University of maryland i t security
Download
1 / 12

University of Maryland I.T. Security - PowerPoint PPT Presentation


  • 77 Views
  • Uploaded on

University of Maryland I.T. Security. Gerry Sneeringer IT Security Officer [email protected] Slides Online. http://nts.umd.edu/~sneeri/6dec02.ppt. Information Technology Security Officer. Develop University Security Architecture Lead Incident Handling Efforts Develop User Education Program

loader
I am the owner, or an agent authorized to act on behalf of the owner, of the copyrighted work described.
capcha
Download Presentation

PowerPoint Slideshow about ' University of Maryland I.T. Security' - gray-boone


An Image/Link below is provided (as is) to download presentation

Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author.While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server.


- - - - - - - - - - - - - - - - - - - - - - - - - - E N D - - - - - - - - - - - - - - - - - - - - - - - - - -
Presentation Transcript
University of maryland i t security

University of MarylandI.T. Security

Gerry Sneeringer

IT Security Officer

[email protected]


Slides online

Slides Online

http://nts.umd.edu/~sneeri/6dec02.ppt


Information technology security officer
Information Technology Security Officer

  • Develop University Security Architecture

  • Lead Incident Handling Efforts

  • Develop User Education Program

  • .


University environment
University Environment

  • Major administrative and business systems ($1 Billion enterprise)

  • 30,000 research and administration computers (hundreds of system managers)

  • 11,000 networked residential students

  • 12,500 remote access users

  • Wireless access

  • .


Vulnerabilities
Vulnerabilities

  • Discovery of new weaknesses in common software

  • Poorly maintained computers

  • Human Nature

    • Poor Passwords

    • Accepting strange attachments

    • Operating dangerous software

  • .


Current threats
Current Threats

  • Computer Viruses/Worms

  • Script Kiddies

  • Media Pirates

  • Denial of Service

  • .


Security architecture
Security Architecture

  • Three Objectives

    • PROTECT

    • DETECT

    • INFORM

  • .


Protect
PROTECT

  • Deployment of Multiple Layers of Firewall

    • Campus Borders

    • Individual Networks

    • Individual Computers

  • Distribution of Anti-Virus Software

    • On all computers

    • On campus mail server

  • Virtual Private Networks

  • .


Detect
DETECT

  • Deployment of several layers of Intrusion Detection Systems

    • Watch traffic entering/exiting University

    • Watch traffic between segments within University

    • Host based software to detect unauthorized changes

  • .


Detect ii
DETECT - II

  • Systemic use of vulnerability scanning software.

  • Monitor bandwidth trends

  • .


Inform
INFORM

  • User Education Programs

    • Project NEThics (www.umd.edu/nethics)

    • Forums for System Administrators

    • Forums for computer users

    • Web Pages

  • .


Additional urls
Additional URLs

  • Intrusion Detection System:

    • www.snort.org

  • Vulnerability Scanning

    • www.nessus.org


ad