作者: Tomas Olovsson , Ulf Gustafson , Erland Jonsson
DOI:
关键词:
摘要: This paper presents an intrusion experiment in which the target system was a Personal Computer network connected to Novell NetWare 3.12 server. Undergraduate students with little security expertise and hardly any knowledge of served as attackers were given task performing many intrusions possible. The objectives twofold: first, learn more about how gather process data from experiments form methodology applicable generic class computer systems; and, second, find out whether it is actually possible create secure based on insecure PC workstations. deals mainly latter objective, investigates what extent unevenly distributed features, such “secure” file server untrusted clients, affect overall security. Furthermore, experiments, opposed real life situations, collect information attacking carried out. Before experiment, we anticipated that would Trojan Horses clients spoof other users during login process, but did not expect them serious vulnerabilities concept they did. shows have ample possibilities, can be compensated by features elsewhere system. has undoubtedly spent effort securing its assets than contains summary problems found, evident several new mechanisms must added before regarded secure.