CCSP CSI Exam Certification Guide phần 5

QoS, và kết nối điều khiển truy cập cho các máy chủ doanh nghiệp và quản lý giao thông lọc giữa các mạng conViệc chuyển đổi Layer 3 cung cấp các phân đoạn riêng biệt cho các máy chủ doanh nghiệp, máy chủ quản lý, | 130 Chapter 9 Mitigating Sophisticated Network Attacks Mitigating Man-In-The-Middle Attacks Man-in-the-middle attacks can be mitigated effectively only through cryptography. If communication is encrypted the attacker can capture only the cipher text. If however the attacker can determine or capture the session key man-in-the-middle attacks become possible. A man-in-the-middle attack against an encrypted session can succeed only if attackers can insert themselves into the key-exchange process. Before an encrypted session can be set up both parties must agree on a session key that will be used to encrypt traffic in both directions. To do so both parties must either perform a Diffie-Hellman key exchange whereby the session key is derived from a combination of private and public encryption keys or communicate in some other fashion preferably out-of-band to agree on the session key. An attacker can insert themselves between the two parties in a man-in-the-middle attack in such a way that the attacker negotiates a separate session key with both parties and relays the communication sufficiently fast enough to keep up with the other two computers as shown in Figure 9-2. Figure 9-2 Man-In-The-Middle Attack During Session Setup In Figure 9-2 system A initiates a key exchange in step 1. The attacker s system intercepts the keyexchange request and responds with a key that is forged to appear to come from system B step 2 . System B sends a key-exchange request step 3 to system A and before system A can respond the attacker responds with his own key in step 4. In this way the attacker sets up encrypted sessions with both system A and system B and in each case masquerades as the other system. When system A sends traffic to system B it is actually sent to the attacker s system which can then copy the traffic for later analysis forward it unmodified to system B or forward it after some modification has been made to the message. If the attacker is able to keep up with the speed at .

Không thể tạo bản xem trước, hãy bấm tải xuống
TỪ KHÓA LIÊN QUAN
TÀI LIỆU MỚI ĐĂNG
427    245    2    19-05-2024
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.