distance education team 1 adrian sia xavier appé anoop georges salvador gonzales augustine ani...

23
Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Upload: natasha-bromley

Post on 31-Mar-2015

216 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Distance Education Team 1

Adrian SiaXavier AppéAnoop GeorgesSalvador GonzalesAugustine AniZijian CaoJoe Ondercin

SNA Step 3

November 14, 2001

Page 2: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Overview

Project ProgressEssential Services & AssetsClient Security ConcernsRelevant Attacker Profile, Level of Attack, and Probability of AttackAttack ScenariosCompromisable ComponentsNext Step

Page 3: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Project ProgressOne meeting every two weeks at 1PM on Saturday09/15/01 1st project meeting – step 1 discussion (completed)09/20/01 client interview with Mel Rosso (completed)09/22/01 2nd project meeting – step 1 presentation dry run (completed)09/25/01 client interview with Michael Carriger (completed)09/26/01 Step 1 presentation (completed)10/13/01 3rd project meeting – step 2 discussion (completed)10/27/01 4th project meeting – step 2 presentation dry run (completed)10/31/01 Step 2 presentation (completed)11/10/01 5th project meeting – step 3 presentation dry run (completed) 11/14/01 Step 3 presentation11/24/01 6th project meeting – step 4 and final report discussion12/1/01 7th project meeting – step 4 presentation dry run12/5/01 Step 4 presentation12/12/01 Project report submittalNote: additional client interview(s) may be conducted when deemed necessary.

Page 4: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Essential Services & Assets

CS Network

Apache Web Server

IMeet Chat Server

MySql

Admin App

Oracle

Inte

rnet

E-MailServer

Hub

CMU Network

Tech Staff

Instructor

Admin Staff

Admin Server

Product Server

Essential Services

•Course Web Site Access

•Email

•Chat

Essential Assets

Page 5: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Potential AttackersRecreational Hackers Script Kiddies Vandals

DE StudentsDisgruntled Employee Current Former

Intellectual Property SpyTransit Seeker

Page 6: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Attacker Attributes

ResourcesTimeToolsRiskAccessObjectives

Page 7: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Attacker Profile

Recreational Hackers Varied skills, knowledge levels, support No particular time constraints Distributed Tool, toolkit, script Not averse, may not understand risk External/Internet access Status, thrills and challenges

Level: Target-of-OpportunityProbability: High

Page 8: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Attacker ProfileDE Students Varied skills, knowledge of process Immediate needs Distributed tool, toolkit, script Risk averse Internal access via Internet Spy on other students’ homework,modify

records and browse unregistered courses

Level: Target-of-opportunityProbability: Low/Medium

Page 9: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Attacker Profile

Disgruntled Employee Knowledge of process, depends on personal

skills Very patient and wait for chance Physical attack, toolkit, self-created program Risk averse Internal/external, LAN, dialup, or Internet Personal gain, get even, embarrass organization

Level: IntermediateProbability: High

Page 10: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Attacker ProfileIntellectual Property Spy Medium to expert skills, knowledge and

experience Current desire to access the information Customized tool, tap Very risk averse External, Internet Measurable gains

Level: SophisticatedProbability: Low

Page 11: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Attacker ProfileTransit Seekers Medium to expert skills, knowledge and

experience Patience depends on mission User commands, customized tool,

autonomous tool, social engineering Risk averse External, Internet Gain access to other CMU network

Level: intermediate/SophisticatedProbability: Low

Page 12: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Client Security Concerns

Web page access to student infoGrades online through blackboardWork submission onlineStudent assignmentsBilling information

Page 13: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Attack Scenarios

Page 14: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

IUS1 – Denial of ServiceComponent Based AttackPossible Attackers Recreational Hacker Disgruntled employee

Instigating Network Traffic and Connection Request Distributed denial of service SYN flood Ping of death

Compromise the Availability of the System

Page 15: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Tracing IUS1

CS Network

Apache Web Server

IMeet Chat Server

MySql

Admin App

Oracle

Inte

rnet

E-MailServer

Hub

CMU Network

Tech Staff

Instructor

Admin Staff

Admin Server

Product Server

Essential Assets

Apache Web Server

HACKER

Page 16: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

IUS2 – Unauthorized Access

User Access Based AttackPossible Attackers DE student Disgruntled employee

Using Incomplete or Improperly Assigned Access Rights to View or Modify Information Privilege escalation Password sniffing Brute force

Compromise the Privacy and/or Integrity of Information

Page 17: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Tracing IUS2

CS Network

Apache Web Server

IMeet Chat Server

MySql

Admin App

Oracle

Inte

rnet

E-MailServer

Hub

CMU Network

Tech Staff

Instructor

Admin Staff

Admin Server

Product Server

Essential Assets

Apache Web Server

Disgruntled Emp

Student

Page 18: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

IUS3 – Data CorruptionUser Access/Application Content Based AttackPossible Attackers Disgruntled employee Recreational Hacker

Logic Bombs and Data Corruption Privilege escalation Attachment to email Virus or scripting

Compromise Data Integrity and Availability

Page 19: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Tracing IUS3

CS Network

Apache Web Server

IMeet Chat Server

MySql

Admin App

Oracle

Inte

rnet

E-MailServer

Hub

CMU Network

Tech Staff

Instructor

Admin Staff

Admin Server

Product Server

Essential Assets

Former Staff

hacker

Page 20: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

IUS4 – Backdoor/Trojan Attack

User Access/Application Content Based AttackPossible Attackers Disgruntled employee Recreational hacker Intellectual property spy Transit seeker

Possible Upload of Malicious Code Attachment to email Virus or scripting Salami Buffer overflow

Compromise Privacy, Integrity and Availability

Page 21: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Tracing IUS4CMU Network

CS Network

Apache Web Server

IMeet Chat Server

MySql

Admin App

Oracle

Inte

rnet

E-MailServer

Hub

Tech Staff

Instructor

Admin Staff

Admin Server

Product Server

Essential Assets

Former Staff

hacker

IP Spy/Transit

Page 22: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Next StepIdentify SoftspotsBrief Existing Strategies for 3 R’sPresent Survivability Map Recommendations

Page 23: Distance Education Team 1 Adrian Sia Xavier Appé Anoop Georges Salvador Gonzales Augustine Ani Zijian Cao Joe Ondercin SNA Step 3 November 14, 2001

Questions?