Computer Network Security
Computer security. With many people switching their systems to a broadband network, the need for computer security education has grown. This lens provides an overview of computer security topics as well as links to resources I use to keep the systems I manage at home and at work secure.
I have taken most of my computer security training from the SANS Institute. For those wondering, I have completed Firewalls, Perimeter Protection and VPNs, Intrusion Detection, Incident Handling and Hacker Techniques, Windows Security, LAMP Secure Online Presence and Wireless Network Auditing.
News: NIST 800-53 Final has been completed in August.
Keep up with the latest security information
- Internet Storm Center
- The SANS organization hosts the Internet Storm Center. This site is a good place to start off your morning, helping you to be aware of the latest issues discovered relating to computer security.
- CERT
- CERT tracks current security alerts and know vulnerabilities.
- Security Focus
- Another site which posts articles on computer security as well as new vulnerabilities.
- French Security Incident Response Team
- Sometimes International sources know about problems before they show up in the United States.
My Other Featured Lenses
These are my other computer security lenses.-
Social Engineering
-
This lens is about how social engineering attacks are attempted against companies in order to gain access to computer system, data or other company assets. Social attacks are attacks which use employees as a way to gain unauthorized access and inform...
-
Computer Security Jump Bag
-
A Jump Bag is the term used to describe the bag or container holding all of the tools you need to appropriately respond to a computer security incident. The hard part is ensuring that the jump bag is ready to deploy at a moment's notice and that it w...
-
Physical Security
-
Securing the physical environment is a challenge but standards are being created to help with this effort. ISACA's COBIT framework covers the areas of site selection, physical security, controlling physical access, protecting against environmental fa...
-
Learn to Wardrive
-
Auditing wireless networks is a good way to start exploring wireless networks, their popularity and the risks associated with them. This lens provides information on wardriving and wireless network security. I learned a lot by obtaining my SANS GAWN-...
Got a Security Policy?
A policy will guide decisions about how to implement security.
- SANS Security Policy Project
- The ultimate goal of this SANS project is to offer everything you need for rapid development and implementation of information security policies. You'll find a great set of resources posted here already including policy templates for twenty-four important security requirements.
- Site Security Handbook
- RFC 2196 documents a Site Security Handbook that is a guide to developing computer security policies and procedures for sites that have systems on the Internet.
- ISO17799
- ISO 17799, is a detailed security standard. It is organised into ten major sections, each covering a different topic or area; Business Continuity Planning, System Access Control, System Development and maintenance, physical and environmental security, compliance, personal security, security organisations, computer and operations management, asset classification and control and security policy.
- NIST
- The National Institute for Standards and Technology has publicly available security documents. Review NIST 800-53 Recommended Security Controls for Federal Information Systems which is a very detailed document explaining security controls covering 17 categories.
Secure your hosts
- Center for Internet Security
- The Center for Internet Security maintains a site with benchmarking and scoring tools for many different operating systems. They have great documentation on how to secure your hosts, with detailed instructions and explinations of why each step should be taken.
*** If you have never seen the documents produced by the Center for Internet Security, do yourself a favor and review one. They are the best I have seen on securing operating systems. *** - Secure Your Laptop!
- Lundquist's Guide To Not Getting Fired for Losing Your Laptop. Eric Lundquist makes many very important points about what data you should keep on your laptop and additional steps you can take to keep the data safe and confidential in this article.
- Home PC Security Tips
- For those of you who are looking for information on securing your home PC, or would like to know who to call for help with your home system, checkout Kim Kamando's site and Radio show.
Spyware, Viruses
- Symantec Virus Software and more
- If you are running email applications on your host, be sure to have anti-virus software installed.
- AVG is a free Anti Virus Product
- AVG's newest security product provides real-time protection against online threats for free-forever. There are millions of poisoned web pages out there. Let AVG LinkScanner check them out first. If a link is dangerous, you'll be protected
- Spybot Search and Destroy
- Open source tool to deal with spyware.
Perimeter Secuity
Firewalls, Screened Subnets
- Defense in Depth
- The term defense in depth comes from the military.
- How Firewalls work
- Firewalls come in many different configurations which provide different levels of support. They are often called packet filtering, stateful or proxy firewalls. Many different free firewalls exist, for example, ipf, ipchains, m0n0wall, and sonic wall to name just a few.
Monitor your hosts and network
- Nagios Host Monitoring
- Nagios is gaining popularity as a good open source monitoring solution.
- Cacti
- A network graphing solution using PHP and MySQL.
- Tripwire - Now Open Source
- Open Source Tripwire® software is a security and data integrity tool useful for monitoring and alerting on specific file change(s) on a range of systems. The project is based on code originally contributed by Tripwire, Inc. in 2000.
- Osiris
- Osiris is a Host Integrity Monitoring System that periodically monitors one or more hosts for change. It maintains detailed logs of changes to the file system, user and group lists, resident kernel modules, and more. Osiris can be configured to email these logs to the administrator. Hosts are periodically scanned and, if desired, the records can be maintained for forensic purposes. Osiris keeps an administrator apprised of possible attacks and/or nasty little trojans. The purpose here is to isolate changes that indicate a break-in or a compromised system. Osiris makes use of OpenSSL for encryption and authentication in all components.
- SamHain
- Samhain is a multiplatform, open source solution for centralized file integrity checking / host-based intrusion detection on POSIX systems (Unix, Linux, Cygwin/Windows). It has been designed to monitor multiple hosts with potentially different operating systems from a central location, although it can also be used as standalone application on a single host.
- Sisyphus
- Sisyphus is a log analysis application for high performance computing systems.
Security Check Lists
- Linux Security Checklist
- Have you checked your servers?
- Soalris Security Checklist
- Verify your Solaris hosts.
Intrusion Detection Systems
Are you paranoid?
- SNORT
- SNORT is one of the most popular IDS tools.
- ACID
- If you are going to snort, you may as well use ACID. ACID is a php web console you can use to search and process Snort results.
- BASE
- BASE is another web based application useful when analyzing SNORT results.
- OSSEC Host Based Intrusion Detection
- Free Open Source Product.
Auditing your network (Ethical Hacking)
Have you looked yet?
- OWASP
- The Open Web Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of application software. OWASP's Webgoat product will help teach you about how hackers attack web services. Their Webscarab tool is also quite useful. Check out their valuable content, find a local chapter and help build this community.
- Nessus
- Nessus is a free, very popular network auditing tool. A new version exists for MAC OS X.
- NMAP from Insecure.org
- The insecure.org site provides the nmap tool as well as the new list of the top 100 security tools.
- Ethical Hacking
- Ethicalhacker.net provides information and resources for auditing networks.
- The Metasploit Project
- Metasploit is a powerful tool which can help test expoits on a network.
- SQL Injection Cheat Sheet
- Do your applications filter user input to remove bad input characters? Have you tried to use sql injection against your applications to see what information you can extract. An SQL cheat sheet is handy to remember the techniques to use when testing injection attacks.
- XSS Cheat Sheet
- RSnake has put together a Cross Site Scripting Cheat Sheet.
Incident Response / Handling
Are you prepared?
- Intruder Detection Checklist
- Hopefully you already have your own checklist, if not, look at available checklists and see what information your checklist should cover.
- National Institute of Standards and technology
- A 148 page PDF file covering the topic of incident handling.
- SANS Intrusion Discovery Cheat Sheet
- SANS provides a Intrusion Discovery cheat sheet for UNIX administrators which can help you remember many of the items you should look for if you suspect an intrusion.
- Nmap Nessus PDF cheat Sheet
- A PDF nmap and Nessus cheatsheet
- Tools and Hardware for Incident Response
- The Incident Response Book published by O'Reilly contains a lot of information. The Chapter Seven sample provides a list of tools and hardware that you will want to be familiar with or have in your response bag.
- Have a Jump Bag
- Be sure you are prepared to respond appropriately to computer incidents by having a jump bag.
Wireless Security
How far does your signal go?
- Wireless security information.
- I cover many wireless security issues on my wardriving squidoo lens.
TCP/IP
What you must know.
- TCP/IP wikipedia
- The wikipedia is a nice place to start your research of the TCP/IP Protocol.
- SANS TCP/IP Cheat Sheet.
- I keep a copy of this document with me as well as stuck to my cubicle.
- OmniPeek
- WildPackets has recently released OmniPeek in response to the release of WireShark. There are many nice features built into this tool and I am starting to prefer to use it, rather than ethereal or wireshark.
- WireShark (Ethereal)
- A network protocol analyzer which is very useful for analyzing problems or incidents on the network, formerly known as Ethereal. Keep this free product up to date.
- tcpdump
- Many UNIX systems support tcpdump as the tool to use to watch network traffic on a host or network. If tcpdump is not available check for snoop.
- Windump
- Windump is my tool of choice on a windows platform.
Help the good guys!
- Dshield
- Contribute your firewall reports to DShield and help the internet community know what activities are taking place on the internet. The internet storm center has graphs of the activities reported to DShield.
- 10 Most Wanted
- Dshield's report of the top 10 offenders.
Learn from the Bad Guys!
Set out some bait.
- Set up a Honeypot
- A honey pot is a system placed on the network with the intention of letting crackers interact with the system. Logs are kept of the actions taking place on the host with the intention of learning what exploits are being used in the wild.
Wireless honeypots can also be setup to catch wireless crackers. - Tarpits are stickier
- The idea of the tarpit is to set up a host which will answer all request made to it on any port, but never complete the conversation. When the host that is trying to establish the connection checks back with the tarpit, the tarpit responds back saying it will eventually finish the connection. Little does the external host know, but the tarpit will never allow the session to be set up. The idea is to tie up hosts acting badly on the network. These are fun to watch but many people do not consider them an extra layer of security.
Reader Feedback
What do you think of the lens?
-
Reply
- BookNow BookNow Dec 10, 2008 @ 7:10 am
- Great lens! Please visit my lens and tell me what you think about it!
registry cleaner reviews
-
Reply
- IT_risks IT_risks Oct 23, 2008 @ 10:03 pm
- This is a great lens. You've really put together a nice collection of resources and information. I'd love it if you would stop by my lens when you get a chance. Be sure to leave a comment and say hello!
-
Reply
- plastik plastik Aug 13, 2008 @ 3:53 pm
- Great lens, informative and useful. I hadn't heard about the center for internet security, very interesting, I'll def. tell my network admin about that.
Though not as technical as your lens, this is a blog that helps regular people to remove adware and spyware from their machines and improve computer security.
-
Reply
- rose08 rose08 Jul 28, 2008 @ 1:41 am
- Computer Network Security issue is getting along with the convenient and popular internet, the virus infection or trojan can be not only annoying but destructive to you files and privacy.It's extreme headache and nightmare when you need deliver you work or check some information via computer. Thanks for your efforts which have produced such a wonderful lens. As the saying goes, an ounce of prevention is worth a pound of cure. I would like to share with you an interesting and informative site about biometrics, including biometric safes, biometric signature and biometric access control. Please step into the site to find more information.
- Reply
- Load More
General Network Security Tip Book
Network Security Hacks
Take tips from the experts. Investigate O'Reilly's Hacks Book Series.
Network and System Monitoring Book
Know how to monitor your network and systems.
Perimeter Security and Firewall Books
Wireless Security Books
Intrusion Detection Books
Network Auditing Books
Conclusion
by Edmands
security. He likes to learn new skills, often by building or fixing
things himself. Tod... (more)
by 10 people |



