版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
1、Learning ObjectivesDocument the rapid rise in computer and network security attacks.Describe the common security practices of businesses of all sizes.Understand the basic elements of EC security.Explain the basic types of network security attacks.Learning Objectives (cont.)Describe common mistakes t
2、hat organizations make in managing security.Discuss some of the major technologies for securing EC communications.Detail some of the major technologies for securing EC networks components.百分之百的安全?从来不可能实现绝对安全,但是可行的安全策略能够使损害最小化!安全即寻求平衡 安全威胁来自各个方面安全威胁 人为因素自然灾害恶意攻击非恶意攻击缺乏安全意识的疏忽外部攻击者例如:黑客, 罪犯, 竞争对手 内部攻击
3、者例如:对公司不满的员工洪灾,大火 地震,龙卷风 Security IssuesFrom the users perspective:Is the Web server owned and operated by a legitimate company?Does the Web page and form contain some malicious or dangerous code or content?Will the Web server distribute unauthorized information the user provides to some other party
4、?Security Issues (cont.)From the companys perspective:Will the user not attempt to break into the Web server or alter the pages and content at the site?Will the user will try to disrupt the server so that it isnt available to others?Security Issues (cont.)From both parties perspectives:Is the networ
5、k connection free from eavesdropping by a third party “listening” on the line?Has the information sent back and forth between the server and the users browser been altered?Types of Threats and Attacks (cont.)Social engineeringA type of nontechnical attack that uses social pressures to trick computer
6、 users into compromising computer networks to which those individuals have access社会工程学定义利用社会科学(此指其中的社会常识)尤其心理学,语言学,欺诈学将其进行综合,有效的利用(如人性的弱点),并最终获得信息为最终目的学科称为“社会工程学”社会工程学定义社会工程学陷阱就是通常以交谈、欺骗、假冒或口语等方式,从合法用户中套取用户系统的秘密。社会工程学是一种与普通的欺骗和诈骗不同层次的手法。因为社会工程学需要搜集大量的信息针对对方的实际情况,进行心理战术的一种手法。系统以及程序所带来的安全往往是可以避免的。而在人性
7、以及心理的方面来说。社会工程学往往是一种利用人性脆弱点、贪婪等等的心理表现进行攻击,是防不胜防的。利用垃圾邮件进行网络钓鱼垃圾邮件发送者拥有包括几百万使用中电子邮件地址的数据库,因此最新的垃圾邮件群发技术可以用来帮助一个钓鱼者低风险广泛地发布他们的诱骗邮件。垃圾邮件通常通过一些被攻陷的架设在境外主机上的邮件服务器,或是通过一个全球的傀儡主机网络 ( botnets ) 进行发送,因此邮件发送者被追踪的可能性很小。 “尊敬的客户,你的银联卡在某商城消费1280元,已确认成功,如有疑问,请拨银行联合管理局电话*找某先生”如果收到这样的短信你会怎么办?(短信钓鱼) 利用病毒、木马网络钓鱼 最早引起广
8、泛关注的“网络钓鱼”事件,正是借助了一款名为“Mimail.J”的病毒,该病毒伪装成由Paypal网站寄出的信息,表示收件者的账户将在5个工作日后失效,要求用户更新个人信息,才能重新启动账户。再比如,一恶意网站()伪装成联想主页(),前者将数字1取代英文字母L,利用多种IE漏洞植入木马病毒,并散布“联想集团和腾讯公司联合赠送QQ币”的虚假消息,诱使更多用户访问该网站时造成感染。 通过建立欺骗性的网站 欺骗者建立起域名和网页内容都与真正网上银行系统、网上证券交易平台极为相似的网站,引诱用户输入账号密码等信息,并且利用后台数据库把这些信息存储起来。于是欺骗者可以通过真正的网上银行、网上证券系统盗窃
9、资金。欺骗者可能会把假冒网站的链接发布到与目标机构相关的一些聊天室或论坛上,或者通过电子邮件群发的方式发送给用户。鸡尾酒钓鱼术 这是一种比较巧妙的欺骗方法,通过发送一个包含链接的垃圾邮件,用户点击邮件中的链接,就会被带到一个正常网站,同时恶意脚本会在用户电脑上弹出一个小窗口,这样看起来小窗口就像是网站的一部分,用户往往就会在这个小窗口中填入登录账号和密码等。 这种新的钓鱼方式利用了跨站点脚本技术,采用了真网站和假窗口相混合的方式,达到了以假乱真的效果。网络钓鱼与病毒、木马等黑客技术相融合 令普通用户头疼的是,“网络钓鱼”为了达到广泛诈骗的目的,通常都伴随着病毒和木马,或者说病毒邮件、木马也经常
10、包含“网络钓鱼”的内容。 这种方式已经不是传统意义上的网络钓鱼了,通常都是在病毒加载后使用各种手段诱使用户访问具有欺骗性的站点,来达到钓鱼的目的。比较流行的方式有: BHO(浏览器助手工具)。 通过恶意软件在受害者的计算机上安装一个恶意的浏览器助手工具( Browser Helper Object ),然后由其将受害者重定向到假冒的钓鱼网站。BHO是一些设计用于定制和控制 IE 浏览器的 DLL,如果成功,受害者将会被欺骗,相信他们正在访问合法的网站内容,然而实际上却在访问一个假冒的钓鱼网站。修改hosts 文件 用恶意软件去修改受害者计算机上用来维护本地 DNS 域名和 IP 地址映射的 h
11、osts 文件,这将使用户的网页浏览器在连接假冒网站时,让其看起来像是在访问合法网站。蠕虫成为网络钓鱼的诱饵 最新的Mytobs恶意邮件信息通常将自己伪装成IT部门或网络服务商,其中可能包括接收者的域名或邮件地址。恶意邮件告诉接收者他们的账户出现了问题,需要点击某个链接进行再一次确认。 Types of Threats and Attacks (cont.)Multiprong approach used to combat social engineering: Education and trainingPolicies and proceduresPenetration testingT
12、ypes of Threats and Attacks (cont.)Technical attackAn attack perpetrated using software and systems knowledge or expertise Types of Threats and Attacks (cont.)Denial-of-service (DoS) attackAn attack on a Web site in which an attacker uses specialized software to send a flood of data packets to the t
13、arget computer with the aim of overloading its resourcesTypes of Threats and Attacks (cont.)Distributed denial-of-service (DDoS) attackA denial-of-service attack in which the attacker gains illegal administrative access to as many computers on the Internet as possible and uses these multiple compute
14、rs to send a flood of data packets to the target computerTypes of Threats and Attacks (cont.)Types of Threats and Attacks (cont.)Malware: A generic term for malicious softwareThe severity of the viruses increased substantially, requiring much more time and money to recover85% of survey respondents s
15、aid that their organizations had been the victims of e-mail viruses in 2002Types of Threats and Attacks (cont.)VirusA piece of software code that inserts itself into a host, including the operating systems, to propagate; it requires that its host program be run to activate itTypes of Threats and Att
16、acks (cont.)WormA software program that runs independently, consuming the resources of its host in order to maintain itself and is capable of propagating a complete working version of itself onto another machineTypes of Threats and Attacks (cont.)Macro virus or macro wormA virus or worm that is exec
17、uted when the application object that contains the macro is opened or a particular procedure is executedTypes of Threats and Attacks (cont.)Trojan horseA program that appears to have a useful function but that contains a hidden function that presents a security riskTypes of Threats and Attacks (cont
18、.)Buffer Overflowbuffer overrun,smash the stack,trash the stack, scribble the stack, mangle the stack,spam,alias bug,fandango on core, memory leak,precedence lossage,overrun screw.Types of Threats and Attacks (cont.)间谍软件(Spyware)间谍软件顾名思义就是干间谍干的事情,它们收集并发送用户的个人资料和电脑操作记录等信息。如果运气好,这些信息可能只包括很普通的浏览模式信息,但如
19、果碰上和它的发明者一样用心险恶的间谍软件,用户的银行帐号和密码很可能就成为可怜的羔羊。无论从工作方式还是传播方式上讲,间谍软件都与木马程序很类似。根据调查公司Forrester Research今年2月发布的2005年反间谍软件方案(Antispyware adoption in 2005)报告指出,间谍软件已成为企业组织最关切的安全问题之一。Types of Threats and Attacks (cont.)Key LoggerKeylogger是一个直接和硬件设备有关系的恶意软件,它所直接关系到的硬件设备是键盘。Keylogger可以将电脑用户敲击过的那些键盘按顺序记录下来,事后在通过
20、网络发送给黑客。通常,Keylogger只有在它发现受害用户连接到了一个安全级别较高的网站时才会被“叫醒”,比如说银行网站。因为只有那个时候,它记录下来的信息才可能对那些图谋不轨的黑客有用,比如在银行网站上,Keylogger记录下来的很可能就包括了电脑使用者的银行帐号和密码等信息。这种软件的出现,让黑客们可以绕开银行等安全级别较高的网站对数据的高水平加密,在用户把个人信息通过网络传输出去,甚至是进入电脑存储设备之前就把它记录下来。Types of Threats and Attacks (cont.)Dialers恶意拨号器,这种自动拨号程序常常做一些损人不利己的事情。比如,Dialers可
21、能会在用户睡熟的时候,大半夜“爬起来”,通过用户的电话线打长途电话。 同时,他们可以在把电话拨通之后,把Keylogger记录下来的用户机密或其他信息发送给它的主人黑客。Security RequirementsAuthenticationThe process by which one entity verifies that another entity is who they claim to be AuthorizationThe process that ensures that a person has the right to access certain resourcesSe
22、curity Requirements (cont.)AuditingThe process of collecting information about attempts to access particular resources, use particular privileges, or perform other security actionsSecurity Requirements (cont.)ConfidentialityKeeping private or sensitive information from being disclosed to unauthorize
23、d individuals, entities, or processesSecurity Requirements (cont.)IntegrityAs applied to data, the ability to protect data from being altered or destroyed in an unauthorized or accidental mannerSecurity Issues (cont.)NonrepudiationThe ability to limit parties from refuting that a legitimate transact
24、ion took place, usually by means of a signatureManaging EC Security (cont.)Methods of securing ECAuthentication systemAccess control mechanismPassive tokensActive tokensAuthenticationAuthentication systemSystem that identifies the legitimate parties to a transaction, determines the actions they are
25、allowed to perform, and limits their actions to only those that are necessary to initiate and complete the transactionAuthentication (cont.)Access control mechanismMechanism that limits the actions that can be performed by an authenticated person or groupBiometric ControlsBiometric systemsAuthentica
26、tion systems that identify a person by measurement of a biological characteristic such as a fingerprint, iris (eye) pattern, facial features, or voiceBiometric Controls (cont.)Physiological biometricsMeasurements derived directly from different parts of the body (e.g., fingerprints, iris, hand, faci
27、al characteristics)Behavioral biometricsMeasurements derived from various actions and indirectly from various body parts (e.g., voice scans or keystroke monitoring)Biometric Controls (cont.)Fingerprint scanningMeasurement of the discontinuities of a persons fingerprint, converted to a set of numbers
28、 that are stored as a template and used to authenticate identityIris scanningMeasurement of the unique spots in the iris (colored part of the eye), converted to a set of numbers that are stored as a template and used to authenticate identityBiometric Controls (cont.)Voice scanningMeasurement of the
29、acoustical patterns in speech production, converted to a set of numbers that are stored as a template and used to authenticate identityBiometric Controls (cont.)Keystroke monitoringMeasurement of the pressure, speed, and rhythm with which a word is typed, converted to a set of numbers that are store
30、d as a template and used to authenticate identity; this biometric is still under developmentEncryption MethodsPublic key infrastructure (PKI)A scheme for securing e-payments using public key encryption and various technical componentsEncryption Methods (cont.)Private and public key encryptionEncrypt
31、ion: The process of scrambling (encrypting) a message in such a way that it is difficult, expensive, or time-consuming for an unauthorized person to unscramble (decrypt) itEncryption Methods (cont.)Private and public key encryptionPlaintext: An unencrypted message in human-readable formCiphertext: A
32、 plaintext message after it has been encrypted into a machine-readable formEncryption algorithm: The mathematical formula used to encrypt the plaintext into the ciphertext, and vice versaEncryption Methods (cont.)Symmetric (private) key systemKey: The secret code used to encrypt and decrypt a messag
33、eSymmetric (private) key system: An encryption system that uses the same key to encrypt and decrypt the message第二节 加密技术 1加密的相关概念 一般情况下,把信息的原始形式称为明文,明文经过变换加密后的形式称为密文。由明文变成密文的过程称为加密,由密文变成明文的过程称为解密。计算机解决问题的方法和步骤,就是计算机的算法。密钥是一个数值,它和加密算法一起生成特别的密文。 数据加密的基本过程就是对原来为明文的文件或数据按某种算法进行处理,使其成为不可读的一段代码,通常称为“密文”,使其
34、只能在输入相应的密钥之后才能显示出本来内容,通过这样的途径来达到保护数据不被非法人窃取、阅读的目的。该过程的逆过程为解密。 第二节 加密技术 2加密技术方法 (1)对称式加密技术 第二节 加密技术 (2)非对称式加密技术 第二节 加密技术 (3)混合加密技术 混合加密技术不是一种单一的加密技术,而是一个结合体,是上述两种数据加密技术相互结合的产物。通信双方的通信过程分为两个部分,双方先利用非对称加密技术传送本次通信所用的对称密钥,然后再用对称加密技术加密传送文件。 混合加密技术是用户在实际应用中总结出来的,它可以弥补对称加密技术和非对称加密技术的弱点,使二者优势互补,同时达到方便用户的目的。第
35、二节 加密技术 3加密技术在电子商务中的应用 (1)加密技术在商务信息保密中的应用 加密技术是人们防止信息失密而常采取的安全技术手段,在电子商务中实现数据加密既可以采用DES算法,也可以采用RSA算法。 (2)加密技术在身份认证中的应用 数字签名技术是确定交易信息内容的真实性的主要鉴别手段,其基础是数据加密中的公开密钥加密技术。 第三节 认证技术 一、 数字证书 二、 数字签名技术 三、 数字信封技术 四、 数字时间戳 五、 认证中心一、数字证书 1数字证书的定义 数字证书就是网络通讯中标志通讯各方身份信息的一系列数据,其作用类似于现实生话中的身份证。 数字证书是一个经证书授权中心数字签名的包
36、含公开密钥拥有者信息以及公开密钥的文件。最简单的证书包含一个公开密钥、用户名以及证书授权中心的数字签名。一般情况下证书中还包括密钥的有效时间,发证机关(证书授权中心)的名称,该证书的序列号等信息,证书的格式遵循X.509国际标准。 一、数字证书一、数字证书 2数字证书的原理 数字证书采用公钥体制,即利用一对互相匹配的密钥进行加密、解密。 每个用户自己设定一把特定的仅为本人所知的私有密钥(私钥),用它进行解密和签名;同时设定一把公共密钥(公钥)并由本人公开,为一组用户所共享,用于加密和验证签名。当发送一份保密文件时,发送方使用自己的私钥对数据加密,而接收方则使用发送方的公钥解密,这样就起到了身份
37、认证作用。 通过数字的手段保证加密过程是一个不可逆过程,即只有用私有密钥才能解密。公开密钥技术解决了密钥发布的管理问题,商户可以公开其公开密钥,而保留其私有密钥。一、数字证书 3数字证书的应用 数字证书可以应用于互联网上的电子商务活动和电子政务活动,其应用范围涉及需要身份认证及数据安全的各个行业,包括传统的商业、制造业、流通业的网上交易,以及公共事业、金融服务业、工商税务、海关、政府行政办公、教育科研单位、保险、医疗等网上作业系统。 二、数字签名技术 1数字签名的概念 所谓“数字签名”就是通过某种密码运算生成一系列符号及代码组成电子密码进行签名,来代替书写签名或印章,对于这种电子式的签名还可进
38、行技术验证。其验证的准确度是一般手工签名和图章验证无法比拟的。 “数字签名”是目前电子商务、电子政务中应用最普遍、技术最成熟的、可操作性最强的一种电子签名方法。它采用了规范化的程序和科学化的方法,用于鉴定签名人的身份以及对一项电子数据内容的认可。二、数字签名技术 2数字签名的原理及步骤 数字签名是由数字签字软件在计算机上自动完成的,数字签字软件在产生数字签名时是分为两个步骤来完成的: 第一步是数字签字软件根据特定的算法(哈希函数)将被签文件转换成一个比原来文件短得多的杂散码,这个杂散码对该文件是唯一的,当被签文件的任何地方被更改时,相应的杂散码也随之改变。 第二步是由发送者用个人所独有的私人密
39、钥将得到的杂散码进行加密,形成数字签名。发送方将原文和数字签名同时传给接收方。二、数字签名技术 3数字签名的功能 数字签名可以解决否认、伪造、篡改及冒充等问题。具体功能有:发送者事后不能否认发送的报文签名;接收者能够核实发送者发送的报文签名;接收者不能伪造发送者的报文签名;接收者不能对发送者的报文进行部分篡改;网络中的某一用户不能冒充另一用户作为发送者或接收者。 数字签名的应用范围十分广泛,在保障电子数据交换(EDI)的安全性上是一个突破性的进展,凡是需要对用户的身份进行判断的情况都可以使用数字签名。三、数字信封技术 数字信封是公钥密码体制在实际中的一个应用,是用加密技术来保证只有规定的特定收
40、信人才能阅读通信的内容。 在一些重要的电子商务交易中密钥必须经常更换,为了解决每次更换密钥的问题,结合对称加密技术和公开密钥技术的优点,它克服了秘密密钥加密中秘密密钥分发困难和公开密钥加密中加密时间长的问题,使用两个层次的加密来获得公开密钥技术的灵活性和秘密密钥技术高效性。 三、数字信封技术五、认证中心 1什么是CA认证 所谓CA(Certificate Authority)认证中心,对于任何一个国家来说,要实现B2B、B2C交易方式,建设CA(认证中心或称认证体系)和支付网关是必不可少的,其中CA尤其重要。其作用主要体现在事先验证或识别参与网上交易活动的各个主体的身份,并用相应的电子(数字)
41、证书代表他们在网上的身份,而这些电子证书就是由权威认证机构(即CA)来颁发的。 CA中心在整个电子商务环境中处于至关重要的位置。它是整个信任链的起点,CA中心是开展电子商务的基础。 如果CA中心不安全或发放的证书不具权威性,那么网上电子交易就根本无从谈起。 五、认证中心 2CA功能和组成部分 认证中心(CA)的功能有:证书发放、证书更新、证书撤销和证书验证。CA的核心功能就是发放和管理数字证书 。 认证中心为了实现其功能,主要由以下三部分组成: 注册服务器:通过Web Server建立的站点,可为客户提供每日24小时的服务。 证书申请受理和审核机构:它的主要功能是接受客户证书申请并进行审核。
42、认证中心服务器:是数字证书生成、发放的运行实体,同时提供发放证书的管理、证书废止列表(CRL)的生成和处理等服务。Security ProtocolsSecure Socket Layer (SSL)Protocol that utilizes standard certificates for authentication and data encryption to ensure privacy or confidentialityTransport Layer Security (TLS)As of 1996, another name for the SSL protocolSecur
43、ity Protocols (cont.)Secure Electronic Transaction (SET) A protocol designed to provide secure online credit card transactions for both consumers and merchants; developed jointly by Netscape, Visa, MasterCard, and othersSecuring EC NetworksTechnologies for organizational networksFirewall: A network
44、node consisting of both hardware and software that isolates a private network from a public networkPacket-filtering routers: Firewalls that filter data and requests moving from the public Internet to a private network based on the network addresses of the computer sending or receiving the requestSecuring EC Networks (cont.)Technologies for organizational networksPacket filters: Rules that can accept or reject incoming packets based on source and destination addresses
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 数学一期中试卷(2022考研全国统考·历年真题分类汇编)
- 中山大学有机化学强化试卷|2024考研(权威解析版)
- 2025年全国统考数学二冲刺试卷(提分冲刺卷)
- 中医大考试题及答案
- 中药药师考试题及答案
- 2026年高职酒店管理(宴会策划)试题及答案
- 2026年中职畜牧兽医(动物营养与饲料)试题及答案
- 特岗计划考试题目及答案
- 甘肃工会考试题目及答案
- 全科医生考试题及答案6
- 2026年贵州贵州省粮食储备集团有限公司招聘真题及答案
- 中国马克思主义与当代2024版教材课后思考题答案
- 《言语治疗技术》课程考试复习题库及答案
- 采购合规培训
- 各专业文件准备目录-肾内科药物临床试验机构GCP SOP
- 租冷库合同模板版
- GB/T 44484-2024公开街景地图安全处理技术要求
- 智能制造工程专业《生产实习》教学大纲
- 3DMine-矿业工程软件-帮助手册说明书
- 肠内营养堵管的护理方法
- 2024年陕西省安康兴达路桥集团有限公司招聘笔试参考题库附带答案详解
评论
0/150
提交评论