- 大約有60~80的網路濫用(misuse)是出自於內部網路
- 三個安全的目標為
- confidentiality (Keep Data Private)
- integrity (Data has not been modified in transmit)
- availability (A measure of the data’s accessibility)
- 政府和軍隊使用的機密等級範例
- Unclassified
- Sensitive but unclassified(SBU)
- Confidential
- Secret
- Top-Secret
- 美國政府的三種機密等級
- Confidential
- Secret
- Top-Secret
- 組織使用的機密等級範例
- Public
- Sensitive
- Private
- Confidential
- 可用於資料分級的特徵
- 價值 (Value)
- 年份 (Age)
- 可用期 (Useful life)
- 相關者 (Personal association)
- 分類原則
- Owner
- Custodian (保管人)
- User
- 安全方案控制
- Administrative Control
- Physical Control
- Technical Control
- 承8. 以上方法又可以分為下列的控制方案
- Preventive
- Deterrent (遏止的)
- Detective
- 描述安全事件需要紀錄的項目
- Motive
- Means
- Opportunity.
- 不同等級的法律規範
- Criminal law
- Civil law
- Administrative law
- 五種概分的攻擊種類
- Passive
- Active
- Close-in
- Insider
- Distribution
- Defense in Depth design philosophy
- Defend multiple attack targets in the network
- Create overlapping defenses
- Let the value of protected resource dictate the strength of the security mechanism
- Use strong encryption technologies
- AES
- PKI
- NIDS, NIPS, HIPS
- NIDS (Network-based Intrusion Detection System)
- NIPS (Network-based Intrusion Prevention System)
- HIPS (Host-based Intrusion Prevention System)
- Types of IP Spoofing Attacks
- NonBlind Spoofing (攻擊者和目標在同一個subnet)
- Blind Spoofing (攻擊者和目標在不同subnet)
- Source Routing 的二種類型
- Loose
- Strict
- 防止IP spoofing Attacking的方法
- ACL
- IPsec tunnel
- cryptographic authentication
- 機密性攻擊方法
- Packet Capture
- Ping sweep and port scan
- Dumpster diving
- EMI interception
- Wiretapping
- Social engineering
- Sending information over overt channels
- Sending information over covert channels
- 完整性攻擊方法
- Salami Attack
- Data diddling
- Trust relationship exploitation
- Password attack
- Trojan horse
- Packet capture
- Keylogger
- Brute force
- Dictionary attack
- Botnet
- Hijacking a session
- 可用性攻擊方法
- Denial of Service (DoS)
- Distributed denial of service (DDoS)
- TCP SYN flood
- ICMP attacks
- Electrical disturbances
- Power Spike
- Electrical surge
- Power fault
- Blackout
- Power sag
- Brownout
- Attacks on a system’s physical environment
- Temperature
- Humidity
- Gas
全站熱搜
留言列表