Presentation is loading. Please wait.

Presentation is loading. Please wait.

TCOM 59901 Information Assurance Management Casing the Establishment.

Similar presentations


Presentation on theme: "TCOM 59901 Information Assurance Management Casing the Establishment."— Presentation transcript:

1 TCOM 59901 Information Assurance Management Casing the Establishment

2 TCOM 59902 Target Acquisition Systematic Footprinting -building a profile of your security posture Focused on information relating to Internet, intranet, remote access and extranet…of your system

3 TCOM 59903 Internet Footprinting Determine the Scope of Your Activities –Open Source –SEC EDGAR DB –Countermeasure: Public Database Security...

4 TCOM 59904 Internet Footprinting Network Enumeration –InterNIC DB –Organizational Query -”Whois” All information related to a particular organization May be hundreds or thousands of entries

5 TCOM 59905 Internet Footprinting –Domain Query The registrant The domain name The admin contact When the record was created and updated The DNS servers

6 TCOM 59906 Internet Footprinting –Network Query American Registry of Internet Numbers Other Domains the DNS server is authoritative Backbone provider, network class Confirm network belongs to target

7 TCOM 59907 Internet Footprinting –POC Query All e-mail addresses of POCs Complete help reference

8 TCOM 59908 Internet Footprinting Countermeasure: Public Database Security –Update admin, tech, and billing information –Fictitious contact as tripwire

9 TCOM 59909 Internet Footprinting DNS Interrogation –Serious misconfiguration –Internet Zone Transfers –Can provide a complete roadmap of an organizations internal network

10 TCOM 599010 Internet Footprinting Countermeasure: DNS Security –Reduce the available information –External servers must never be configured to reveal internal network information

11 TCOM 599011 Internet Footprinting Network Reconnaissance –Tracerouting –Build an access path diagram Countermeasure: IDS –RotoRouter - logs traceroute requests and generates false responses


Download ppt "TCOM 59901 Information Assurance Management Casing the Establishment."

Similar presentations


Ads by Google