150 likes | 317 Views
TIR Solutions. Tim Wostradowski , Ian Brophy, John Ang. Baseline Security. Agenda. Project Conception Developing the Idea Refining the Method Gathering the Data From Data to Information Results Linux Windows Overall The Future of the Project Final Thoughts Q & A.
E N D
TIR Solutions Tim Wostradowski , Ian Brophy, John Ang
Agenda • Project Conception • Developing the Idea • Refining the Method • Gathering the Data • From Data to Information • Results • Linux • Windows • Overall • The Future of the Project • Final Thoughts • Q & A
Project Conception • Security Based • Interested in Security Related Matters • Research Based • The Pursuit of Knowledge • Sponsor • Seccuris’ Project Idea
Developing the Idea • Open Source • Testing • Backtrack • Storing Data • Database • Viewing Data • Web interface
Refining the Method • Operating Systems • Stock Installations • What Data is Relevant? • Ports, fingerprint, exploits • Default security measures? • Analyze Vulnerabilities
Gathering the Data • BackTrack • NMAP • Port Mapping/Scanning • Metasploit Framework • Exploits
From Data to Information • Analysis of Baseline Security • Default Security Measures? • Open ports? • Exploits? • Digging Deeper • Comparisons • Logical Conclusions
Results - Linux • Fedora • Ubuntu • openBSD • freeBSD
Results – Windows • Pre XP • Defenseless • XP • SP2: the dawn of Windows firewalls • Post XP • Solid baseline security measures
Analysis of Results • Windows • Firewall • The XP Transition • Defender • Linux • Closed Ports • Windows vs Linux • Equilibrium or landslide?
The Future of the Project • Non-default Software • Explore the Adverse Affects • Web Interface • More Features • ie: Comparison Tool • Implement on Real Hardware • Are Virtual Machines Really On Par?
Final Thoughts • Windows and Linux • Surprising Equality • Upgrade Your Operating System • ie: Windows XP to Windows 7 • Keep It On • Firewall • Application Defender
Q & A • Some Ideas: • Did you learn anything from this presentation? • What did we learn from this project? • Does something need clarification? • What was our favorite aspect of the project?