Security Fundamentals

1、Threat Capabilities – More dangerous and easier to use
–password guessing –> self-replicating code –> password cracking
–expoiting known vulnerablities –> Back door –> scanners –>stealth diagnostics –>
packet forging/spoofing
–disabling audits –> hijacking sessions –>sniffers

2、Netowrk security is a continuous Process build around a security policy

Step1: Secure
—> Methods
– Authentication
– Encryption
– Firewalls
– Vulnerability patching

Step2: Monitor
— Vulnerablity scanners
— IDSs
Step3: Test
Step4: Improve

3、Network Security Policy
–” A formal statement of the rules by which people who are given access to
an organization’s technology and information assets must abide.”

4、What should the security policy contain?
– Statemnet of authority and scope ‘申明权利范围
– Acceptable use policy
– Identification and authentication policy
– Internet use policy
– Campus access policy
– Remote access policy
– Incident handling procedure

5、Netowrk Security Threats
– unstructured threats/structured threats/internal threats/external threats

6、 Four Primary Attack Categories
–Reconnaissance attacks/Access attacks/Denial of service attacks
/Worms,viruses,Trojan horses …

转载请注明 :IT樵客

此条目发表在 网络技术 分类目录,贴了 标签。将固定链接加入收藏夹。

关于 logger

2010年网络规划设计师证书寻挂靠!

发表评论

电子邮件地址不会被公开。 必填项已用 * 标注

*

您可以使用这些 HTML 标签和属性: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>