2008 cams-ii users’ conference · • the “nat” router • network address translation •...

42
2008 CAMS-ii Users’ Conference CAMS-ii and Technology The Good, The Bad, The Other

Upload: others

Post on 16-Aug-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

2008 CAMS-ii Users’ Conference

CAMS-ii and TechnologyThe Good, The Bad, The Other

Page 2: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

• LAN, WAN, WLAN, WWAN• Firewalls• Intrusion Detection• Email• Encryption• Phishing• Anti-Virus, Anti-Spyware• And some other stuff……….

Technology Topics

Page 3: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Technology

• Technology is changing at a brisk pace.• Moore’s Law

In 1965 Intel co-founder Gordon Moore predicted that the number of transistors on a chip will double about every two years.

• Computers are more powerful, less expensive, and become obsolete sooner

• More ways to “get it done” better, faster, and cheaper.

• As hardware capabilities increase, software is modified to need more hardware capability…the cycle continues

Page 4: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Upgrade or Replace?

Page 5: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Networks

• LAN – Local Area Network• Inside the building (Intranet)

• WAN – Wide Area Network• Outside the building (Internet)

• WLAN – Wireless LAN• WWAN – Wireless WAN

Page 6: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Typical Network Layout

Page 7: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Typical Network Layout

Page 8: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Typical Network Layout

Page 9: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Firewall

• Firewalls protect your network• Keep unwanted traffic and data out

• Hackers, viruses, spyware, etc.

• Hardware and Software Solutions• Routers• Security Appliances• Gateway Computer (Proxy Server)• Individual Computer Programs

Page 10: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Hardware Firewall

• The “NAT” Router• Network Address Translation• Linksys, Dlink, Netgear• Inexpensive• Blocks unwanted entry• Hides networked computers• Typically does not watch outbound

Page 11: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Hardware Firewall

A popular wireless router from Linksys

Page 12: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Hardware Firewall

• The security appliance• Cisco, Sonicwall, Watchguard• More expensive• Provides all basic router functions• Adds additional monitoring and prevention

tools• Anti-virus, anti-spyware, content filter• Intrusion detection / prevention• Outbound monitoring

Page 13: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Intrusion Detection / Prevention

• IDS / IPS adds to the firewall capability

• IDS watches for suspicious activity

• IPS stops suspicious activity

Page 14: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

IDS/IPS Sample Reports

Page 15: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

IDS/IPS Sample Reports

Page 16: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

IDS/IPS Sample Reports

Page 17: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

IDS/IPS Sample Reports

Page 18: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

IDS/IPS Sample Reports

Page 19: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

IDS/IPS Sample Reports

Page 20: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

IDS/IPS Sample Reports

Page 21: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

IDS/IPS Sample Reports

Page 22: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Software Firewall

• The proxy server• Network Computer with firewall• All other computers get to the internet

through it• Provides all basic router functions• Works like a router• May slow down network traffic• More complex to configure

Page 23: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Software Firewall

• Firewall software on a pc• Norton, McAfee, Zone Alarm• Can identify rogue software • Difficult to configure• Interferes with internal networking• Resource hog• Useful if configured properly

Page 24: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Encryption

• Protects data from prying eyes• Free or cost-based

• Truecrypt• Ccrypt

• Most necessary with removable media• USB devices• CD/DVD media

• CAMS-ii External Backups are encrypted

Page 25: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Security at the Desktop

• Safeguard your data• Notebooks are risky• USB Flash Drives are even riskier

• Don’t forget to back up the pc!!• USB external hard drive• CD/DVD media• Network storage

• Education is important

Page 26: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Phishing and Pharming

• Phishing• Lures people to give up

personal information• Email looks official

• Pharming• Misdirect to fake web site• Modification of hosts file

Page 27: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Malware

• Viruses and Trojan Horses• May turn your pc into a spam machine

• Spyware• May log keystrokes and send home

• Spam• HUGE irritant and wastes time

• Protection• Network• Individual PC

Page 28: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Email

Email is NOT secure!!!!You never know who might be reading your

email

Page 29: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Secure Email

Can Be Simple or Complicated;

Expensive or Inexpensive

• Personal Security Certificate (SSL)

• Cumbersome

• Limited Functionality

• Encryption Software

• Freeware (less integrated)

• Cost-Based (more integrated)

• Password Protected Files

• Zip Files (less secure)

Page 30: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Email File Encryption

• Encrypt the file, then send it as an attachment

• Cryptainer LE and DeCypherIT are free programs used for this example.

• Cryptainer LE limits file size to 25mb – more than sufficient

• Use DeCypherIT to decrypt the file

• OR…….

• Create an ecrypted “.exe” file to send

• Many firewalls and email clients block .exe files

Page 31: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

File Encryption Example

Page 32: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

File Encryption Example

Page 33: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

File Encryption Example

Page 34: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

File Encryption Example

Page 35: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

How Security Measures Affect CAMS-ii

• CAMS-ii is on the Intranet• Internet Explorer

• Trusted Sites Zone• ActiveX Controls

• Toolbars and Popup Blockers• Can affect CAMS-ii behavior• Learn how they work

• Anti-Virus / Anti-Spyware• Can stop approved controls

Page 36: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

How Security Measures Affect CAMS-ii

• Software Firewalls on PCs• Accessing shared resources• Printing• File transfers

• Where is CAMS-ii?• The Windows “hosts” file

Page 37: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Automatic Windows Updates

• Controversial• Can fix problems• Can cause problems

• Recommendations• Auto-download, manual install• Read install notes

Page 38: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Windows Vista

• Moving to new computers is never much fun for most of us

• It’s not “if” – it’s “when”• Higher hardware requirements

• Lots of memory (RAM)• Robust video capability

• Will my programs work?• Will CAMS-ii work?

Page 39: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Windows Vista

• Which version to use?• Home Basic

• Very Basic – not recommended

• Home Premium• Supports multimedia (Windows Media Center)• Will not work in a Windows Domain

• Business• Will work in a Windows Domain• Does not have all the multimedia features

• Ultimate• Everything included (even the batteries!)

Page 40: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Windows Vista

• User Access Control

•What is it?

•Can I turn it off?

•Changes to file locations in CAMS-ii

•Allows more flexibility for securing the PC

Page 41: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

Miscellaneous

Page 42: 2008 CAMS-ii Users’ Conference · • The “NAT” Router • Network Address Translation • Linksys, Dlink, Netgear • Inexpensive • Blocks unwanted entry • Hides networked

The End