5. Use of procedural error to attack
1 ping of death
2 teardrop attack
3land attack
Chapter 6 backdoors and net invisibility
1. Horses
A wooden horse is a program that can be located in the server system of the other party, and the wooden horse program typically consists of two parts: a server-end and a client-end program. The function of the horse is to manipulate the server through the client, thus manipulating the host of the other party。
In essence, both the wooden horse and the back door function provide the back door of the network, but the horse function is a little more powerful, generally with remote control, while the back door function is more single, providing the client with access to the host of the other party。
Chapter 8. Operational system security base
1. Overview and characteristics of commonly used operating systems
There are currently four types of operating systems commonly used by servers: freebsd, unix, linux and windows nt/2000/2003 server。
These operating systems are operating systems that meet security levels above c2, but there are a number of gaps that, if not understood, would expose the operating systems to the security of the invaders. All applications are operated on operating systems, and solid operating systems are the cornerstone of network security。
2. Security operating systems and operating system security are different concepts, and if the source code of the operating system contains a specific security policy, commonly referred to as a security operating system, while operating system security refers to operations such as settings that make the operating system more reliable。
Multics was the earliest attempt to develop a secure operating system. In 1965, a new operating system called multics was developed jointly by laboratories of the united states of america and mac team from mit
4. In 1969, b. W. Lampson made the issue of access control abstract for the first time through the idea of formalizing the use of subject (subject), object (object) and access matrix. The subject is the active entity in the access operation, the object is the passive entity in the access operation, and the subject visits the object. The access matrix is indexed by the main line and by the object, and each element of the matrix represents a set of modes of access and is a collection of several modes of access. The element of column j in line i of the matrix, mij, records the mode of access to object j oj that is enforceable by subject i si, such as mjj=read, write}, indicates that si can read and write on oj。
Subject and object

Each physical component of the operating system must be the subject or object, or both. The subject is a proactive entity that includes users, user groups, processes, etc. The most basic body of the system should be the user (including the general user and system administrator, the system warden, the system auditor, etc.). Each user entering the system must be uniquely marked and identified as authentic. Almost all event requirements in the system are driven by users. The process is the most active entity in the system, and all user event requirements are addressed through the operation of the process. Here, the process is the object of the user and the subject of its visit。
The object is a passive entity. In the operating system, the object can be either a data information stored in a certain format on a record medium (usually in file system format) or a process in the operating system. Processes in operating systems (including user and system processes) generally have a dual identity. When a process is run, it must serve a particular user - directly or indirectly addressing the user's event requirements. As a result, the process became the object of the user, or of another entering city (at that time the other entering city was the object of the user)。
6. Security strategy and model
Security strategies and safety models are two concepts in computer security theory that can easily be confused. Security strategy refers to laws and regulations governing, protecting and disseminating sensitive information。
An operating system is safe, meaning that it meets a given security strategy. The security strategy consists of a tight set of rules that determine authorized access as the basis for determining access control。
The security model is a simple, abstract and unambiguous description of the security needs expressed in the security strategy and provides a framework for the linkage between the security strategy and the security strategy's mechanisms. The security model describes the mechanism that needs to be used to meet a security strategy, while its realization describes how a specific mechanism is applied to the system to achieve the security protection required for a particular security strategy。
7. Marking and identification
Marking and identification involve systems and users. The identification is the system to identify the user, and not every user takes an internal name that the system can recognize - the user identifier. User identifiers must be the only one that cannot be forged, the process of communication between the user identifier and the user is identified, the identification operation always requires the user to have special information that can prove his identity and that no other user of this information can own him。
In the operating system, identification usually occurs when the user logs in, the system alerts the user to enter the password and then determines whether the password entered by the user is consistent with that of the user that exists in the system. The safer password should be not less than six characters, with both numbers and letters, and limit the life cycle of a population order. Biotechnology is also a more promising method of identifying users, such as the use of fingerprints, retinas, etc。
8. Access control generally involves two forms
1 autonomous access control dac2 forced access control mac
The initial section of the security configuration program, which focuses on conventional operating system security configurations, includes 12 basic configuration principles: physical security, stopping guest accounts, limiting the number of users, creating multiple administrator accounts, changing the administrator account number, trap account number, changing default privileges, setting security passwords, screen protection passwords, using ntfs partitions, running anti-virus software and ensuring backup disk security。
10. The mid-level section of the security configuration programme provides information on the security policy configuration of the operating system, including 10 basic configuration principles: operating system security strategy, closing of unnecessary services, closing of unnecessary ports, opening of clearance policy, opening of password policy, opening of account policy, backup of sensitive documents, not showing last login, prohibition of creating empty connections and downloading of new patches。
Chapter 9 password and information encryption
1. The science related to cryptography can be broadly divided into three areas: code science, code coding, and code analysis。

2. In principle, attacks on electronic data take two forms
1 passive attack, i. E. Unlawful interception of information from transmission channels or theft of information from storage carriers。
2 active attack, i. E. Malicious deletion, modification, etc. Of data transmitted or stored。
In addition to providing confidentiality, passwords need to provide three functions: identification, integrity and creditworthiness。
4. Des encryption requires four key points: ip replacement table and ip reverse replacement table, function f, working principles for subkey k and s boxes。
5. The rationale for the rsa algorithm
The rsa algorithm is a public key system based on the assumption that no prime factor is possible. Simply put, it is to find two large prime numbers, one for the world to be known as the “public key” and the other not to tell anyone about it as the “private key”。
The rsa system can be described briefly as follows:
1 generates two large prime numbersp and q
2 calculates the product of two prime numbers n=p*q
Number of integers calculated to be less than n and interacting with n, i. E. Euler function(n)=(p-1) (q-1)
4. Select a random numbere to meet 1,5 calculations de=1 mod(n)
6 secrecy d, p and q, public n and e
When using rsa encryption, encrypt explicitly by grouping, i. E. Each group should have fewer bits than log2n. When encrypted, the corresponding secretc is obtained using the public key (e,n) to calculate c=x mod n. When decrypted, the express x can be restored by calculating x=cmodn. In rsa systems, (e,n) constitutes the encryption secret key, i. E. The public key, and (d,n) constitutes the decryption secret key, i. E. The private key。
The selected prime numbers p and q are large enough to have a sufficiently large product n, and decomposition n is not possible to calculate without the prior knowledge of p and q. Common public key encryption algorithms include: rsa password system, eigamal password system and hash function password system (md4 and md5, etc.)。
6. Digital signatures refer to data obtained by the user using its own private key to encrypt the al-hashi summary of the original data. The recipient of the information, using the public key of the sender of the information, obtains a hashi summary after decrypting the digital signature attached to the original information and is satisfied that the original information has been tampered with by comparing it with the hashi summary generated by the original data it received. This ensures the authenticity of information sources and the integrity of data transmissions。

The functions of a digital envelope are similar to those of an ordinary envelope. The ordinary envelope is bound by the law to ensure that only the addressee can read the content of the letter; the digital envelope uses password technology to ensure that only the intended recipient can read the content of the information. A single key password system and a public key password system are used in digital envelopes. The sender of the message first encrypts the symmetric password using randomly generated symmetric passwords, then encrypts the symmetric password using the recipient's public key, which is referred to as a digital envelope if it is encrypted by the public key。
Firewall and intrusion detection
Limitations of firewalls
The firewall does not protect against attacks within the network. For example, firewalls cannot prevent defectors or internal spies from copying sensitive data on diskettes。
The wall also failed to prevent hackers disguised as super-users or as fraudulent new employees from persuading users who were not prepared to disclose their passwords and granting them temporary internet access。
Firewalls cannot prevent the transmission of infected software or documents and cannot be expected to scan each file and identify potential viruses。
2. Categorization of firewalls (realization of firewalls)
Group 1 filters: function in the network and transmission layers of the protocol community, determine whether the package is allowed to pass according to the labels of the cluster package header address, destination address and port number, protocol type, only the package meeting the filter logic is forwarded to the export end of the corresponding destination, and the remaining package is discarded from the data stream。
2 application agents: also known as the application gateway, which functions at the application level and is characterized by a complete “blocking” of network traffic, which is monitored and controlled by the development of a dedicated proxy program for each application service. The application gateway in practice is usually implemented by dedicated workstations。
State 3 monitoring: the data in the cluster are processed directly, combined with the data in the grouping, before deciding whether to allow the package to pass。
3. Common firewall system models are generally divided into four categories: the screening router model, the single-host fort (fortress fort) model, the two-host fort (fortress for firewall system) model and the shield subnet model。
4. Concept of intrusion detection systems
Invasive detection systems refer to a hardware or software system that allows timely judgement, recording and alerting of unauthorized use of system resources. Intrusion classes fall into two categories: external and internal. External invasions generally refer to illegal users from outside the lan and internal users who have access to restricted resources; internal invaders identify internal users who pretend to or have access to sensitive data, or who are able to shut down system audits, and internal invaders are not only difficult to detect but also more dangerous。
Invasive detection is an effective way of enhancing the security of the system by detecting activities in the system that violate the system's security rules or threaten the system's security. At the time of testing, the system administrator is assisted with security management or response to attacks on the system by assessing the degree of suspicion of user or system behaviour and, based on the results of the evaluation, identifying the normality of the system's behaviour。
5. Comparison of type and performance of intrusion detection systems




