Network Security and Emergency Response - PowerPoint PPT Presentation

1 / 21
About This Presentation
Title:

Network Security and Emergency Response

Description:

Brute force attack:ssh/135/Sql Server. Website attack. AD spam (1025-1032 UDP) ... ssh-brute force. China Science & Technology Network Computer Emergency Response Team ... – PowerPoint PPT presentation

Number of Views:115
Avg rating:3.0/5.0
Slides: 22
Provided by: Hei166
Category:

less

Transcript and Presenter's Notes

Title: Network Security and Emergency Response


1
Network Security and Emergency Response
  • Tao Jing
  • jingtao_at_cstnet.cn
  • (86)-010-58812898
  • CANS 2007 Xi An
  • 2007-8-26

2
Agenda
  • Current security status of CSTNET
  • About CSTCERT Our work
  • Future work

3
Current security status of CSTNET- (1)
  • 2006.8.9-2007.8.8 about 540 vulnerabilities (data
    from US-CERT)
  • Consumption of network bandwidth
  • P2P
  • Worm
  • botnet

4
Current security status of CSTNET-(2)
  • Security threat
  • Worm slammer(1434 UDP)?MSblast(135
    TCP)?Zotob(445 TCP) and etc.
  • Botnet (TCP 135/137/139/445/1433)
  • Phishing
  • attachment of spams
  • ARP cheat
  • Brute force attackssh/135/Sql Server
  • Website attack
  • AD spam (1025-1032 UDP)

5
abnormal traffic -worm and botnet
  • Worm
  • Slammer
  • MSblast
  • botnet
  • SYN flood

6
Slammer
  • A memory resident worm
  • The time to reach saturation is short
  • 75,000 hosts were infected in 30 minutes on Jan
    25 2003.

7
Botnet
  • Botnet can cause
  • DDos SYN flood
  • spam
  • Port scan
  • Cybercrime
  • Website hits
  • Phishing
  • spy

8
Botnet
  • SYN flood,TCP 135/139/445/1433

9
UDP 1025-1033 AD spam
10
About CSTCERT
  • Founded in 2002 , CSTCERT(China Science and
    Technology Network Computer Emergency Response
    Team)
  • CSTCERT is supervised by CSTNET.
  • Services
  • Incidents handling, include attack ,complaints ,
    abnormal traffic detect and other related
    security incidents
  • research and development
  • Emergency Response
  • Security training
  • Web site http//cert.cstnet.cn
  • Phone86-010-58812935
  • Email cert_at_cstnet.cn

11
Our work
  • 2006.7 -2007.7 ,we have handled 389 security
    events.
  • security incidents291
  • security complaints 98

12
Mocbot
  • On August 14, 2006 ,we noticed a large increase
    in TCP traffic targeted at port 445.
  • Its a new worm , and use MS06-040 vulnerability.
  • Reported CNCERT/CC and informed all the CSTNET
    users.

13
Least Time for us to Cope with Attack
14
Botnet
  • 3 botnet hosts scanned TCP 1433
  • In 10 minutes,port 1433 587,302 attacks
    (944times/sec,)
  • Report to CNCERT/CC

15
(No Transcript)
16
Security complaint
17
phishing
18
ssh-brute force
19
Data from www.securityfocus.com
20
Future work
  • Botnet control research IM/P2P
  • Monitoring and countermeasure for large-scale
    network worm
  • Enhance cooperation between CERTs

21
The end
  • Thank you!

jingtao_at_cstnet.cn (86)-010-58812898
Write a Comment
User Comments (0)
About PowerShow.com