Enhancing Network Security through SCAP Compliance and Community Cloud Solutions
This document outlines strategies for improving network security by leveraging SCAP (Security Content Automation Protocol) compliant tools and community cloud solutions. It covers key security measures such as audit processes, system hardening, and security operation APIs. Topics include how to mitigate risks from IP, ARP, and MAC spoofing, as well as TCP session hijacking. Additionally, it discusses the integration of SCAP-enabled scanners and the role of community cloud frameworks in maintaining robust security protocols in both Windows and Linux environments.
Enhancing Network Security through SCAP Compliance and Community Cloud Solutions
E N D
Presentation Transcript
C3S Idea 诸葛建伟 2010-12
C3S Idea • C3S: CERNET Community Cloud for Security • Bones: Community Cloud • Body: SCAP(Security Content Automation Protocol) • Security Audit • Security Harden • Flood • Security Content Data API • Security Operation API
SCAP • System Security • Desktop: SCAP-FDCC • Server: SCAP-FSCC • Network Security - SCAP-FNCC? • Network Protocol Security • IP Spoofing • ARP Spoofing • MAC Spoofing • TCP Session Hijacking • …… • Network Device Security Configuration • Routers, Switches, APs, …
SCAP Scanner • SCAP-enabled Scanners • Nessus System Center/Pro Feed • For Windows • Via SMB (needs credentials configured at Scanners) • For Linux ? • Via SSH? SNMP? • OpenSCAP • Open Source Project • For Windows? Not supported. • For Linux, supported • Need Local Root Access? Yes