您好,欢迎访问三七文档
当前位置:首页 > 商业/管理/HR > 管理学资料 > 淘宝怎么延长收货时间
April,2006StanfordCleanSlateSeminarAProtectionArchitectureforEnterpriseNetworks(andcommentsonsecurity-centricnetworkdesign)MartinCasado(Stanford)TalGarfinkel(Stanford)AdityaAkella(CMU/Stanford)MichaelFreedman(NYU)DanBoneh(Stanford)NickMcKeown(Stanford)ScottShenker(ICSI/Berkeley)淘宝网’mGoingtoTalkAboutAlotaboutsecurityintheEnterpriseAlittlebitaboutsecurityontheInternetGenerallyexploitthisopportunitytopontificateApril,2006StanfordCleanSlateSeminarPublicvs.PrivateNetworksPublic(google,ebay,stanford.eduetc.)Getaswideexposure(mostly)everyonewelcomeWantsomeprotectionfromevil-doersPrivate(internalcommercial,financialetc.)SpecialpurposeLimiteduserbaseKnowswhat’srunningwhereFundamentallydifferent(butusesametechnologies)April,2006StanfordCleanSlateSeminarAbilitytoidentifyindividualusersAbilitytorevokeaccesstoindividualusers(stopthemfromusingyournetworkresources)Abilitytodeterminelocationofindividualusers(regulatorycompliance)(moreonthislater)InfrastructureSupportforPublicServicesApril,2006StanfordCleanSlateSeminaridentifyindividualusersbyuseridrevokeaccesstousersdeterminelocationofindividualusersandstrictlydefineconnectivitybetweenusers,hosts,services,protocolsandaccesspointscontrolroutesatthesessionlevelcentralizedtrustandcontrolrestrictaccesstoinformationInfrastructureSupportforPrivateNetworksApril,2006StanfordCleanSlateSeminaridentifyindividualusersbyuseridrevokeaccesstousersdeterminelocationofindividualusersandstrictlydefineconnectivitybetweenusers,hosts,services,protocolsandaccesspointscontrolroutesatthesessionlevelCentralizedtrustandcontrolRestrictaccesstoinformationSupportedbyIPApril,2006StanfordCleanSlateSeminarMotivationPunchLineAttemptingtodoallthesethingstoday…butwithoutthesupportofthearchitectureResultis:InsecurenetworkInflexiblenetworkHardtomanagenetworkApril,2006StanfordCleanSlateSeminarDefiningConnectivityWhy?AttemptatlimitingresourcestothatwhichisneededLimitdamageofinternalmalware,perimeterbreach,orinsiderToday:UselotsoffilteringMAC,IP,transportPhysicalports(VLANs)Deeppacketinspection(e.g.firstdatapacketofaprotocol)FullproxiesAccesscontrollistsonservices(notnetworkaware…butcouldbe!)April,2006StanfordCleanSlateSeminarDefiningConnectivity(thebad)NetworkonlyreallyawareofaddressesFirewallrulesembedstopologyintoconfigurationstateDifficulttomovemachinesHardtoreadandunderstand(100klinesofproprietary,differentconfigurations)ForwardingpathunawareoffilteringrulesWilltrytocircumventifitcanAddinganewnetworkcomponentnotgood(hencehave“choked”networks)Higherlevelfilteringcanbeunderminedbylowerlevels(e.g.permissivelinklayer)April,2006StanfordCleanSlateSeminarControlOverRoutingWhy?Differentaccesspointshavedifferentsecurityrequirements(e.g.wirelessusersmustgothroughhttpproxy)Differentprotocolshavedifferentsecurityrequirements(e.g.allfilessentoverIMmustbecheckedforviruses)Differentusergroupshavedifferentsecurityrequirements(e.g.logallconnectionsfrommarketing)Today:makeallroutesgothroughthesamepoint(large,expensivedo-it-allproxies)Orusetwo/three/fourseparatenetworksOrapplicationprotocolawarerouting(CiscosOER,applicationawarerouting)April,2006StanfordCleanSlateSeminarCentralizedTrustandControlWhy?LimitednumberoftrustedcomponentsNetworksoftencentrallyadministeredPrettynewarea,butproductsarestartingtopopupConsentryApaniSecurifyNetworksbynaturearedistributedDistributedroutingcomputation(trusteveryrouter)Many(manymany)heavilytrustedcomponents(DNS,DHCPserver,gateway,routers,switches,end-hosts,directoryservices,authenticationservices,proxiesetc.)April,2006StanfordCleanSlateSeminarRestrictAccesstoInformationWhy?(firstresourceavailabletoattacker)Turnoff(normallyfilterathostorperimeterfirewall)RSTICMP(TTLTimeexceeded,echoreply,portunreach)DetectARPscansAutomatedIPscansLimitvisibilitynetworkresourcesVLANNATs,Proxiesetc.Stillreallyhardtodo(e.gTopologyinformationpassedunencryptedinroutingprotocols)No“switch”forauditing(shouldbecontrolledthesameasotherresources)April,2006StanfordCleanSlateSeminarRetrofittingSecurityontoIPDesignedforSecurityFirewalls,RouterACLSPortSecurityIDS/NDS/IPS(scandetection,anomalydetection,signaturedetection)VLANsPushedIntoServiceEthernetSwitchesNATs,ProxiesPhysicalDatalinkNetworkTransportApplicationApril,2006StanfordCleanSlateSeminarInflexibleHardtomoveamachine(yetdifficulttoknowifsomeonehasmoved)ReallydifficulttodeployanewprotocolBrittleChangeafirewallrule,breaksecuritypolicyAddaswitch,breaksecuritypolicyConfusingManydisparatepointsolutionsState=abunchofsoftstateHardtostatemeaningfulpoliciesLoseredundancyIntroducechokepointsCan'tmigrateroutesb/cofallthesoftstateCommonSolutions=CrummyNetworks(andmediocresecurity)April,2006StanfordCleanSlateSeminarLetsStartfromScratchLeveragecharacteristicsuniquetoEnterpriseCentrallymanagedKnownusersStructuredconnectivityReducenumberoftrustedcomponentsSimplifypolicydeclarationRetainflexibilityandredundancy(de
本文标题:淘宝怎么延长收货时间
链接地址:https://www.777doc.com/doc-735069 .html