




免費(fèi)預(yù)覽已結(jié)束,剩余66頁(yè)可下載查看
下載本文檔
版權(quán)說(shuō)明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡(jiǎn)介
CitrixNetScalerApplicationFirewall培訓(xùn) Agenda CitrixWAF簡(jiǎn)述順網(wǎng)拓?fù)浼軜?gòu)簡(jiǎn)介業(yè)務(wù)上線流程ApplicationFirewall技術(shù)概述 網(wǎng)頁(yè)應(yīng)用程序防火墻 NetworkFirewall IDSIPS DatabaseServersCustomerInfoBusinessDataTransactionInfo 私密資料 客制化網(wǎng)頁(yè)程序客制化套裝應(yīng)用程序自行開(kāi)發(fā)或第三方程式 特征碼 HTTP HTTPS 我看得懂文檔 WAF 我看不懂不讓你過(guò) 正常訪問(wèn) 我看不懂放行 依據(jù)網(wǎng)頁(yè)程序內(nèi)容邏輯 制定合法規(guī)則 檢測(cè)進(jìn)出聯(lián)機(jī)內(nèi)容 正向防護(hù)白名單 預(yù)設(shè)行為 阻擋符合規(guī)則 放行效益 防范已知 未知攻擊防護(hù)產(chǎn)品 網(wǎng)絡(luò)防火墻網(wǎng)頁(yè)應(yīng)用程序防火墻其他 不易誤判 除非設(shè)定錯(cuò)誤 需時(shí)間學(xué)習(xí) 設(shè)定 反向防護(hù)黑名單 預(yù)設(shè)行為 放行符合特征 阻擋效益 防范已知攻擊防護(hù)產(chǎn)品 防病毒軟件 防毒墻入侵偵沒(méi)系統(tǒng) IPS 其他 容易誤判容易繞過(guò) 防護(hù)邏輯 WAFvsIPSvsNetworkFirewall WAF運(yùn)作機(jī)制 雙向保護(hù) 用戶請(qǐng)求 服務(wù)器回應(yīng) Internet Intranet WAF 請(qǐng)求檢查 輸入正確性檢測(cè) 安全轉(zhuǎn)發(fā) ProtectedAP 用戶請(qǐng)求 安全轉(zhuǎn)發(fā) 服務(wù)器回應(yīng) 內(nèi)容響應(yīng)防護(hù)處理 NetScaler網(wǎng)頁(yè)應(yīng)用防火墻采用混合安全模型 正面表列自我學(xué)習(xí)應(yīng)用程序 負(fù)面表列特征碼偵測(cè) Negative Positive Hybrid 混合模型防護(hù)已知和未知的安全威脅 DDos SSL VPN SSL WAF XMLFW AAA SSO Reporting NetScalerMPXandVPX CitrixNetScaler融合多種應(yīng)用安全 Internet WebAppUsers 允許合法流量通過(guò)響應(yīng)內(nèi)容檢測(cè) 應(yīng)用程序攻擊阻擋 防御Zeroday攻擊雙向檢測(cè) 進(jìn)階式攻擊防御SSL加密聯(lián)機(jī)支持ICSA CommonCriteria認(rèn)證 Agenda CitrixWAF簡(jiǎn)述順網(wǎng)拓?fù)浼軜?gòu)及Netscaler架構(gòu)概述業(yè)務(wù)上線流程ApplicationFirewall技術(shù)概述 現(xiàn)網(wǎng)拓?fù)?NetScalerArchitectureOverview NetScaler ownedIPAddresses TheNetScalersystemusesdifferenttypesofIPaddressesformanagementandproxyingconnectionstotheserverTheseIPaddressesare NetScalerIP NSIP addressesSubnetIP SNIP addressesVirtualIP VIP addresses NetScalerIPAddress TheNetScalerIPaddress NSIP istheprimaryaddressformanagementandgeneralsystemaccessThedefaultIPaddressandnetmaskis192 168 100 1 16 255 255 0 0 修改該IP地址 設(shè)備需要重啟 SubnetIPAddress ThesubnetIP SNIP addressisusedinconnectionmanagementandservermonitoringASNIPaddressprovidestheNetScalersystemwithanAddressResolutionProtocol ARP presenceinsubnetstowhichthesystemmaynotbedirectlyconnectedANetScalersystemshouldhaveaSNIPaddressconfiguredforeverydirectlyconnectedsubnet VirtualIPAddress VIPaddressesareusedforclient to NetScaler systemcommunicationWhentheVIPaddressisapublicIPaddress itusuallycorrespondstotheDNSentryforadomainAVIPaddressisautomaticallycreatedwhenavirtualserverisadded EntityManagement HighAvailabilityFunctionality 上線后全網(wǎng)配置調(diào)整 NS上對(duì)外發(fā)布一個(gè)VIP F5的VIP作為NSVIP的Service 防火墻將原先的到F5VS的映射改為到NSVS的映射 由于服務(wù)器端需要看到客戶端的真實(shí)IP地址 現(xiàn)在的架構(gòu)是在F5上通過(guò)插入一個(gè)HTTPX Forwarded For報(bào)頭 報(bào)頭里面記錄了客戶端IP地址 服務(wù)器端解這個(gè)報(bào)頭來(lái)獲得客戶端真實(shí)IP NS部署后 添加這個(gè)報(bào)頭的工作由NS完成 即將F5上配置的這個(gè)功能取消 將這個(gè)功能在NS上配置 在NS上配置的報(bào)頭名稱(chēng)不變 這樣后臺(tái)服務(wù)器就不需要做任何修改 HardwareComponents HardwarecomponentsoftheNetScalersysteminclude NetworkinterfacesLCDSerialinterfaceFilesystemRAMdrive Flashmemory flash Harddisk var HardwareComponents NetScalerArchitectureOverview Agenda CitrixWAF簡(jiǎn)述順網(wǎng)拓?fù)浼軜?gòu)及Netscaler架構(gòu)概述業(yè)務(wù)上線流程ApplicationFirewall技術(shù)概述 操作流程 通過(guò)GUI方式登錄設(shè)備進(jìn)行配置 客戶端需要JRE環(huán)境 NSIP SNIP都可以對(duì)設(shè)備進(jìn)行配置管理通過(guò)SSH登錄設(shè)備進(jìn)行命令行下查看配置等操作 上線流程 創(chuàng)建Service F5VS地址 創(chuàng)建對(duì)外發(fā)布的VS地址并關(guān)聯(lián)相應(yīng)Service創(chuàng)建WAFPolicy將WAFPolicy與相對(duì)應(yīng)的VS關(guān)聯(lián) Agenda CitrixWAF簡(jiǎn)述順網(wǎng)拓?fù)浼軜?gòu)及Netscaler架構(gòu)概述業(yè)務(wù)上線流程ApplicationFirewall技術(shù)概述 WAF技術(shù)介紹 INTERNAL DataFlowProcess NetScaler WebApplications Database 1 ClientRequest EXTERNAL 2 RequestInspections 3 ClientR 4 ServerR 5 ResponseInspections 6 ServerResponse StartURLsXSSSQLInjectionFieldConsistencyBufferOverflow CreditCardsSAFEObject FullADCIntegration ProfilesEnableBasicorAdvanceddefaultsConsistsofSecuritySettingsPoliciesDirectstraffictoprofilesMatchesonrequestorresponseparametersPolicy創(chuàng)建后 即可以設(shè)置為全局生效 即所以流量都通過(guò)該policy進(jìn)行檢查 或者關(guān)聯(lián)到一個(gè)VS上單獨(dú)生效 CustomizableProfilesandPolicy CompleteWebAppProtectionwithLearning PositiveSecurity ApplicationFirewall Advancedprofile Whenconfigureapplicationfirewall appfw 1stthingtodoiscreateaprofile AndthereisBasicandAdvancedprofile whatisthedifference Withadvancedprofile sessionization orsessiontrackingwillbeenabled Thesecuritychecksrequiredsessionizationare URLClosureCookieConsistencyFormFieldConsistency ApplicationFirewall sessionization Whatissessionization ItmeansAppfwhastotrackallrequestsandresponsesfromaclientaslongasthebrowserremainsopenwithinthesessiontimeoutperiod thatistrackeachsession Thesessionismarkedbysessioncookie thedefaultcookienameiscitrix ns idDefaultsessiontimeoutis900seconds 15minutes AppFw whysessionizationisneeded Example1 bufferoverflowprotection Asanexample assumetheAppfwisconfiguredwithbufferoverflowsuchthatmaximumallowedURLlengthis10characters Appfwdoesnotneedtocarewhosendstherequest aslongastheURLislongerthan10characters itwillblockit AppFw whysessionizationisneeded Example2 URLClosure Asanexample assumetheAppfwisconfiguredwithstartURLandURLClosureprotection thestartURLallowedishome1 htm UserA Inthisexample wecanobservethatfeaturelikeURLClosurerequiredtheAppfwto record somesortofactivitiesforeachuser sessioninordertodeterminetoalloworblocktherequest Intheotherwords thesession shistoryisafactortodetermineallow block Appfw sessionization Wehavetopaythepriceforsessionization thatisMemory Sinceweneedtostoreinformationforeachsession morememoryisrequiredThereissomethinginterestinghere exceptfromthenumberofuser therearesomeotherfactorsthataffecthowmuchmemoryisrequired Appfw URLClosureexample Webpage1 Webpage2 ForURLClosure whichoftheabovepagewillconsumemorememorywhenauseraccessthepageasstartURL Appfw Memoryusage Ofcourse webpage2 willtakesmorememorybecauseithasmuchmorehyperlink whenappfwstoresinformationonwhichlinktheusercanaccess itneedstostoremoreinformationURLClosure Morehyperlink morememoryisrequiredFormFieldConsistency Moreform largerform morememoryisrequired UsuallymostmemoryconsumingisURLClosurebecausewebpagewithalotoflinksarecommonbutwebpagewithalotofformsislesscommon EasyDeploymentModeProtectsagainstSQLInjectionCrossSiteScriptingCrosssiteRequestForgery Referrerheader ForcefulBrowsing Start DenyURLs BufferOverflowFormFieldFormattingNosessionizationrequiredLearningaideddeployment BasicDefaults PositiveSecurityModel SQLInjectionattacks Howthismightbedone UserentersdataintoaformonawebpageTheapplicationsendsthisaspartofanSQLquerytothebackenddatabase ItemNumber ItemLookup EnterDesiredItemNumber SUBMIT 1234 or 1 1 Cross siteScripting XSS Attacks Attackingtrustrelationships CrossSiteRequestForgeryAttacks Protectionactions VerifyReferrerheadersTageachformwithuniquetokenandverifyonformsubmission Attackingtrustrelationships CSRF ReferrerHeaderProtection X ForcefulBrowsing ForcefulBrowsingAttack ManipulatingrequestURLstogainaccesstocontentyouarenotentitledtosee Brute forcepenetrationoftheinfrastructure ParisHilton sSidekickhacked hackerNicolasJacobsenpledguiltytoasinglechargeofintentionallyaccessingaprotectedcomputerandrecklesslycausingdamage JacobsenwasarrestedbyUSauthoritieslastOctober buthadhadaccesstoT Mobile sserversformorethanayear HereportedlyamusedhimselfbyaccessingUSSecretServiceemail andraidingotherSidekickusers accounts Igothacked BufferOverflowProtection Hacker BufferOverflowAttack Application Platform OS GainapplicationPrivileges Gainplatformprivileges Gainrootserveraccess Preventhackersfromgainingunauthorizedsystemprivileges ApplicationFirewalllimitsinputparametersizesfor URLsHeadersCookies ApplicationServer Internet AdvancedDefaultsSessionbasedenablesadditionalprotectionsCookieFormFieldConsistencyURLClosureprotectionTagBasedCrossSiteRequestForgeryIncludesallbasicprotections Session basedProtectionwithAdvancedDefaults CookiePoisoningdefense Preventsidentitytheftandsessionhijacking Clientreturnscookietoserver Webserversendsclientcookie ApplicationFirewallverifiesthatcookieshavenotbeenmodifiedbyclient CookieAttackProtection EncryptCookies Encryptonlysessioncookies non persistent orallapplicationcookies AES 192encryption CookieAttackProtection ProxyCookies ReplaceallservercookieswithasingleAppFirewallsessioncookie CookieAttackProtection FlagCookies HTTPOnly MakecookieunavailabletoJavaScriptSecure CookiesubmittedonlyforHTTPSURLsAll BothattributesareaddedtotheSet Cookieheader CSRF FormTaggingProtection X CitrixConfidential DoNotDistribute HTMLFormFieldProtection Clientcompletesandreturnsform Applicationsendsformtoclient Protectapplicationsbyblockingmaliciousandillegalinputparameters ForeachusersessionAppFwensuresthat EachfieldisreturnedNofieldswereaddedbyclientRead onlyandhiddenfieldsareunalteredDataindrop downlistorradiobuttonfieldconformsMaxlengthofformfieldsisadheredto AdditionalSecurityMeasures ClicktoRuleApplicationFirewall ApplicationFirewallrelaxationrulescannowbedeployedfromthelogsThelogsmustbeinCEFlogformatConvenientoptiontorelaxaruleblockingalegitimaterequest LogusingCEF basedlogsMar1516 48 1410 90 196 150CEF 0 Citrix NetScaler NS10 0 APPFW APPFW STARTURL 6 src 10 90 33 39spt 52737method GETrequest http 10 90 196 152 msg DisallowIllegalURL cn1 69cn2 3999cs1 Application Firewall Profilecs2 PPE2cs3 edw9DRH XRTNya64AIYNZM1sgfUA020cs4 ALERTcs5 2012act blockedEasyintegrationwithnumerousvendorsthatsupportCEFformat CommonEventFormatLoggingSupport BusinessObjectProtectionModules FinancialTheftPrevention Preventtheinadvertentdisclosureofcustomerorcorporatedata ConfigurableProtections CreditCardNumbers Customer definedDataObjects Mastercard5168701720999598548710669503982253742473462950375229226821960783512077224560856554182441660268145214846392378060559321982241412253024957748417185141463445796112VISA4532804852500010432838048818612645327409122469234716318594729561491602234704926349296934539258794916392627322353448549592428390445322039361620554916164014266109 MastercardXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXVISAXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX Server Msg547 Level16 State1 Procedureerror demo sp Line2UPDATEstatementconflictedwithCOLUMNFOREIGNKEYconstraint fk7 acc cur Theconflictoccurredindatabase bos sommar table currencies column curcode The
溫馨提示
- 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒(méi)有圖紙預(yù)覽就沒(méi)有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 2025年城市道路拓寬改造社會(huì)穩(wěn)定風(fēng)險(xiǎn)評(píng)估與社區(qū)和諧發(fā)展報(bào)告
- 玩轉(zhuǎn)財(cái)務(wù)管理考試試題及答案
- 醫(yī)療機(jī)構(gòu)網(wǎng)絡(luò)安全體系建設(shè)指南
- 2025年工業(yè)互聯(lián)網(wǎng)平臺(tái)異構(gòu)數(shù)據(jù)庫(kù)融合技術(shù)智能海洋資源應(yīng)用研究報(bào)告
- 工程法規(guī)考試有效學(xué)習(xí)方法試題及答案
- 2025年財(cái)務(wù)科技應(yīng)用試題及答案
- 2025年新能源與環(huán)保產(chǎn)業(yè)太陽(yáng)能光伏發(fā)電技術(shù)發(fā)展報(bào)告
- 2025年中部地區(qū)房地產(chǎn)市場(chǎng)區(qū)域分化與投資策略前瞻性分析報(bào)告
- 中級(jí)會(huì)計(jì)實(shí)務(wù)考試目的性試題及答案概述
- 2025年羽毛球裁判試題
- 2024-2025學(xué)年人教版七年級(jí)(下)期中數(shù)學(xué)試卷(考試范圍:第7~9章) (含解析)
- 人工智能安全監(jiān)控系統(tǒng)開(kāi)發(fā)協(xié)議
- 油田夏季十防培訓(xùn)課件
- 工傷賠償私了協(xié)議書(shū)范本
- 學(xué)生心理健康一生一策檔案表
- 2025年佛山市三水海江建設(shè)投資有限公司招聘筆試參考題庫(kù)含答案解析
- 急性心梗診療(2025 )
- 國(guó)家義務(wù)教育質(zhì)量監(jiān)測(cè)八年級(jí)美術(shù)樣卷
- 2024年江蘇宿遷中考滿分作文《夢(mèng)想照進(jìn)現(xiàn)實(shí):我的未來(lái)職業(yè)暢想》
- 上海市2022年中考英語(yǔ)卷試題真題及答案詳解
- 2025年江蘇鳳凰新華書(shū)店集團(tuán)有限公司招聘筆試參考題庫(kù)含答案解析
評(píng)論
0/150
提交評(píng)論