TDC477: Advanced Network Security


Assignment #1: Network Security Attacks and Vulnerability Scanning

Due: April 22, 2009, 5:30pm


Part I:

We survey in class a wide range of computer and network attack (see handout #1). In this assignment, you are asked to do research to identify at least two novel system or infrastructure attacks that were not discussed in class. The identified attacks should not a variation of one of the attacks but it could have a similar affect like DDOS or others. Examples of suggested attacks to be searched includes attacks on security devices, VoIP, Quality of services, skype, overlay, P2P, new protocols (SIP, IGMP), wireless, sensor networks, mobile networks, cellular, palm/handheld devices, Grid, and multimedia services ..etc. For each of the identified attacks, you must show the following: clear description of the attack (including figures if necessary), the impact of the attack, detection mechanism(s) for this attack (proposed by you or others) and your references. Cite your references clearly (max 2 pages).

The grading will be based on the novelty of the attack and the quality of your description.

Part II:

In this lab exercise, you will use the some vulnerability analysis tool to accomplish the specified tasks below:

A-    Use Nmap to do IP scanning using TCP and ICMP and port scanning using Stealth FIN. Show the command and the output.

B-    Use NeWT or Nessus and show examples of vulnerability you discovered on a real network

All submissions are through DLWEB.

Submission Guidelines:

Submit your assignment as a Word document into DLWEB. Late submission will have 10% deduction per day.