Remote Access & Security Technology Overview Medizinische Technik Erlangen Markus Feeß Netze / Sicherheit SGK 2 1
John and the broken leg - Part I Archiv A? B C 2
WAN Technologies GSM Global System for Mobile Communications POTS Plain Old Telephon Service ISDN Integrated Services Digital Network DDV Datendirektverbindung xdsl Digital Subcriber Line GAN ATM Global Area Network Asynchronous Transfer Mode 3
GSM Global System for Mobile Communications Irda GSM POTS Derzeit: max 9600 bits/sec Ende 99: HSCSD (HighSpeed Circuit Switched Data) mit 28,8kbps - eplus Mitte 00: GPRS mit 9,6... 115kbps variabel 02: UMTS (Universal Mobile Telecommunications System) bis zu 2 Mbps 4
Digitale Datenverbindung DDV Only one partner Deutsche Telekom: e.g. D64S, D64S2 6
DK Konfigurator 8
DK Konfigurator 9
10
Bandwidth hungry Online/ Internet and Business services Entertainment Movies Transaction Services Homebanking ShopStop Fast Internet LAN connection Games What you need... Interactive Learning... your existing telephone line and a PC. Teleworking e.g. Joint Editing News 11
14
Security Policy RFC 2196 http://ds.internic.net/rfc/rfc2196.txt Maintain a written Policy 16
Ausgewogenheit Connectivität Performance Transparenz Authentication Authorization Accounting Verfügbarkeit Vertraulichkeit Zugang Sicherheit 17
18
Router / Network Security Access Control Closed Usergroup (Germany: GBG) Calling Line Identifikation Callback CHAP / PAP Packet Filter Not released! Encryption Radius Server 19
20
Encryption Router / Network Security IOS (3620/40) - 56 Bit Key DES Babylon - 128 Bit Key DES Not released! Modem Encryption Not compatible because of missing standards 21
Kosten / Zeitaufwand zum Hacken der DES Schlüssel Type of Attacker Budget 40-Bit 56-Bit 168-Bit 3DES Individual Hacker $400 5 Hours 38 Year Too Long Dedicated Hacker $10,000 12 Minutes 556 Days 10 19 Years Intelligence Community $10m 0.02 Sec 21 Minutes 10 17 Years Source: Blaze et al, Scheiner 1996 22
Ebenen der Verschlüsselung Application- Layer Application Headers im Klartext Network-Layer Netzwerk- und Transport Header im Kartext Application-Layer Encryption Network-Layer Encryption SSL IOS Encryption Link-Layer Datalink Header im Klartext Link-Layer Encryption Link-Layer Encryption 24
25
Security Architecture - IPsec RFC 1825 beschreibt die Architektur Bietet sich an für: Authentifizierung Privacy unterstützt IP Version 4 und IP Version 6 herstellerunabhängige Verschlüsselung 26
27
Protokollstack Firewall (proxy) intern Application Presentation Session Transport Packetfilter Network Physical Data-Link IPFORWARDING = 0 extern 28
Zweistufiges Firewall Design extern Internet nur von innen nach außen intern kontrollierter Zugang über Screening Router (Access Control Lists) Public WWW Public FTP Server in DMZ DNS Mail Intranet 29
VPDN (Virtual Private Dialup Network) ATM Encrypted VPN Workgroup IBM Core Intranet Home Gateways ISP Virtual Private Dialup Network 31
John and the broken leg - Solution Video Live 200 Archiv Bingo A 4/8 S 0 S 0 ISDN 4/8 S 0 Cisco 3620/40 B Cisco 3620/40 Video Live 200 C 32