Active attacks
How to get our network free from Security threats?
Using security Services and Mechanism:
Security Services:
- a service provided by a layer of communicating open systems, which ensures adequate security of the systems or of data transfers
Security Mechanism:
- a mechanism that is designed to detect, prevent, or recover from a security attack
What are the Security Services?
Authentication
Access Control
Confidentiality
Integrity
Non-repudiation
Availability
How to attack each security services?
Authentication
- IP spoofing, cracking passwords
Access Control
- wire-tapping, breaking authentication
Confidentiality
- eavesdropping, traffic analysis
Integrity
- man-in-the-middle attack, replay attack
Non-repudiation
- deletion of log files, masquerading
Availability
- denial of service attacks