Search Anything You Like

Wednesday, March 14, 2012

Intrusion Prevention Systems (IPS)


Intrusion prevention systems (IPS), also known as intrusion detection and prevention systems (IDPS), are network security appliances that monitor network and/or system activities for malicious activity. The main functions of intrusion prevention systems are to identify malicious activity, log information about said activity, attempt to block/stop activity, and report activity.
Intrusion prevention systems are considered extensions of intrusion detection systems because they both monitor network traffic and/or system activities for malicious activity. The main differences are, unlike intrusion detection systems, intrusion prevention systems are placed in-line and are able to actively prevent/block intrusions that are detected. More specifically, IPS can take such actions as sending an alarm, dropping the malicious packets, resetting the connection and/or blocking the traffic from the offending IP address. An IPS can also correct Cyclic Redundancy Check (CRC) errors, unfragment packet streams, prevent TCP sequencing issues, and clean up unwanted transport and network layer options. 
Classifications
Intrusion prevention systems can be classified into four different types:
Network-based intrusion prevention (NIPS): monitors the entire network for suspicious traffic by analyzing protocol activity.
Wireless intrusion prevention systems (WIPS): monitors a wireless network for suspicious traffic by analyzing wireless networking protocols.
Network behavior analysis (NBA): examines network traffic to identify threats that generate unusual traffic flows, such as distributed denial of service (DDoS) attacks, certain forms of malware, and policy violations.
Host-based intrusion prevention (HIPS): an installed software package which monitors a single host for suspicious activity by analyzing events occurring within that host.
Detection Method
The majority of intrusion prevention systems utilize one of three detection methods: signature-based, statistical anomaly-based, and stateful protocol analysis.
Signature-Based Detection: This method of detection utilizes signatures, which are attack patterns that are preconfigured and predetermined. A signature-based intrusion prevention system monitors the network traffic for matches to these signatures. Once a match is found the intrusion prevention system takes the appropriate action. Signatures can be exploit-based or vulnerability-based. Exploit-based signatures analyze patterns appearing in exploits being protected against, while vulnerability-based signatures analyze vulnerabilities in a program, its execution, and conditions needed to exploit said vulnerability.
Statistical anomaly-based detection: This method of detection baselines performance of average network traffic conditions. After a baseline is created, the system intermittently samples network traffic, using statistical analysis to compare the sample to the set baseline. If the activity is outside the baseline parameters, the intrusion prevention system takes the appropriate action.
Stateful Protocol Analysis Detection: This method identifies deviations of protocol states by comparing observed events with “predetermined profiles of generally accepted definitions of benign activity.

Tuesday, March 13, 2012

ITIL Interview Preparation


Access Management Process
The purpose of the Access Management process is to provide the rights for
users to be able to access a service or group of services, while preventing access
to non-authorized users.
Access Management helps to manage confidentiality, availability and integrity
of data and intellectual property.
Access Management is concerned with identity (unique information that
distinguishes an individual) and rights (settings that provide access to data
and services). The process includes verifying identity and entitlement, granting
access to services, logging and tracking access, and removing or modifying
rights when status or roles change.

Problem Management Process
A problem is a cause of one or more incidents. The cause is not
usually known at the time a problem record is created, and the
problem management process is responsible for further
investigation.
The key objectives of Problem Management are to prevent problems and
resulting incidents from happening, to eliminate recurring incidents and to
Minimize the impact of incidents that cannot be prevented.
Problem Management includes diagnosing causes of incidents, determining
the resolution, and ensuring that the resolution is implemented. Problem
Management also maintains information about problems and the appropriate
Workarounds and resolutions.
Problems are categorized in a similar way to incidents, but the goal is to
understand causes, document workarounds and request changes to
Permanently resolve the problems. Workarounds are documented in a Known
Error Database, which improves the efficiency and effectiveness of Incident
Management

Event Management Process
An event is a change of state that has significance for the
management of a configuration item or IT service.
An event may indicate that something is not functioning correctly, leading to an
incident being logged. Events may also indicate normal activity, or a need for
routine intervention such as changing a tape.
Event management depends on monitoring, but it is different. Event
management generates and detects notifications, whilst monitoring checks the
status of components even when no events are occurring.

Incident Management Process
An incident is an unplanned interruption to an IT service, or a
reduction in the quality of an IT service. Failure of a
configuration item that has not yet impacted service is also an
incident.
The purpose of Incident Management is to restore normal service as quickly as
possible, and to minimize the adverse impact on business operations.
Incidents are often detected by event management, or by users contacting the
service desk. Incidents are categorized to identify who should work on them
and for trend analysis, and they are prioritized according to urgency and
business impact.
If an incident cannot be resolved quickly, it may be escalated. Functional
escalation passes the incident to a technical support team with appropriate
skills; hierarchical escalation engages appropriate levels of management.
After the incident has been investigated and diagnosed, and the resolution has
been tested, the Service Desk should ensure that the user is satisfied before the
incident is closed.
An Incident Management tool is essential for recording and managing incident
information.

Service Measurement
There are four basic reasons to monitor and measure, to:
_ validate previous decisions that have been made
_ direct activities in order to meet set targets - this is the most prevalent
reason for monitoring and measuring
_ justify that a course of action is required, with factual evidence or proof
_ intervene at the appropriate point and take corrective action.

 Transition Planning and Support
The goals of Transition Planning and Support are to:
_ plan and coordinate resources to ensure that the requirements of Service
Strategy encoded in Service Design are effectively realized in Service
Operations
_ identify, manage and control the risks of failure and disruption across
transition activities.
Effective Transition Planning and Support can significantly improve a service
provider’s ability to handle high volumes of change and releases across its
customer base.

Change Management
Change Management ensures that changes are recorded, evaluated,
authorized, prioritized, planned, tested, implemented, documented and
reviewed in a controlled manner.
The purpose of the Change Management process is to ensure that standardized
methods are used for the efficient and prompt handling of all changes, that all
changes are recorded in the Configuration Management System and that
overall business risk is optimized.
The process addresses all service change.
A Service Change is the addition, modification or removal of an
authorised, planned or supported service or service component
and its associated documentation.
Therefore change management is relevant across the whole lifecycle, applying
to all levels of service management – strategic, tactical and operational.

Supplier Management
The Supplier Management process ensures that suppliers and the services they
provide are managed to support IT service targets and business expectations.
The purpose of the Supplier Management process is to obtain value for money
from suppliers and to ensure that suppliers perform to the targets contained
within their contracts and agreements, while conforming to all of the terms and
conditions.
The Supplier and Contract Database (SCD) is a vital source of information on
suppliers and contracts and should contain all of the information necessary for
the management of suppliers, contracts and their associated services.

Capacity Management
Capacity Management includes business, service and component capacity
management across the service lifecycle. A key success factor in managing
capacity is ensuring that it is considered during the design stage.
The purpose of Capacity Management is to provide a point of focus and
management for all capacity and performance-related issues, relating to both
services and resources, and to match the capacity of IT to the agreed business
demands.
The Capacity Management Information System (CMIS) is the cornerstone of a
successful Capacity Management process. Information contained within the
CMIS is stored and analyzed by all the sub-processes of Capacity
Management for the provision of technical and management reports, including
the Capacity Plan.

Service Design is a stage within the overall service lifecycle and an important
element within the business change process. The role of Service Design within
the business change process can be defined as:
The design of appropriate and innovative IT services, including
their architectures, processes, policies and documentation, to
meet current and future agreed business requirements.
The main goals and objectives of Service Design are to:
_ design services to meet agreed business outcomes
_ design processes to support the service lifecycle
_ identify and manage risks
_ design secure and resilient IT infrastructures, environments, applications
and data/information resources and capability
_ design measurement methods and metrics
_ produce and maintain plans, processes, policies, standards, architectures,
frameworks and documents to support the design of quality IT solutions
_ develop skills and capability within IT
_ contribute to the overall improvement in IT service quality.

Service Portfolio Management (SPM)
SPM involves proactive management of the investment across the service
lifecycle, including those services in the concept, design and transition pipeline,
as well as live services defined in the various service catalogues and retired
services.
SPM is an ongoing process, which includes the following:
_ Define: inventory services, ensure business cases and validate portfolio
data
_ Analyze: maximize portfolio value, align and prioritize and balance supply
and demand
_ Approve: finalize proposed portfolio, authorize services and resources
_ Charter: communicate decisions, allocate resources and charter services.

Problems are categorized in a similar way to incidents, but the goal is to
understand causes, document workarounds and request changes to
permanently resolve the problems. Workarounds are documented in a Known
Error Database, which improves the efficiency and effectiveness of Incident
Management

Continual Service Improvement (CSI) is concerned with maintaining value for
customers through the continual evaluation and improvement of the quality of
services and the overall maturity of the ITSM service lifecycle and underlying
processes.
CSI combines principles, practices and methods from quality management,
Change Management and capability improvement, working to improve each
stage in the service lifecycle, as well as the current services, processes, and
related activities and technology.
CSI is not a new concept, but for most organizations the concept has not moved
beyond the discussion stage. For many organizations, CSI becomes a project
when something has failed and severely impacted the business. When the issue
is resolved the concept is promptly forgotten until the next major failure occurs.
Discrete time-bound projects are still required, but to be successful CSI must be
embedded within the organizational culture and become a routine activity.



Saturday, March 10, 2012

Classful vs Classless Routing Protocols



Classful routing protocols do not send subnet mask information with their
routing updates. A router running a classful routing protocol will react in one
of two ways when receiving a route:

• If the router has a directly connected interface belonging to the same
major network, it will apply the same subnet mask as that interface.

• If the router does not have any interfaces belonging to the same major
network, it will apply the classful subnet mask to the route.
Belonging to same “major network” simply indicates that they belong to the
same “classful” network. For example:

• 10.3.1.0 and 10.5.5.0 belong to the same major network (10.0.0.0)
• 10.1.4.5 and 11.1.4.4 do not belong to the same major network
• 192.168.1.1 and 192.168.1.254 belong to the same major network (192.168.1.0)
• 192.168.1.5 and 192.167.2.5 do not belong to the same major  network.

Take the following example (assume the routing protocol is classful):





If Router B sends a routing update to Router A, it will not include the subnet
mask for the 10.2.0.0 network. Thus, Router A must make a decision.
If Router A has a directly connected interface that belongs to the same major
network (10.0.0.0), it will use the subnet mask of that interface for the route.
For example, if Router A has an interface on the 10.4.0.0/16 network, it will
apply a subnet mask of /16 to the 10.2.0.0 network. If Router A does not have
 a directly connected interfacing belonging to the same major network, it will
apply  the classful subnet mask of /8. This can obviously cause routing difficulties.
When using classful routing protocols, the subnet mask must remain
consistent throughout your entire network.

ITIL (Information Technology Infrastructure Library)


ITIL (IT Infrastructure Library) provides a framework of Best Practice
guidance for IT Service Management and since its creation, ITIL has grown to
become the most widely accepted approach to IT Service Management in the
world.
The challenges for IT managers are to co-ordinate and work in partnership with
the business to deliver high quality IT services. This has to be achieved while
adopting a more business and customer oriented approach to delivering
services and cost optimization.

The primary objective of Service Management is to ensure that the IT services
are aligned to the business needs and actively support them. It is imperative
that the IT services underpin the business processes, but it is also increasingly
important that IT acts as an agent for change to facilitate business
transformation.

To understand what service management is, we need to understand what
services are, and how service management can help service providers to deliver
and manage these services.
A service is a means of delivering value to customers by
facilitating outcomes customers want to achieve without the
ownership of specific costs and risks.

A simple example of a customer outcome that could be facilitated by an IT
service might be: “Sales people spending more time interacting with
customers” facilitated by “a remote access service that enables reliable access
to corporate sales systems from sales people’s laptops”.
The outcomes that customers want to achieve are the reason why they purchase
or use the service. The value of the service to the customer is directly dependent
on how well it facilitates these outcomes. Service management is what enables
a service provider to understand the services they are providing, to ensure that
the services really do facilitate the outcomes their customers want to achieve, to
understand the value of the services to their customers, and to understand and
manage all of the costs and risks associated with those services.

Service Management is a set of specialized organizational
capabilities for providing value to customers in the form of
services.

These “specialized organizational capabilities” are described in this pocket
guide. They include all of the processes, methods, functions, roles and activities
that a Service Provider uses to enable them to deliver services to their
customers.
Service management is concerned with more than just delivering services. Each
service, process or infrastructure component has a lifecycle, and service
management considers the entire lifecycle from strategy through design and
transition to operation and continual improvement.
The outcomes that customers want to achieve are the reason why they purchase
or use the service. The value of the service to the customer is directly dependent
on how well it facilitates these outcomes. Service management is what enables
a service provider to understand the services they are providing

Service Management is a set of specialized organizational
capabilities for providing value to customers in the form of
services.

Effective service management is itself a strategic asset of the service provider,
providing them with the ability to carry out their core business of providing
services that deliver value to customers by facilitating the outcomes customers
want to achieve.

ITIL was published between 1989 and 1995 by Her Majesty’s Stationery Office
(HMSO) in the UK on behalf of the Central Communications and
Telecommunications Agency (CCTA) – now subsumed within the Office of
Government Commerce (OGC). Its early use was principally confined to the
UK and Netherlands. A second version of ITIL was published as a set of
revised books between 2000 and 2004.

Wednesday, March 7, 2012

Flie Systems (FAT & NTFS)


File Allocation Table (FAT) is the name of a computer file system architecture and a family of industry standard file systems utilizing it.
The FAT file system is technically relatively simple yet robust. It offers reasonably good performance even in light-weight implementations and is therefore widely adopted and supported by virtually all existing operating systems for personal computers. This makes it a well-suited format for data exchange between computers and devices of almost any type and age from the early 1980s up to the present.
Originally designed in the late 1970s for use on floppy disks, it was soon adapted and used almost universally on hard disksthroughout the DOS and Windows 9x eras for two decades. With the introduction of more powerful computers and operating systemsits use on hard drives has since started to decline, but it continues to be used on many computer systems.
Today, FAT file systems are still commonly found on floppy disks, solid-state memory cards, flash memory cards, and on many portable and embedded devices.
The name of the file system originates from the file system's prominent usage of an index table, the FAT, statically allocated at the time of formatting. The table contains entries for each cluster, a contiguous area of disk storage. Each entry contains either the number of the next cluster in the file, or else a marker indicating end of file, unused disk space, or special reserved areas of the disk. The root file directory of the disk contains the number of the first cluster; the operating system can then traverse the FAT table, looking up the cluster number of each successive part of the disk file as a cluster chain until the end of the file is reached.
As disk drives have evolved, the maximum number of clusters has significantly increased, and so the number of bits used to identify each cluster has grown. The successive major versions of the FAT format are named after the number of table element bits: 12 (FAT12), 16 (FAT16), and 32 (FAT32).
FAT was also commonly used on hard disks throughout the DOS and Windows 9x eras, but its use on hard drives has declined since the introduction of Windows XP, which primarily uses the newer NTFS. FAT is still used in hard drives expected to be used by multiple operating systems, such as in shared Windows and Linux environments.
Due to the widespread use of FAT formatted media since its introduction many operating systems have provided support for FAT and subsequently VFAT and FAT32 through official or third-party file system handlers. For example, Mac OS 9 and Mac OS X also support FAT file systems on volumes other than the boot disk. AmigaOS supports FAT through the CrossDOS file system.
For many purposes, the NTFS file system is superior to FAT in terms of features and reliability; its main drawbacks are the size overhead for small volumes and the very limited support by anything other than the NT-based versions of Windows, since the exact specification is a trade secret of Microsoft. The availability of NTFS-3G since mid 2006 has led to much improved NTFS support in Unix-like operating systems, considerably alleviating this concern. It is still not possible to use NTFS in DOS-like operating systems without third-party drivers, which in turn makes it difficult to use a DOS floppy for recovery purposes. Microsoft provided a recovery console to work around this issue, but for security reasons it severely limited what could be done through the Recovery Console by default. The movement of recovery utilities to boot CDs based on BartPE or Linux (with NTFS-3G) is finally eroding this drawback.
Due to its long history of usage on desktops and portable computers meanwhile spanning over more than three decades and its frequent use in embedded solutions, the FAT file system continues to be the most widespread file system worldwide.
NTFS (New Technology File System) is the standard file system of Windows NT, including Windows 2000, Windows XP, and all their successors to date.
NTFS supersedes the FAT file system as the preferred file system for Microsoft’s Windows operating systems. NTFS has several improvements over FAT and HPFS (High Performance File System) such as improved support for metadata and the use of advanced data structures to improve performance, reliability, and disk space utilization, plus additional extensions such as security access control lists(ACL) and file system journaling.
In the mid 1980s, Microsoft and IBM formed a joint project to create the next generation of graphical operating system. The result of the project was OS/2, but Microsoft and IBM disagreed on many important issues and eventually separated. OS/2 remained an IBM project. Microsoft started to work on Windows NT. The OS/2 file system HPFS contained several important new features. When Microsoft created their new operating system, they borrowed many of these concepts for NTFS.
The new features in Windows XP require on-disk data structures that make these volumes unavailable to Microsoft Windows NT 4.0-based computers. In anticipation of dual-boot scenarios, Microsoft recommends that you upgrade Windows NT 4.0 to Service Pack 4 (SP4) before you start the Windows XP installation. The version of NTFS included with Windows XP cannot be interpreted correctly by Windows NT 4.0. However, there is an updated Ntfs.sys driver in Windows NT 4.0 SP4 that enables Windows NT 4.0 to read from and write to NTFS volumes in Windows XP. Features of the NTFS 3.1 file system include:
·         Disk quotas: Administrators can limit the amount of disk space users can consume on a per-volume basis. The three quota levels are: Off, Tracking, and Enforced.
·         Encryption: The NTFS 3.1 file system can automatically encrypt and decrypt file data as it is read and written to the disk.
·         Reparse points: Programs can trap open operations against objects in the file system and run their own code before returning file data. This feature can be used to extend file system features such as mount points, which you can use to redirect data that is read and written from a folder to another volume or physical disk.
·         Sparse files: This feature permits programs to create very large files, but to consume disk space only as needed.
·         USN journal: This feature provides a persistent log of all changes made to files on the volume. This feature is one of the reasons that Windows domain controllers must use an NTFS 3.1 partition as the system volume.
NOTE:Microsoft Windows 2000 uses NTFS 3.0. NTFS 3.0 and 3.1 have compatible on-disk formats, so volumes upgraded to NTFS 3.1 by Windows XP can continue to be accessed by Windows 2000 or by Windows NT 4.0 with SP4 or later.