Aggressive Network Self-Defense

by Bruce Potter
When defending networks and systems, we can lose sight of acritical fact: at the other end of the wire, there is ultimately a human being attempting to breakinto our systems. Even though a self-replicating worm may be the tactical cause of a break-in,someone had to write the worm and deploy it. When a script kiddie uses a known vulnerability withan already developed exploit to break into a system, even though it is a trivial attack there isstill a person executing it.
In the case of many cyber-attacks, the attacker is a long way from the victim host. However,when an insider attack occurs in a corporation or a campus environment, the attacker may be veryclose. In this case, attackers have new capabilities that may not be available to remote attackers.ARP spoofing and other local trickery are now in play. Further, physical access to a host changesthe game considerably. Defending a host from an attacker with physical access is impressivelydifficult.
Similarly, the response to a local cyber-attack may be much more physical than normal.Sometimes, corporate policy indicates what is to be done. For instance, immediately confiscating anemployee s system and escorting him to the door may be the best course of action. Other times,however, the concept of appropriate response is either overlooked or unknown to the systemadministrator who is responding to the incident.
This chapter is meant to demonstrate new options that are available to attackers anddefenders when a local attack occurs. From a defensive standpoint, physical...