The Experts below are selected from a list of 189 Experts worldwide ranked by ideXlab platform
Thomas W Shinder - One of the best experts on this subject based on the ideXlab platform.
-
installing and configuring the isa Firewall Software
The Best Damn Firewall Book Period (Second Edition), 2007Co-Authors: Thomas W ShinderAbstract:This chapter focuses on installing and configuring the ISA Firewall Software. The routing table on the ISA Firewall machine should be configured before you install the ISA Firewall Software. The routing table should include routes to all networks that are not local to the ISA Firewall's network interfaces. The split-Domain Name System (DNS) infrastructure provides transparent access to resources for users, regardless of their location. Users can move between the corporate network and remote locations, and use the same name to reach the same corporate resources. Requirements for the split-DNS infrastructure include a DNS server authoritative for the domain that resolves names for resources for that domain to the internal addresses used to access those resources. The ISA Firewall Software can be installed on a machine with a single network interface card. To correctly configure the network interfaces on the ISA Firewall it is required to assign IP addresses to the internal and external network interfaces. It is observed that when internal network computers are on the same network ID as the internal interface of the ISA Firewall, the default gateway of the internal network computers is set as the internal IP address on the ISA Firewall machine.
-
chapter 3 installing and configuring the isa Firewall Software
Dr. Tom Shinder's ISA Server 2006 Migration Guide, 2007Co-Authors: Thomas W ShinderAbstract:Publisher Summary This chapter focuses on installing and configuring the ISA Firewall Software. The routing table on the ISA Firewall machine should be configured before you install the ISA Firewall Software. The routing table should include routes to all networks that are not local to the ISA Firewall's network interfaces. The split-Domain Name System (DNS) infrastructure provides transparent access to resources for users, regardless of their location. Users can move between the corporate network and remote locations, and use the same name to reach the same corporate resources. Requirements for the split-DNS infrastructure include a DNS server authoritative for the domain that resolves names for resources for that domain to the internal addresses used to access those resources. The ISA Firewall Software can be installed on a machine with a single network interface card. To correctly configure the network interfaces on the ISA Firewall it is required to assign IP addresses to the internal and external network interfaces. It is observed that when internal network computers are on the same network ID as the internal interface of the ISA Firewall, the default gateway of the internal network computers is set as the internal IP address on the ISA Firewall machine.
-
Chapter 3 – Installing and Configuring the ISA Firewall Software
Dr. Tom Shinder's ISA Server 2006 Migration Guide, 2007Co-Authors: Thomas W ShinderAbstract:Publisher Summary This chapter focuses on installing and configuring the ISA Firewall Software. The routing table on the ISA Firewall machine should be configured before you install the ISA Firewall Software. The routing table should include routes to all networks that are not local to the ISA Firewall's network interfaces. The split-Domain Name System (DNS) infrastructure provides transparent access to resources for users, regardless of their location. Users can move between the corporate network and remote locations, and use the same name to reach the same corporate resources. Requirements for the split-DNS infrastructure include a DNS server authoritative for the domain that resolves names for resources for that domain to the internal addresses used to access those resources. The ISA Firewall Software can be installed on a machine with a single network interface card. To correctly configure the network interfaces on the ISA Firewall it is required to assign IP addresses to the internal and external network interfaces. It is observed that when internal network computers are on the same network ID as the internal interface of the ISA Firewall, the default gateway of the internal network computers is set as the internal IP address on the ISA Firewall machine.
-
chapter 3 instaling and configuring the isa Firewall Software
How to Cheat at Configuring ISA Server 2004, 2006Co-Authors: Thomas W ShinderAbstract:Publisher Summary The chapter explains the installing and configuring of the ISA Firewall Software. It discusses default System Policy and Firewall configuration after installation is complete. There are several key pre-installation tasks and considerations one needs to address before installing the ISA Firewall Software. These include system requirements, configuring the routing table, DNS server placement, and so on. The routing table on the ISA Firewall machine should be configured before one installs the ISA Firewall Software. The routing table should include routes to all the networks that are not local to the ISA Firewall's network interfaces. These routing table entries are required because the ISA Firewall can have only a single default gateway. The routing table entries are critical to support the ISA Firewall's “network-within-a- Network” scenarios. A network within a network is a network ID located behind a NIC on the ISA Firewall that is a nonlocal network.
-
Chapter 3 – Instaling and Configuring the ISA Firewall Software
How to Cheat at Configuring ISA Server 2004, 2006Co-Authors: Thomas W ShinderAbstract:Publisher Summary The chapter explains the installing and configuring of the ISA Firewall Software. It discusses default System Policy and Firewall configuration after installation is complete. There are several key pre-installation tasks and considerations one needs to address before installing the ISA Firewall Software. These include system requirements, configuring the routing table, DNS server placement, and so on. The routing table on the ISA Firewall machine should be configured before one installs the ISA Firewall Software. The routing table should include routes to all the networks that are not local to the ISA Firewall's network interfaces. These routing table entries are required because the ISA Firewall can have only a single default gateway. The routing table entries are critical to support the ISA Firewall's “network-within-a- Network” scenarios. A network within a network is a network ID located behind a NIC on the ISA Firewall that is a nonlocal network.
Mikel Izal - One of the best experts on this subject based on the ideXlab platform.
-
A Survey on Detection Techniques for Cryptographic Ransomware
IEEE Access, 2019Co-Authors: Eduardo Berrueta, Daniel Morato, Eduardo Magaña, Mikel IzalAbstract:Crypto-ransomware is a type of malware that encrypts user files, deletes the original data, and asks for a ransom to recover the hijacked documents. It is a cyber threat that targets both companies and residential users, and has spread in recent years because of its lucrative results. Several articles have presented classifications of ransomware families and their typical behaviour. These insights have stimulated the creation of detection techniques for antivirus and Firewall Software. However, because the ransomware scene evolves quickly and aggressively, these studies quickly become outdated. In this study, we surveyed the detection techniques that the research community has developed in recent years. We compared the different approaches and classified the algorithms based on the input data they obtain from ransomware actions, and the decision procedures they use to reach a classification decision between benign or malign applications. This is a detailed survey that focuses on detection algorithms, compared to most previous studies that offer a survey of ransomware families or isolated proposals of detection algorithms. We also compared the results of these proposals.
Sanjeev Kumar - One of the best experts on this subject based on the ideXlab platform.
-
McAfee SecurityCenter Evaluation under DDoS Attack Traffic
Journal of Information Security, 2011Co-Authors: Sirisha Surisetty, Student Member, Sanjeev KumarAbstract:During the Distributed Denial of Service (DDoS) attacks, computers are made to attack other computers. Newer Firewalls now days are providing prevention against such attack traffics. McAfee SecurityCenter Firewall is one of the most popular security Software installed on millions of Internet connected computers worldwide. “McAfee claims that if you have installed McAfee SecurityCentre with anti-virus and antispyware and Firewall then you always have the most current security to combat the ever-evolving threats on the Internet for the duration of the subscription”. In this paper, we present our findings regarding the effectiveness of McAfee SecurityCentre Software against some of the popular Distributed Denial Of Service (DDoS) attacks, namely ARP Flood, Ping-flood, ICMP Land, TCP-SYN Flood and UDP Flood attacks on the computer which has McAfee SecurityCentre installed. The McAfee SecurityCentre Software has an in built Firewall which can be activated to control and filter the Inbound/Outbound traffic. It can also block the Ping Requests in order to stop or subside the Ping based DDoS Attacks. To test the McAfee Security Centre Software, we created the corresponding attack traffic in a controlled lab environment. It was found that the McAfee Firewall Software itself was incurring DoS (Denial of Service) by completely exhausting the available memory resources of the host computer during its operation to stop the external DDoS Attacks.
-
is mcafee securitycenter Firewall Software providing complete security for your computer
International Conference on the Digital Society, 2010Co-Authors: Sirisha Surisetty, Sanjeev KumarAbstract:McAfee SecurityCenter Firewall is one of the most popular security Software installed on millions of Internet connected computers worldwide. “McAfee claims that if you have installed McAfee SecurityCentre with anti-virus and anti-spyware and Firewall version 9.3 then you always have the most current security to combat the ever-evolving threats on the Internet for the duration of the subscription”. In this paper, we present our findings regarding the effectiveness of McAfee SecurityCentre Software against one of the most popular Distributed Denial Of Service (DDoS) attack, namely Ping-flood attack on the computer which has McAfee SecurityCentre installed. The McAfee SecurityCentre Software has an in built Firewall which can be activated to control and filter the Inbound/Outbound traffic. It can also block the Ping Requests in order to stop or subside the Ping based DDoS Attacks. To test the McAfee Security Centre Software, we created the Ping traffic in the controlled lab environment of Networking Research Lab here at The University of Texas-Pan American. It was found that the McAfee Firewall Software itself was incurring DoS (Denial of Service) by completely exhausting the available memory resources during its operation of stopping the external Ping Attack.
-
ICDS - Is McAfee SecurityCenter/Firewall Software Providing Complete Security for Your Computer?
2010 Fourth International Conference on Digital Society, 2010Co-Authors: Sirisha Surisetty, Sanjeev KumarAbstract:McAfee SecurityCenter Firewall is one of the most popular security Software installed on millions of Internet connected computers worldwide. “McAfee claims that if you have installed McAfee SecurityCentre with anti-virus and anti-spyware and Firewall version 9.3 then you always have the most current security to combat the ever-evolving threats on the Internet for the duration of the subscription”. In this paper, we present our findings regarding the effectiveness of McAfee SecurityCentre Software against one of the most popular Distributed Denial Of Service (DDoS) attack, namely Ping-flood attack on the computer which has McAfee SecurityCentre installed. The McAfee SecurityCentre Software has an in built Firewall which can be activated to control and filter the Inbound/Outbound traffic. It can also block the Ping Requests in order to stop or subside the Ping based DDoS Attacks. To test the McAfee Security Centre Software, we created the Ping traffic in the controlled lab environment of Networking Research Lab here at The University of Texas-Pan American. It was found that the McAfee Firewall Software itself was incurring DoS (Denial of Service) by completely exhausting the available memory resources during its operation of stopping the external Ping Attack.
Eduardo Berrueta - One of the best experts on this subject based on the ideXlab platform.
-
A Survey on Detection Techniques for Cryptographic Ransomware
IEEE Access, 2019Co-Authors: Eduardo Berrueta, Daniel Morato, Eduardo Magaña, Mikel IzalAbstract:Crypto-ransomware is a type of malware that encrypts user files, deletes the original data, and asks for a ransom to recover the hijacked documents. It is a cyber threat that targets both companies and residential users, and has spread in recent years because of its lucrative results. Several articles have presented classifications of ransomware families and their typical behaviour. These insights have stimulated the creation of detection techniques for antivirus and Firewall Software. However, because the ransomware scene evolves quickly and aggressively, these studies quickly become outdated. In this study, we surveyed the detection techniques that the research community has developed in recent years. We compared the different approaches and classified the algorithms based on the input data they obtain from ransomware actions, and the decision procedures they use to reach a classification decision between benign or malign applications. This is a detailed survey that focuses on detection algorithms, compared to most previous studies that offer a survey of ransomware families or isolated proposals of detection algorithms. We also compared the results of these proposals.
Keith Whisnant - One of the best experts on this subject based on the ideXlab platform.
-
Modeling and Evaluating the Security Threats of Transient Errors in Firewall Software
2004Co-Authors: Shuo Chen, Zbigniew Kalbarczyk, Ravishankar K. Iyer, Keith WhisnantAbstract:This paper experimentally evaluates and models the error-caused security vulnerabilities and the resulting security violations on two Linux kernel Firewalls: IPChains and Netfilter. There are two major aspects to this work: to conduct extensive error injection experiments on the Linux kernel and to quantify the possibility of error-caused security violations using a Stochastic Activity Network (SAN) model. The error injection experiments show that about 2 % of errors injected into the Firewall code segment cause security vulnerabilities. Two types of error-caused security vulnerabilities are distinguished: temporary, which disappear when the error disappears, and permanent, which persist even after the error is removed, as long as the system is not rebooted. Results from simulating the SAN model indicate that under an error rate of 0.1 error per day during a 1-year period in a networked system protected by 20 Firewalls, two machines (on the average) will experience security violations. This indicates that error-caused security vulnerabilities can be a non-negligible source of a security threat to a highly secure system
-
Modeling and Evaluating the Security Threats of Transient Errors in Firewall Software. Performance Evaluation
2004Co-Authors: Shuo Chen, Zbigniew Kalbarczyk, Ravishankar K. Iyer, Keith WhisnantAbstract:This paper experimentally evaluates and models the error-caused security vulnerabilities and the resulting security violations on two Linux kernel Firewalls: IPChains and Netfilter. There are two major aspects to this work: to conduct extensive error injection experiments on the Linux kernel and to quantify the possibility of error-caused security violations using a SAN model. The error injection experiments show that about 2 % of errors injected into the Firewall code segment cause security vulnerabilities. Two types of error-caused security vulnerabilities are distinguished: temporary, which disappear when the error disappears, and permanent, which persist even after the error is removed, as long as the system is not rebooted. Results from simulating the SAN model indicate that under an error rate of 0.1 error/day during a 1-year period in a networked system protected by 20 Firewalls, 2 machines (on the average) will experience security violations. This indicates that error-caused security vulnerabilities can be a non-negligible source of a security threat to a highly secure system. 1