Problématique et concepts de base


Web server, mail….(traffic to Internet)



Yüklə 446 b.
səhifə35/43
tarix02.01.2022
ölçüsü446 b.
#32251
1   ...   31   32   33   34   35   36   37   38   ...   43

Web server, mail….(traffic to Internet)

  • Application server (hidden behind a FW)



  • PAT : Port Address Translation (I)



    PAT : Port Address Translation (II)

    • Connections are open from an exterior host

    • Translation table

    • Use of lesser public addresses

    • Flexible management of server ports





    Masking (I)



    Masking (II)

    • Connections are open by internal hosts

    • Dynamic connection table (IP address + source port number)

    • One single address is known outside (the FW address)

    • Spare IP addresses





    Hacking… and security tools (I)

    • Network auditing (probing)

      • Checks if the network presents security weaknesses (accessible ports, badly configured services, etc.)
    • Network/Host Intrusion Detection Systems (NIDS/HIDS)

      • NIDS can be put before the FW, on the DMZ, on the internal network
      • NIDS are based on intrusion signatures and statistics (abnormal behavior)
      • HIDS on sensitive hosts e.g. bastions, application servers



    Yüklə 446 b.

    Dostları ilə paylaş:
    1   ...   31   32   33   34   35   36   37   38   ...   43




    Verilənlər bazası müəlliflik hüququ ilə müdafiə olunur ©www.muhaz.org 2025
    rəhbərliyinə müraciət

    gir | qeydiyyatdan keç
        Ana səhifə


    yükləyin