 |
 |
webpointmorpheus Network Info
Threats, Shares, & Permissions
|
|
Overview
Definitions
Internal
External
Major OSs
General Notes
©2005 - material compiled by Bob Carnaghi, www.webpointmorpheus.com
|
- Overview Top of Page
- Since the dawn of the computer era, the concept of security has taken on new dimensions. Prior to computers and the Internet, the act of theft, vandalism, and destruction was largely governed by physical presence, access, and proximity to the items targeted. Since the advent of computers and the Internet, an individual no longer needs to be in close proximity to re-route bank funds, to access sensitive information, or to perform a variety of other tasks. As new means of accessing and facilitating movement of data have been developed, so have the means of performing illegal, immoral, and unethical actions. Hence, computer security is mandated to keep pace with these developments.
- Computer and network threats come in two basic forms: those that originate from inside of a network system, and those that come from outside the network system. Listed below are some considerations for each of these categories.
- If you have a difficult time with the acronymn drenched terms used in this document, check out the Network Definitions Page.
- Definitions Top of Page
- Permissions: Attributes set by administrators to resources that define allowed actions on files, folders, or other shared resources.
- Universal Naming Convention (UNC): A system of resource identification that is of the format \\SERVER\RESOURCE\
- User Account: The basic level of information that identifies an individual to a system.
- Group: A collection of user accounts given a certain level of access permissions for ease of administration.
- Bindery: Novell Netware database that uses NDS (Netware Directory Services) for user accounts and stores information regarding resources, groups, and rights.
- Internal Threats Top of Page
- Internal threats to a network system are those threats to the stability and security of the system that originate from within the system itself. They can range from user carelessness to theft by employees to Trojan Viruses which enter through email or other seemingly harmless sources.
-
- Access to resources by unauthorized persons
- Data destruction by carelessness or neglect
- Administrative Access
- System/Hardware Failure
- Physical Access/Theft
- Infiltration of viruses
- Solutions Top of Page
-
- Strong passwords - mandate changes
- User account control and management
- Permissions
- Group management and policies
- External Threats Top of Page
- External threats are those potential problems that attempt to gain system control from outside the network. These may be electronic/software oriented, or some form of socially engineered attempt to gain access to passwords, logins, or other sensitive data.
-
- Snoopers/Eaves Droppers
- Packet Sniffers
- Gaining Control of the System
- Denial of Service
- Social Engineering
- Solutions Top of Page
-
- Firewalls: Hide IPs, filter ports, filter packets, encrypt, authenticate.
- PAP - Password Authentication Protocol
- CHAP - Challenge Handshake Authentication Protocol
- MS-CHAP
- Data Encryption
- VPN - L2TP, PPTP
- Application Encryption
- HTTP Proxy
- Written disaster plan/SOP
- The Mike Meyers Security Model a
- This outline is a distinction that can be made among the different NOSs. Each NOS treats each of the items differently, making each NOS suitable for a different level of application.
-
- Resource-based Security - permissions assigned to a specific resource.
- Server-based Security - access and permission system controlled by individual servers on the network.
- Organization-based Security - a centralized domain controller that sets permissions and access restrictions at logon.
- Major Operating Systems Top of Page
- Listed below are the major NOSs (Network Operating Systems.) Each of these systems addresses network security in different ways, and to different degrees.
-
- Novell Netware - 3.x, 4.x, 5.x
- Windows Workgroups - peer to peer systems
- Windows Server Models - domain based systems such as Windows NT domains or Active Directory.
- Unix/Linux - has three levels of access only: Read, Write, Execute. Also has concept of User, Group, Everyone.
- Macintosh - Appletalk.
- General Notes Top of Page
- This list is a (random) collection of items for consideration.
-
- Windows workgroups operate at the level of resource-level security. This system becomes an admistrative burden beyond about 10 nodes.
- The power of the Windows NT network system (Windows NT, Windows 2000, Windows XP) is in the NTFS file system. When utilized, NTFS embeds it powerful system of permissions into each resource.
- NTFS Permissions (Windows NT version):
- No Access
- List
- Read
- Add
- Add & Read
- Change
- Full Control
- NTFS Permissions (Windows 2000 version):
- Deny Access
- List Contents
- Read
- Write
- Read & Execute
- Modify
- Full Control
- Files and folders are the typical share items, followed by printers and other hardware items.
- Individual files are never set to be shared. Files can have permissions applied, but on a network system, only folders are set to be shared.
- Notes Top of Page
-
- From 'Network+ Certification' by Mike Meyers. See Chapter 13.
|
Top of Page
Introduction to Network Documents
IEEE & The OSI Model
Network Topology & Hardware
Network Protocols
Network Operating Systems
Wireless Network Technology
Threats, Shares, & Permissions
DNS - Domain Name System
LAN - WAN - Remote
Network Operation and Optimization
TCP/IP
Problems & Troubleshooting
Network Incidentals
Network Definitions
|
|
webpointmorpheus Home
Technical Pages
|
Site Map
This page was last modified: Wednesday July 20, 2005 7:35 AM |
|
 |