U2.6 SNMPv3

Description

Nework Security Mind Map on U2.6 SNMPv3, created by jjanesko on 10/04/2014.
jjanesko
Mind Map by jjanesko, updated more than 1 year ago
jjanesko
Created by jjanesko about 10 years ago
43
0

Resource summary

U2.6 SNMPv3
  1. Designed to take care of threats from SNMPv1 and SNMPv2
    1. data modification
      1. masquerade
        1. massage stream modification
          1. reorder
            1. replay
              1. delay
              2. eavesdropping
              3. adopted security services
                1. data origin authentication
                  1. HMAC on encrypted message
                    1. shared key (K2) derived from snmpEngineID of authoritative entity + network admin passphrase
                      1. pretects against masquerade
                      2. data integrity
                        1. HMAC on encrypted message
                          1. shared key (K2) derived from snmpEngineID of authoritative entity + network admin passphrase
                            1. protects against data modification
                              1. protects against message stream modification (reorder)
                              2. data confidentiality
                                1. DES cipher block chaining
                                  1. shared key (K1) derived from snmpEngineID of authoritative entity + network admin passphrase
                                    1. protects against eavesdropping
                                    2. message timelines (limited replay protection)
                                      1. entities must synchronize clocks
                                        1. 150 second window for communication exchanges
                                          1. protects against message stream modification
                                            1. replay
                                              1. delay
                                          2. general setup
                                            1. network admin gives to all SNMP entities
                                              1. a unique snmpEngineID
                                                1. network admin's SNMP passphrase
                                                2. encryption and HMAC keys based on values from "authoritative entity" in a communication exchange
                                                  1. GET, SET SNMP PDU
                                                    1. receiver is authoritative entity
                                                    2. TRAP, REPORT, RESPONSE SNMP PDU
                                                      1. sender is the authoritative entity
                                                  Show full summary Hide full summary

                                                  Similar

                                                  U2.1 Cables, Hubs, Sniffers
                                                  jjanesko
                                                  U2.4 LANs, MANs, WANs
                                                  jjanesko
                                                  U2.5 SNMPv1
                                                  jjanesko
                                                  U2.1 Cables,Hubs,Sniffers- Thin Ethernet
                                                  jjanesko
                                                  U2.5 SNMPv1 - architectural model
                                                  jjanesko
                                                  U2.1 Cables, Hubs, Sniffers - Hub Diagram
                                                  jjanesko
                                                  U2.2 Switches, ARP - ARP spoofing steps
                                                  jjanesko
                                                  U2.3 TCP, Routers - Router Diagram
                                                  jjanesko
                                                  U2.5 SNMPv1 - SNMPv1 protocol stack
                                                  jjanesko
                                                  U2.2 Switches, ARP
                                                  jjanesko
                                                  U2.3 TCP, Routers, VLAN
                                                  jjanesko