Luận án tiến sĩ: Chiến lược bảo vệ mạng khỏi backdoor intrusions - Rivera-Lopez

Luận văn TS Rivera Lopez (2018), Colorado Technical University: Phân tích sâu về [chủ đề luận văn] với phương pháp tiên tiến.

Trường ĐH

Colorado Technical University

Chuyên ngành
Computer Science
Tác giả

Luan An

Thể loại

Dissertation

Năm xuất bản

Số trang

199

Thời gian đọc

30 phút

Lượt xem

0

Lượt tải

0

Phí lưu trữ

50 Point

Tóm tắt nội dung

I. Chiến lược phòng thủ mạng từ backdoor

Nghiên cứu này phân tích các chiến lược bảo vệ mạng khỏi xâm nhập backdoor dựa trên kinh nghiệm từ 12 chuyên gia an ninh mạng. Bốn chủ đề chính được xác định: yếu tố con người, kỹ thuật phát hiện backdoor, chiến lược phòng thủ đa lớp và giám sát mạng. Mỗi chiến lược được đánh giá dựa trên thực tiễn và thách thức hiện tại.

1.1. Yếu tố con người trong bảo vệ mạng

Yếu tố con người đóng vai trò quan trọng trong phòng chống backdoor. Quản lý cấp cao cần cam kết đầu tư tài chính và nhân lực. Chính sách quản trị hiệu quả giúp giảm thiểu rủi ro từ lỗi con người. Đào tạo an ninh mạng định kỳ là cần thiết để nâng cao nhận thức.

1.2. Kỹ thuật phát hiện backdoor

Các phương pháp phát hiện backdoor hiện nay còn phức tạp và không hoàn hảo. Sử dụng phân tích hành vi mạng và giám sát lưu lượng giúp phát hiện sớm lỗ hổng. Công cụ tự động hóa cần được cải thiện để tăng độ chính xác và giảm sai số.

II. Chiến lược phòng thủ đa lớp cho mạng

Phòng thủ đa lớp kết hợp nhiều lớp bảo vệ để ngăn chặn backdoor. Các công cụ như tường lửa, hệ thống phát hiện xâm nhập (IDS) và mã hóa dữ liệu tạo thành hàng rào an ninh. Sự kết hợp này giúp giảm thiểu rủi ro khi một lớp bảo vệ bị vượt qua.

2.1. Tường lửa và công cụ giám sát mạng

Tường lửa cấu hình đúng cách lọc lưu lượng mạng. Giám sát lưu lượng thời gian thực giúp phát hiện hoạt động bất thường. Công nghệ ảo hóa mạng hỗ trợ phân tách môi trường để hạn chế lây lan.

2.2. Cập nhật và bảo trì hệ thống

Cập nhật phần mềm định kỳ là bước thiết yếu để vá lỗ hổng. Quản lý bản vá (patch management) cần có quy trình rõ ràng. Kiểm tra định kỳ hệ thống và thiết bị mạng đảm bảo tính toàn vẹn của kiến trúc an ninh.

III. Giám sát và phản ứng xâm nhập mạng

Giám sát mạng liên tục là chìa khóa phát hiện backdoor. Các hệ thống giám sát cần tích hợp phân tích dữ liệu lớn để nhận diện mẫu xâm nhập. Phản ứng nhanh chóng sau khi phát hiện lỗ hổng giúp giảm thiểu thiệt hại.

3.1. Phân tích lưu lượng mạng thời gian thực

Phân tích lưu lượng mạng giúp phát hiện truy cập trái phép. Sử dụng công cụ SIEM (Security Information and Event Management) tập trung dữ liệu từ nhiều nguồn. Cảnh báo tức thì khi phát hiện hành vi đáng ngờ.

3.2. Phản ứng và phục hồi sau xâm nhập

Kế hoạch ứng phó xâm nhập cần được xây dựng trước. Phân tích nguyên nhân sự cố để ngăn chặn tái diễn. Khôi phục hệ thống từ bản sao lưu an toàn là bước quan trọng trong quản lý rủi ro.

IV. Vai trò của đạo đức và hợp tác trong an ninh mạng

Đạo đức nghề nghiệp và hợp tác quốc tế là yếu tố then chốt. Dịch vụ kiểm tra an ninh đạo đức (ethical hacking) giúp đánh giá hiệu quả phòng thủ. Chia sẻ thông tin giữa các tổ chức tạo nên hệ sinh thái an ninh mạng bền vững.

4.1. Dịch vụ kiểm tra an ninh đạo đức

Ethical hacking phát hiện lỗ hổng mà hacker có thể lợi dụng. Các chuyên gia kiểm thử phải tuân thủ quy tắc đạo đức. Kết quả kiểm tra cần được báo cáo chi tiết để cải thiện hệ thống.

4.2. Hợp tác quốc tế và chia sẻ thông tin

Chia sẻ thông tin mối đe dọa giữa các quốc gia giúp ngăn chặn tấn công quy mô lớn. Các tổ chức cần tham gia mạng lưới an ninh chung. Chuẩn hóa giao thức chia sẻ thông tin là điều kiện tiên quyết.

Xem trước tài liệu
Tải đầy đủ để xem toàn bộ nội dung
Rivera lopez l o 2018 doctoral dissertation colorado technical university

Tải xuống file đầy đủ để xem toàn bộ nội dung

Tải đầy đủ (199 trang)

Trích đoạn nội dung luận án

Tải xuống để đọc toàn bộ

EXPLORING THE STRATEGIES NETWORK SECURITY MANAGERS NEED TO PROTECT THEIR NETWORKS FROM BACKDOOR INTRUSIONS A Dissertation Presented in Partial Fulfillment of the Requirements for the Degree of Doctor of Computer Science By Luis Omar Rivera-Lopez Colorado Technical University November, 2018     ProQuest Number: 10982503     All rights reserved  INFORMATION TO ALL USERS The quality of this reproduction is dependent upon the quality of the copy submitted.  In the unlikely event that the author did not send a complete manuscript and there are missing pages, these will be noted. Also, if material had to be removed, a note will indicate the deletion.      ProQuest 10982503  Published by ProQuest LLC (2019 ).

Copyright of the Dissertation is held by the Author.   All rights reserved. This work is protected against unauthorized copying under Title 17, United States Code Microform Edition © ProQuest LLC. 789 East Eisenhower Parkway P.

Box 1346 Ann Arbor, MI 48106 - 1346 Committee Debra Burrington, Ph. Hughes, DCS, Committee Member Mary L., Committee Member November 2, 2018 Date Approved © Luis Omar Rivera-Lopez, 2018 i Abstract The problem addressed is the strategies network security managers need to protect their networks from backdoor intrusions. Twelve participants that had experience as network managers or systems administrators were interviewed using nine open-ended questions. The research methodology chosen for this study is a qualitative exploratory approach.

The findings on this research resulted in four major themes including human factor, backdoor detection techniques, defense-in-depth and network monitoring strategies. The three prominent topics found were involvement of management, effective administrative policies and ethical hacking services. The analysis based on the responses provided details related to strategies needed to protect networks from backdoor intrusions relying on the experience of twelve participants. The implications for practice in the cybersecurity and information assurance field suggests that current backdoor detection techniques are complex and challenges are still present in order to enhance strategies to deter backdoor intrusions.

Keywords: backdoor, network defense strategies, network countermeasures ii Dedication To my wife, Kari Ann Edwards. iii Acknowledgements After 14 arduous months, my dissertation is finally complete. This would not be the case however, where it not for a few very important people who kicked me into gear and kept pushing me to work. My deepest thanks go out to Dr.

Debra Burrington who never gave up on me, offering both guidance and motivation. Without your dedication, I would not be writing this. Rae Denise Madison, Dr. Munkeby, and Dr.

Marva Brewington, for giving me the advice and knowledge I needed to make my dream a reality. To my loving wife Kari, for all of your help and sacrifice; with your support I was able to focus all of my time on this project. iv Table of Contents Table of Contents. v List of Tables.

x List of Figures. xiv Chapter One. 1 Topic Overview/Background. 6 Significance of the Study.

10 Definition of Terms. 10 General Overview of the Research Design. 11 Summary of Chapter One. 12 Organization of Dissertation.

15 v Synthesis of the Literature. 17 Four Strategies to Defend and Secure IT networks from backdoor intrusions. 19 A Brief History of Information Technology (IT) Network Security. 19 Defense-in-Depth Strategy.

21 Defense Countermeasures as a Strategy. 24 Information Assurance Core Principles. 25 Defense Tools & Practices Strategy. 27 Strategic Use of Many Security Technologies and Network Management Tools.

28 Firewall Practice on Networks. 32 Network Operations Best Practices. 33 Defense Funding (Cost) & Staffing Strategy. 34 Defense Funding Allocated for the Information Technology Department.

34 Possible Lower Cost Solutions for Information Technology (IT) Departments. 35 Cost of Staffing and Devices. 36 Defense Culture & Awareness Strategy. 36 Importance of Ethics.

36 Shared Culture Values. 37 vi Information Technology (IT) Best Practices. 38 Sharing Intrusion Response System Techniques. 38 Information Security Awareness.

40 Information Assurance and Enterprise Information Systems Awareness. 43 Summary of Literature Review. 49 Population and Sample. 56 Summary of Chapter Three.

58 vii Chapter Four. 59 Presentation of the Data. 120 Presentation and Discussion of Findings. 128 Summary of Chapter Four.

134 Findings and Conclusions. 135 Major Theme 1: Human Factor. 143 Major Theme 2: Defense-in-Depth Strategies. 143 Major Theme 3: Backdoor Detection Techniques.

144 Major Theme 4: Network Monitoring Strategies. 145 viii Prominent Topic 1: Involvement of Management. 146 Prominent Topic 2: Effective Administrative Policies. 146 Prominent Topic 3: Ethical Hacking Services.

147 Limitations of the Study. 147 Implications for Practice. 150 Implications of Study and Recommendations for Future Research. 153 Defense-in-Depth Strategies.

153 Backdoor Detection Techniques. 154 Network Monitoring Strategies. 182 ix List of Tables Table 1 Participant Demographics………….60 Table 2 Additional Statistics from Participants.61 Table 3 Themes for Interview Question 1……………………………………………………….64 Table 4 Interview Question 1, Theme 1 Responses: Protect Data.65 Table 5 Interview Question 1, Theme 2 Responses: Risk Analysis ……………………….……66 Table 6 Interview Question 1, Theme 3 Responses: Recommend Findings……………….67 Table 7 Interview Question 1, Theme 4 Responses: Monitoring Team …………………….…68 Table 8 Interview Question 1, Theme 5 Responses: Internal Message Alerts ……………….69 Table 9 Interview Question 1, Theme 6 Responses: Log Notifications ………………….70 Table 10 Interview Question 1, Theme 7 Responses: Third Party Services ………….71 Table 11 Themes for Interview Question 2…………………………………………………….72 Table 12 Interview Question 2, Theme 1 Responses: Backdoor Analysis…………………….72 Table 13 Interview Question 2, Theme 2 Responses: Brute Force………………………….73 Table 14 Interview Question 2, Theme 3 Responses: Backdoors Detection .74 Table 15 Interview Question 2, Theme 4 Responses: Phishing Emails ……………………….75 Table 16 Interview Question 2, Theme 5 Responses: Compartmentalized Email Gateways .…76 Table 17 Interview Question 2, Theme 6 Responses: Zero Day ……………………….77 Table 18 Interview Question 2, Theme 7 Responses: Identifying Backdoors……………….78 Table 19 Themes for Interview Question 3………………………………………………….79 Table 20 Interview Question 3, Theme 1 Responses: Executive ………………………….…79 Table 21 Interview Question 3, Theme 2 Responses: Organizational ………………….80 x Table 22 Interview Question 3, Theme 3 Responses: Information Technology…….…81 Table 23 Interview Question 3, Theme 4 Responses: Client ……………………….…82 Table 24 Interview Question 3, Theme 5 Responses: Financial ……………………….83 Table 25 Interview Question 3, Theme 6 Responses: Staffing ……………………….84 Table 26 Interview Question 3, Theme 7 Responses: Leadership…………………….…………85 Table 27 Themes for Interview Question 4…………………………………………………….86 Table 28 Interview Question 4, Theme 1 Responses: Notify Upper Management …….86 Table 29 Interview Question 4, Theme 2 Responses: Systems Update ……………….87 Table 30 Interview Question 4, Theme 3 Responses: Collecting Evidence……….88 Table 31 Interview Question 4, Theme 4 Responses: Isolate Devices …………………….89 Table 32 Interview Question 4, Theme 5 Responses: Backdoor Issue ………………………….90 Table 33 Interview Question 4, Theme 6 Responses: Firmware……….…………………………90 Table 34 Themes for Interview Question 5…………………………………………………….91 Table 35 Interview Question 5, Theme 1 Responses: Educate and Share ……………….…92 Table 36 Interview Question 5, Theme 2 Responses: Investigate Network Sections…………….93 Table 37 Interview Question 5, Theme 3 Responses: Disabling Traffic ………………….94 Table 38 Interview Question 5, Theme 4 Responses: Counter Intrusion Service ………….95 Table 39 Interview Question 5, Theme 5 Responses: Isolate software ………………….96 Table 40 Interview Question 5, Theme 6 Responses: Identify Anomalies …………….……97 Table 41 Interview Question 5, Theme 7 Responses: Stopping Traffic…………………….98 Table 42 Themes for Interview Question 6………………………………………….99 Table 43 Interview Question 6, Theme 1 Responses: Certifications …………………….100 Table 44 Interview Question 6, Theme 2 Responses: Awareness ………………………….101 xi Table 45 Interview Question 6, Theme 3 Responses: Expertise…………………………….…102 Table 46 Interview Question 6, Theme 4 Responses: Culture …………………….103 Table 47 Interview Question 6, Theme 5 Responses: Teamwork ……………………….104 Table 48 Interview Question 6, Theme 6 Responses: Weakest Link …………………….105 Table 49: Interview Question 6, Theme 7 Responses: Network Protocol Analysis …….106 Table 50 Themes for Interview Question 7……………………………………………….107 Table 51 Interview Question 7, Theme 1 Responses: Dynamic Awareness ……………….107 Table 52 Interview Question 7, Theme 2 Responses: Understanding Defense……….108 Table 53 Interview Question 7, Theme 3 Responses: Network Security…………….…109 Table 54 Interview Question 7, Theme 4 Responses: Understanding Threats ……….110 Table 55 Interview Question 7, Theme 5 Responses: Human Factor…………………….111 Table 56 Interview Question 7, Theme 6 Responses: Enforcing Defense……….112 Table 57 Interview Question 7, Theme 7 Responses: Defense Tasks ………………….113 Table 58 Themes for Interview Question 8………………………………………………….114 Table 59 Interview Question 8, Theme 1 Responses: Weak Network Sections…………….114 Table 60 Interview Question 8, Theme 2 Responses: Network Layers…………………….115 Table 61 Interview Question 8, Theme 3 Responses: Access Points……………………….117 Table 62 Interview Question 8, Theme 4 Responses: Defense-in-depth………………….118 Table 63 Interview Question 8, Theme 5 Responses: Network Segmentation…….119 Table 64 Interview Question 8, Theme 6 Responses: Internal Network Defense………….119 Table 65 Interview Question 8, Theme 7 Responses: Strategic Value……………….…120 Table 66 Themes for Interview Question 9………………………………………………….121 Table 67 Interview Question 9, Theme 1 Responses: Internet Security…………………….121 xii Table 68 Interview Question 9, Theme 2 Responses: Risk Assessment Team……………….…123 Table 69 Interview Question 9, Theme 3 Responses: Leaders…………………….………124 Table 70 Interview Question 9, Theme 4 Responses: Ethical Hacking………………….…125 Table 71 Interview Question 9, Theme 5 Responses: Administrative Policies………….126 Table 72 Interview Question 9, Theme 6 Response: Cloud Security………………….……126 Table 73 Interview Question 9, Theme 7 Responses: Wireless Security……….127 Table 74 Themes and Topics Emerging from the 12 Interviews…………………….128 Table 75 Major Themes and Prominent Topics of Research Data.132 xiii List of Figures Figure 1 Low Cost-Effective Information Assurance Program …….…35 Figure 2 Conceptual Framework ………………………………………………………….……45 xiv CHAPTER ONE Defense-in-depth is an essential principle in the field of information assurance. It is used as a strategy based on adding layers of security to information systems because no single product can detect multiple cyberattacks that happen simultaneously (Boggs, Du, & Stolfo, 2014).

This important principle has been widely adopted by the United States Department of Defense and its information assurance policies. Best practices and product reviews support organizations in designing their defense-in-depth strategy (Boggs et al. One of the issues with the defense-in-depth strategy is when a business transfers large amounts of data, this can result in a weakness against the fiber route passing the data (Goztepe, Kilic, & Kayaalp, 2014), thus making the system vulnerable to backdoor intrusions. Choi and Cho (2013) stated that many policies are needed to detect backdoors.

These backdoors are easy to install on network devices and are subject to exploits contributing to the weakening of the defense-in-depth strategy. According to Almorsy, Grundy, and Ibrahim (2013), defense-in-depth is a process that takes a long time to identify threats and is based on adding layers of security to computer network systems. Information assurance professionals implement security controls as part of a strategy to ensure the network infrastructure of the organization is protected by adding security layers to the system. It is unknown if network administrators have the tools to detect stealth intrusions entering the network systems via unknown network devices.

Poonia (2014) stated the development of information technology has made it possible for cybercrimes to happen. Also, he declared that information could be obtained from logs, including added backdoors. The networks and infrastructures framework area relies on the principle of defense-in- depth, in which many security layers are added in order to protect information and computer systems. For example, malware can be installed in networks, resulting in systems creating bots 1 that can open backdoor intrusions to computers (Crossler & Bélanger, 2014).

Weak points in networks can enable backdoor intrusions and compromise the operation of information systems which can then be exploited by attackers (Fielder & Hankin, 2016). Mansfield-Devine (2016) argued that defense-in-depth causes challenges by not knowing exactly what is going on in the networks, resulting in misunderstandings on security devices. Governments, corporations and the public depend on computer information systems whether the network is used at the workplace, at home or on mobile devices. Investigating strategies needed to protect networks from backdoor intrusions can benefit network managers and systems administrators.

Nội dung được bảo vệ bản quyền — Tải xuống đầy đủ

Câu hỏi thường gặp

Luận án "Chiến lược bảo vệ mạng khỏi backdoor: Nghiên cứu tiến sĩ" nghiên cứu về vấn đề gì?

Luận văn TS Rivera Lopez (2018), Colorado Technical University: Phân tích sâu về [chủ đề luận văn] với phương pháp tiên tiến.

Luận án "Chiến lược bảo vệ mạng khỏi backdoor: Nghiên cứu tiến sĩ" được bảo vệ tại trường nào?

Luận án này được bảo vệ tại Colorado Technical University. Năm bảo vệ: 2018.

Luận án "Chiến lược bảo vệ mạng khỏi backdoor: Nghiên cứu tiến sĩ" thuộc chuyên ngành gì?

Luận án "Chiến lược bảo vệ mạng khỏi backdoor: Nghiên cứu tiến sĩ" thuộc chuyên ngành Computer Science. Danh mục: Khoa Học Máy Tính.

Luận án "Chiến lược bảo vệ mạng khỏi backdoor: Nghiên cứu tiến sĩ" có bao nhiêu trang?

Luận án "Chiến lược bảo vệ mạng khỏi backdoor: Nghiên cứu tiến sĩ" có 199 trang. Bạn có thể xem trước một phần tài liệu ngay trên trang web trước khi tải về.

Cách tải luận án "Chiến lược bảo vệ mạng khỏi backdoor: Nghiên cứu tiến sĩ" về máy như thế nào?

Để tải luận án về máy, bạn nhấn nút "Tải xuống ngay" trên trang này, sau đó hoàn tất thanh toán phí lưu trữ. File sẽ được tải xuống ngay sau khi thanh toán thành công. Hỗ trợ qua Zalo: 0559 297 239.

Luận án liên quan

Chia sẻ tài liệu: Facebook Twitter