I have paper that need modifications below and I need this in 8 hours
2
Running Head: Network Design and Plan
Residency Weekend Paper for WEEK 5
Telecomm Network Security (ISOL-532-M30) - Full Term
Navaneeth Kumar Gundlahalli Venakteshappa
Kiran Singh Thakur
Sai Sourabh Gujja
Ashok Kumar Endla
University of Cumberland’s
Dr. Raed Omar Sbeit
September 27, 2020
Project Part 1: Network Survey
PCAP data provides the happening on the company's networks. It is appropriate to have the power towards drilling into a network as well as application layers. There are multiple products, which offer one a deeper acquaintance contained within a complete packet capture and session analysis. Again, the internet provides unprecedented anonymity sense as well as invulnerability towards the criminals. These happened to the in-terrorism planning, fraud committing, pirating software, performing corporate espionage, and distributing controlled substances. Again, this happens when it comes to child pornography trafficking, and many more. In most cases, it is a huge predicament, and one needs to know the appropriate tools to employ. This assists in data collection required for the case otherwise avert issues within the first place.
Additionally, the need for a proficient security feature within the institution (Corporation Tech) is critical. According to the scan which took place using the NetWitness Investigator, there are multiple vulnerabilities inside the Corporate Tech systems, and such loopholes need to be sealed. NetWitness Investigator is a security tool that helps institutions deal with sensitive information to identify loopholes within their defense systems. NetWitness, a forensic tool, is widely used to investigate the company's possibility of being attacked with malwares from other hosts. The NetWitness also gives accounts or reports of bags in the system. all malicious activities within the system are detected and noted by the NetWitness Investigator tool. NetWitness Investigator tools also help in preventing cybersecurity threats, fraud, and aids in IT audit investigations.
It is also important to note that NetWitness Investigator is easy to use and, at the same time, portable. The tool forensically collects all information in the institution's website without bypassing any traffic details (whether significant or insignificant). NetWitness Investigator uses segmentation to help in preventing risks such as unauthorized access to the organization's infrastructure. There are three layers of security network covered by the NetWitness Investigator. The layers, as mentioned above, include the Demilitarized Zone, internal and external system
The hosts within the Corporation Techs' network include
· besespecially.com (4)
Service:53 (UDP / DNS)
· protectedreally.com (3)
Service:53 (UDP / DNS)
· definitelyfriendly.com (3) –
Service:53 (UDP / DNS)
· bestremarkably.com (3) –
Service:53 (UDP / DNS)
· www.netwitness.com (2) –
Service: 80 (http/Web Browsing)
· truly-secure.com (1)
Service:53 (UDP / DNS)
· securetruly.com (1)
Service:53 (UDP / DNS)
· securereally.com (1)
Service:53 (UDP / DNS)
· resolution-sharp.com (1)
Service:53 (UDP / DNS)
· definitelysociable.com (1)
Service:53 (UDP / DNS)
· decision-intelligent.com (1)
Service:53 (UDP / DNS)
· -bright-decision.com (1)
Service:53 (UDP / DNS)
· Protocols in use within the Corporation Techs' system include:
TCP (31) - UDP (30) - ICMP (6)
· The user is accessing the websites mentioned in the screenshot above and trying to make DNS Query to the websites. The protocols used for the websites are TCP, UDP and ICMP
· 10.21.3.35 this is the source IP Address and 68.100.1630 is the destination address and it is trying to access over port 53(UDP DNS)
· 10.21.3.39 is the source IP address and 68.78.4.164 is th destination Address and is trying access over port 80 (IP / TCP / HTTP)
· Host Address: truly-secure.com.
· 72.2.9.22 alias. Host: truly-secure.com.
· 68.115.251.70 alias. Host: resolution-sharp.com.
· 62.182.74.248 alias. Host: bright-decision.com.
· Website hosted at united states and France
· Internet service provider COX.net
Section 2: Network Design
List of Host with Vulnerabilities:
1)172.30.0.1
Number of vulnerabilities
· Open ports: 9
· High: 2
· Medium :0
· Low:19
2)172.30.0.2
Number of vulnerabilities
· Open ports:13
· High:1
· Medium:5
· Low:37
3)172.30.0.200
Number of vulnerabilities
· Open ports:9
· High:2
· Medium:0
· Low : 19
4)172.30.0.3
Number of vulnerabilities
· Open ports : 12
· High : 15
· Medium : 1
· Low : 20
5)172.30.0.4
Number of vulnerabilities
· Open ports : 9
· High : 3
· Medium : 13
· Low : 27
6)172.30.0.8
Number of vulnerabilities
· Open ports :14
· High :1
· Medium :5
· Low: 49
7)172.30.0.9
Number of vulnerabilities
· Open ports :5
· High :1
· Medium :1
· Low :10
As mentioned in the previous section (Project Part 1: Network Survey), the company suffered a significant data breach or what we know as a network breach. The external attackers were probably able to steal data using their sophisticated technology. Still, NetWiness and Zenmpa helped the company unmask what had happened, as shown in the screenshot shared in section one of this project paper. The NetWiness tool scanned vulnerabilities and traffic going into the company's web. The scans revealed what needed to be accomplished based on the findings/discoveries made after learning that some data had been breached (evidence – shown in the screenshot in section one Network Survey).
Low or unstable configurations directly affects the security of the company's public and private individual/company's information. Therefore, the use of od NetWitness is a way of helping to fix bugs that result from hidden loopholes. The company can easily avoid or bypass all security threats when its defense mechanism is updated and subjected to regular checkups.
Another essential factor to consider when addressing the company's security issues is that it uses the Class C I.P. address range – a public. As mentioned above, the devices incorporate all the secure, public websites and email authentication. In this case, the main objective is to develop a solid network design to secure the organization's information. The result will also be geared towards improving a large number of client's addresses and lowering the Internet Service Providers.
The Design Part
The design of the network survey took place under the help of the Zenmap and NetWitness. The NetWitness investigator tool showed plenty of gadgets connected to the networked devices connected to the server needing access to the internet. This implies that the network serving the investigator tool and the other devices must always be powered and connected ta a strong internet connection. Crippling the information in a system is possible, mainly if the person controlling the recording events does not concern themselves. Additionally, when all the information is getting recorded as the server keeps running on the network, the system can bypass some info. Lastly, Zenmap and NetWitness tools are perfect devices in creating a network design that will keep the Corporate Tech's information safe/secure.
Network Survey brought to light three zones in security design. The three zones, as mentioned earlier, include the Internal, DMZ Server, and External network zone. The design diagram of the network framework is as shown below:
· External Zone
· Demilitarized Zone (DMZ)
· Private Zone
Demilitarized Zone – there is a point in this zone that identifies hackers' activities in the company's information system networks, thus enabling the defense department or persons in charge of the I.T department to stay alert. These servers take the form of DNS, Email, P/S, and proxy servers in this area. IDS/IPS is the next security server after the servers are in the DNS, P/S, and Proxy servers. The IPS stands for Intrusion Prevention Systems. The IPS prevents the destruction of information systems and preserves security triad, integrity, availability (CIA), and confidentiality.
Additionally, the DLP (Data Leakage Prevention also takes place within this zone. The DLP sends sensitive emails by shielding it from hackers. The server is designed so that it can detect key words mostly found in sensitive information but can also be used to extract essential information under the advice of the management of the security department.
In the private zone, Firewall Black-End forms as dual firewall security. Further, a barracuda filters content after an extra firewall for security reasons.
Further, in the external network, the SSL VPN connection is accessible. Encrypted data are more likely to be transported by IPSEC. There are two main categories of the firewall. The firewall mentioned above includes back-end and front-end firewalls. The front-end requires the system to be configured so that information can be passed through freely. On the other hand, the back-end permits data traffic from the DMZ towards the internal network.
Additionally, based on the data provided as the traffic flow of information, the use of NetWiness and Zenmap made it possible for all the traffic to be reflected on the network. The system has a domain name that can turn the name of the company into an I.P. address. A hyper transfer protocol is necessary to aid administrators and users to communicate. Point to point communication is also made possible through the use of Remote Procedure Call (RPC). On the other hand, the DHCP enables all devices to connect to the internet with the I.P. address. Lastly, NETBIOS allows for communication within local channels in the company.
Some of the other vulnerable factors for a network are overworking operating system of the computers or devices involved. The company runs the Kerberos server. The server mentioned in the previous sentence can easily harm the company, resulting in the loss of information through spoofing and exposing the company's information to attackers. Moreover, the RPC mentioned earlier tells the services to possible attacks, thus increasing the chances of worms being used against the company's systems. With the above information, the network design can be created, and a representation of the company's network design is as shown below:
Network Design: For the network Design we need to have a firewall between the Company LAN and Internet. For Hosting a website on the Internal server and preventing the hackers to get in to the website it is best we follow the design as below
· External Firewall: It will only allow the access to the website on Specific ports. For example when we launch the website Internal to the company and it is allowed access only over port 80 (http) and 443(https).We can specify a rule in the firewall the source as any, the Destination as the website IP Address (If we have Next Generation firewalls then we can mention the URL) and the ports will be specified as port TCP 80 and 443 The external firewall will prevent the access to the website on other ports.
· F5 Load Balancer: For better security controls we will not expose the server directly to the Internet. We will create a Virtual IP Address on the firewall and then on the f5 load Balancer we will load balance between the servers with the Virtual IP Address. Even when the External user tries to access the servers, he will not know the actual server IP Address because we will specify the Virtual IP Address on the firewall and that VIP IP Address will load balance between the servers.
· Internal Firewall: To create an extra security to the company websites we will user the Firewall between the webserver and Application server. so that we can control the traffic that has been passes between the Servers. The Internal firewall will allow the traffic that is allowed between the Web servers and the Application Servers. This NAT IP Address will secure the Internal ip address space of the company so that the users outside the company will never know the actual ip address of the user Internal to the company.
· NAT- Network address translation is the process of Translating the Range of Internal IP Address to an external IP Address and usually the NAT ip address will be assigned on the firewall. The group of people accessing the external resource will go out through an IP Address. We can reduce the cost ISP by selecting a group of users going out through the firewall on a single NAT IP Address.
· NAT IP Address Range: 192.168.0.1/24
· Internal IP Address Range: 10.21.0.1/21
· DMZ IP Address Range: 172.16.0.0./16
Destination Port (14 items)
21 (ftp) (6) - 22 (ssh) (5) - 23 (telnet) (4) - 1039 (3) - 1038 (3) - 1037 (3) - 80 (http) (2) - 6667 (irc) (1) - 6346 (gnuetella) (1) - 1863 (msn im) (1) - 1433 (ms-sql-s) (1) - 443 (https) (1) - 110 (pop3) (1) - 81 (1)
Location of Host:
Source Country :united states (1)
Destination Country (2 items) :united states (27) - France (1)
Final Project: Network Security Plan
In network security preparation, the corporation will be using the network security plan to solve loopholes for the discovered problems. Network protection systems and network intrusion detection will be used to access the internal network to create a secure site. Measures for the use of the VPN and remotes access will also be established. The strategies for mitigating risk and improving security measures will be in this plan. Users will only be able to access keys functions by using company-issued computers. Additionally, the MAC address will be used to filter remote connections through VPN (D. Bourgeois and T. Bourgeois, 2019).
Users will create a local password and username to log in to the VPN. SSL protects connections utilizing a VPN. The SSL encryption offers security protection for users using the internet. The approved remote access devices (laptops, tablets, and desktops computers) will be protected by McAfee software. The user will have login successfully before accessing any service from the institution's accounts. IDI internal network requires additional login features or users using the safe boot encrypted McAfee (Alsmadi et al., 2018).
The security team (network) will incorporate the web server in the internal structure. As mentioned above, the webserver will only be accessible within the intrusion detection system' (IDS) locality. The internal servers of the IDI will be protected using a layered approach. The institution's applications are configured to run via the multi-tenant environment (Vacca, 2012). The consumer's electronically stored data are distributed between the shared system made of several homogeneous machines which are located within data centers of Corporate Tech.
The organization storage stack and application's security layers demand that all alerts from other devices be authenticated and approved. Another authentication (service-service) is found on security procedures, which heavily depend on the authentication system incorporated into the Corporation Tech production unit to merged authentication devices between application services (Vacca, 2012).
Corporation Tech's Multi-Layered Network Security Plan
General
This Multi-Layer Network Security plan will outline an overview of the techniques which will probably be implemented at the information technology level (Edward Amoroso, 2012).
I. User Domain
· The security awareness usage will coach to employees of Corporate Tech security policies/plans
· Auditing of user activities
II. Workstation Domain
· The implementation/use of anti-malware software on each computer
· Stringent access rights to organization data/servers
· Disabling the media ports for clients' computers reduces the chances of data or network breach.
III. LAN Domain
· WPA 2 security to all wireless access stations
· Utilizing network switches
· Shielding server decks from the unauthorized entrance of access by hackers and strangers (Vacca, 2012).
IV. LAN to WAN Domain
· Closure of unused ports
· Monitoring internal IP traffic
· Use updated security patches to manage the operating systems and run security operations (Vacca, 2012).
V. WAN Domain
· Enforce VPN tunneling and encryption for remotely connected devices
· Configure network firewalls and routers to limit Ping requests (Vacca, 2012).
VI. Remote Access Domain
· Create strong user password policies
· Activate authorization tokens, establish a real-time lockout process if the ticket mentioned above is lost
· Secure the hard drives of Corporate Tech's devices to lower the chances of losing sensitive data.
Policies and Procedures
Determining a suitable security approach for end-users is exceptionally vital when working with inaccessible clients. These clients should be held to specific arrangements to direct their utilization and guarantee secure and dependable work. The taking after could be a list of ten security approaches required for inaccessible users (John R. Vacca, 2006).
Acceptable Utilize Policy
The to begin with thing that must be pushed to all clients is a satisfactory utilize arrangement. This arrangement will educate the clients around what they can and cannot do with company gear. For illustration, it may be an infringement of the worthy utilize approach to utilize your company portable workstation for online poker (John R. Vacca, 2006).
Remote Get to Policy
Remote access must be control by an interesting username and secret word for each client. This will take responsibility for anything the client does, whereas logged onto the organizing. All get to any arrange assets from a farther area must be scrambled sometime recently, getting to any company resources.
Remote Access Password Policy
All clients are required to have a one-of-a-kind secret word that's distinctive than their typical client secret word. This will anticipate the compromise of both accounts ought to one secret word ever be compromised. The secret word is required to alter every three months and is required to be at the slightest eight characters with at smallest one capital, one lowercase, one number, and one extraordinary character (Levy et al., 2008).
Remote Device Policy
All gadgets utilized to get to company assets must be endorsed by the IT compliance office sometime recently, being permitted to get to company assets. As of this time, no individual gadgets are allowed to be utilized for inaccessible get to. Company tablets that have been issued for farther get to must be brought in twice a month for schedule support and patching (Levy et al., 2008).
Security Awareness Policy
This approach is to form the client mindful and comfortable with particular security policies, whereas utilizing inaccessible get to. Clients ought to keep in mind to bolt their tablet when venturing absent, indeed for a moment. Clients must also keep in mind that they get to secure and dependable web hotspots to anticipate somebody from listening in on their activity. This and more will be instructed at required yearly security mindfulness preparing for all inaccessible users.
Web Use Policy
Users must be made mindful of shrewd web utilization and what is suitable to see on company hardware. Clients must learn how to recognize a malware disease and what to do within the occasion of a disease. Moreover, clients must learn how to recognize noxious e-mail substance and how to maintain a strategic distance from it (John E. Canavan, 2001).
Access Control Policy
Access control records and security settings must be arranged in development and executed in understanding with the set up put. Clients will be given get to based exclusively on their work title and what they are required to have got to. Any changes in user get to will ought to be endorsed by the user's prompt administrator and submitted to the IT department (John E. Canavan, 2001).
Information Classification Policy
Data will be divided into four classifications; open information, for inner utilization as it were, secret, and confined. Open information is lovely self-explanatory; it is information that's permitted to be discharged to the public. Information that's classified for inside utilizing as it were is for inside individuals of the organization to see and ought not to be made accessible to the public. Secret information is information that's limited by controls, contracts, or approaches. Confined information is allowed to be seen by a select gathering of individuals inside the organization (John E. Canavan, 2001).
VPN Policy
The VPN customers will, as it was, be allowed on the company possessed resources such as portable workstations. Beneath no circumstances will a VPN association to company assets be allowed on somebody's individual computer. Clients will be required to disengage their VPN association when not in utilize to avoid anybody who may pick up unauthorized get to from having to get to into the network (Edward Amoroso, 2012).
References
Alsmadi et al. (2018). Practical Information Security: A Competency-Based Education Course. Springer. D. Bourgeois and T. Bourgeois. (, 2019). Chapter 6: Information Systems Security. In B. e. al., INFORMATION SYSTEMS FOR BUSINESS AND BEYOND. Edward Amoroso. (, 2012). Cyber Attacks: Protecting National Infrastructure, STUDENT EDITION. Elsevier. John E. Canavan. (, 2001). Fundamentals of Network Security. Artech House. John R. Vacca. (, 2006). Guide to Wireless Network Security. Springer Science & Business Media. Levy et al. (2008). SonicWALL Secure Wireless Networks Integrated Solutions Guide. Elsevier Science. Vacca, J. R. (2012). Computer and Information Security Handbook. Newnes.