Analyse the network and enlist all vulnerabilities found

Assignment Help Computer Networking
Reference no: EM131066639

Assignment-

Introduction:

A mining company based in Perth operates from three separate offices: Perth Head Office, branch offices in the Pilbara Region and at Port Hedland. There is also a Mobile Ad-Hoc Network deployed at one of the mining company's plants in North-West WA. Based on a regular audit of the network, it has been noted that several security vulnerabilities are exposing the internal network to third-parties. These security issues are to be rectified.

You are a network security consultant who has been hired to advice on the issues present in the current architecture from a network security perspective and to proposed possible architectural improvements to the network in response to the identified vulnerabilities. Following is a description of the corporate network.

Perth Head Office:

  • 60 client desktop PCs running Windows 10
  • 20 client desktop PCs running Windows 8
  • Web server (external) running Apache on Redhat Linux
  • MS Exchange Server on Windows Server 2008
  • 802.11 wireless links using WPA TKIP
  • Executives are allowed to BYOD and access the internal network from their personal devices
  • Connection between Head Office and PH Site over a leased line
  • External Access is via VPN (PPTP) user name and password
  • There is an anti-virus server

Port Hedland Office and Pilbara Region Offices:

  • 20 PCs each with Windows 10
  • Authentication to ADS over the WAN link to Perth office
  • Connected to the Mobile Ad-Hoc Network site via an 802.11 wireless (WPA TKIP) Mining Site
  • No ADS - all PCs belong to a workgroup
  • Connection to Perth Office via 802.11g point to point link (WPA TKIP)

Mobile Ad-Hoc Network:

  • 5 machines running Windows 10
  • Wireless connectivity to the Port Hedland Office
  • No Firewall or Anti-Virus Deployed

Other information:

  • The network security policy has not been updated since 2010
  • There is no patching regime
  • See attached network diagram (Note: this may be out of date but is the most current we can find)
  • The VPN at the Head Office and the VPN at the mine site are not connected

2292_Figure.png

Tasks:

You are required to produce the following deliverables as part of your contract:

1. Analyse the network and enlist all vulnerabilities found.

2. The vulnerabilities identified in the network architecture from (1) above should be explained in detail.

3. Provide recommended improvements to the network architecture in order to harden the entire network and to fix the vulnerabilities identified above.

4. Draw the improved network architecture.

5. Based on a rough estimate of the number of operating devices at the Perth HO and the Port Hedland Offices, as well as the network bandwidth, estimate the network traffic intensity during a given time of the day (approximated in numbers). Is there any bottleneck identified on this link that can be exploited by the adversary for launching a DoS attack? If so, propose a solution for countering this threat.

6. Create a JMeter profile to generate network traffic with intensity calculated in (5) above.

7. Generate the network traffic based on the profile from (6) above.

8. Capture the generated network traffic using Wireshark. (Hint: Run Wireshark on a separate virtual machine from JMeter).

9. Write-up network security policies for the resources of the network (devices and technologies). Do not write access policies for end-users rather define policies appertaining solely to the network architecture.

Verified Expert

Reference no: EM131066639

Questions Cloud

What is the expected loss per exposure : Y2K Inc. has estimated that half of their twenty workers will be injured in the coming year. The expected severity per occurrence is $1,000. What is the expected loss per exposure?
Hereditary component of intelligence : It is likely that parents' achievements have some predictive power for their children's outcomes, as a result of both a hereditary component of intelligence and the possibility that higher educated parents stimulate their children to do well at sc..
What are the major benefits of budgeting : Why is budgeted performance better than past performance as a basis for judging actual results and what are the major benefits of budgeting?
Explain ways you envision it implementing a desired change : Include a paragraph describing your interpretation of the Action Research (n.d.) quote above for this discussion including how it specifically relates to your action research proposal. Then, in one-to-two paragraphs, explain the ways you envision ..
Analyse the network and enlist all vulnerabilities found : CSI 3207/CSI 5212 (Term 161) Major Assignment. You are required to produce the following deliverables as part of your contract: Analyse the network and enlist all vulnerabilities found. The vulnerabilities identified in the network architecture from ..
Problem regarding the realization principle : Sky Bound Airlines has provided the following information regarding cash received for ticket sales in September and October:
How does nursing home differ from skilled nursing facility : How does a nursing home differ from a skilled nursing facility? What is the difference between a rehabilitation hospital and a rehabilitation care facility?
Calculate the cost of preference capital : Question 1: Calculate the cost of preference capital (kp) for a non-redeemable preference share which has the following:
What is the correct cost of capital : Question 1: The 90 day bank bill rate is quoted as 3.8 in the financial press. What is the correct cost of capital kbb to be used in the WACC calculation. Express as a number accurate to four places (to the nearest basis point).

Reviews

Write a Review

Computer Networking Questions & Answers

  Design a lan for firm with five departments in one building

You have been asked to design a LAN for very successful CPA firm with 5 departments in one building and total of 500 employees.

  Consider this scenario.a new three level building

Consider this scenario. A new three level building will be built to accommodate three computer labs. It will be a separate building from the existing one. Each level will accommodate one lab. 50 personal computers (PCs) and a shared printer will b..

  Describe the wireless spectrum

Describe the wireless spectrum. Describe how interference can distort and weaken a wireless signal. Describe the Frequency-Hopping Spread Spectrum (FHSS) and Direct-Sequence Spread Spectrum (DSSS) spread spectrum technologies

  Write a memo describing the upgrade computer network

Write a memo describing the upgrade computer network

  Explore signal handling techniques, such as modulation, ofdm

Also explore signal handling techniques, such as modulation, OFDM, and MIMO, particularly used in wireless systems.

  What is the url name and dotted quad ip address of an

the current ip address standard is 32 bits. ipv6 will increase the address length to 128 bits. an ip socket address

  Could you reduce the amount of data that would be lost

Could you get enough information from the Internet to take out a loan in another person's name? You should provide any recent cases in Australia to support your explanation.

  What is the ethernet standard used in such a vlan

Explain in detail with the help of diagrams the CSMA/CD media access control technique used in Ethernet and write a report on your observations analyzing the data collected in previous step.

  Identify and describe the processes involved in the windows

identify and describe the processes involved in the windows client server environment.explain the role of clientserver

  What is utc and why is it used

The topics above are linked to each other and the question, they are not independent of each other. They are provided as a minimal guide only. Do not simply write an unconnected paragraph on each without linking the concepts together.

  Outline the design of a wireless network

Outline the design of a wireless network to support user mobility over a wide area. Include in your answer a discussion of addressing, routing and the used of fixed versus ad hoc network access nodes or base stations.

  Configure a site-to-site ipsec vpn on the dallas router

Configure a Site-to-Site IPSec VPN on the Dallas Router, Which IKE (isakmp) policy would have the highest priority

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd