BLOGGER TEMPLATES AND TWITTER BACKGROUNDS »

Tuesday, November 17, 2009

~Aurat Wanita Di Luar Solat~

Aurat wanita dengan lelaki ajnabi di luar sembahyang adalah sama dengan auratnya dalam sembahyang, iaitu seluruh badan kecuali muka dan dua tapak tangan, termasuk kekura tangan hingga ke sendi yang memisahkan tapak tangan dengan tangan, iaitu tempat wanita memakai gelang.

Hujah wajib menutup aurat

Banyak nas-nas syarak yang menunjukkan aurat wajib ditutup.

1. Allah menyebut dalam ayat 31 surah al-Nur yang bermaksud:

“Dan katakanlah kepada perempuan-perempuan yang beriman, supaya menahan pandangan mereka (daripada memandang perkara-perkara yang haram) dan memelihara kehormatan mereka dan janganlah memperlihatkan perhiasan tubuh mereka kecuali yang zahir daripadanya. Dan mereka perlu melabuhkan kain tudung mereka ke dada.”

Ayat ini melarang wanita menunjukkan perhiasan yang di pakai kecuali perhiasan yang pada kebiasaannya terdedah. Ini bermaksud, anggota yang boleh didedahkan adalah anggota yang pada kebiasaannya dijadikan tempat memakai perhiasan zahir, iaitu muka dan tapak tangan. Ia juga memerintahkan wanita supaya melabuhkan tudung kepala hingga ke paras dada. Ertinya, tengkok dan leher tidak boleh didedahkan.

2. Allah berkata dalam ayat 59 surah al-Ahzab yang bermaksud:

“Wahai Nabi, suruhlah isteri-isterimu, anak-anak perempuanmu serta perempuan-perempuan yang beriman supaya mereka melabuhkan pakaian bagi menutup seluruh tubuhnya.”

Ayat ini mengarahkan Rasulullah supaya memerintahkan para isterinya dan wanita Islam melabuhkan pakaian di tubuh mereka.

3. Aisyah melaporkan:

“Asma’ binti Abu Bakar pernah masuk ke tempat Nabi, di badannya (dipakai) pakaian yang jarang, lalu Rasulullah berpaling dan berkata: ‘Ya Asma’, apabila perempuan sampai usia haid (iaitu baligh, dengan datang haid, genap usia 15 tahun ataupun mimpi dan kelur mani) tidak wajar lagi dilihat anggota tubuhnya kecuali ini dan ini. Beliau mengisyaratkan muka dan dua tapak tangannya.” (Direkodkan oleh Abu Daud)

Maksud tangan dalam hadis ini ialah bermula daripada pergelangan tangan, kekura tangan hingga ke hujung jari (bahagian atas tapak tangan) dan tapak tangan. Hadis ini menjelaskan, anggota yang boleh di dedahkan adalah muka dan dua tangan. Selain daripada itu mestilah ditutup.

Image000

Pakaian wanita yang sempurna menutup aurat untuk sembahyang – kaki berstoking

aurat wanita-1

Adakah kaki wanita aurat?

Maksud kaki di sini ialah mulai daripada pergelangan kaki ke bawah, termasuklah buku lali, kekura kaki hingga ke hujung jari, tumit dan tapak kaki. Ulama berbeza pendapat sama ada ia aurat ataupun tidak:

1. Majoriti ulama’ berpendapat, kaki wanita adalah aurat. Hujah yang mereka pegang adalah hadis yang dilaporkan oleh Ibnu Umar, Rasulullah berkata:

“Allah tidak melihat kepada sesiapa yang mengheret pakaiannya yang labuh kerana bermegah. Ummu Salamah bertanya: ‘Bagaimana wanita patut lakukan dengan hujung-hujung pakaian mereka yang labuh?’. Beliau menjawab: ‘Labuhkanlah kadar sejengkal.”

Dalam hadis ini, Rasulullah memerintahkan wanita supaya melabuhkan pakaian mereka kadar sejengkal bagi menutup kaki mereka. Perintah ini menunjukkan kaki wanita adalah aurat, sebab itu ia wajib ditutup.

2. Mazhab Hanafi berpendapat, kaki wanita bukan aurat. Hujah yang nereka pegang adalah; Kaki termasuk dalam anggota yang dikecualikan daripada larangan mendedahkannya seperti mana Allah menyebut (kecuali anggota yang zahir). Oleh itu, kaki adalah sama dengan muka dan tapak tangan. Ia dianggap anggota zahir, bukan aurat yang wajib ditutup.

Bagi Mazhab Shafie, walaupun wanita ini tidak memakai sarong kaki dia sempurna menutup aurat kerana pekerjaaannya menyukarkan beliau memakai stoking

Bagi Mazhab Shafie, walaupun wanita ini tidak memakai sarong kaki dia sempurna menutup aurat kerana pekerjaaannya menyukarkan beliau memakai stoking

Pakaian wanita ini belum sempurna menutup aurat mengikut pendapat semua mazhab

Pakaian wanita ini belum sempurna menutup aurat mengikut pendapat semua mazhab

Ini pakaian wanita sempurna bagi Mazhab Syafie

Ini pakaian wanita sempurna bagi Mazhab Syafie

Dipetik daripada buku Islam yang Mudah oleh:

Ustaz Alias Othman dan Dr. Anisah bt Abdul Ghani

p/s:sekadar perkongsian bersama untuk semua sahabat

~JODOH ITU KETENTUAN ALLAH~



Jodoh tiada kaitan dengan keturunan. Hanya belum sampai masanya. Ia bagai menanti jambatan untuk keseberang. Kalau panjang jambatannya, jauhlah perjalanan kita. Ada orang jodohnya cepat sebab jambatannya singkat. Usia 25 tahun rasanya belumlah terlalu lewat. Dan usia 35 tahun belum apa-apa kalau sepanjang usia itu telah digunakan untuk membina kecemerlangan. Nyatakanlah perasaan dan keinginan anda dalam doa-doa lewat solat. Allah itu Maha Mendengar. Wanita baik untuk lelaki yang baik, sebaliknya wanita jahat untuk lelaki yang jahat. Yakinlah pada janji-Nya kerana kita orang yang beriman.

Biar lambat jodoh asalkan mendapat Mr. Right dan biar seorang diri daripada menjadi mangsa lelaki yang tidak beriman kemudian nanti. Memang kita mudah tersilap mentafsir kehidupan ini. Kita selalu sangka, aku pasti bahagia kalau mendapat ini. Hakikatnya, apabila kita benar-benar mendapat apa yang kita inginkan itu, ia juga datang bersama masalah. Kita juga selalu melihat orang memandu kereta mewah dan terdetiklah dihati kita, alangkah bahagianya orang itu. Hakikatnya, apabila kita sendiri telah memiliki kereta mewah, kita ditimpa pelbagai karenah. Tidak mustahil pula orang yang memandu kereta mewah terpaksa membayar lebih tatkala berhenti untuk membeli durian di tepi jalan.


Ketika anda terperangkap dalam kesesakan jalan raya, motosikal mencelah-celah hingga mampu berada jauh dihadapan. Anda pun mengeluh, alangkah baiknya kalau aku hanya menunggang motosikal itu dan cepat sampai ke tempat yang dituju. Padahal si penunggang motosikal sedang memikirkan bilakah dia akan memandu kereta. Bukan semua yang anda sangka membahagiakan itu benar-benar membahagiakan. Bahagianya mungkin ada tapi deritanya juga datang sama. Semua benda pasti ada baik dan buruknya.

Demikian juga perkahwinan. Ia baik sebagai saluran yang betul untuk melepaskan syahwat tapi ramai juga orang yang berkahwin hidupnya semakin tidak terurus. Ramai orang menempah neraka sebaik melangkahkan kaki ke alam berumahtangga. Bukankah dangan ijab dan Kabul selain menghalalkan hubungan kelamin, tanggungjawab yang terpaksa dipikul juga turut bertambah? Bukankah apabila anda gagal melaksanakannya, anda membina dosa seterusnya jambatan ke neraka? Berapa ramaikah yang menyesali perkahwinan padahal dahulunya mereka bermati-matian membina janji, memupuk cinta kasih malah ada yang sanggup berkorban apa sahaja asal impian menjadi nyata?

Jika tidak sanggup bergelar isteri tidak usah berkahwin dulu. Jika merasakan diri belum cukup ilmu bergelar ibu ayah, belajarlah dulu. Jika belum bersedia untuk bersabar dengan karenah anak-anak, carilah dulu kesabaran itu. Jangan berkahwin dahulu sebab kenyataannya ramai yang tidak bersedia untuk melangkah tetapi setelah melompat, akhirnya jatuh terjerumus dan tidak jumpa akar berpaut tatkala cuba mendaki naik.

Berkahwin itu indah dan nikmat bagi yang benar-benar mengerti segala tuntutannya. Berkahwin itu menjanjikan pahala tidak putus-putus bagi yang menjadikannya gelanggang untuk menjadikan syurga sebagai matlamat. Berkahwin itu sempadan dari ketidaksempurnaan insan kepada kesempurnaan insan – bagi yang mengetahui rahsia-rahsianya. Berkahwinlah demi Tuhan dan Nabi-Nya, bukan kerana perasaan dan mengikut kebiasaan. Jodoh usah terlalu dirisaukan, tiba masanya ia akan datang menjemput, namun perlu juga anda membuka lorong-lorongnya agar jemputan itu mudah sampai.

Kadangkala Allah sembunyikan matahari, Dia datangkan petir dan kilat. Kita menangis dan tertanya-tanya, kemana menghilangnya sinar. Rupa-rupanya Allah nak hadiahkan kita pelangi. Cinta yang disemadikan tidak mungkin layu selagi ada imbas kembali. Hati remuk kembali kukuh selagi ketenangan dikecapi. Jiwa yang pasrah bertukar haluan selagi esok masih ada.Parut lama pastikan sembuh selagi iman terselit di dada. Kekayaan yang paling kaya adalah akal, kemiskinan yang paling besar adalah jahil, keburukan yang paling hodoh adalah sesat.

Tidak berguna adanya mata andai tidak dapat melihat, tak guna adanya hati kalau tak tahu menilai. Nilailah hati itu dengan teliti sebelum pergi mengundur diri kerana segalanya bermula dengan niat yang bertempat di hati.

Thursday, November 5, 2009

Hilang Dalam Ramai


Hasil Nukilan: Nhazz Ayunie

Editor:Ismiraihan

Dalam keramaian itu, aku merasakan gegak gempita suara orang –orang yang leka dengan kesibukan dunia, suka pada kefasikan dan kefakiran hati budi. Dari situ aku melewati mereka dalam keramaian. Kewujudanku seolah-olah tidak diperasankan oleh sesiapa jua orang yang berada di situ. Sungguhpun ramai di antara mereka adalah kenalanku sendiri.

Aku berjalan dan terus berjalan. Sehingga akhirnya aku tiba di suatu persimpangan. Aku memperlahankan langkahku. Demi memilih simpang yang manakah akan ku tuju, aku melihat ramai diantara mereka memilih jalan itu. Lalu aku pun melalui jalan yang mereka lalui itu dengan harapan mereka dapat membawa aku bersama mereka.

Dipertengahan jalan, aku merasakan jalan yang ku lalui semakin sempit. Sempit dengan ramai manusia yang pelbagai ragamnya. Dadaku menjadi sempit, sesempitnya jalan itu. Nafas kian sesak dan aku ingin mencari jalan keluar. Aku mahu keluar daripada kesempitan dan kesesakan itu.

Dengan nafas yang tersekat-sekat aku meneruskan perjalanan mencari jalan keluar. Dihadapanku terdapat satu simpang. Dan dihadapan simpang itu ada banyak lagi simpang. Aku buntu memikirkan manakah simpang yang harus aku pilih. Dengan nafas yang kian sesak, aku akhirnya memilih jalan yang kurang dilalui oleh orang ramai. Nafasku kembali pulih.

Namun begitu, perjalanan yang aku lalui ini tidak mudah untukku lalui. Banyak onar duri yang merintangi jalanku. Sesekali kaki ini berdarah dihiris duri-duri. Sesekali langkahku ini tersadung dibatasi akar kayu yang melintang. Aku melihat, ramai diantara mereka yang sama melalui jalan ini telah tersungkur rebah ke bumi. Ada juga diantara mereka yang berputus asa untuk meneruskan perjalanan lagi lalu berhenti sampai disini sahaja. Ada pula diantara mereka yang kembali kejalan yang lama dan ada juga yang memilih simpang yang lain.

Dalam ramai itu, masih ada yang kuat dan tegar dari tusukan duri-duri. Dan ada juga di antara mereka tidak langsung terkena duri mahupun tersadung akar. Tetapi mereka hanya membawa diri mereka tanpa memikirkan orang lain dibelakang mereka. Mereka tergamak hanya mampu melihat penderitaan dan kesakitan yang di alamiku dan orang2 yang senasib denganku. Aku merasa hampa. Tiada tempat untuk bersandar.

Dibawah suatu pohon, kusandarkan tubuhku. Bukan niat untuk berhenti berjalan tapi sekadar menghilangkan lelah dan merawat luka ini sendirian. Air mata menemani duka. Tiada kata yang dapat menggambarkan rasa. Tatkala melihat ramai yang megah berjalan, aku cuba melambai tangan dengan harapan mereka dapat menghulurkan bantuan. Tetapi tiada siapa pun diantara ramai itu yang sudi singgah apatah lagi menghulur tangan.

Aku kembali berdiri, tertingkut-tingkut berjalan dan terus berjalan lagi. Setibanya disuatu simpang, aku tersadung lagi. Ada dua simpang lewat dihadapanku. Ramai mereka melalui simpang kedua dan kurang yang melalui simpang pertama. Tiba-tiba aku disapa lembut oleh seseorang. Dan dia mengajakku pergi bersamanya. Dia memimpin dan memapahku dan melalui simpang yang pertama itu. Aku memandangnya dengan rasa terharu.

Pada jalan ini, kurasakan damai. Walaupun kurang yang melaluinya namun ia lebih menenangkan. Mereka yang memilih jalan ini saling kenal mengenali, bantu membantu, nasihat menasihati. Setiap orang yang melaui jalan ini, ramah dan mesra. Sungguhpun baru ku kenali tetapi lagak bicara mereka denganku seolah-olah telah lama berkenalan. Tidak seperti orang ramai pada jalan yang kulalui sebelum ini, ramai antara mereka adalah kenalan lama. Tapi lagak bicaranya seperti x pernah bersua.

Akhirnya pada jalan ini aku menetapkan perjalananku. Bersama mereka yang sudi memimpin jalanku. Lalu kutinggalkan jalan dahulu. Maka aku hilang dalam ramai itu. Aku meniti perjalananku kini dengan penuh rasa sayu dan terharu. Sungguhpun jalan ini masih terdapat banyak duri tetapi aku mengerti, duri ini adalah penawar segala duka lama. Walaupun sesekali langkahku lemah, namun ada banyak tempat untukku berpaut. Dan jika sesungguhnya jalan ini adalah jalan yang benar, maka aku berharap agar suatu hari nanti aku dapat memimpin yang lain untuk melalui jalan ini…

Monday, October 26, 2009

Lec 10:Legal And Ethical Issue In Computer Security

INTRODUCTION

To know what protection the provides for computer and data to appropriate laws that protect the right of other with respect to computer, program and data, and to understand how existing laws provide a basis for recommending new laws to protect computers, data and computer.

Law is not always the appropriate way to deal with issues of human behavior.

LEGAL AND ETHICAL

  • Law
    • Law is not always the appropriate way to deal with issue of human behavior.
    • Impossible or impractical to develop laws to describe and enforce all form or behavior acceptable to society.
    • Society relies on ethics or morals to prescribe generally accepted standards of proper behavior.
  • Ethics
    • An ethic is an objective defined standard of right and wrong.
    • Ethical standard are often idealistic principles.
    • Each person is responsible for deciding what to do in a specific situation, hence defines a personal set of ethical practies.
DIFFERENCES BETWEEN LAWS AND ETHICS

LAW
  • Formal, documented
  • Interpreted by courts
  • Established by legislature representing everyone
  • Applicable to everyone
  • Priority determined by courts if two laws conflict
  • Enforceable by police and courts
ETHIC
  • Described by unwritten principles
  • Interpreted by individuals
  • Presented by philosophers, religions, professional group
  • Personal choice
  • Priority determined by individual if two principles conflict
ETHIC CONCEPT IN INFORMATION SECURITY
  • ž
    žEthical Differences Across Cultures
  • Software License Infringement
  • Illicit use
  • Misuse of Corporate Resources
  • Ethics and Education
  • žDeterrence
PROTECTING PROGRAM AND DATA
  • Copyright
    • Are designed to protect the expression of idea.
    • Must apply to an original work and it must be in some tangible medium of expression. Example printed, recorded, or mode concrete in some other way.
    • must apply to an original work and it must be in some tangible medium of expression
  • Patents
    • Designed to protect the device pr process for carrying out an idea, not the idea itself.
    • Can valid only for something that is truly novel or unique.
    • The invention to be patented must not been previously patented.
    • Patented object may be marked with a patent number to warn others that the technology is patent.
  • Trade Secret
    • ¡must be kept a secret
    • the owner must protect the secret by any means, such as by storing it in a safe, encrypting it and by making employees sign a statement that they will not disclose the secret
    • trade secret protection can also vanish through reverse engineering
INFORMATION AND THE LAW
  • Information as an object

    • Information is valuable in that it is used in businesses and everyday life. Businesses pay for credit reports and client list. We also want inside information about competitors. Information does not fit other familiar commercial paradigms.

  • Features of information as an object
    • It is not depletable
    • It can be replicated
    • It has a minimal marginal cost
    • It's value if often timely
    • It is often tranferred intangibly
Right of Employees and Employers
  • Ownership of a Patent
  • Ownership of copyright
  • Work for Hire
  • Licenses
  • Trade Secret Protection
  • Employment Contracts
Computer Crimes
A separate category for computer crime is needed because of the following reason:
  • Rules of properties
  • Rules of Evidence
  • Threats to Integrity and Confidentiality
  • Value of Data
  • Acceptance of Computer Terminology
Privacy
Many ethical issue in security seem to be in the domain of individual's right to privacy verses to greater good of a larger entity. Example: tracking employee computer use, crowd surveillance and etc.

There are four ethical issues of information age:
  • Privacy
  • Accuracy
  • Property
  • Accessibility
Control Protecting Privacy
Several controls methods can be used to protect privacy:
  • Authentication
  • Anonymity
  • Computer Voting
  • Pseudonymity
  • Legal Control
Ethical Issues in Computer Security
  • Ethics and Religion
  • Ethics is not universal
  • Ethics Does Not Provide Answers
  • Ethical Reasoning
Examining a Case for Ethical Issue
  • Understand the situation
  • know several theories of ethical reasoning.
  • List the ethical principles involed
  • Determine which principles outweigh others.





Lec 9: Intrusion Detection System

Intruders

  • significant issue hostile/unwanted trespass from benign to serious
  • user trespass :unauthorized logon, privilege abuse
  • software trespass: virus, worm, or trojan horse
  • classes of intruders: masquerader, misfeasor, clandestine user

Examples of Intrusion

  • Remote root compromise
  • Web server defacement
  • Guessing / cracking passwords
  • Copying viewing sensitive data / databases
  • Running a packet sniffer
  • Distributing pirated software
  • Using an unsecured modem to access net
  • Impersonating a user to reset password
  • Using an unattended workstation


Security Intrusion & Detection


Security Intrusion

  • A security event, or combination of multiple security events, that constitutes a security incident in which an intruder gains, or attempts to gain, access to a system (or system resource) without having authorization to do so.


Intrusion Detection

  • A security service that monitors and analyzes system events for the purpose of finding, and providing real-time or near real-time warning of attempts to access system resources in an unauthorized manner.


Hackers

The terms and hack are marked by contrasting positive and negative connotations. Computer programmers often use the words hacking and hacker to express admiration for the work of a skilled software developer, but may also use them in a negative sense to describe the production of inelegant . Some frown upon using hacking as a synonym for security cracking in distinct contrast to the larger kludges, wohacker rld, in which the word hacker is typically used to describe someone who "hacks into" a system by evading or disabling security measures.


Hacker Behavior Example

  • Select target using IP lookup tools
  • Map network for accessible services
  • Identify potentially vulnerable services
  • Brute force (guess) passwords
  • Install remote administration tool
  • Wait for admin to log on and capture password
  • Use password to access remainder of network


Criminal Enterprise

• Organized groups of hackers now a threat

– corporation / government / loosely affiliated gangs

– typically young

– often Eastern European or Russian hackers

– common target credit cards on e-commerce server

• Criminal hackers usually have specific targets

• Once penetrated act quickly and get out

• IDS / IPS help but less effective

• Sensitive data needs strong protection


Criminal Enterprise Behavior

1. act quickly and precisely to make their

activities harder to detect

2. exploit perimeter via vulnerable ports

3. use trojan horses (hidden software) to

leave back doors for re-entry

4. use sniffers to capture passwords

5. do not stick around until noticed

6. make few or no mistakes.


What is hacking?

  • Hacking is unauthorized use of computer and network resources. (The term "hacker" originally meant a very gifted programmer. In recent years though, with easier access to multiple systems, it now has negative implications.)
  • Hacking is a felony in the United States and most other countries. When it is done by request and under a contract between an ethical hacker and an organization, it's OK.
  • The key difference is that the ethical hacker has authorization to probe the target.


Intrusion Detection Systems

  • An Intrusion detection system (IDS) is software and/or hardware designed to detect unwanted attempts at accessing, manipulating, and/or disabling computer systems, mainly through a network, such as the Internet. These attempts may take the form of attacks, as examples, by crackers, malware and/or disgruntled employees. An IDS cannot directly detect attacks within properly encrypted traffic.
  • An intrusion detection system is used to detect several types of malicious behaviors that can compromise the security and trust of a computer system. This includes network attacks against vulnerable services, data driven attacks on applications, host based attacks such as privilege escalation, unauthorized logins and access to sensitive files, and malware (viruses, trojan horses, and worms).
  • An IDS can be composed of several components: Sensors which generate security events, a Console to monitor events and alerts and control the sensors, and a central Engine that records events logged by the sensors in a database and uses a system of rules to generate alerts from security events received. There are several ways to categorize an IDS depending on the type and location of the sensors and the methodology used by the engine to generate alerts. In many simple IDS implementations all three components are combined in a single device or appliance.


IDS Terminology

Alert/Alarm- A signal suggesting a system has been or is being attacked.

True attack stimulus- An event that triggers an IDS to produce an alarm and react as though a real attack were in progress.

False attack stimulus- The event signaling an IDS to produce an alarm when no attack has taken place.

False (False Positive)- An alert or alarm that is triggered when no actual attack has taken place.

False negative- A failure of an IDS to detect an actual attack.

Noise- Data or interference that can trigger a false positive.

Site policy- Guidelines within an organization that control the rules and configurations of an IDS.

Site policy awareness- The ability an IDS has to dynamically change its rules and configurations in response to changing environmental activity.

Confidence value- A value an organization places on an IDS based on past performance and analysis to help determine its ability to effectively identify an attack.

Alarm filtering- The process of categorizing attack alerts produced from an IDS in order to distinguish false positives from actual attacks.


Types of Intrusion-Detection systems

Network intrusion detection system (NIDS)

  • It is an independent platform which identifies intrusions by examining network traffic and monitors multiple hosts.
  • Network Intrusion Detection Systems gain access to network traffic by connecting to a hub, network switch configured for port mirroring, or network tap. An example of a NIDS is Snort.


Protocol-based intrusion detection system (PIDS)

  • It consists of a system or agent that would typically sit at the front end of a server, monitoring and analyzing the communication protocol between a connected device (a user/PC or system) and the server.
  • For a web server this would typically monitor the HTTPS protocol stream and understand the HTTP protocol relative to the web server/system it is trying to protect.
  • Where HTTPS is in use then this system would need to reside in the "shim", or interface, between where HTTPS is un-encrypted and immediately prior to its entering the Web presentation layer.


Application protocol-based intrusion detection system (APIDS)

  • It consists of a system or agent that would typically sit within a group of servers, monitoring and analyzing the communication on application specific protocols.
  • For example, in a web server with a database this would monitor the SQL protocol specific to the middleware/business logic as it transacts with the database.


Host-based intrusion detection system (HIDS)

  • It consists of an agent on a host which identifies intrusions by analyzing system calls, application logs, file-system modifications (binaries, password files, capability/acl databases) and other host activities and state.
  • An example of a HIDS is OSSEC.


Hybrid intrusion detection system

  • It combines two or more approaches.
  • Host agent data is combined with network information to form a comprehensive view of the network. An example of a Hybrid IDS is Prelude.
  • Intrusion detection systems can also be system-specific using custom tools and honeypots.


IDS Principles

  • Assume intruder behavior differs from
    • legitimate users
      • expect overlap as shown
      • observe deviations
      • from past history
    • problems of:
      • false positives
      • false negatives
      • must compromise


Distributed Host-Based IDS


NIDS Sensor Deployment


Passive system vs. reactive system

  • Intrusion Prevention System (IPS), the IPS responds to the suspicious activity by resetting the connection or by reprogramming the firewall to block network traffic from the suspected malicious source.
  • This can happen automatically or at the command of an operator. Though they both relate to network security, an intrusion detection system (IDS) differs from a firewall in that a firewall looks outwardly for intrusions in order to stop them from happening.
  • Firewalls limit access between networks to prevent intrusion and do not signal an attack from inside the network.
  • An IDS evaluates a suspected intrusion once it has taken place and signals an alarm. An IDS also watches for attacks that originate from within a system. This is traditionally achieved by examining network communications, identifying heuristics and patterns (often known as signatures) of common computer attacks, and taking action to alert operators.
  • A system which terminates connections is called an intrusion prevention system application layer firewall IDPS is commonly used to refer to hybrid security systems that both "detect" and "prevent".

Statistical anomaly and signature based IDSes

All Intrusion Detection Systems use one of two detection techniques: statistical anomaly based and/or signature based.

Statistical anomaly based IDS

  • A statistical anomaly based IDS establishes a performance baseline based on normal network traffic evaluations.
  • It will then sample current network traffic activity to this baseline in order to detect whether or not it is within baseline parameters.
  • If the sampled traffic is outside baseline parameters an alarm will be triggered.

Signature based IDS

  • Network traffic is examined for preconfigured and predetermined attack patterns known as signatures. Many attacks today have distinct signatures.
  • In good security practice, a collection of these signatures must be constantly updated to mitigate emerging threats.

Distributed Adaptive Intrusion Detection


Intrusion Detection Exchange Format


Honeypots

In computer terminology, a honeypot is a trap set to detect, deflect, or in some manner counteract attempts at unauthorized use of information systems. Generally it consists of a computer, data, or a network site that appears to be part of a network, but is actually isolated, (un)protected, and monitored, and which seems to contain information or a resource of value to attackers.


Honeypot Deployment


SNORT

  • lightweight IDS
    • real-time packet capture and rule analysis
    • passive or inline

SNORT Rules

  • use a simple, flexible rule definition language
  • with fixed header and zero or more options
  • header includes: action, protocol, source IP, source port, direction, dest IP, dest port
  • many options

Lec 8: Firewall (Dinding Berapi)

Introduction

Firewall is a part of a computer system or network that is designed to block unauthorized access while permitting authorized communications. It is a device or set of devices configured to permit, deny, encrypt, decrypt, or proxy all (in and out) computer traffic between different security domains based upon a set of rules and other criteria.

Firewalls can be implemented in either hardware or software, or a combination of both. Firewalls are frequently used to prevent unauthorized Internet users from accessing private networks connected to the Internet, especially intra nets. All messages entering or leaving the intra net pass through the firewall, which examines each message and blocks those that do not meet the specified security criteria.

There are several types of firewall techniques:

1. Packet filter: Packet filtering inspects each packet passing through the network and accepts or rejects it based on user-defined rules. Although difficult to configure, it is fairly effective and mostly transparent to its users. In addition, it is susceptible to IP spoofing.





2. Application gateway: Applies security mechanisms to specific applications, such as FTP and Telnet servers. This is very effective, but can impose a performance degradation.


3. Circuit-level gateway: Applies security mechanisms when a TCP or UDP connection is established. Once the connection has been made, packets can flow between the hosts without further checking.

4. Proxy server: Intercepts all messages entering and leaving the network. The proxy server effectively hides the true network addresses.



Firewall hosting


  • 1. Bastion host = single firewall that cover a network territory

  • 2. Host-base = single firewall protect a single workstation/server



Virtual Private Networks (VPNs)

  • In essence, a VPN consists of a set of computers that interconnect by means of a relatively unsecure network.
  • Use of a public network exposes corporate traffic to eavesdropping and provides an entry point for unauthorized users. To counter this problem, a VPN is needed.
  • In essence, a VPN uses encryption and authentication in the lower protocol layers to provide a secure connection through an otherwise insecure network, typically the Internet.
  • VPNs are generally cheaper than real private networks using private lines but rely on having the same encryption and authentication system at both ends.
  • The encryption may be performed by firewall software or possibly by routers.
  • The most common protocol mechanism used for this purpose is at the IP level and is known as IPSec.

Distributed firewall


  • A distributed firewall configuration involves standalone firewall devices plus host-based firewalls, personal firewall working together under a central administrative control.
  • Administrators can configure host-resident firewalls on hundreds of servers and workstation as well as configuring personal firewalls on local and remote user systems. Tools let the network administrator set policies and monitor security across the entire network.

Lec 7: Wireless Security

Introduction

  • Wireless security is the prevention of unauthorized access or damage to computers using wireless networks.
  • Wireless networks are very common, both for organizations and individuals. Many laptop computers have wireless cards pre-installed. The ability to enter a network while mobile has great benefits.
  • The risks to users of wireless technology have increased as the service has become more popular. There were relatively few dangers when wireless technology was first introduced.
There is a types of WLAN standards

802.11
  • The Institute of Electrical and Electronics Engineers (IEEE) created the first WLAN standard in the 1997.
  • Called it 802.11 after the name of the group formed to oversee its development. Unfortunately, 802.11 only supported a maximum network bandwidth of 2 Mbps - too slow for most applications.
  • This reason, ordinary 802.11 wireless products are no longer manufactured.
802.11b
  • IEEE expanded on the original 802.11 standard in July 1999, creating the 802.11b specification. 802.11b supports bandwidth up to 11 Mbps, comparable to traditional Ethernet.
  • 802.11b uses the same unregulated radio signaling frequency (2.4 GHz) as the original 802.11 standard. Vendors often prefer using these frequencies to lower their production costs. Being unregulated, 802.11b gear can incur interference from microwave ovens, cordless phones, and other appliances using the same 2.4 GHz range. However, by installing 802.11b gear a reasonable distance from other appliances, interference can easily be avoided.
  • Pros of 802.11b - lowest cost; signal range is good and not easily obstructed.
  • Cons of 802.11b - slowest maximum speed; home appliances may interfere on the unregulated frequency band.
802.11a

  • 802.11a supports bandwidth up to 54 Mbps and signals in a regulated frequency spectrum around 5 GHz.
  • This higher frequency compared to 802.11b shortens the range of 802.11a networks. The higher frequency also means 802.11a signals have more difficulty penetrating walls and other obstructions.
  • 802.11a and 802.11b utilize different frequencies, the two technologies are incompatible with each other. Some vendors offer hybrid 802.11a/b network gear, but these products merely implement the two standards side by side (each connected devices must use one or the other).
  • Pros of 802.11a - fast maximum speed; regulated frequencies prevent signal interference from other devices.
  • Cons of 802.11a - highest cost; shorter range signal that is more easily obstructed.

802.11n
  • The newest IEEE standard in the Wi-Fi category is 802.11n. It was designed to improve on 802.11g in the amount of bandwidth supported by utilizing multiple wireless signals and antennas (called MIMO technology) instead of one.
  • When this standard is finalized, 802.11n connections should support data rates of over 100 Mbps. 802.11n also offers somewhat better range over earlier Wi-Fi standards due to its increased signal intensity. 802.11n equipment will be backward compatible with 802.11g gear.
  • Pros of 802.11n - fastest maximum speed and best signal range; more resistant to signal interference from outside sources
  • Cons of 802.11n - standard is not yet finalized; costs more than 802.11g; the use of multiple signals may greatly interfere with nearby 802.11b/g based networks.


    Accidental association

    • Unauthorized access to company wireless and wired networks can come from a number of different methods and intents.
    • One of these methods is referred to as “accidental association”. When a user turns on a computer and it latches on to a wireless access point from a neighboring company’s overlapping network, the user may not even know that this has occurred.
    • It is a security breach in that proprietary company information is exposed and now there could exist a link from one company to the other.
    • This is especially true if the laptop is also hooked to a wired network.

    Malicious association

    • “Malicious associations” are when wireless devices can be actively made by crackers to connect to a company network through their cracking laptop instead of a company access point (AP).
    • Once the cracker has gained access, he/she can steal passwords, launch attacks on the wired network, or plant trojans.
    • Wireless 802.1x authentications do help with protection but are still vulnerable to cracking.
    • The idea behind this type of attack may not be to break into a VPN or other security measures. Most likely the cracker is just trying to take over the client at the Layer 2 level.

    Ad-hoc networks

    • etworks can pose a security threat. Ad-hoc networks are defined as peer-to-peer networks between wireless computers that do not have an access point in between them.
    • Types of networks usually have little protection, encryption methods can be used to provide security.

    Non-traditional networks

    • Non-traditional networks such as personal network Bluetooth devices are not safe from cracking and should be regarded as a security risk.
    • Barcode readers, handheld PDAs, and wireless printers and copiers should be secured. These non-traditional networks can be easily overlooked by IT personnel who have narrowly focused on laptops and access points.

    Identity theft (MAC spoofing)

    • Identity theft (or MAC spoofing) occurs when a cracker is able to listen in on network traffic and identify the MAC address of a computer with network privileges.
    • Most wireless systems allow some kind of MAC filtering to only allow authorized computers with specific MAC IDs to gain access and utilize the network.
    • Combine these programs with other software that allow a computer to pretend it has any MAC address that the cracker desires, and the cracker can easily get around that hurdle.
    • MAC filtering is only effective for small residential(SOHO)networks, since it only provides protection when the wireless device is "off the air".
    • Any 802.11 device "on the air" freely transmits it unencrypted MAC address in it's 802.11 headers, and it requires no special equipment or software to detect it.
    • Anyone with an 802.11 receiver (laptop and wireless adapter) and a freeware wireless packet analyzer can obtain the MAC address of any transmitting 802.11 within range.
    • In an organizational environment, where most wireless devices are "on the air" throughout the active working shift, MAC filtering only provides a false sense of security since it only prevents "causal" or unintended connections to the organizational infrastructure and does nothing to prevent a directed attack.

Man-in-the-middle attacks

    • A man-in-the-middle attacker entices computers to log into a computer which is set up as a soft AP (Access Point).
    • The hacker connects to a real access point through another wireless card offering a steady flow of traffic through the transparent hacking computer to the real network. The hacker can then sniff the traffic.
    • One type of man-in-the-middle attack relies on security faults in challenge and handshake protocols to execute a “de-authentication attack”. This attack forces AP-connected computers to drop their connections and reconnect with the cracker’s soft AP.
    • Man-in-the-middle attacks are enhanced by software such as LANjack and AirJack, which automate multiple steps of the process.

Denial of service

    • A Denial-of-Service attack (DoS) occurs when an attacker continually bombards a targeted AP (Access Point) or network with bogus requests, premature successful connection messages, failure messages other commands.
    • These cause legitimate users to not be able to get on the network and may even cause the network to crash.
    • These attacks rely on the abuse of protocols such as the Extensible Authentication Protocol (EAP).
    • The DoS attack in itself does little to expose organizational data to a malicious attacker, since the interruption of the network prevents the flow of data and actually indirectly protects data by preventing it from being transmitted.
    • The usual reason for performing a DoS attack is to observe the recovery of the wireless network, during which all of the initial handshake codes are re-transmitted by all devices, providing an opportunity for the malicious attacker to record these codes and use various "cracking" tools to analyze security weaknesses and exploit them to gain unauthorized access to the system.

Network injection

    • In a network injection attack, a cracker can make use of access points that are exposed to non-filtered network traffic, specifically broadcasting network traffic.
    • The cracker injects bogus networking re-configuration commands that affect routers, switches, and intelligent hubs. A whole network can be brought down in this manner and require rebooting or even reprogramming of all intelligent networking devices.