Datei: her-sec.ppt Freitag, Index 1 University Würzburg, Dr. L.Marten University Würzburg Bavarian future offensive SAP / Higher Education & Research User Group 4 th Meeting, Amsterdam, the Netherlands on 20 th - 22 th April, 1999 An Approach For SAP R/3 Security In Open Networks
Datei: her-sec.ppt Freitag, Index 2 University Würzburg, Dr. L.Marten University Würzburg Bavarian future offensive Contact Dr. Lutz Marten IT–Management Bayerische Julius-Maximilians-Universität Würzburg Am Hubland D Würzburg, Germany phone: +49 (0) 931 / fax: +49 (0) 931 /
Datei: her-sec.ppt Freitag, Index 3 University Würzburg, Dr. L.Marten University Würzburg Bavarian future offensive Facts & Figures University Würzburg first foundation: 1402, refoundation: faculties 70 departments wide spectrum of disciplines largest university in northern Bavaria over students about staff-members 350 professors, about 2700 academic assistants 19 university clinics budget 400 Mio. DM (without patient care, incl. research)
Datei: her-sec.ppt Freitag, Index 4 University Würzburg, Dr. L.Marten University Würzburg Bavarian future offensive User Access To Applications Students / Staff Application Systems SAP R/3, HISSOS World Wide Web up to user campus = internet administration = intranet
Datei: her-sec.ppt Freitag, Index 5 University Würzburg, Dr. L.Marten University Würzburg Bavarian future offensive Basic Security By A Firewall Client PC Internal Application Systems Firewall campus internet adminitration intranet
Datei: her-sec.ppt Freitag, Index 6 University Würzburg, Dr. L.Marten University Würzburg Bavarian future offensive Network Topology
Datei: her-sec.ppt Freitag, Index 7 University Würzburg, Dr. L.Marten University Würzburg Bavarian future offensive WWW Transaction Model - 3 Tier Model Web Browser Presentation representaion of the application Firewall Web Server Web-Adaption homogenisation authentification Application System Application Transaction data manipulation
Datei: her-sec.ppt Freitag, Index 8 University Würzburg, Dr. L.Marten University Würzburg Bavarian future offensive WWW Transaction Model - General Model Web-Browser / Java-VM Presentation Web Server ( e.g. MS-IIS) Web-Adaption Application Server Application Transaction Database Server HTML/Java Transformation / User Authentication
Datei: her-sec.ppt Freitag, Index 9 University Würzburg, Dr. L.Marten University Würzburg Bavarian future offensive WWW Transaction Model - TranSON Model Web-Browser Presentation TranSON Server Web-Adaption Web Server enciphered Firewall Application Server Application Transaction Database Server (optionally enciphered)
Datei: her-sec.ppt Freitag, Index 10 University Würzburg, Dr. L.Marten University Würzburg Bavarian future offensive WWW Transaction Model - SAP R/3 Model Web-Browser Presentation R/3 Application Server Application Transaction R/3 Database Server (optionally enciphered) manufacturer-dependent SAP-Protokoll manufacturer-dependent SAP-Protokoll Web Server ( z.B. MS-IIS) Web-Adaption Internet Transaction Server - ITS enciphered ISAPI HTTP
Datei: her-sec.ppt Freitag, Index 11 University Würzburg, Dr. L.Marten University Würzburg Bavarian future offensive WWW Transaction Model - HISSB Web-Browser with HISSB Java-applet Presentation HISSOS/GX Informix Database Application Transaction ODBC / JDBC (optionally enciphered) Web Server ( z.B. MS-IIS) Web-Adaption JDesignerPro Enterprise Server (JAGG) enciphered TCP Port 4899
Datei: her-sec.ppt Freitag, Index 12 University Würzburg, Dr. L.Marten University Würzburg Bavarian future offensive WWW Transaction Model- TranSON + SAP R/3 Web-Browser / Java-VM Presentation Web Server ( z.B. MS-IIS) Web-Adaption Internet Transaction Server - ITS enciphered ISAPI TCP Port 4444 and HTTP TranSON Server Firewall manufacturer-dependent SAP protocol manufacturer-dependent SAP protocol Application Server Application Transaction Database Server (optionally enciphered)
Datei: her-sec.ppt Freitag, Index 13 University Würzburg, Dr. L.Marten University Würzburg Bavarian future offensive WWW PKI (public key) Model - TranSON + SAP R/3 Web-Browser / Java-VM Web Server ( z.B. MS-IIS) Application Server Database Server Internet Transaction Server - ITS, Agate/Wgate running on one or two servers optionally with SNC TranSON Server / Firewall SAP protocol SNC optional Smartcard with keys and crtificates CA - Certificate Authority CA - Certificate Authority SSLv3 / TLSv1 using private key public key certificate Directory Services LDAP
Datei: her-sec.ppt Freitag, Index 14 University Würzburg, Dr. L.Marten University Würzburg Bavarian future offensive more information and contacts can be found at Thank you for your attention !