Teaching Network Security through Signature Analysis of Computer Network Attacks
Te‐Shun Chou · 2020
Abstract Teaching Network Security Through Signature Analysis of Computer Network AttacksWith the rapid growth of Internet based technology, applications of computer networks such asweb service, file transfer, and voice IP are extensively being used. In the meantime, the networksinevitably become as the targets of computer attacks and the attacks can easily cause millions ofdollars worth of damage to an organization. To introduce to students the behavior of novelattacks in the real world becomes an important task to those students who want to pursue careersin information assurance and security. Therefore, this paper presents an investigation on fourcategories of network attacks, which are: Denial of Service (DoS) attacks: Attackers disrupt a host or network service in order to make legitimate users not be able to have an access to a machine; Probe attacks: Attackers use programs to automatically scan networks for gathering information or finding known vulnerabilities; User to Root (U2R) attacks: Local users get access to root access of a system without authorization and then exploit the machine’s vulnerabilities; and Remote to Local (R2L) attacks: Unauthorized attackers gain local access from a remote machine and then exploit the machine’s vulnerabilities.In order to build an experimental network environment, virtualization technology is used. Twovirtual machines are configured, where one is used to launch attacks and the other acts as avictim host. A variety of network tools are installed for generation, collection and analysis ofattack traffic traces. In each attack category, one real world attack is simulated. They are bufferoverflow attack, TCP SYN scanning attack, backdoors attack, and guessing username andpassword attack. Finally, the attack traffic traces are analyzed and their attack signatures areextracted.