Jumat, 11 Juni 2010

OSI

OSI reference model of open network or OSI Reference Model for open networking is a network architectural model that was developed by the International Organization for Standardization (ISO) in Europe in 1977. OSI itself is an acronym of the Open Systems Interconnection. This model is also called the model "seven layers of OSI Model" (OSI seven layer model).

Before the emergence of the OSI reference model, a computer network system depends on the supplier (vendor). OSI tries to form a general standard computer networks to support interoperatibilitas between different suppliers. In a large network there are usually many different network protocols. The absence of a similar protocol, making many devices can not communicate with each other.
This reference model in awalnnya intended as a basis for developing network protocols, despite the fact that this initiative had failed. The failure was caused by several factors:

This standard reference model, as compared with the reference model of DARPA (the Internet model) developed by the Internet Engineering Task Force (IETF), very close together. DARPA model is the base model of TCP / IP protocol that is popular.
This reference model is considered very complex. Some functions (such as connectionless communication method) is considered not good enough, while other functions (such as flow control and error correction) are repeated in several layers.
The growth of the Internet and TCP / IP (a real-world network protocol) to make the OSI Reference Model became less attractive.
The U.S. government tried to support the OSI Reference Model protocol in the government network solutions in the 1980s, with the implementation of some standard called Open Systems Interconnection Profile Government (gossip). Nevertheless. This effort finally abandoned in 1995, and implementation of networks using the OSI Reference model is rarely found outside Europe.

OSI Reference Model was eventually seen as an ideal model of logical connections that have to happen for data communication in a network can take place. Some of the protocols used in the real world, a kind of TCP / IP, DECnet and IBM Systems Network Architecture (SNA) to map the protocol stack (protocol stack) them to the OSI Reference Model. OSI Reference Model was used as a starting point to learn how some network protocols in a set of protocols can function and interact.

OSI Reference Model has seven layers, namely the following
Layer to layer-Name Description
7 Application Layer
Functioning as an interface with applications with network functionality, govern how applications can access the network, and then make the error messages. Protocols that are in this layer is the HTTP, FTP, SMTP, and NFS.

6 Presentation Layer
Serves to translate the data to be transmitted by the application into a format that can be transmitted through the network. Protocols that are in this level is redirektor software (Redirector software), such as the Workstation service (in Windows NT) and Network shell (such as Virtual Network Computing (VNC) or Remote Desktop Protocol (RDP)).

5 Session Layer
Serves to define how connections can be created, maintained, or destroyed. In addition, at this level is also performed name resolution.
4 Transport Layer
Serves to break down data into packets of data and to provide serial numbers to the packages so it can be rearranged on the side of the goal after receipt. In addition, at this level also makes a sign that the packet is received successfully (acknowledgment), and re-transmits terhadp packages lost in the middle of the road.
3 Network Layer
Serves to define the IP addresses, create a header for the packets, and then make internetworking routing through routers and switches using Layer-3.

2 Data-link layer
Befungsi to determine how the bits are grouped into a format called a frame. In addition, at this level error correction, flow control, addressing hardware (such as Media Access Control Address (MAC Address)), and determining how network devices such as hubs, bridges, repeaters, and Layer 2 switches operate. IEEE Specification 802, divide this level into two levels, that is, layers Logical Link Control (LLC) and Media Access Control layer (MAC).

1 Physical layer
Serves to define the network transmission media, signaling method, synchronization bits, network architecture (such as Ethernet or Token Ring), network topology and pengabelan. In addition, this level also defines how the Network Interface Card (NIC) can interact with the media, cable or radio.
Read more..

Steps to Building a firewall

1. Identify owned network form
Knowing the particular form of networks owned toplogi that is in use
and network protocols, will facilitate in designing a firewall
2. Determining Policy or policies
Policy Determination or Policy is a matter that should be doing, good or
poor in the wake of a firewall that is determined by policy / policy
that apply. Among them:
- Determining what needs to serve. That is, what will be
subject to policy or the policy that we will create
- Defining individuals or groups to be charged
policy or that policy
- Determining which services are needed by each individual or
group using the network
- Based on each service that is in use by individuals or groups
will be determined how best configuration that will
makes it even more safe
- Implementing all the policy or that policy
3. Setting up the software or hardware that will be used
Both the operating system that supports or special software support
firewall such as ipchains, or iptables on Linux, etc.. And hardware configuration
that will support the firewall.
4. Configuration test
Tests on the firewall that has been completed in the wake must be done,
especially to know the results we will get, how can
using the usual tools tools such as nmap to audit.
• Bastion Host is a system / part are considered the strongest in the system
by administrator.atau network security can be at the forefront of the blind
considered the most powerful in keeping the attack, thereby becoming part
important in securing a network, usually a firewall component
or the outer portion of the public system. Bastion host will generally use
The operating system that can handle all the needs (eg, Unix, Linux, NT)
Read more..

Firewall Configuration

1. Screened host firewall system (single-homed bastion)
In this configuration, the firewall function will be performed by a packet filtering router
and the bastion host *. This router is configured such that for all
flow data from the Internet, only the IP packet toward the bastion host are allowed.
While for the data flow (traffic) from the internal network, only IP packets from
bastion hosts that are allowed to exit. This configuration supports
fleksibilitasdalam Internet access directly, for example if there are
web server on the network can be configured so that the web server can
accessed directly from the Internet. Bastion Host performs authentication and
function as a proxy. This configuration provides a better level of security
better than packet-filtering router or an application-level gateway
separately.
2. Screened host firewall system (dual-homed bastion)
In this configuration, there will be a physical fault / gaps in the network.
The advantages is the existence of two paths which are physically so separete
will further enhance security configuration than the first, as for for
servers that require direct access (direct access) then it can be in
put in place / segmenrt directly connected to the internet. This
can be done by using two pieces NIC (network interface card)
on the bastion host.
3. Screened subnet firewall
This is the highest configuration level of security. why?
because in this configuration is in use two pieces of packet filtering router, first among
Internet and the bastion host, while a longer Bastian between host and local network
This configuration forms an isolated subnet.
The advantages are:
- There are three layers / levels of defense against penyususp / intruder.
- Router to serve out only the relationship between the Internet and the bastion
hosts so that local networks become invisible (invisible)
- The local network can not direct routing
construct
Internet, or in other words, the Internet becomes Invinsible (not
means can not make an internet connection).

Read more..

Firewall

A firewall is a way or mechanism that applies both to the
hardware, software or the system itself. The purpose of the use of a firewall is
to protect by filtering, limiting, or even reject any or all
relationships or activities of a segment on a private network with external network that is not
is the scope. These segments can be a workstation,servers, routers, or a local area network (LAN). Simply put, the firewall configuration
are as follows:
pc <==> firewall <==> internet

The first time, firewall to the computer by using the principle
"Non-routing" on a Unix host that uses two pieces network interface card,
The first network interface card to connect to the Internet (other network) while
others connected to the pc (with the note did not happen "route" between the two
network interface card in this pc). To be able to connect to the Internet, should be
entering the firewall server (can be remote, or directly), then use
existing resources at this computer to connect to the Internet (other network)
and if necessary to save the file / data, then the file can be stored temporarily on your pc
mengkopikannya your firewall and then to pc. Thus, the Internet can not
directly related to the pc. Such methods have many
shortages that developed in various shapes, configurations and types of firewalls
with various rules in it. Firewalls are generally reserved for
serving:
1. Machinery / ComputerEach machine / computer that is connected directly to the external network or the internet
and wants all contained on their computers protected.
2. Network
Computer network consisting of more than one computer and various types of
network topology is used, whether owned by companies, organizations
and so forth.
Characteristics of a firewallIn general, the characteristics of a firewall can be explained as follows:
1. The whole relationship / activities from inside to outside, must pass through the firewall. This
can be done in a way to block / restrict all access to network
local, except when passing the firewall. Many forms of network
This configuration allows to materialize.
2. Only the activities listed / known that can pass / make relationships,
this can be done by setting the local security policy on the configuration.
3. Firewall itself should be relatively immune or strong against attacks / weaknesses. Case
this means the use and reliable system with which system
relatively safe.
Techniques used by a firewall1. Service control (control of the service)
Based on the types of services used on the Internet and can be accessed either
for into or out of the firewall. Usually the firewall will check the IP number
Address and port number that is in use both on TCP and UDP,
can even be equipped with software for proxy which will receive and
translates every request for a service before it allows it.
2. Direction Conrol (control of direction)
Under the direction of the various requests (request) to the services that will
recognized and permitted through the firewall.3. User control (control of the user)Based on user / user to be able to run a service, meaning there
existing users who can and who can not run a service, this in
karenakan user is not allowed to pass through the firewall. Usually
used to restrict users from the local network to access the exit,
but it can also be applied to restrict the user from the outside.
4. Behavior Control (control over their treatment)
Based on how many services have been used. For example, a firewall
can filter the email to address / prevent spam.Firewall Types1. Packet Filtering Router
Packet filtering is applied in a way better manage all the IP packet
towards, past or will be addressed by the packet. In this type of packet
will be regulated or whether to be received and forwarded or rejected.
Packet filtering is configured to filter the packet that will be
transfer in both directions (both from and to the local network). Filtering rules
based on the IP header and transport header, which also includes the beginning address (IP)
and destination address (IP), transport protocol used (UDP, TCP), as well as
port number used. The advantages of this type is easy to
implemented, transparent to users, relatively faster.
The weakness was quite complicated to set its package to be
appropriately filtered, and the weak in terms of authentication.
The attacks that can occur in this type of firewall are:
- IP address spoofing: Intruder (intruders) from the outside can do
This in a way to include / use the ip address of local network
which has been allowed to go through a firewall.
- Source routing attacks: This type is not to analyze the routing information
source IP, making it possible to bypass a firewall.
- Tiny fragment attacks: Intruder IP divide into parts
(Fragments) which are smaller and forcing the division of information
about the TCP header. This type of attack designed to deceive
filtering rules that depend on information from the TCP
header. Striker hoping only part (fragment) only the first
which will be examined and the rest will be able to pass freely. Case
This can be in tanggulangi by refusing all packets with
TCP protocol and had Offset = 1 in the IP fragment (the IP)
2. Application-Level Gateway
Application-level Gateway is also commonly known as a proxy server
serves to reinforce / deliver the application flow. This type will be set
all relations that uses the application layer, whether it is FTP, HTTP,
Gopher etc.How it works is if there are users who use one application
such as FTP to access remotely, the gateway will prompt the user
enter the address of the remote host to be accessed. When a user submits
useer ID and other information according to the gateway will perform
relation to the application found on the remote host, and
data channel between the two points. if the data is not appropriate then
firewall will not forward such data or reject it. Furthermore,
on this type of firewall can be configured to only support some
application only and reject other applications to pass through the firewall. Excess
is relatively more secure than the type of packet filtering router is easier to
checks (audits) and records (logs) all incoming data streams at the level
application. The drawback is the excessive additional processing at every
relationship. which will result in a connection there are two connections
between the user and the gateway, where gateway will check and forward the
all flows from two directions.


3. Circuit-level Gateway
This third type can be a stand-alone system, or can also
is a special function which is formed from the type of application-level gateway.tipe
This does not allow TCP connections end to end (direct)
How it works: Gateway will arrange a second TCP connection, the first between
his will (i) with TCP on the local user (inner host) and a longer between
his will (i) with TCP outside users (outside the host). When two relations
materialize, the gateway will deliver TCP segments from one relationship to the
other without examining its contents. Lies in the determination of its security functions
Which relationship on the permits. Use of this type are usually driven
administrators believe with internal users (internal users).



Read more..

iklan,,klik me..

Blog Terkait