★ wanayoo — archive 1999 http://www.data.com/miscellani/simulated_attack.htmlNouvelle recherche | Portail wanayoo
CMP's TechWeb Click Here to Vist CMPNET


Data Communications
Search Data Communications

 Browse By...
 Technology/Topic
 Vendor
 Issue

 Visitors Center

 FAQs
 Contact the Editors
 Registration
 Subscriptions

 Content
 TECH TUTORIALS
 ATM
 Carrier-Class Gear
 Internet/Intranets
 IP Tools/Issues
 Network Software
 Net Management/SLAs
 QOS
 Remote Access
 Routers/Switches
 Security
 Servers/Peripherals
 Services/Outsourcing
 Workgroup Networks

 NEW PUBLIC NETWORK

 LAB TEST CENTER

 GLOBAL NETWORKS

 PRODUCT LEADERS

 OPINIONS/COLUMN
 Viewpoint
 Lippis on Internetworking
 Sound Byte

 Marketing Services
 T99 Media Services
 Industry Front & Center
 Reader Service

 Custom Publishing
 Vendor Strategies
 Sponsorships

Click Here to Vist CMPNET

TechWeb Sites
 Byte.com
 CMPmetrics
 Data Communications
 File Mine
 InformationWeek
 InternetWeek
 Network Computing
 Planet IT
 TechShopper
 TechWeb News
 Tele.com
 WebTools
 Winmag.com

Data Communications: Roundups

November 21, 1995


By Johna Till Johnson

Simulated Attack for Real Network Security

Internet Security Systems' Internet Scanner lets net managers find the network's weak spots before hackers do

[ Product Summary ]

How do hackers wreak their havoc? Net managers would like to find out: Knowing the enemy is a big part of any battle, and in cyberspace it's no different.

Internet Security Systems (Norcross, Ga.) is letting net managers experience the hacker attack from the other side of the firewall. Its Internet Scanner "attack simulator" software automatically scans each networked machine, searching for weaknesses and misconfigurations that cybervillains would be only too willing to exploit.

Internet Scanner is similar to the Satan (Security Administrator Tool for Analyzing Networks) package released as freeware over the 'Net, except that it's a commercial product-and that's its chief advantage. The vendor issues several upgrades each year and provides online and telephone support. In addition, the sale of Internet Scanner is limited to legitimate users, and Internet Security Systems preconfigures it to work only on a specified set of IP addresses. If it's lost or stolen, it doesn't work. The Internet Scanner also includes a feature not available with Satan: suggested fixes for holes.

There is a limit to the software's scanning abilities, however: It only scans Unix platforms. The vendor is deciding on whether to add scanning capabilities for Windows NT-a platform that's becoming increasingly popular for corporate Internet connections-but users of NT for now will have to wait.

THE SCAN PLAN

Internet Scanner consists of a master program-running on either HP-UX, AIX, SunOS, or Solaris-that starts up a variety of processes as needed (see the figure). Each process goes out over the network and probes host machines, looking for specific security holes and scanning each host for each type of hole. Users can probe multiple hosts simultaneously to limit the amount of time required to scan a network.

Scanning for Security


The Internet Scanner master program, which runs on a Unix workstation, initiates multiple scanning processes (1). Each process launches "attacks" against a host (2). The host's replies (3) are monitored by a listening process, which reports them back to the master program (4). The master program sends them to a report writer (5), which issues a detailed statement for users (6).

Of particular significance for corporate customers is the package's ability to scan firewalls. Internet Scanner knows to look for certain weaknesses, including source routing (allowing packets that appear to have come from inside the network to pass) and source porting (keeping a specific port on the firewall open to allow FTP [file transfer protocol] transfers). Internet Scanner also tests Socks configuration. Socks is a proxy service that lets net managers configure firewalls in a wa y that will block users from getting onto the Internet. But frequent misconfiguration has the opposite effect: It allows Internet users inside.

In addition, the package includes a "listener" process that checks for responses from the scanned host. The program then compiles a report displaying any flaws found, along with suggested responses.

WHAT'S THE PASSWORD?

Another way the Internet Scanner looks for configuration weaknesses is by attempting to log into scanned hosts using common user passwords. But it doesn't stop with common log-ins-it also checks for information about authorized users using the "finger" command, which can often uncover such information as a user's birth date and full name, and the names of family members. It then uses this information to attempt log-ins.

Internet Scanner also checks directories to see if they have been modified by outsiders, and it probes Unix utilities for software that includes known security holes. It can, for example, determine whet her a system is afflicted by the "sendmail" bug, by which an executable program could be sent via e-mail (this was the flaw that permitted the Internet Worm to crash large parts of the Internet in 1987). It also checks World Wide Web software for known flaws-such as the Netscape bug discovered last summer.

In addition, the package can determine which machines are considered "trusted" by the scanned machine (that is, which devices have access to the scanned machine). It will then check to make sure that there is no flaw that would allow the file containing the list of trusted hosts to be modified to include the hacker's host.

That's the story on scanning-but what happens when a weakness is discovered? Internet Scanner sends a report to the network manager containing a description of the weakness found and an indication of its seriousness (vulnerability is classified as high, medium, or low). It also generates a list of suggestions for repairing the flaw. These suggestions can be fairly specific . For example, users of flawed software from a particular vendor are told to request a specific patch or upgrade, and they are given the contact information that enables them to do so.

The vendor releases new versions of Internet Scanner every few months, and each version contains new types of probes to enable users to keep pace with hackers. The availability of these upgrades distinguishes it from Satan, and it makes the package attractive to users. "Internet Scanner does a nice job," says Kenneth Miles, a network manager at Argonne National Labs (Argonne, Ill.). "It's money well spent."


[ Home ]

[ Registration | Subscriptions ]
[ Contact Us | E-Mail ]



Home Contact Editors Lab Tests Registration Tech Tutorials
Buyer's Guide Global Networks Opinion / Columns FAQs Subscriptions

CMPnet Click Here to Vist CMPNET