Skip to the content.

Index

Network Security Summary

Web

Vulnerabilities

XSS: Reflected, Store, DOM

SQL Injection

Shellcode

Defense

HTTPS

Blacklist: Malformed URL(gogle.com)/Filtering XSS/SQL Injection

Defend Shellcode: Static/Dynamic

Static: Fast but easily bypassed

Dynamic: Slow but complete filtered

Botnet

Attack

LifeCycle: Attack -> Connect to CnC -> Control

Topology:

Pathfind:

Detection

E-Mail

Vulnerability

Defense

PGP&S/MIME: Digital envelope based(enc)

Spam

Attack

Defense

Security Bug

Static Analysis

Symbolic Execution: Generate tree forked by condition

Dynamic Analysis

Fuzzing:

Fuzzing for full of coverage of codes

DOS

Attack

Defense

SYN Flood:

Generic:

Source Identification

Network Defense

TCP/IP: Use VPN

Local Area Network Firewall: split local net and internet

Network Infrastructure

終わり