{"id":64,"date":"2018-07-03T11:18:05","date_gmt":"2018-07-03T11:18:05","guid":{"rendered":"http:\/\/lisp5.epgpbooks.inflibnet.ac.in\/?post_type=chapter&#038;p=64"},"modified":"2018-07-31T09:16:09","modified_gmt":"2018-07-31T09:16:09","slug":"network-security-core-concepts","status":"publish","type":"chapter","link":"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/chapter\/network-security-core-concepts\/","title":{"rendered":"Network Security: Core Concepts"},"content":{"raw":"<div style=\"text-align: justify\">\r\n\r\n&nbsp;\r\n\r\n<strong>I.\u00a0\u00a0 <\/strong><strong>Object<\/strong><strong>iv<\/strong><strong>e<\/strong><strong>s<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">The prifinite Objective of this module is to provide the over all idea of the Network Security and its importance \u00a0in an organization. \u00a0The threats and challenges against network security and major kinds of threats found in a network will be discussed. In addition, proper remedies and measures to be taken to protect the data and information in a network environment is also highlighted. Major threats like virus, Trojan, malware, spyware, DoS attack, Hacking, IDS and implementation of anti virus as well as Firewall etc., are discussed.<\/p>\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n<strong>II.\u00a0\u00a0 Learning Outcome<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">On completion of this lesson, you would attain knowledge on basics of network security and its importance for network \u00a0and \u00a0data \u00a0integrity. You will learn about major threats and challenges to network security and software and hardware solutions available for \u00a0network \u00a0security. You would also gain knowledge about implementation \u00a0of \u00a0proper network security by formulating appropriate policies for \u00a0the \u00a0user \u00a0as well as for the organization with proper network security devices.<\/p>\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n<strong>III.\u00a0\u00a0 Module Structure<\/strong>\r\n\r\n&nbsp;\r\n\r\n1.\u00a0 Introduction\r\n\r\n2.\u00a0 Network Authentication\r\n\r\n3.\u00a0 Types of Network Attacks\r\n\r\n3.1\u00a0 Eavesdropping\r\n\r\n3.2\u00a0 Data Modification\r\n\r\n3.3\u00a0 Identity Spoofing (IP Address Spoofing)\r\n\r\n3.4\u00a0 Password-Based Attacks\r\n\r\n3.5\u00a0 Denial-of-Service (DOS) Attack\r\n\r\n3.6\u00a0 Man-in-the-Middle Attack\r\n\r\n<span style=\"text-align: initial;font-size: 1em\">3.7\u00a0 Compromised-Key Attack<\/span>\r\n\r\n<span style=\"text-align: initial;font-size: 1em\">3.8\u00a0 Sniffer Attack<\/span>\r\n\r\n<span style=\"text-align: initial;font-size: 1em\">3.9\u00a0 Application-Layer Attack<\/span>\r\n\r\n<span style=\"text-align: initial;font-size: 1em\">4.\u00a0 Virus<\/span>\r\n\r\n<span style=\"text-align: initial;font-size: 1em\">4.1\u00a0 Trojan Horse<\/span>\r\n\r\n<span style=\"text-align: initial;font-size: 1em\">4.2\u00a0 Malware\/Spyware<\/span>\r\n\r\n<span style=\"text-align: initial;font-size: 1em\">4.3\u00a0 Anti- Virus Programmes<\/span>\r\n\r\n<span style=\"text-align: initial;font-size: 1em\">5.\u00a0 Protection using UTM and \u00a0Firewall<\/span>\r\n\r\n<span style=\"text-align: initial;font-size: 1em\">6.\u00a0 DMZ for hosting and IDS 7. Summary<\/span>\r\n\r\n<span style=\"text-align: initial;font-size: 1em\">8. References<\/span>\r\n\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n<strong>1.\u00a0\u00a0 Introduction<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Security is a global issue and one need to protect his valuables, data and information, even our home and nation with proper security. Physical security can be easily achieved by safeguarding it by physical means such as lock and key, fencing, creating walls, making compartments, etc. Physical security of computer system also can be attained by placing it in a safe place or put it \u00a0in \u00a0a \u00a0lock \u00a0and \u00a0key \u00a0or inside a compartment with proper security. But network security is a challenge since it involves interconnections of computers for resource sharing. Security for computer networks and information is to be implemented at various levels in order to protect data and information. The objective of this module is to discuss threats and \u00a0challenges towards network security, such as hacking, phishing attempt, virus, trojan, spyware, etc. over the network \u00a0and \u00a0various \u00a0measures \u00a0and methods of protection against these threats.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">The\u00a0\u00a0\u00a0 prime\u00a0\u00a0\u00a0 objective\u00a0\u00a0\u00a0\u00a0 of\u00a0\u00a0\u00a0 network\u00a0\u00a0\u00a0 security\u00a0\u00a0\u00a0 is\u00a0\u00a0\u00a0 to\u00a0\u00a0\u00a0 protect\u00a0\u00a0\u00a0 the confidentiality of data by keeping the integrity and correctness of data\u00a0<span style=\"text-align: initial;font-size: 1em\">and make the availability of data for use over the network on 24 \u00d7 7 basis. Everyone would\u00a0 like to get seamless and uninterrupted access to the resources over the network. Since computer networks are technically a cluster of interconnections of computers, with the heterogeneous nature in its content and technology, ensuring security for the network is a major challenging task. The threats to the network may appear from both internal and external. The scope and function of network has grown into a bigger \u00a0magnitude \u00a0with \u00a0worldwide connections of \u00a0computers \u00a0i.e. \u00a0Internet. \u00a0Since, \u00a0each \u00a0computer \u00a0is getting connected to a global network, security is to \u00a0be \u00a0ensured \u00a0for every user and machines. The security has to be implemented at various levels, such as user level, organizational level \u00a0and \u00a0national level. Security also needs to be enforced for network of computers as well as information. Once the network is protected, information is also automatically getting protected to a great extent.<\/span><\/p>\r\n\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">A major threat to individual user in a network environment \u00a0is \u00a0the threat of viruses and its variances. In addition to viruses, \u00a0there \u00a0are similar threats like Trojan, Spyware, Addware, etc. Before exploring these threats, let us discuss how does a legitimate user enter into \u00a0a system which is connected in the network and ensure \u00a0user \u00a0level security.<\/p>\r\n&nbsp;\r\n\r\n<strong>2.\u00a0\u00a0 Network Authentication<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">In a network, if a user is allowed to access information from his\/her computer, one can ensure that he\/she is a legitimate user on the network. This is established by using or by giving an identity for the user in the network system. Checking of such valid identity is called <strong><em>authentication<\/em><\/strong>. Authentication can be established \u00a0on \u00a0computer networks by providing a username and password or store IP address of the machine in advance in a centralised server. The IP address \u00a0is \u00a0a unique ID for a user over a network. It can be a local IP address (example 192.168.x.x or 172.16.x.x) or global IP address or public IP address (example 14.139.x.x or 8.8.8.8).<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">In addition to these mechanisms of authentication, one can also have recent techniques such as biometric, fingerprint, \u00a0face \u00a0reading software, voice recognition, etc. for making valid entry into a system.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"text-indent: 2em;font-size: 1em\">These kind of tools are used for authenticating simple 'login' into the computer systems with his user name and password, a user \u00a0can \u00a0get his\/her credentials for authenticating with the network. Unauthorized users can be denied access to information by providing a valid authentication for each and every user in the network. But, no one can create user names and passwords \u00a0for \u00a0all \u00a0users \u00a0over \u00a0a \u00a0wide \u00a0network like Internet. It is possible to provide service level passwords similar to assigning passwords for email services (example Gmail) as well as a user can have password for accessing e-resources, user can have different passwords for login purpose, but not easy to assign a single password for all services.<\/span><\/p>\r\n\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">It is suggested to create users \u00a0with \u00a0authentication \u00a0at \u00a0different \u00a0level and every organization must have their own authentication policy for it. This level of authentication can protect the network from unauthorised user or strange user while trying to access resources. If a user is denied access into the network, he\/she cannot access other resources as well. Therefore, authentication is the mechanism \u00a0by which one generally prevent illegitimate user to access the resources. As mentioned, a good password is a secured mechanism for a user to log in to a network. It is suggested not to use simple words or dictionary words for passwords, instead one should use alphanumeric characters along with combination of special characters for password. Banking sectors and other financial services over the Internet do not accept simple passwords. It is also suggested to change password at least once in three or six months so that even some inexperienced person cannot hack the system and get access to the data temporarily, the password change will help to retrieve the access. Authenticated systems are also vulnerable for threats from outside as well as from inside. Few of such threats are discussed below.<\/p>\r\n&nbsp;\r\n\r\n<strong>3.\u00a0\u00a0 Types of Network Attacks<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Without proper security measures, data might be subjected to various kinds of attacks. Attacks are classified as passive attacks and active attack where information is altered \u00a0with \u00a0intent \u00a0to \u00a0corrupt \u00a0or \u00a0destroy the data or the network.\u00a0<span style=\"text-align: initial;font-size: 1em\">Networks and data are vulnerable to any of the following types of attacks if one does not have a security plan in place.<\/span><\/p>\r\n\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n\r\n<strong>3.1.\u00a0 Eavesdropping<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Network communication happens in unsecured or \"clear text\" format, which allows an attacker to \"listen in\" or interpret (read) \u00a0the \u00a0data which passes through the network if he\/she get access to the network by wrong means. When an attacker is eavesdropping, it is referred to as sniffing or snooping. This kind of eavesdropping is the \u00a0biggest security problem that administrators face \u00a0while \u00a0managing \u00a0the network. Eavesdropping can be avoided by using strong encryption services that are based on cryptography.<\/p>\r\n&nbsp;\r\n\r\n<strong>3.2.\u00a0\u00a0\u00a0\u00a0 Data Modification<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">If an attacker gets access to someone's data, the next logical step is to modify it. The smart attacker can even modify the data in the packet without the knowledge of the sender or receiver.<\/p>\r\n&nbsp;\r\n\r\n<strong>3.3.\u00a0\u00a0\u00a0\u00a0 Identity Spoofing (IP Address Spoofing)<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">The identity of a user on a network is through the IP address assigned to the user while login into the network. An IP address is a valid and unique identity which gives authorisation for a user. It is \u00a0possible \u00a0a smart attacker for an IP address to be falsely assumed, i.e. identity spoofing. An attacker can also use a special program to construct IP packets that appear to originate from valid addresses. After gaining access to the network with a valid IP address, the attacker can modify, reroute, or delete the data.<\/p>\r\n&nbsp;\r\n\r\n<strong>3.4.\u00a0\u00a0\u00a0\u00a0 Password-Based Attacks<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">As discussed in network authentication, \u00a0a \u00a0user \u00a0is \u00a0getting \u00a0access through a password-based access control. Access rights to a computer and network resources are determined by the identity a user has normally a user name and \u00a0password.\u00a0<span style=\"text-align: initial;font-size: 1em\">When an attacker finds a valid user account and get the password, the attacker has the same rights as the real user. It will be very dangerous, if the user has administrator-level rights. In \u00a0such \u00a0cases \u00a0the \u00a0attacker gets full access right to do anything in the \u00a0system. \u00a0After \u00a0gaining access to a network with a valid account, an attacker can do any of the following:<\/span><\/p>\r\n\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0 Obtain\u00a0\u00a0 lists\u00a0\u00a0 of\u00a0\u00a0 valid\u00a0\u00a0 user\u00a0\u00a0 and\u00a0\u00a0 computer\u00a0 names\u00a0\u00a0 and\u00a0\u00a0 network information;\r\n\r\n\u2022\u00a0\u00a0\u00a0 Modify\u00a0\u00a0 server\u00a0\u00a0 and\u00a0\u00a0 network\u00a0\u00a0 configurations,\u00a0\u00a0 including\u00a0\u00a0 access controls and routing tables which is a very serious threat; or\r\n\r\n\u2022\u00a0\u00a0\u00a0 Modify, reroute, or delete \u00a0data.\r\n\r\n&nbsp;\r\n\r\n<strong>3.5.\u00a0\u00a0\u00a0\u00a0 Denial-of-Service (DOS) Attack<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Unlike a password-based attack, the denial-of-service attack prevents normal use of a computer or network by valid users. DOS attack is generally caused by flooding a computer or the entire network with traffic until a shutdown occurs due to overload. DOS can also cause blocking the traffic, which results in a loss of access to network resources by authorized users.<\/p>\r\n&nbsp;\r\n\r\n<strong>3.6.\u00a0\u00a0\u00a0\u00a0 Man-in-the-Middle Attack<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Man-in-the-middle attacks are like someone assuming the identity of a user in order to read his\/her message. The person \u00a0on \u00a0the \u00a0other \u00a0end might believe it is you, because the attacker might be actively replying you to keep the exchange going and gain more information.<\/p>\r\n&nbsp;\r\n\r\n<strong>3.7.\u00a0\u00a0\u00a0\u00a0 Compromised-Key Attack<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">A key is a secret code or number necessary to interpret secured information. After an attacker obtains a key, that key is referred to as a compromised key. An attacker uses the compromised key to gain access to a secured communication without the sender or receiver being aware of the attack. With the compromised key, the attacker can decrypt or modify data, and tries to use the compromised key to compute additional keys.<\/p>\r\n\r\n<\/div>\r\n&nbsp;\r\n\r\n<strong style=\"text-align: initial;font-size: 1em\">3.8.\u00a0\u00a0\u00a0\u00a0 Sniffer Attack<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\"><span style=\"text-align: justify;font-size: 1em\">A sniffer is an application or device that can read, monitor, and capture network data exchanges and read network packets. If the packets are not encrypted, a sniffer provides a full view of \u00a0the \u00a0data inside the packet. Even encapsulated packets can be broken open and read unless they are encrypted. Using a sniffer, an attacker can analyze the entire network and gain information \u00a0to \u00a0eventually \u00a0cause \u00a0the network to crash or to become corrupted.<\/span><\/p>\r\n\r\n<div>\r\n\r\n&nbsp;\r\n\r\n<strong>3.9.\u00a0\u00a0\u00a0\u00a0 Application-Layer Attack<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">An application-layer attack targets application servers by causing \u00a0a fault in the server's operating \u00a0system \u00a0or \u00a0applications. \u00a0This \u00a0results \u00a0in the attacker gaining the ability to bypass normal access controls. The attacker takes advantage of this situation, gaining control of your application, system, or network for introducing a virus Program or introduce a sniffer Program or disable other security controls to enable future attacks. Virus, Trojan, Worms, Addware and Spyware generally belongs to active attacks and major threats to the security.<\/p>\r\n&nbsp;\r\n\r\n<strong>4.\u00a0\u00a0 Virus<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">A virus is a computer program with malicious logic and replicate itself repeatedly over the network. Though Computer virus is working like a biological virus, i.e. enter into the computer without notice to the user of the system and spread to other \u00a0computers, \u00a0maintains \u00a0its \u00a0dormancy and keeps its polymorphic nature. The name is coined from Vital Information Resource Under Siege (VIRUS). Computer viruses are executable computer programs designed to replicate and damage the computer system without users' knowledge and permission. Computer virus gets activated on certain triggered conditions known as \u201cCatalyst\u201d. A computer virus program is logical activity and have its own mechanism to avoid detection by the user and activate on a particular time or occasion. Such viruses are called \u201cstealth viruses\u201d. The trigger could be a particular date for example Thursday 12th (Alias CD), Friday the 13th for Jerusalem Virus. Some time a code is\u00a0<span style=\"text-align: initial;font-size: 1em\">also embedded in some legislate programme, i.e. set to explore when certain conditions made and such viruses are called logical viruses.<\/span><\/p>\r\n\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">A virus can affect operating system, computer files, data files, executable programs, bootable disk, hard disk partitions, \u00a0boot \u00a0sector etc. Generally, when it gets activated it can hide in RAM (Random Access Memory), Upper memory, High memory, TSR \u00a0(Terminate \u00a0and Stay Resident), MBR (Master Boot Record) extended and expanded memory. Viruses are categorized into boot sector \u00a0infectors \u00a0and program \u00a0file \u00a0infectors \u00a0(for example \u00a0.exe, \u00a0.doc, \u00a0.sys, \u00a0.dill, \u00a0.ovl, \u00a0.scr,.xa, .xls)<\/p>\r\n&nbsp;\r\n\r\nNature of following viruses and illegal activities on the network may be \u00a0learned from anti-virus web sites:\r\n\r\n\u2022\u00a0\u00a0\u00a0 Adware (advertising software)\r\n\r\n\u2022\u00a0\u00a0\u00a0 Armored viruses\r\n\r\n\u2022\u00a0\u00a0\u00a0 Benign virus\r\n\r\n\u2022\u00a0\u00a0\u00a0 Bomb virus\r\n\r\n\u2022\u00a0\u00a0\u00a0 Boot virus (boot sector virus)\r\n\r\n\u2022\u00a0\u00a0\u00a0 Botware\r\n\r\n\u2022\u00a0\u00a0\u00a0 Browser hijacker\r\n\r\n\u2022\u00a0\u00a0\u00a0 Companion virus\r\n\r\n\u2022\u00a0\u00a0\u00a0 Dialer (phone dialer)\r\n\r\n\u2022\u00a0\u00a0\u00a0 FAT virus (File Allocation Table virus)\r\n\r\n\u2022\u00a0\u00a0\u00a0 File deleting viruses\r\n\r\n\u2022\u00a0\u00a0\u00a0 Keyloggers\r\n\r\n\u2022\u00a0\u00a0\u00a0 Macro virus\r\n\r\n\u2022\u00a0\u00a0\u00a0 Malware (malicious software)\r\n\r\n\u2022\u00a0\u00a0\u00a0 Mass mailer viruses\r\n\r\n\u2022\u00a0\u00a0\u00a0 Memory resident virus\r\n\r\n\u2022\u00a0\u00a0\u00a0 Multipartite virus\r\n\r\n\u2022\u00a0\u00a0\u00a0 Multiple characteristic viruses\r\n\r\n\u2022\u00a0\u00a0\u00a0 Parasitic virus\r\n\r\n\u2022\u00a0\u00a0\u00a0 Polymorphic virus\r\n\r\n\u2022\u00a0\u00a0\u00a0 Programme virus\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Some of the viruses attack web servers and network managed programme and stop the legitimate user to access data from the server\u00a0<span style=\"text-align: initial;font-size: 1em\">by denial of service (DoS attacks) as discussed earlier. Zombi is an example of this type of virus. It is expected at least \u00a0100000 \u00a0viruses spread as on date. Use of proper anti-virus software, regular update on the signature of the new virus can prevent the system from virus attack. The virus cannot damage hardware such as keyboards, monitor, printer etc. On the detection of the virus this can be isolated from the normal programme such can be quarantine time.<\/span><\/p>\r\n\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n\r\n<strong>4.1.\u00a0\u00a0\u00a0\u00a0 Trojan Horse<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Trojan Horse is a type of non-self-replicating type of malware programmes containing \u00a0malicious \u00a0code \u00a0which \u00a0carries \u00a0out predetermined actions based on the nature of Trojan. On execution it cost, loss or theft of data for slowing down the performance of the system. Trojan act as back-door entry programme gets dropped in a system without notice of the user. A trojan may also give \u00a0remote access to a hacker for the targeted computer systems. Harmful \u00a0trojan horse can damage system in many ways such as crashing the computer, data corruption, formatting disk, keystroke logging, deletion of files, data theft, perform automated spamming or denial-of-service attack, viewing user \u2019s webcam, modification of registry, downloading and installing third party malware etc.<\/p>\r\n&nbsp;\r\n\r\n<strong>4.2.\u00a0\u00a0\u00a0\u00a0 Malware\/Spyware<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Now \u00a0a \u00a0days,\u00a0 \u00a0virus\u00a0 \u00a0can \u00a0also \u00a0get \u00a0attacked \u00a0to \u00a0data \u00a0files \u00a0such \u00a0as \u00a0.doc, .xls, .pps, .mdb, etc. Such viruses called \u201cMacros\u201d. Some of these viruses are polymorphic in nature which mutates and changes its identifiable codes with each infection. Macro viruses are generally independent 'malware' programme which do not require any host. It replicates itself and spreads. In contrast to virus, some malicious programme do to replicate such programmes are called \u00a0\u201cTrojan Horses\u201d.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">Spyware programme helps in gathering information \u00a0about \u00a0a \u00a0person and organisation without knowledge. Spyware is classified into four types: System monitors, Trojans, Adware and tracking cookies.<\/p>\r\n\r\n<\/div>\r\n&nbsp;\r\n\r\n<strong style=\"text-align: initial;font-size: 1em\">4.3.\u00a0\u00a0\u00a0\u00a0 Anti-Virus Programmes<\/strong>\r\n<div>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">The threats like Virus, Trojan, Malware, Spyware, etc. can \u00a0be prevented by using anti-software from the popular vendors. Anti-virus software is a set of programme data designed to prevent, search for, detect and remove viruses and other malicious software like worms, trojan, adware, etc. These tools are critical at users level and has to be updated daily for the new inclusion of the viruses since more than 60,000 new pieces of \u00a0Malware \u00a0created \u00a0daily. \u00a0The\u00a0 Anti-virus programme perform basic functions like scan specific files of directories, allow scheduled scans automatically. Initiate scan for specific drive, folders, CD ROM, Flash Drives in any time. The infected files can\u00a0 be removed or quarantined to prevent the infection to other PCs.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">Popular free anti-virus programs are AVG antivirus, Kaspersky, F Secure, and Avaste, and commercial software are Norton by Symantec, MaCafe, Trend Micro, eScan, Bitdefender, inoculate etc. It \u00a0depends upon organisation to choose the best product.<\/p>\r\n&nbsp;\r\n\r\n<strong>5.\u00a0\u00a0\u00a0 Protection using UTM and Firewall<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">We have learned how to protect the computers against \u00a0unauthorised entry and also seen that whether a user is legitimate user or not with authentication. If unauthorised person can get access to a computer through network what she\/he can \u00a0do? \u00a0Such \u00a0unauthorized \u00a0or illegitimate users are called <strong><em>hackers<\/em><\/strong>. Hackers use the vulnerability on a system. There could be loopholes in any \u00a0software \u00a0which \u00a0allows \u00a0to open ports (open entry) for entering data or programmes into the system. Such loopholes are called vulnerabilities in a system. This generally happens with computer programmes installed on the system to get access to valid resources of the computer. The attack by \u00a0a hacker could be passive in nature by which hacker just eavesdrops on information without modifying it. On the other hand, an active hacker can modify the data or destroy the data.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">Hacker can get into the resources once he gets into the system \u00a0and he\/she can work like any other normal user. This is one of the serious threats \u00a0in \u00a0the \u00a0network. \u00a0Hacking \u00a0attempt \u00a0is \u00a0there \u00a0in \u00a0every sectors \u00a0and\u00a0<span style=\"text-align: initial;font-size: 1em\">banking sector loses huge amounts of money every year because unscrupulous people try to get access to confidential information through hacking and once this information is with hacker, he can play around with data, including malpractices, \u00a0which he has with him.<\/span><\/p>\r\n\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">A Hacker or an unauthorized user can get access to system by \u00a0any means. Computer programme generally works in \u00a0a system \u00a0by connecting to another system over the network so that it allows \u00a0to access data. These relations are called connections in \u00a0the \u00a0network. These connections are generally open through some ports. Since ports are open to create some of the connections, security on this connection are compromised and through these open connections, unauthorised people can also get access to the computer. Technically, it can be said that each programme has a port that is an open place in the computer, through the port only a programme can communicate. For example, suppose we have a database server with us. Database server works on a particular port to get connected so that this port can also get accessed by a user or a network expert and he \u00a0can \u00a0launch \u00a0some \u00a0of \u00a0the programmes through the same open port. There are more \u00a0than \u00a065000 ports which get opened on a system and some of them automatically open for services at the time of booting. A hacker can try to get access through this port into the computer and the process is called hacking attempt.<\/p>\r\n&nbsp;\r\n\r\n<img class=\"size-full wp-image-65 aligncenter\" src=\"http:\/\/lisp5.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/10\/2018\/07\/hacking-attempt.png\" alt=\"\" width=\"650\" height=\"414\" \/>\r\n\r\n<\/div>\r\n<div><\/div>\r\n<div style=\"text-align: center\">Fig.1: Hacking Attempt<\/div>\r\n&nbsp;\r\n<div>\r\n<p class=\"indent\" style=\"text-align: justify\">This is a very serious security threat as whatever activities \u00a0a \u00a0user \u00a0is doing can be monitored as a spy or data can be sent to another website without notice of the user. It is also possible that whatever key a user is typing, it can be sent to a web site without knowledge of the user. This is possible by launching some of \u00a0the \u00a0programme \u00a0by \u00a0the \u00a0hacker into the system. Hence hacking threat on individual system as well as network is to be detected, network has to be monitored always for this kind of attempt on the server. There are sophisticated programmes called IDS (Intrusion Detection System) which are part of firewall which takes care of such attempts. Implementing Firewall and UTM appliances (Unified Threat Management Systems) in network can prevent many threats.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">As shown in figure, network is created with many devices such as PCs, Mobile, Laptops, servers and other network devices. Once connected, the same machine\/devices can launch an attack. Firewall creates a virtual protection mechanism to protect the network. Unauthorised attempts with data or traffic will be discarded by the firewall, if it is not through the known ports. Firewall protects the network against all sorts of known attacks and threats. Appliance based Firewall with Gateway level Anti Virus scanning can protect \u00a0spreading \u00a0of \u00a0viruses over the network. Spam Filtering in UTM can check for data whether it is a spam or \u00a0not. \u00a0Intrusion \u00a0Detection\/Prevention \u00a0System \u00a0monitors the unauthorised entry into the \u00a0network \u00a0and \u00a0prevent \u00a0it. \u00a0Firewall \u00a0also has the facilities for bandwidth management, web content filtering, anti-phishing, load balancing, DNS resolution, \u00a0creation \u00a0of \u00a0proxy server, DMZ support etc.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">This can be explained in detail by \u00a0using \u00a0the \u00a0following \u00a0diagram \u00a0that how a server and client is connected to share data. As it is seen in the diagram the PCs used by a user on the Internet \u00a0will \u00a0be \u00a0acting \u00a0as \u00a0a client and he\/she will try to access the \u00a0information \u00a0from \u00a0the \u00a0server (web server) through the \u00a0network. \u00a0The \u00a0server \u00a0will \u00a0push \u00a0the information based on request to the client\u2019s or user \u2019s \u00a0computer. \u00a0If there is no security between the user and server, \u00a0the \u00a0server \u00a0can \u00a0get direct access to the PC as well as the PC can also get direct access to server. The traffic will as well as nature of data will not be monitored in an unprotected environment.<\/p>\r\n\r\n<\/div>\r\n<div><\/div>\r\n<div>\r\n\r\n<img class=\"size-full wp-image-66 aligncenter\" src=\"http:\/\/lisp5.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/10\/2018\/07\/firewall.png\" alt=\"\" width=\"685\" height=\"323\" \/>\r\n<div style=\"text-align: center\">Fig.2: Firewall<\/div>\r\n&nbsp;\r\n<p style=\"text-align: justify\">Firewall plays a role to protect the network where servers \u00a0are connected. In organizational level, \u00a0this \u00a0protection \u00a0can \u00a0be \u00a0introduced by using a checkpoint between the user and outside network. Such check\/verification point is called firewall. Firewall is an intermediary layer which can be software or hardware or appliances, \u00a0which \u00a0can reside in between the user and outside network. Any request which go through this equipment will be scanned and filtered for the content at the firewall level. Firewall is also added \u00a0as \u00a0filtering mechanism \u00a0for data through filtering gateways between the user and the outside network. It is essential that if one host the content in a network, then the hosting server is to be protected from outside world. For example, as shown in diagram, if an institution host web server, network admin need only to open the port which are required for accessing web service For example 8080 is a port number for Tomcat and 80 is port number for website. In general when a user type http: \/\/ URL, then by default, the request comes through the port number 80. If he is using any other web server like tomcat, it will be through 8080. \u00a0If \u00a0the hosting is done using web server, one need to open only two or three ports. All other ports than these 3 ports has to be \u00a0blocked. \u00a0Firewall works based on this principle. \u00a0Firewall \u00a0blocks \u00a0all \u00a0the \u00a0ports \u00a0and network admin has to open the valid port(s) for the user. As it is seen in the diagram, first deny all connections and allow only connections which are required for use.<\/p>\r\n\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n\r\n<strong>6.\u00a0\u00a0\u00a0 DMZ for hosting and IDS<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">In an organization, restriction on the server can be established by creating a special zone. First, allow only known used ports from the system which is to be used for service. In this context, there is an area in a normal network with a '<strong>de militarized zone' (DMZ) <\/strong>which means to militarize the complete zone by denying all connections and allow only the known connections\/ programmes to access the resource. Any other attempt to access can be stopped at the firewall level as shown in programme. In addition to stopping \u00a0such \u00a0request, \u00a0a \u00a0firewall \u00a0can \u00a0also act as a tool for the content filtering or \u00a0even \u00a0restricted \u00a0access \u00a0to content (for example Child sites restriction). Firewall blocks unauthorized network connections to the PC or local area networks including the server if a user is hosting services in the public domain. A firewall can also act as an I<strong>ntru<\/strong><strong>sion Detection System <\/strong>(IDS) which is a very common term used in network security to check any unauthorized entry into the system.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">Any attempt by a hacker for passive as well as active intrusion has to be monitored and detected. There are many popular \u00a0firewalls \u00a0which have the facility for IDS as well as IPS i.e.. Intrusion Prevention System. Thus, the; firewall will function for checking each and every connection request even at the content level. Some of the programmes can also carry harmful content and need to be filtered before it enters into the system. In addition to protection, firewall can also act \u00a0as \u00a0a 'proxy' for sharing common Internet connection to many users. UTM equipment can also filter content,\u00a0 act \u00a0as \u00a0load \u00a0balancing \u00a0between Internet connections from various ISPs, \u00a0or \u00a0authentication \u00a0mechanism for users for proxy. Now a days, all vendors come out with firewall products, which works as single UTM (Unified Threat Management system) so that UTM box or appliance available in the market can be procured directly and implement it in a network and configure the network so that every Internet connection or local connection for accessing outside or the internal data can be routed the traffic through this UTM (firewall). Some of the popular names of firewall\/UTMs available in the market are Fortigate<strong>, <\/strong>Sonicwall, \u00a0Cyberoam \u00a0etc. Firewall can filter the content \u00a0as \u00a0mentioned \u00a0earlier, \u00a0which \u00a0can \u00a0check the port number through which a programme is \u00a0trying \u00a0to \u00a0access \u00a0and deny \u00a0any \u00a0kind \u00a0of \u00a0access \u00a0based \u00a0on \u00a0defined \u00a0rules.\u00a0 \u00a0Another \u00a0important\u00a0<span style=\"text-align: initial;font-size: 1em\">threat is that many users try to continuously connect to a single server at same time which is also a kind of attack on the network.<\/span><\/p>\r\n\r\n<\/div>\r\n<div>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Since many organisations have limited network resources like bandwidth, etc. proxy server can be used. \u00a0Proxy \u00a0servers \u00a0are vulnerable for DoS attacks. Suppose one network can accommodate 10000 users congruently at a time, an attempt by over 100000 users try to access the same server, the network will definitely chock \u00a0due \u00a0to heavy traffic which will lead to one of the threat like denial of service attack. Firewall can protect these kind of attacks for chocking the network by the hacker by monitor the flooding (UDP as well as ICMP). These are other kind \u00a0of \u00a0programmes \u00a0created \u00a0by \u00a0the unauthorised persons who generally does not seriously work for resources access but just for spying the information. These attacks can be classified as passive attack and active attack. In passive attack, people will be getting into a system to \u00a0know \u00a0what \u00a0is \u00a0available. \u00a0It \u00a0is kind of eves dropping, release of message content, traffic analysis etc and active attack, the hacker will also get into the system and modify the data, masquerading, replay, denial of service and alter data without giving any hint of change. Some people argue that ethical hacking is permitted, but cracking of a server is not permitted. Both ways, this kind of activity is a crime under \u00a0the \u00a0IT act. A person \u00a0should \u00a0not \u00a0get into the some's server without someone\u2019s asking permission. This kind of attack can be stopped by using suitable firewall rules.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">Few products are named as solutions for antivirus, trojans, spyware, adware and other kind of threats. Firewall can be implemented as software programme also (for eg in Linux, IP table) \u00a0in \u00a0addition \u00a0to using as an equipment. This way firewall can take a shape of software as well as hardware and if software in the system, it comes along with the operating system where the firewall has to be enabled. It depends upon the user to prevent his system from external attack as well as internal attack. If the security is compromised at user level and organisation may not be aware who is using the resource since hacker generally will not reveal the identity. If an organisation is not protecting their system, it will not only damage but it will also work as platform for others to attack. It is important to take care of security of computer systems, information, data as well as network so that user will \u00a0enjoy seamless access to information world.<\/p>\r\n\r\n<\/div>\r\n&nbsp;\r\n\r\n<strong>7<\/strong><strong>.\u00a0\u00a0\u00a0 Summary<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Proper network security can be \u00a0implemented \u00a0by \u00a0formulating\u00a0 very strong policy for the user as well as for the organisation with proper network\u00a0 \u00a0security\u00a0 \u00a0devices.\u00a0 \u00a0The\u00a0 \u00a0UTM\u00a0 \u00a0(Unified\u00a0 \u00a0Threat Management) appliances integrate \u00a0many \u00a0security \u00a0protection \u00a0features in systematic security implementation. \u00a0Restriction \u00a0on \u00a0the \u00a0user \u00a0is always required in the organization to protect network from local threats. Use of proper antivirus software on individual PCs as well as gateway level protection against virus attacks is to be strictly implemented. Use of pendrives, flashdrives,CDs, DVDs, and other storage devices plugging directly into PC is to be strictly monitored. As per the IT Act, log records are to be created for each network activity as well as Internet usage in organization. All users should be given an individual user account with authentication and user privileges. Network security should be treated as an organization culture where ethical use of services is to be followed religiously.<\/p>\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n<strong>8.\u00a0 References<\/strong>\r\n<ol>\r\n \t<li><a href=\"http:\/\/www.webroot.com\/in\/en\/home\/resources\/tips\/pc-security\/security-what-is-anti-virus-software\">htt p:\/ \/ w w w. w e broot. c om\/ i n\/e n\/home \/ r e s ourc e s \/ t i ps\/ pc- <\/a><a href=\"http:\/\/www.webroot.com\/in\/en\/home\/resources\/tips\/pc-security\/security-what-is-anti-virus-software\">s e c uri t y \/ s e c uri t y - wha t - i s - a nti - vir us- s o ftw are<\/a><\/li>\r\n \t<li style=\"text-align: justify\">An\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 information\u00a0\u00a0 Security\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Handbook,\u00a0\u00a0\u00a0 By\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 John\u00a0\u00a0\u00a0 M\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 D\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Hunter\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 , Springer Publication<\/li>\r\n<\/ol>","rendered":"<div style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p><strong>I.\u00a0\u00a0 <\/strong><strong>Object<\/strong><strong>iv<\/strong><strong>e<\/strong><strong>s<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The prifinite Objective of this module is to provide the over all idea of the Network Security and its importance \u00a0in an organization. \u00a0The threats and challenges against network security and major kinds of threats found in a network will be discussed. In addition, proper remedies and measures to be taken to protect the data and information in a network environment is also highlighted. Major threats like virus, Trojan, malware, spyware, DoS attack, Hacking, IDS and implementation of anti virus as well as Firewall etc., are discussed.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>II.\u00a0\u00a0 Learning Outcome<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">On completion of this lesson, you would attain knowledge on basics of network security and its importance for network \u00a0and \u00a0data \u00a0integrity. You will learn about major threats and challenges to network security and software and hardware solutions available for \u00a0network \u00a0security. You would also gain knowledge about implementation \u00a0of \u00a0proper network security by formulating appropriate policies for \u00a0the \u00a0user \u00a0as well as for the organization with proper network security devices.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>III.\u00a0\u00a0 Module Structure<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>1.\u00a0 Introduction<\/p>\n<p>2.\u00a0 Network Authentication<\/p>\n<p>3.\u00a0 Types of Network Attacks<\/p>\n<p>3.1\u00a0 Eavesdropping<\/p>\n<p>3.2\u00a0 Data Modification<\/p>\n<p>3.3\u00a0 Identity Spoofing (IP Address Spoofing)<\/p>\n<p>3.4\u00a0 Password-Based Attacks<\/p>\n<p>3.5\u00a0 Denial-of-Service (DOS) Attack<\/p>\n<p>3.6\u00a0 Man-in-the-Middle Attack<\/p>\n<p><span style=\"text-align: initial;font-size: 1em\">3.7\u00a0 Compromised-Key Attack<\/span><\/p>\n<p><span style=\"text-align: initial;font-size: 1em\">3.8\u00a0 Sniffer Attack<\/span><\/p>\n<p><span style=\"text-align: initial;font-size: 1em\">3.9\u00a0 Application-Layer Attack<\/span><\/p>\n<p><span style=\"text-align: initial;font-size: 1em\">4.\u00a0 Virus<\/span><\/p>\n<p><span style=\"text-align: initial;font-size: 1em\">4.1\u00a0 Trojan Horse<\/span><\/p>\n<p><span style=\"text-align: initial;font-size: 1em\">4.2\u00a0 Malware\/Spyware<\/span><\/p>\n<p><span style=\"text-align: initial;font-size: 1em\">4.3\u00a0 Anti- Virus Programmes<\/span><\/p>\n<p><span style=\"text-align: initial;font-size: 1em\">5.\u00a0 Protection using UTM and \u00a0Firewall<\/span><\/p>\n<p><span style=\"text-align: initial;font-size: 1em\">6.\u00a0 DMZ for hosting and IDS 7. Summary<\/span><\/p>\n<p><span style=\"text-align: initial;font-size: 1em\">8. References<\/span><\/p>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>1.\u00a0\u00a0 Introduction<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Security is a global issue and one need to protect his valuables, data and information, even our home and nation with proper security. Physical security can be easily achieved by safeguarding it by physical means such as lock and key, fencing, creating walls, making compartments, etc. Physical security of computer system also can be attained by placing it in a safe place or put it \u00a0in \u00a0a \u00a0lock \u00a0and \u00a0key \u00a0or inside a compartment with proper security. But network security is a challenge since it involves interconnections of computers for resource sharing. Security for computer networks and information is to be implemented at various levels in order to protect data and information. The objective of this module is to discuss threats and \u00a0challenges towards network security, such as hacking, phishing attempt, virus, trojan, spyware, etc. over the network \u00a0and \u00a0various \u00a0measures \u00a0and methods of protection against these threats.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The\u00a0\u00a0\u00a0 prime\u00a0\u00a0\u00a0 objective\u00a0\u00a0\u00a0\u00a0 of\u00a0\u00a0\u00a0 network\u00a0\u00a0\u00a0 security\u00a0\u00a0\u00a0 is\u00a0\u00a0\u00a0 to\u00a0\u00a0\u00a0 protect\u00a0\u00a0\u00a0 the confidentiality of data by keeping the integrity and correctness of data\u00a0<span style=\"text-align: initial;font-size: 1em\">and make the availability of data for use over the network on 24 \u00d7 7 basis. Everyone would\u00a0 like to get seamless and uninterrupted access to the resources over the network. Since computer networks are technically a cluster of interconnections of computers, with the heterogeneous nature in its content and technology, ensuring security for the network is a major challenging task. The threats to the network may appear from both internal and external. The scope and function of network has grown into a bigger \u00a0magnitude \u00a0with \u00a0worldwide connections of \u00a0computers \u00a0i.e. \u00a0Internet. \u00a0Since, \u00a0each \u00a0computer \u00a0is getting connected to a global network, security is to \u00a0be \u00a0ensured \u00a0for every user and machines. The security has to be implemented at various levels, such as user level, organizational level \u00a0and \u00a0national level. Security also needs to be enforced for network of computers as well as information. Once the network is protected, information is also automatically getting protected to a great extent.<\/span><\/p>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">A major threat to individual user in a network environment \u00a0is \u00a0the threat of viruses and its variances. In addition to viruses, \u00a0there \u00a0are similar threats like Trojan, Spyware, Addware, etc. Before exploring these threats, let us discuss how does a legitimate user enter into \u00a0a system which is connected in the network and ensure \u00a0user \u00a0level security.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>2.\u00a0\u00a0 Network Authentication<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">In a network, if a user is allowed to access information from his\/her computer, one can ensure that he\/she is a legitimate user on the network. This is established by using or by giving an identity for the user in the network system. Checking of such valid identity is called <strong><em>authentication<\/em><\/strong>. Authentication can be established \u00a0on \u00a0computer networks by providing a username and password or store IP address of the machine in advance in a centralised server. The IP address \u00a0is \u00a0a unique ID for a user over a network. It can be a local IP address (example 192.168.x.x or 172.16.x.x) or global IP address or public IP address (example 14.139.x.x or 8.8.8.8).<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">In addition to these mechanisms of authentication, one can also have recent techniques such as biometric, fingerprint, \u00a0face \u00a0reading software, voice recognition, etc. for making valid entry into a system.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"text-indent: 2em;font-size: 1em\">These kind of tools are used for authenticating simple &#8216;login&#8217; into the computer systems with his user name and password, a user \u00a0can \u00a0get his\/her credentials for authenticating with the network. Unauthorized users can be denied access to information by providing a valid authentication for each and every user in the network. But, no one can create user names and passwords \u00a0for \u00a0all \u00a0users \u00a0over \u00a0a \u00a0wide \u00a0network like Internet. It is possible to provide service level passwords similar to assigning passwords for email services (example Gmail) as well as a user can have password for accessing e-resources, user can have different passwords for login purpose, but not easy to assign a single password for all services.<\/span><\/p>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">It is suggested to create users \u00a0with \u00a0authentication \u00a0at \u00a0different \u00a0level and every organization must have their own authentication policy for it. This level of authentication can protect the network from unauthorised user or strange user while trying to access resources. If a user is denied access into the network, he\/she cannot access other resources as well. Therefore, authentication is the mechanism \u00a0by which one generally prevent illegitimate user to access the resources. As mentioned, a good password is a secured mechanism for a user to log in to a network. It is suggested not to use simple words or dictionary words for passwords, instead one should use alphanumeric characters along with combination of special characters for password. Banking sectors and other financial services over the Internet do not accept simple passwords. It is also suggested to change password at least once in three or six months so that even some inexperienced person cannot hack the system and get access to the data temporarily, the password change will help to retrieve the access. Authenticated systems are also vulnerable for threats from outside as well as from inside. Few of such threats are discussed below.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>3.\u00a0\u00a0 Types of Network Attacks<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Without proper security measures, data might be subjected to various kinds of attacks. Attacks are classified as passive attacks and active attack where information is altered \u00a0with \u00a0intent \u00a0to \u00a0corrupt \u00a0or \u00a0destroy the data or the network.\u00a0<span style=\"text-align: initial;font-size: 1em\">Networks and data are vulnerable to any of the following types of attacks if one does not have a security plan in place.<\/span><\/p>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p><strong>3.1.\u00a0 Eavesdropping<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Network communication happens in unsecured or &#8220;clear text&#8221; format, which allows an attacker to &#8220;listen in&#8221; or interpret (read) \u00a0the \u00a0data which passes through the network if he\/she get access to the network by wrong means. When an attacker is eavesdropping, it is referred to as sniffing or snooping. This kind of eavesdropping is the \u00a0biggest security problem that administrators face \u00a0while \u00a0managing \u00a0the network. Eavesdropping can be avoided by using strong encryption services that are based on cryptography.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>3.2.\u00a0\u00a0\u00a0\u00a0 Data Modification<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">If an attacker gets access to someone&#8217;s data, the next logical step is to modify it. The smart attacker can even modify the data in the packet without the knowledge of the sender or receiver.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>3.3.\u00a0\u00a0\u00a0\u00a0 Identity Spoofing (IP Address Spoofing)<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The identity of a user on a network is through the IP address assigned to the user while login into the network. An IP address is a valid and unique identity which gives authorisation for a user. It is \u00a0possible \u00a0a smart attacker for an IP address to be falsely assumed, i.e. identity spoofing. An attacker can also use a special program to construct IP packets that appear to originate from valid addresses. After gaining access to the network with a valid IP address, the attacker can modify, reroute, or delete the data.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>3.4.\u00a0\u00a0\u00a0\u00a0 Password-Based Attacks<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">As discussed in network authentication, \u00a0a \u00a0user \u00a0is \u00a0getting \u00a0access through a password-based access control. Access rights to a computer and network resources are determined by the identity a user has normally a user name and \u00a0password.\u00a0<span style=\"text-align: initial;font-size: 1em\">When an attacker finds a valid user account and get the password, the attacker has the same rights as the real user. It will be very dangerous, if the user has administrator-level rights. In \u00a0such \u00a0cases \u00a0the \u00a0attacker gets full access right to do anything in the \u00a0system. \u00a0After \u00a0gaining access to a network with a valid account, an attacker can do any of the following:<\/span><\/p>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Obtain\u00a0\u00a0 lists\u00a0\u00a0 of\u00a0\u00a0 valid\u00a0\u00a0 user\u00a0\u00a0 and\u00a0\u00a0 computer\u00a0 names\u00a0\u00a0 and\u00a0\u00a0 network information;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Modify\u00a0\u00a0 server\u00a0\u00a0 and\u00a0\u00a0 network\u00a0\u00a0 configurations,\u00a0\u00a0 including\u00a0\u00a0 access controls and routing tables which is a very serious threat; or<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Modify, reroute, or delete \u00a0data.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>3.5.\u00a0\u00a0\u00a0\u00a0 Denial-of-Service (DOS) Attack<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Unlike a password-based attack, the denial-of-service attack prevents normal use of a computer or network by valid users. DOS attack is generally caused by flooding a computer or the entire network with traffic until a shutdown occurs due to overload. DOS can also cause blocking the traffic, which results in a loss of access to network resources by authorized users.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>3.6.\u00a0\u00a0\u00a0\u00a0 Man-in-the-Middle Attack<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Man-in-the-middle attacks are like someone assuming the identity of a user in order to read his\/her message. The person \u00a0on \u00a0the \u00a0other \u00a0end might believe it is you, because the attacker might be actively replying you to keep the exchange going and gain more information.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>3.7.\u00a0\u00a0\u00a0\u00a0 Compromised-Key Attack<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">A key is a secret code or number necessary to interpret secured information. After an attacker obtains a key, that key is referred to as a compromised key. An attacker uses the compromised key to gain access to a secured communication without the sender or receiver being aware of the attack. With the compromised key, the attacker can decrypt or modify data, and tries to use the compromised key to compute additional keys.<\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p><strong style=\"text-align: initial;font-size: 1em\">3.8.\u00a0\u00a0\u00a0\u00a0 Sniffer Attack<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><span style=\"text-align: justify;font-size: 1em\">A sniffer is an application or device that can read, monitor, and capture network data exchanges and read network packets. If the packets are not encrypted, a sniffer provides a full view of \u00a0the \u00a0data inside the packet. Even encapsulated packets can be broken open and read unless they are encrypted. Using a sniffer, an attacker can analyze the entire network and gain information \u00a0to \u00a0eventually \u00a0cause \u00a0the network to crash or to become corrupted.<\/span><\/p>\n<div>\n<p>&nbsp;<\/p>\n<p><strong>3.9.\u00a0\u00a0\u00a0\u00a0 Application-Layer Attack<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">An application-layer attack targets application servers by causing \u00a0a fault in the server&#8217;s operating \u00a0system \u00a0or \u00a0applications. \u00a0This \u00a0results \u00a0in the attacker gaining the ability to bypass normal access controls. The attacker takes advantage of this situation, gaining control of your application, system, or network for introducing a virus Program or introduce a sniffer Program or disable other security controls to enable future attacks. Virus, Trojan, Worms, Addware and Spyware generally belongs to active attacks and major threats to the security.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>4.\u00a0\u00a0 Virus<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">A virus is a computer program with malicious logic and replicate itself repeatedly over the network. Though Computer virus is working like a biological virus, i.e. enter into the computer without notice to the user of the system and spread to other \u00a0computers, \u00a0maintains \u00a0its \u00a0dormancy and keeps its polymorphic nature. The name is coined from Vital Information Resource Under Siege (VIRUS). Computer viruses are executable computer programs designed to replicate and damage the computer system without users&#8217; knowledge and permission. Computer virus gets activated on certain triggered conditions known as \u201cCatalyst\u201d. A computer virus program is logical activity and have its own mechanism to avoid detection by the user and activate on a particular time or occasion. Such viruses are called \u201cstealth viruses\u201d. The trigger could be a particular date for example Thursday 12th (Alias CD), Friday the 13th for Jerusalem Virus. Some time a code is\u00a0<span style=\"text-align: initial;font-size: 1em\">also embedded in some legislate programme, i.e. set to explore when certain conditions made and such viruses are called logical viruses.<\/span><\/p>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">A virus can affect operating system, computer files, data files, executable programs, bootable disk, hard disk partitions, \u00a0boot \u00a0sector etc. Generally, when it gets activated it can hide in RAM (Random Access Memory), Upper memory, High memory, TSR \u00a0(Terminate \u00a0and Stay Resident), MBR (Master Boot Record) extended and expanded memory. Viruses are categorized into boot sector \u00a0infectors \u00a0and program \u00a0file \u00a0infectors \u00a0(for example \u00a0.exe, \u00a0.doc, \u00a0.sys, \u00a0.dill, \u00a0.ovl, \u00a0.scr,.xa, .xls)<\/p>\n<p>&nbsp;<\/p>\n<p>Nature of following viruses and illegal activities on the network may be \u00a0learned from anti-virus web sites:<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Adware (advertising software)<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Armored viruses<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Benign virus<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Bomb virus<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Boot virus (boot sector virus)<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Botware<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Browser hijacker<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Companion virus<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Dialer (phone dialer)<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 FAT virus (File Allocation Table virus)<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 File deleting viruses<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Keyloggers<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Macro virus<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Malware (malicious software)<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Mass mailer viruses<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Memory resident virus<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Multipartite virus<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Multiple characteristic viruses<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Parasitic virus<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Polymorphic virus<\/p>\n<p>\u2022\u00a0\u00a0\u00a0 Programme virus<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Some of the viruses attack web servers and network managed programme and stop the legitimate user to access data from the server\u00a0<span style=\"text-align: initial;font-size: 1em\">by denial of service (DoS attacks) as discussed earlier. Zombi is an example of this type of virus. It is expected at least \u00a0100000 \u00a0viruses spread as on date. Use of proper anti-virus software, regular update on the signature of the new virus can prevent the system from virus attack. The virus cannot damage hardware such as keyboards, monitor, printer etc. On the detection of the virus this can be isolated from the normal programme such can be quarantine time.<\/span><\/p>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p><strong>4.1.\u00a0\u00a0\u00a0\u00a0 Trojan Horse<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Trojan Horse is a type of non-self-replicating type of malware programmes containing \u00a0malicious \u00a0code \u00a0which \u00a0carries \u00a0out predetermined actions based on the nature of Trojan. On execution it cost, loss or theft of data for slowing down the performance of the system. Trojan act as back-door entry programme gets dropped in a system without notice of the user. A trojan may also give \u00a0remote access to a hacker for the targeted computer systems. Harmful \u00a0trojan horse can damage system in many ways such as crashing the computer, data corruption, formatting disk, keystroke logging, deletion of files, data theft, perform automated spamming or denial-of-service attack, viewing user \u2019s webcam, modification of registry, downloading and installing third party malware etc.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>4.2.\u00a0\u00a0\u00a0\u00a0 Malware\/Spyware<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Now \u00a0a \u00a0days,\u00a0 \u00a0virus\u00a0 \u00a0can \u00a0also \u00a0get \u00a0attacked \u00a0to \u00a0data \u00a0files \u00a0such \u00a0as \u00a0.doc, .xls, .pps, .mdb, etc. Such viruses called \u201cMacros\u201d. Some of these viruses are polymorphic in nature which mutates and changes its identifiable codes with each infection. Macro viruses are generally independent &#8216;malware&#8217; programme which do not require any host. It replicates itself and spreads. In contrast to virus, some malicious programme do to replicate such programmes are called \u00a0\u201cTrojan Horses\u201d.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Spyware programme helps in gathering information \u00a0about \u00a0a \u00a0person and organisation without knowledge. Spyware is classified into four types: System monitors, Trojans, Adware and tracking cookies.<\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p><strong style=\"text-align: initial;font-size: 1em\">4.3.\u00a0\u00a0\u00a0\u00a0 Anti-Virus Programmes<\/strong><\/p>\n<div>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The threats like Virus, Trojan, Malware, Spyware, etc. can \u00a0be prevented by using anti-software from the popular vendors. Anti-virus software is a set of programme data designed to prevent, search for, detect and remove viruses and other malicious software like worms, trojan, adware, etc. These tools are critical at users level and has to be updated daily for the new inclusion of the viruses since more than 60,000 new pieces of \u00a0Malware \u00a0created \u00a0daily. \u00a0The\u00a0 Anti-virus programme perform basic functions like scan specific files of directories, allow scheduled scans automatically. Initiate scan for specific drive, folders, CD ROM, Flash Drives in any time. The infected files can\u00a0 be removed or quarantined to prevent the infection to other PCs.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Popular free anti-virus programs are AVG antivirus, Kaspersky, F Secure, and Avaste, and commercial software are Norton by Symantec, MaCafe, Trend Micro, eScan, Bitdefender, inoculate etc. It \u00a0depends upon organisation to choose the best product.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>5.\u00a0\u00a0\u00a0 Protection using UTM and Firewall<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">We have learned how to protect the computers against \u00a0unauthorised entry and also seen that whether a user is legitimate user or not with authentication. If unauthorised person can get access to a computer through network what she\/he can \u00a0do? \u00a0Such \u00a0unauthorized \u00a0or illegitimate users are called <strong><em>hackers<\/em><\/strong>. Hackers use the vulnerability on a system. There could be loopholes in any \u00a0software \u00a0which \u00a0allows \u00a0to open ports (open entry) for entering data or programmes into the system. Such loopholes are called vulnerabilities in a system. This generally happens with computer programmes installed on the system to get access to valid resources of the computer. The attack by \u00a0a hacker could be passive in nature by which hacker just eavesdrops on information without modifying it. On the other hand, an active hacker can modify the data or destroy the data.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Hacker can get into the resources once he gets into the system \u00a0and he\/she can work like any other normal user. This is one of the serious threats \u00a0in \u00a0the \u00a0network. \u00a0Hacking \u00a0attempt \u00a0is \u00a0there \u00a0in \u00a0every sectors \u00a0and\u00a0<span style=\"text-align: initial;font-size: 1em\">banking sector loses huge amounts of money every year because unscrupulous people try to get access to confidential information through hacking and once this information is with hacker, he can play around with data, including malpractices, \u00a0which he has with him.<\/span><\/p>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">A Hacker or an unauthorized user can get access to system by \u00a0any means. Computer programme generally works in \u00a0a system \u00a0by connecting to another system over the network so that it allows \u00a0to access data. These relations are called connections in \u00a0the \u00a0network. These connections are generally open through some ports. Since ports are open to create some of the connections, security on this connection are compromised and through these open connections, unauthorised people can also get access to the computer. Technically, it can be said that each programme has a port that is an open place in the computer, through the port only a programme can communicate. For example, suppose we have a database server with us. Database server works on a particular port to get connected so that this port can also get accessed by a user or a network expert and he \u00a0can \u00a0launch \u00a0some \u00a0of \u00a0the programmes through the same open port. There are more \u00a0than \u00a065000 ports which get opened on a system and some of them automatically open for services at the time of booting. A hacker can try to get access through this port into the computer and the process is called hacking attempt.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-65 aligncenter\" src=\"http:\/\/lisp5.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/10\/2018\/07\/hacking-attempt.png\" alt=\"\" width=\"650\" height=\"414\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-content\/uploads\/sites\/10\/2018\/07\/hacking-attempt.png 650w, https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-content\/uploads\/sites\/10\/2018\/07\/hacking-attempt-300x191.png 300w, https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-content\/uploads\/sites\/10\/2018\/07\/hacking-attempt-65x41.png 65w, https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-content\/uploads\/sites\/10\/2018\/07\/hacking-attempt-225x143.png 225w, https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-content\/uploads\/sites\/10\/2018\/07\/hacking-attempt-350x223.png 350w\" sizes=\"auto, (max-width: 650px) 100vw, 650px\" \/><\/p>\n<\/div>\n<div><\/div>\n<div style=\"text-align: center\">Fig.1: Hacking Attempt<\/div>\n<p>&nbsp;<\/p>\n<div>\n<p class=\"indent\" style=\"text-align: justify\">This is a very serious security threat as whatever activities \u00a0a \u00a0user \u00a0is doing can be monitored as a spy or data can be sent to another website without notice of the user. It is also possible that whatever key a user is typing, it can be sent to a web site without knowledge of the user. This is possible by launching some of \u00a0the \u00a0programme \u00a0by \u00a0the \u00a0hacker into the system. Hence hacking threat on individual system as well as network is to be detected, network has to be monitored always for this kind of attempt on the server. There are sophisticated programmes called IDS (Intrusion Detection System) which are part of firewall which takes care of such attempts. Implementing Firewall and UTM appliances (Unified Threat Management Systems) in network can prevent many threats.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">As shown in figure, network is created with many devices such as PCs, Mobile, Laptops, servers and other network devices. Once connected, the same machine\/devices can launch an attack. Firewall creates a virtual protection mechanism to protect the network. Unauthorised attempts with data or traffic will be discarded by the firewall, if it is not through the known ports. Firewall protects the network against all sorts of known attacks and threats. Appliance based Firewall with Gateway level Anti Virus scanning can protect \u00a0spreading \u00a0of \u00a0viruses over the network. Spam Filtering in UTM can check for data whether it is a spam or \u00a0not. \u00a0Intrusion \u00a0Detection\/Prevention \u00a0System \u00a0monitors the unauthorised entry into the \u00a0network \u00a0and \u00a0prevent \u00a0it. \u00a0Firewall \u00a0also has the facilities for bandwidth management, web content filtering, anti-phishing, load balancing, DNS resolution, \u00a0creation \u00a0of \u00a0proxy server, DMZ support etc.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">This can be explained in detail by \u00a0using \u00a0the \u00a0following \u00a0diagram \u00a0that how a server and client is connected to share data. As it is seen in the diagram the PCs used by a user on the Internet \u00a0will \u00a0be \u00a0acting \u00a0as \u00a0a client and he\/she will try to access the \u00a0information \u00a0from \u00a0the \u00a0server (web server) through the \u00a0network. \u00a0The \u00a0server \u00a0will \u00a0push \u00a0the information based on request to the client\u2019s or user \u2019s \u00a0computer. \u00a0If there is no security between the user and server, \u00a0the \u00a0server \u00a0can \u00a0get direct access to the PC as well as the PC can also get direct access to server. The traffic will as well as nature of data will not be monitored in an unprotected environment.<\/p>\n<\/div>\n<div><\/div>\n<div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-66 aligncenter\" src=\"http:\/\/lisp5.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/10\/2018\/07\/firewall.png\" alt=\"\" width=\"685\" height=\"323\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-content\/uploads\/sites\/10\/2018\/07\/firewall.png 685w, https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-content\/uploads\/sites\/10\/2018\/07\/firewall-300x141.png 300w, https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-content\/uploads\/sites\/10\/2018\/07\/firewall-65x31.png 65w, https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-content\/uploads\/sites\/10\/2018\/07\/firewall-225x106.png 225w, https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-content\/uploads\/sites\/10\/2018\/07\/firewall-350x165.png 350w\" sizes=\"auto, (max-width: 685px) 100vw, 685px\" \/><\/p>\n<div style=\"text-align: center\">Fig.2: Firewall<\/div>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Firewall plays a role to protect the network where servers \u00a0are connected. In organizational level, \u00a0this \u00a0protection \u00a0can \u00a0be \u00a0introduced by using a checkpoint between the user and outside network. Such check\/verification point is called firewall. Firewall is an intermediary layer which can be software or hardware or appliances, \u00a0which \u00a0can reside in between the user and outside network. Any request which go through this equipment will be scanned and filtered for the content at the firewall level. Firewall is also added \u00a0as \u00a0filtering mechanism \u00a0for data through filtering gateways between the user and the outside network. It is essential that if one host the content in a network, then the hosting server is to be protected from outside world. For example, as shown in diagram, if an institution host web server, network admin need only to open the port which are required for accessing web service For example 8080 is a port number for Tomcat and 80 is port number for website. In general when a user type http: \/\/ URL, then by default, the request comes through the port number 80. If he is using any other web server like tomcat, it will be through 8080. \u00a0If \u00a0the hosting is done using web server, one need to open only two or three ports. All other ports than these 3 ports has to be \u00a0blocked. \u00a0Firewall works based on this principle. \u00a0Firewall \u00a0blocks \u00a0all \u00a0the \u00a0ports \u00a0and network admin has to open the valid port(s) for the user. As it is seen in the diagram, first deny all connections and allow only connections which are required for use.<\/p>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p><strong>6.\u00a0\u00a0\u00a0 DMZ for hosting and IDS<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">In an organization, restriction on the server can be established by creating a special zone. First, allow only known used ports from the system which is to be used for service. In this context, there is an area in a normal network with a &#8216;<strong>de militarized zone&#8217; (DMZ) <\/strong>which means to militarize the complete zone by denying all connections and allow only the known connections\/ programmes to access the resource. Any other attempt to access can be stopped at the firewall level as shown in programme. In addition to stopping \u00a0such \u00a0request, \u00a0a \u00a0firewall \u00a0can \u00a0also act as a tool for the content filtering or \u00a0even \u00a0restricted \u00a0access \u00a0to content (for example Child sites restriction). Firewall blocks unauthorized network connections to the PC or local area networks including the server if a user is hosting services in the public domain. A firewall can also act as an I<strong>ntru<\/strong><strong>sion Detection System <\/strong>(IDS) which is a very common term used in network security to check any unauthorized entry into the system.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Any attempt by a hacker for passive as well as active intrusion has to be monitored and detected. There are many popular \u00a0firewalls \u00a0which have the facility for IDS as well as IPS i.e.. Intrusion Prevention System. Thus, the; firewall will function for checking each and every connection request even at the content level. Some of the programmes can also carry harmful content and need to be filtered before it enters into the system. In addition to protection, firewall can also act \u00a0as \u00a0a &#8216;proxy&#8217; for sharing common Internet connection to many users. UTM equipment can also filter content,\u00a0 act \u00a0as \u00a0load \u00a0balancing \u00a0between Internet connections from various ISPs, \u00a0or \u00a0authentication \u00a0mechanism for users for proxy. Now a days, all vendors come out with firewall products, which works as single UTM (Unified Threat Management system) so that UTM box or appliance available in the market can be procured directly and implement it in a network and configure the network so that every Internet connection or local connection for accessing outside or the internal data can be routed the traffic through this UTM (firewall). Some of the popular names of firewall\/UTMs available in the market are Fortigate<strong>, <\/strong>Sonicwall, \u00a0Cyberoam \u00a0etc. Firewall can filter the content \u00a0as \u00a0mentioned \u00a0earlier, \u00a0which \u00a0can \u00a0check the port number through which a programme is \u00a0trying \u00a0to \u00a0access \u00a0and deny \u00a0any \u00a0kind \u00a0of \u00a0access \u00a0based \u00a0on \u00a0defined \u00a0rules.\u00a0 \u00a0Another \u00a0important\u00a0<span style=\"text-align: initial;font-size: 1em\">threat is that many users try to continuously connect to a single server at same time which is also a kind of attack on the network.<\/span><\/p>\n<\/div>\n<div>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Since many organisations have limited network resources like bandwidth, etc. proxy server can be used. \u00a0Proxy \u00a0servers \u00a0are vulnerable for DoS attacks. Suppose one network can accommodate 10000 users congruently at a time, an attempt by over 100000 users try to access the same server, the network will definitely chock \u00a0due \u00a0to heavy traffic which will lead to one of the threat like denial of service attack. Firewall can protect these kind of attacks for chocking the network by the hacker by monitor the flooding (UDP as well as ICMP). These are other kind \u00a0of \u00a0programmes \u00a0created \u00a0by \u00a0the unauthorised persons who generally does not seriously work for resources access but just for spying the information. These attacks can be classified as passive attack and active attack. In passive attack, people will be getting into a system to \u00a0know \u00a0what \u00a0is \u00a0available. \u00a0It \u00a0is kind of eves dropping, release of message content, traffic analysis etc and active attack, the hacker will also get into the system and modify the data, masquerading, replay, denial of service and alter data without giving any hint of change. Some people argue that ethical hacking is permitted, but cracking of a server is not permitted. Both ways, this kind of activity is a crime under \u00a0the \u00a0IT act. A person \u00a0should \u00a0not \u00a0get into the some&#8217;s server without someone\u2019s asking permission. This kind of attack can be stopped by using suitable firewall rules.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Few products are named as solutions for antivirus, trojans, spyware, adware and other kind of threats. Firewall can be implemented as software programme also (for eg in Linux, IP table) \u00a0in \u00a0addition \u00a0to using as an equipment. This way firewall can take a shape of software as well as hardware and if software in the system, it comes along with the operating system where the firewall has to be enabled. It depends upon the user to prevent his system from external attack as well as internal attack. If the security is compromised at user level and organisation may not be aware who is using the resource since hacker generally will not reveal the identity. If an organisation is not protecting their system, it will not only damage but it will also work as platform for others to attack. It is important to take care of security of computer systems, information, data as well as network so that user will \u00a0enjoy seamless access to information world.<\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p><strong>7<\/strong><strong>.\u00a0\u00a0\u00a0 Summary<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Proper network security can be \u00a0implemented \u00a0by \u00a0formulating\u00a0 very strong policy for the user as well as for the organisation with proper network\u00a0 \u00a0security\u00a0 \u00a0devices.\u00a0 \u00a0The\u00a0 \u00a0UTM\u00a0 \u00a0(Unified\u00a0 \u00a0Threat Management) appliances integrate \u00a0many \u00a0security \u00a0protection \u00a0features in systematic security implementation. \u00a0Restriction \u00a0on \u00a0the \u00a0user \u00a0is always required in the organization to protect network from local threats. Use of proper antivirus software on individual PCs as well as gateway level protection against virus attacks is to be strictly implemented. Use of pendrives, flashdrives,CDs, DVDs, and other storage devices plugging directly into PC is to be strictly monitored. As per the IT Act, log records are to be created for each network activity as well as Internet usage in organization. All users should be given an individual user account with authentication and user privileges. Network security should be treated as an organization culture where ethical use of services is to be followed religiously.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>8.\u00a0 References<\/strong><\/p>\n<ol>\n<li><a href=\"http:\/\/www.webroot.com\/in\/en\/home\/resources\/tips\/pc-security\/security-what-is-anti-virus-software\">htt p:\/ \/ w w w. w e broot. c om\/ i n\/e n\/home \/ r e s ourc e s \/ t i ps\/ pc- <\/a><a href=\"http:\/\/www.webroot.com\/in\/en\/home\/resources\/tips\/pc-security\/security-what-is-anti-virus-software\">s e c uri t y \/ s e c uri t y &#8211; wha t &#8211; i s &#8211; a nti &#8211; vir us- s o ftw are<\/a><\/li>\n<li style=\"text-align: justify\">An\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 information\u00a0\u00a0 Security\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Handbook,\u00a0\u00a0\u00a0 By\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 John\u00a0\u00a0\u00a0 M\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 D\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Hunter\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 , Springer Publication<\/li>\n<\/ol>\n","protected":false},"author":4,"menu_order":7,"template":"","meta":{"_acf_changed":false,"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":["mr-manoj-kumar"],"pb_section_license":""},"chapter-type":[],"contributor":[63],"license":[],"class_list":["post-64","chapter","type-chapter","status-publish","hentry","contributor-mr-manoj-kumar"],"part":3,"_links":{"self":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-json\/pressbooks\/v2\/chapters\/64","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-json\/wp\/v2\/users\/4"}],"version-history":[{"count":5,"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-json\/pressbooks\/v2\/chapters\/64\/revisions"}],"predecessor-version":[{"id":330,"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-json\/pressbooks\/v2\/chapters\/64\/revisions\/330"}],"part":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-json\/pressbooks\/v2\/parts\/3"}],"metadata":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-json\/pressbooks\/v2\/chapters\/64\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-json\/wp\/v2\/media?parent=64"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-json\/pressbooks\/v2\/chapter-type?post=64"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-json\/wp\/v2\/contributor?post=64"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/lisp5\/wp-json\/wp\/v2\/license?post=64"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}