An extended access control list for local network protection from insider attacks / Muamer N. Mohammed

By: Material type: TextTextPublication details: Kuantan, Pahang : UMP, 2011Description: xiv, 82 p. : ill. (some col.) ; 30 cm. + 1 computer discISBN:
  • THE0003672(Local)
Other title:
  • Extended access control list for local network protection from insider attacks [computer file]
Subject(s): Online resources: Dissertation note: Thesis (Master of Science (Computer)) -- Universiti Malaysia Pahang - 2011 Abstract: The security of Local Area Network (LAN) has become one of the most important interesting areas for researches and this connection is prone to vulnerability caused by the attackers in steeling information from the network and possibly makes damages. Protecting the network can be done through many mechanisms among the most effective one is the network firewall. While the firewall focusing on protecting the network from the external attacks, it only limits the internal users accessing the network. Insider attacks can be unauthorized host, application, and/or user backdoor connected to the LAN and reveal information to the outside. These types of attacks can be very dangerous. This thesis proposes solutions for these problems by creating two programs one at each client and the other at the server. At client, the program will provide each outgoing packet destined outside the network with Host Identifier, Application Identifier and User Identifier responsible for sending the current outgoing packet. It also authenticates these Identifiers in order to ensure that it is trustworthy and valid for the second program. The server will receive the authenticated packets and verifies them before passing them to the external network, while dropping and track the unauthorized one. This work based on TCP/IP protocol suite because it is the leading and important current communication protocols. Both programs operate under Microsoft Windows operating system environment. The performance of the new system is computed and the results show that the security aspects have been enhanced with respect to a slight impact in speed (decreased by 1.96 % in download, 2.35% in uploading). Finally, the proposed system implementation was developed using Visual Basic.NET language.
Tags from this library: No tags from this library for this title. Log in to add tags.
Star ratings
    Average rating: 0.0 (0 votes)
Holdings
Item type Current library Call number Copy number Status Date due Barcode
Thesis Thesis UMPLIB GAMBANG CD 5440 | TK5105.7 .M83 2011 rs Thesis (Browse shelf(Opens below)) 1 Not for loan 0000058970
Thesis Thesis UMPLIB PEKAN TK5105.7 .M83 2011 rs Thesis (Browse shelf(Opens below)) 1 Not for loan 0000058969

Thesis (Master of Science (Computer)) -- Universiti Malaysia Pahang - 2011

Bibliography : p. 77-82

The security of Local Area Network (LAN) has become one of the most important interesting areas for researches and this connection is prone to vulnerability caused by the attackers in steeling information from the network and possibly makes damages. Protecting the network can be done through many mechanisms among the most effective one is the network firewall. While the firewall focusing on protecting the network from the external attacks, it only limits the internal users accessing the network. Insider attacks can be unauthorized host, application, and/or user backdoor connected to the LAN and reveal information to the outside. These types of attacks can be very dangerous. This thesis proposes solutions for these problems by creating two programs one at each client and the other at the server. At client, the program will provide each outgoing packet destined outside the network with Host Identifier, Application Identifier and User Identifier responsible for sending the current outgoing packet. It also authenticates these Identifiers in order to ensure that it is trustworthy and valid for the second program. The server will receive the authenticated packets and verifies them before passing them to the external network, while dropping and track the unauthorized one. This work based on TCP/IP protocol suite because it is the leading and important current communication protocols. Both programs operate under Microsoft Windows operating system environment. The performance of the new system is computed and the results show that the security aspects have been enhanced with respect to a slight impact in speed (decreased by 1.96 % in download, 2.35% in uploading). Finally, the proposed system implementation was developed using Visual Basic.NET language.

Perpustakaan Universiti Malaysia Pahang Al-Sultan Abdullah
26600 Pekan, Pahang Darul Makmur
Phone: +609 431 5063 (Gambang) / +609 431 5035 (Pekan)
Email: umplibrary@umpsa.edu.my

Connect With Us