Showing posts with label Network. Show all posts
Showing posts with label Network. Show all posts

Monday, April 9, 2012

Computer Systems Architecture A Networking Approach







Preface xiii
Preface to the first edition xv
Recommended lab sessions xxi
Part 1 Basic functions and facilities of a computer
Introduction: the hardware–software interface 3
1.1 Computer systems – the imprtance of networking 4
1.2 Hardware and software – mutual dependence 5
1.3 Programming your way into hardware – VHDL, a language for
electronic engineers 6
1.4 Systems administration – we all need to know 9
1.5 Voice, image and data – technological convergence 9
1.6 Windowing interfaces – WIMPs 11
1.7 The global Internet – connecting all the networks 13
1.8 Using the PC – a case study; more reasons to study CSA 16
The von Neumann Inheritance 23
2.1 Base 2 – the convenience of binary – 10110011100011110000 24
2.2 Stored program control – general-purpose machines 24
2.3 Instruction codes – machine action repertoire 26
2.4 Translation – compilers and assemblers 28
2.5 Linking – bringing it all together 28
2.6 Interpreters – executing high-level commands 30
2.7 Code sharing and reuse – let’s not write it all again! 31
2.8 Data codes – numeric and character 32
2.9 The operating system – Unix and Windows 36
2.10 Client–server computing – the way of the Net 40
2.11 Reconfigurable hardware – an alternative to fetch–execute 42
Functional units and the fetch–execute cycle 47
3.1 The naming of parts – CPU, memory, IO units 48
3.2 The CPU fetch–execute cycle – high-speed tedium 52
3.3 System bus – synchronous or asynchronous? 56
3.4 System clock – instruction cycle timing 59
3.5 Pre-fetching – early efforts to speed things up 61
3.6 Memory length – address width 63
3.7 Endian-ness – Microsoft vs. Unix, or Intel vs. Motorola? 65
3.8 Simple input–output – parallel ports 67
Building computers from logic: the control unit 73
4.1 Electronic Lego and logic – the advantage of modular units 74
4.2 Basic logic gates – truth tables for AND, OR, XOR and NOT 75
4.3 Truth tables and multiplexers – a simple but effective design tool 77
4.4 Programmable logic – reconfigurable logic chips 79
4.5 Traffic light controllers – impossible to avoid! 82
4.6 Circuit implementation from truth tables – some practical tips 83
4.7 Decoder logic – essential for control units and memories 85
4.8 CPU control unit – the ‘brain’ 87
4.9 Washing machine controllers – a simple CU 88
4.10 RISC vs. CISC decoding – in search of faster computers 91
Building computers from logic: the ALU 97
5.1 De Morgan’s equivalences – logical interchangeability 98
5.2 Binary addition – half adders, full adders, parallel adders 98
5.3 Binary subtraction – using two’s complement integer format 101
5.4 Binary shifting – barrel shifter 103
5.5 Integer multiplication – shifting and adding 105
5.6 Floating-point numbers – from very, very large to very, very small 108
Building computers from logic: the memory 117
6.1 Data storage – one bit at a time 118
6.2 Memory devices – memory modules for computers 120
6.3 Static memory – a lot of fast flip-flops 121
6.4 Dynamic memory – a touch of analogue amid the digital 122
6.5 DRAM refreshing – something else to do 124
6.6 Page access memories – EDO and SDRAM 124
6.7 Memory mapping – addressing and decoding 127
6.8 IO port mapping – integration vs. differentiation 131
The Intel Pentium CPU 137
7.1 The Pentium – a high-performance microprocessor 138
7.2 CPU registers – temporary store for data and address variables 143
7.3 Instruction set – introduction to the basic Pentium set 148
7.4 Structure of instructions – how the CU sees it 149
7.5 CPU status flags – very short-term memory 151
7.6 Addressing modes – building effective addresses 153
7.7 Execution pipelines – the RISC speedup technique 155
7.8 Pentium 4 – extensions 157
7.9 Microsoft Developer Studio – using the debugger 158
Subroutines 167
8.1 The purpose of subroutines – saving space and effort 168
8.2 Return address – introducing the stack 169
8.3 Using subroutines – HLL programming 170
8.4 The stack – essential to most operations 172
8.5 Passing parameters – localizing a subroutine 173
8.6 Stack frame – all the local variables 176
8.7 Supporting HLLs – special CPU facilities for dealing with subroutines 179
8.8 Interrupt service routines – hardware-invoked subroutines 179
8.9 Accessing operating system routines – late binding 180
Simple input and output 185
9.1 Basic IO methods – polling, interrupt and DMA 186
9.2 Peripheral interface registers – the programmer’s viewpoint 187
9.3 Polling – single-character IO 191
9.4 Interrupt processing – service on demand 197
9.5 Critical data protection – how to communicate with interrupts 205
9.6 Buffered IO – interrupt device drivers 209
9.7 Direct memory access (DMA) – autonomous hardware 210
9.8 Single-character IO – screen and keyboard routines 212
Serial Connections 219
10.1 Serial transmission – data, signals and timing 220
10.2 Data format – encoding techniques 221
10.3 Timing synchronization – frequency and phase 224
10.4 Data codes and error control – parity, checksums, Hamming codes
and CRCs 227
10.5 Flow control – hardware and software methods 235
10.6 The 16550 UART – RS232 237
10.7 Serial mice – mechanical or optical 244
10.8 Serial ports – practical tips, avoiding the frustration 246
10.9 USB – Universal Serial Bus 246
10.10 Modems – modulating carrier waves 252
Parallel connections 263
11.1 Parallel interfaces – better performance 264
11.2 Centronics – more than a printer port but less than a bus 264
11.3 SCSI – the Small Computer Systems Interface 267
11.4 IDE – Intelligent Drive Electronics 271
11.5 AT/ISA – a computer standards success story 272
11.6 PCI – Peripheral Component Interconnection 275
11.7 Plug-and-Play – automatic configuration 278
11.8 PCMCIA – Personal Computer Memory Card
International Association 280
The memory hierarchy 285
12.1 Levels of performance – you get what you pay for 286
12.2 Localization of access – exploiting repetition 288
12.3 Instruction and data caches – matching memory to CPU speed 293
12.4 Cache mapping – direct or associative 295
12.5 Virtual memory – segmentation and demand paging 299
12.6 Address formulation – when, where and how much 304
12.7 Hard disk usage – parameters, access scheduling and
data arrangement 306
12.8 Performance improvement – blocking, caching, defragmentation,
scheduling, RAM disk 310
12.9 Optical discs – CD-DA, CD-ROM, CD-RW and DVDs 312
12.10 DVD – Digital Versatile Disc 316
12.11 MPEG – video and audio compression 316
12.12 Flash sticks – the new floppy disk 323
Part 2 Networking and increased complexity
The programmer’s viewpoint 329
13.1 Different viewpoints – different needs 330
13.2 Application user – office packages 331
13.3 Systems administration – software installation and maintenance 333
13.4 HLL programmer – working with Java, C++, BASIC or C# 337
13.5 Systems programming – assembler and C 340
13.6 Hardware engineer – design and hardware maintenance 344
13.7 Layered virtual machines – hierarchical description 345
13.8 Assemblers – simple translators 346
13.9 Compilers – translation and more 347
Local area networks 353
14.1 Reconnecting the users – email, printers and database 354
14.2 PC network interface – cabling and interface card 359
14.3 Ethernet – Carrier Sense, Multiple Access/Collision Detect 363
14.4 LAN addressing – logical and physical schemes 367
14.5 Host names – another layer of translation 370
14.6 Layering and encapsulation – TCP/IP software stack 371
14.7 Networked file systems – sharing files across a network 372
14.8 Interconnecting networks – gateways 374
14.9 Socket programming – an introduction to WinSock 374
Wide area networks 383
15.1 The Internet – origins 384
15.2 TCP/IP – the essential protocols 386
15.3 TCP – handling errors and flow control 390
15.4 IP routing – how packets find their way 392
15.5 DNS – Distributed Name Database 398
15.6 World Wide Web – the start 401
15.7 Browsing the Web – Netscape Navigator 403
15.8 HTTP – another protocol 407
15.9 Search engines – Google 409
15.10 Open Systems Interconnect – an idealized scheme 412
Other networks 419
16.1 The PSTN – telephones 420
16.2 Cellnets – providers of mobile communications 426
16.3 ATM – Asynchronous Transfer Mode 435
16.4 Messaging – radio paging and packet radio networks 440
16.5 ISDN – totally digital 442
16.6 DSL – Digital Subscriber Line 446
16.7 Cable television – facilities for data transmission 447
Introduction to operating systems 455
17.1 Historic origins – development of basic functions 456
17.2 Unix – a landmark operating system 459
17.3 Outline structure – modularization 462
17.4 Process management – initialization and dispatching 463
17.5 Scheduling decisions – time-slicing, demand preemption
or cooperative 469
17.6 Task communication – pipes and redirection 471
17.7 Exclusion and synchronization – semaphores and signals 473
17.8 Memory allocation – malloc( ) and free( ) 479
17.9 User interface – GUIs and shells 481
17.10 Input–output management – device handlers 482
Windows XP 491
18.1 Windows GUIs – responding to a need 492
18.2 Win32 – the preferred user API 494
18.3 Processes and threads – multitasking 495
18.4 Memory management – virtual memory implementation 496
18.5 Windows Registry – centralized administrative database 496
18.6 NTFS – Windows NT File System 498
18.7 File access – ACLs, permissions and security 499
18.8 Sharing software components – OLE, DDE and COM 502
18.9 Windows NT as a mainframe – Winframe terminal server 502
Filing systems 507
19.1 Data storage – file systems and databases 508
19.2 The PC file allocation table – FAT 515
19.3 Unix inodes – they do it differently 518
19.4 Microsoft NTFS – complexity and security 523
19.5 RAID configuration – more security for the disk subsystem 525
19.6 File security – access controls 526
19.7 CD portable file system – multi-session contents lists 528
Visual output 533
20.1 Computers and graphics – capture, storage, processing
and redisplay 534
20.2 PC graphics adapter cards – graphics coprocessors 541
20.3 Laser printers – this is mechatronics! 547
20.4 Adobe PostScript – a page description language 549
20.5 WIMPs – remodelling the computer 554
20.6 Win32 – graphical API and more 555
20.7 The X Window system – enabling distributed processing 557
20.8 MMX technology – assisting graphical calculations 558
RISC processors: ARM and SPARC 563
21.1 Justifying RISC – increased instruction throughput 564
21.2 Pipeline techniques – more parallel operations 569
21.3 Superscalar methods – parallel parallelism 571
21.4 Register files – many more CPU registers 572
21.5 Branch prediction methods – maintaining the pipelines 574
21.6 Compiler support – an essential part of RISC 576
21.7 The ARM 32 bit CPU – origins 576
21.8 StrongARM processor – a 32 bit microcontroller 585
21.9 The HP iPAQ – a StrongARM PDA 588
21.10 Puppeteer – a StrongARM SBC 590
21.11 Sun SPARC – scalar processor architecture as RISC 592
21.12 Embedded systems – cross-development techniques 594
VLIW processors: the EPIC Itanium 601
22.1 Itanium 64 bit processor – introduction 602
22.2 Itanium assembler – increasing the control of the CPU 609
22.3 Run-time debugging – gvd/gdb 613
22.4 Future processor design – debate 615
Parallel processing 619
23.1 Parallel processing – the basis 620
23.2 Instruction-level parallelism (ILP) – pipelining 623
23.3 Superscalar – multiple execution units 623
23.4 Symmetric, shared memory multiprocessing (SMP) – the future? 623
23.5 Single-chip multiprocessors – the IBM Cell 626
23.6 Clusters and grids – application-level parallelism 629
Appendix: MS Visual Studio 8, Express Edition 635
Glossary 647
Answers to end-of-chapter questions 661
References 713
Index 717

Computer architecture - Wikipedia, the free encyclopedia, EE282 - Computer Systems Architecture - Stanford University

A Networking Approach to Grid Computing

Data Warehousing and Data Mining for Telecommunications
Other Core of CS Books
Other Network Books

Saturday, January 7, 2012

Computer Networks A Systems Approach - Solution manual - Peterson and Davies






Dear Instructor:
This Instructors’ Manual contains solutions to almost all of the exercises in the second edition of Peterson and Davie’s Computer Networks: A Systems Approach. The goal of the exercise program for the second edition has been to provide a wide range of exercises supporting the text that are both accessible and interesting. When applicable, exercises were chosen that attempt to illuminate why things are done the way they are, or how they might be done differently. It is hoped that these exercises will prove useful to:

support mastery of basic concepts through straightforward examples
provide a source of classroom examples and discussion topics
provide a study guide and source of exam problems
introduce occasional supplemental topics
support an exercise-intensive approach to the teaching of networks.

Exercises are sorted (roughly) by section, not difficulty. While some exercises are more difficult than others, none are intended to be fiendishly tricky. A few exercises (notably, though not exclusively, the ones that involve calculating simple probabilities) require a modest amount of mathematical background; most do not. There is a sidebar summarizing much of the applicable basic probability theory in Chapter 2.

An occasional exercise (eg 4.21) is awkwardly or ambiguously worded in the text. This manual sometimes suggests better versions; see also the errata at the web site, below.
Where appropriate, relevant supplemental files for these solutions (eg programs) have been placed on the textbook web site, www.mkp.com/pd2e. Useful other material can also be found there, such as errata, sample programming assignments, PowerPoint lecture slides, EPS figures, and the x-kernel code and tutorial. If you have any questions about these support materials, please contact your Morgan Kaufmann sales representative. If you would like to contribute your own teaching materials to this site, please contact Karyn Johnson, Morgan Kaufmann Editorial Department,
kjohnson@mkp.com.

We welcome bug reports and suggestions as to improvements for both the exercises and the solutions; these may be sent to netbugs@mkp.com.
Peter Lars Dordal
pld@cs.luc.edu
Loyola University of Chicago
September, 1999

Other Computer Network Books
Download

Saturday, December 24, 2011

Computer Networks Problem Solution






Covers almost every aspect of networking in detail. It progresses in a very systematic manner to unfold all the concepts related to the 7 layers of the OSI and much more.

Amazon.com: Active Network Analysis: Problems & Solutions (Advanced Series in Electrical and Computer Engineering) (9789810213367): Wai-Kai Chen: Books. Computer Networks Problem Solutions eBook Downloads Computer Networks Problem Solutions free PDF ebook downloads. Computer Network Solutions | Facebook Computer Network Solutions - With 22 years of IT experience, CNS seeks to provide excellence customer service and to resolve our customers problems correctly the. ebook pdf - computer networks tanenbaum problem solutions free. Amazon.com: Active Network Analysis: Problems & Solutions. Computer Networks, Fourth Edition ( Problem Solutions) - Free. Book (CHM) + Solutions Manual (PDF) 9 MB . Tanenbaum - Free chm, pdf ebooks rapidshare download, ebook torrents. Download Free eBook:Computer Networks, Fourth Edition ( Problem Solutions) - Free chm, pdf ebooks rapidshare download COMPUTER NETWORKS PROBLEM SOLUTIONS 5th EDITION Book COMPUTER NETWORKS PROBLEM SOLUTIONS 5th EDITION free books download from our website ebooks download free and download free Cisco Networking book, download free. Computer Networks, Fourth Edition ( Problem Solutions) by Andrew. Computer Networks, Fourth Edition (PROBLEM SOLUTIONS) by Andrew S. Download Free eBook:Computer Networks, Fourth Edition ( Problem Solutions) by Andrew S. The finest network engineer I know (who was. Tanenbaum; This is the long-awaited 3rd Edition of Tanenbaum's classic book on computer networking. ebookpdf.net - Networks computer networks tanenbaum problem solutions free download ebook 1 to 5 of 2059 ( 1 of 412 ) - free ebook for download - free business. ebook chm - tanenbaum computer networks problems solutions ebook tanenbaum computer networks problems solutions ebook 1 to 5 of 2931 ( 1 of 587 ) - free ebook


Another Network Books
Another Core Of CS Books
Download

Tuesday, November 29, 2011

An Introduction to Network Programming with Java






Contents
Chapter 1 Basic Concepts, Protocols and Terminology ......................... 1
1.1 Clients, Servers and Peers ................................................................. 1
1.2 Ports and Sockets .............................................................................. 2
1.3 The Internet and IP Addresses .......................................................... 3
1.4 Internet Services, URLs and DNS .................................................... 4
1.5 TCP ................................................................................................... 5
1.6 UDP .................................................................................................. 7
Chapter 2 Starting Network Programming in Java ............................... 9
2.1 The InetAddress Class ...................................................................... 9
2.2 Using Sockets ................................................................................... 12
2.2.1 TCP Sockets ..... .................................................................... 12
2.2.2 Datagram (UDP) Sockets ....................................................... 18
2.3 Network Programming with GUIs ................................................... 28
2.4 Downloading Web Pages ................................................................. 37
Exercises ................................................................................................... 41
Chapter 3 Multithreading and Multiplexing .......................................... 51
3.1 Thread Basics ................................................................................... 51
3.2 Using Threads in Java ..................................................................... 52
3.2.1 Extending the Thread Class ................................................... 53
3.2.2 Explicitly Implementing the Runnable Interface ...................... 57
3.3 Multithreaded Servers ..................................................................... 60
3.4 Locks and Deadlock ........................................................................ 65
3.5 Synchronising Threads .................................................................... 67
3.6 Non-Blocking Servers ..................................................................... 74
3.6.1 Overview ................................................................................. 74
3.6.2 Implementation ......................................................................... 76
3.6.3 Further Details .......................................................................... 86
Exercises .................................................................................................. 88
Chapter 4 File Handling .......................................................................... 91
4.1 Serial Access Files .......................................................................... 91
4.2 File Methods ................................................................................... 97
4.3 Redirection .................................................................................... 99
4.4 Command Line Parameters ............................................................ 101
4.5 Random Access Files ..................................................................... 102
4.6 Serialisation .................................................................................... 109
4.7 File I/O with GUIs ......................................................................... 113
4.8 Vectors ........................................................................................... 120
4.9 Vectors and Serialisation ............................................................... 123
Exercises ................................................................................................. 132
Chapter 5 Remote Method Invocation (RMI) ...................................... 136
5.1 The Basic RMI Process .................................................................. 136
5.2 Implementation Details .................................................................. 137
5.3 Compilation and Execution ............................................................ 141
5.4 Using RMI Meaningfully ............................................................... 143
5.5 RMI Security .................................................................................. 153
Exercises ................................................................................................. 156
Chapter 6 CORBA ................................................................................... 158
6.1 Background and Basics ................................................................... 158
6.2 The Structure of a Java IDL Specification ...................................... 159
6.3 The Java IDL Process ...................................................................... 163
6.4 Using Factory Objects ..................................................................... 173
6.5 Object Persistence ........................................................................... 184
6.6 RMI-IIOP ........................................................................................ 184
Exercises .................................................................................................. 186
Chapter 7 Java Database Connectivity (JDBC) ................................... 188
7.1 The Vendor Variation Problem ....................................................... 188
7.2 SQL and Versions of JDBC ............................................................ 189
7.3 Creating an ODBC Data Source ..................................................... 190
7.4 Simple Database Access .................................................................. 191
7.5 Modifying the Database Contents ................................................... 199
7.6 Transactions .................................................................................... 203
7.7 Meta Data ........................................................................................ 204
7.8 Using a GUI to Access a Database ................................................. 207
7.9 Scrollable ResultSets in JDBC 2.0 .................................................. 210
7.10 Modifying Databases via Java Methods ......................................... 215
7.11 Using the DataSource Interface ...................................................... 220
7.11.1 Overview and Support Software ............................................ 220
7.11.2 Defining a JNDI Resource Reference ....................................... 222
7.11.3 Mapping the Resource Reference onto a Real Resource ........... 223
7.11.4 Obtaining the Data Source Connection ..................................... 225
7.11.5 Data Access Objects .................................................................. 226
Exercises .................................................................................................. 232
Chapter 8 Servlets .................................................................................... 234
8.1 Servlet Basics .................................................................................... 234
8.2 Setting up the Servlet API ............................................................... 235
8.3 Creating a Web Application ............................................................ 237
8.4 The Servlet URL and the Invoking Web Page ................................ 239
8.5 Servlet Structure ............................................................................... 240
8.6 Testing a Servlet .............................................................................. 242
8.7 Passing Data .................................................................................... 242
8.8 Sessions ........................................................................................... 249
8.9 Cookies ............................................................................................ 260
8.10 Accessing a Database Via a Servlet ................................................ 268
Exercises .................................................................................................. 275
Chapter 9 JavaServer Pages (JSPs) ........................................................ 278
9.1 The Rationale behind JSPs ............................................................... 278
9.2 Compilation and Execution ............................................................. 279
9.3 JSP Tags .......................................................................................... 280
9.4 Implicit JSP Objects ........................................................................ 283
9.5 Collaborating with Servlets ............................................................. 285
9.6 JSPs in Action ................................................................................. 285
9.7 Error Pages ...................................................................................... 291
9.8 Using JSPs to Access Remote Databases ....................................... 294
Exercises .................................................................................................. 295
Chapter 10 JavaBeans ................................................................................ 297
10.1 Introduction to the Bean Builder .................................................... 298
10.2 Creating a JavaBean ....................................................................... 301
10.3 Exposing a Bean's Properties ......................................................... 307
10.4 Making Beans Respond to Events ................................................. 311
10.5 Using JavaBeans within an Application ........................................ 315
10.6 Bound Properties ........................................................................... 317
10.7 Using JavaBeans in JSPs ............................................................... 324
10.7.1 The Basic Procedure ........................................................ 324
10.7.2 Calling a Bean's Methods Directly .................................. 326
10.7.3 Using HTML Tags to Manipulate a Bean's Properties .... 330
Exercises .................................................................................................. 342
Chapter 11 Introduction to Enterprise JavaBeans ................................. 345
11.1 Categories of EJB ........................................................................... 345
11.2 Basic Structure of an EJB ............................................................... 346
11.3 Packaging and Deployment ............................................................ 349
11.4 Client Programs .............................................................................. 351
11.5 Entity EJBs ..................................................................................... 353
Chapter 12 Multimedia ............................................................................. 359
12.1 Transferring and Displaying Images Easily ................................... 360
12.2 Transferring Media Files ................................................................ 365
12.3 Playing Sound Files ....................................................................... 370
12.4 The Java Media Framework ........................................................... 372
Exercises ................................................................................................. 379
Chapter 13 Applets ................................................................................... 380
13.1 Applets and JApplets ...................................................................... 380
13.2 Applet Basics and the Development Process ................................. 381
13.3 The Internal Operation of Applets .................................................. 385
13.4 Using Images in Applets ................................................................ 392
13.4.1 Using Class Image ........................................................... 392
13.4.2 Using Class ImageIcon .................................................... 397
13.5 Scaling Images ................................................................................ 400
13.6 Using Sound in Applets .................................................................. 401
Exercises .................................................................................................. 405
Appendix A Structured Query Language (SQL) ............................. 406
Appendix B Deployment Descriptors for EJBs ................................ 411
Appendix C Further Reading ............................................................. 414
Index ............................................................................................................. 417

Another Java Books

Another Network Books
Download

Friday, October 7, 2011

MPLS and VPN Architectures, Volume II







By Jim Guichard, Ivan Pepelnjak, Jeff Apcar

Publisher: Cisco Press
Pub Date: June 06, 2003
ISBN: 1-58705-112-5
Pages: 504

With MPLS and VPN Architectures, Volume II , you'll learn:
How to integrate various remote access technologies into the backbone providing VPN
service to many different types of customers The new PE-CE routing options as well as other advanced features, including per-VPN Network Address Translation (PE-NAT)
How VRFs can be extended into a customer site to provide separation inside the
customer network The latest MPLS VPN security features and designs aimed at protecting the MPLS VPN backbone

How to carry customer multicast traffic inside a VPN The latest inter-carrier enhancements to allow for easier and more scalable deployment of inter-carrier MPLS VPN services Advanced troubleshooting techniques including router outputs to ensure high availability MPLS and VPN Architectures, Volume II , builds on the best-selling MPLS and VPN Architectures, Volume I (1-58705-002-1), from Cisco Press. Extending into more advanced topics and deployment architectures, Volume II provides readers with the necessary tools they need to deploy and maintain a secure, highly available VPN.
MPLS and VPN Architectures, Volume II , begins with a brief refresher of the MPLS VPN
Architecture. Part II describes advanced MPLS VPN connectivity including the integration of service provider access technologies (dial, DSL, cable, Ethernet) and a variety of routing protocols (IS-IS, EIGRP, and OSPF), arming the reader with the knowledge of how to integrate these features into the VPN backbone. Part III details advanced deployment issues including security, outlining the necessary steps the service provider must take to protect the backbone and any attached VPN sites, and also detailing the latest security features to allow more advanced topologies and filtering. This part also covers multi-carrier MPLS VPN deployments. Finally, Part IV provides a methodology for advanced MPLS VPN troubleshooting.

MPLS and VPN Architectures, Volume II , also introduces the latest advances in customer
integration, security, and troubleshooting features essential to providing the advancedservices based on MPLS VPN technology in a secure and scalable way.
This book is part of the Networking Technology Series from Cisco Press, which offers
networking professionals valuable information for constructing efficient networks,
understanding new technologies, and building successful careers.


With MPLS and VPN Architectures, Volume II , you'll learn:
How to integrate various remote access technologies into the backbone providing VPN
service to many different types of customers
The new PE-CE routing options as well as other advanced features, including per-VPN
Network Address Translation (PE-NAT)
How VRFs can be extended into a customer site to provide separation inside the
customer network
The latest MPLS VPN security features and designs aimed at protecting the MPLS VPN
backbone
How to carry customer multicast traffic inside a VPN
The latest inter-carrier enhancements to allow for easier and more scalable deployment
of inter-carrier MPLS VPN services
Advanced troubleshooting techniques including router outputs to ensure high availability
MPLS and VPN Architectures, Volume II , builds on the best-selling MPLS and VPN
Architectures, Volume I (1-58705-002-1), from Cisco Press. Extending into more advanced
topics and deployment architectures, Volume II provides readers with the necessary tools
they need to deploy and maintain a secure, highly available VPN.
MPLS and VPN Architectures, Volume II , begins with a brief refresher of the MPLS VPN
Architecture. Part II describes advanced MPLS VPN connectivity including the integration of
service provider access technologies (dial, DSL, cable, Ethernet) and a variety of routing
protocols (IS-IS, EIGRP, and OSPF), arming the reader with the knowledge of how to
integrate these features into the VPN backbone. Part III details advanced deployment issues
including security, outlining the necessary steps the service provider must take to protect the
backbone and any attached VPN sites, and also detailing the latest security features to allow
more advanced topologies and filtering. This part also covers multi-carrier MPLS VPN
deployments. Finally, Part IV provides a methodology for advanced MPLS VPN
troubleshooting.
MPLS and VPN Architectures, Volume II , also introduces the latest advances in customer
integration, security, and troubleshooting features essential to providing the advanced

• Table of Contents
• Index
MPLS and VPN Architectures, Volume II
By Jim Guichard, Ivan Pepelnjak, Jeff Apcar

Publisher: Cisco Press
Pub Date: June 06, 2003
ISBN: 1-58705-112-5
Pages: 504

Copyright
About the Authors
About the Technical Reviewers
About the Content Reviewer
Acknowledgments
Introduction
Who Should Read This Book?
How This Book Is Organized
Icons Used in This Book
Command Syntax Conventions
Part I. Introduction
Chapter 1. MPLS VPN Architecture Overview
MPLS VPN Terminology
Connection-Oriented VPNs
Connectionless VPNs
MPLS-Based VPNs
New MPLS VPN Developments
Summary
Part II. Advanced PE-CE Connectivity
Chapter 2. Remote Access to an MPLS VPN
Feature Enhancements for MPLS VPN Remote Access
Overview of Access Protocols and Procedures
Providing Dial-In Access to an MPLS VPN
Providing Dial-Out Access via LSDO
Providing Dial-Out Access Without LSDO (Direct ISDN)
Providing Dial Backup for MPLS VPN Access
Providing DSL Access to an MPLS VPN
Providing Cable Access to an MPLS VPN
Advanced Features for MPLS VPN Remote Access
Summary
Chapter 3. PE-CE Routing Protocol Enhancements and Advanced Features
PE-CE Connectivity: OSPF
PE-CE Connectivity: Integrated IS-IS
PE-CE Connectivity: EIGRP
Summary

MPLS and VPN Architectures, Volume II
By Jim Guichard, Ivan Pepelnjak, Jeff Apcar

Publisher: Cisco Press
Pub Date: June 06, 2003
ISBN: 1-58705-112-5
Pages: 504

With MPLS and VPN Architectures, Volume II , you'll learn:
How to integrate various remote access technologies into the backbone providing VPN
service to many different types of customers
The new PE-CE routing options as well as other advanced features, including per-VPN
Network Address Translation (PE-NAT)
How VRFs can be extended into a customer site to provide separation inside the
customer network
The latest MPLS VPN security features and designs aimed at protecting the MPLS VPN
backbone
How to carry customer multicast traffic inside a VPN
The latest inter-carrier enhancements to allow for easier and more scalable deployment
of inter-carrier MPLS VPN services
Advanced troubleshooting techniques including router outputs to ensure high availability
MPLS and VPN Architectures, Volume II , builds on the best-selling MPLS and VPN
Architectures, Volume I (1-58705-002-1), from Cisco Press. Extending into more advanced
topics and deployment architectures, Volume II provides readers with the necessary tools
they need to deploy and maintain a secure, highly available VPN.
MPLS and VPN Architectures, Volume II , begins with a brief refresher of the MPLS VPN
Architecture. Part II describes advanced MPLS VPN connectivity including the integration of
service provider access technologies (dial, DSL, cable, Ethernet) and a variety of routing
protocols (IS-IS, EIGRP, and OSPF), arming the reader with the knowledge of how to
integrate these features into the VPN backbone. Part III details advanced deployment issues
including security, outlining the necessary steps the service provider must take to protect the
backbone and any attached VPN sites, and also detailing the latest security features to allow
more advanced topologies and filtering. This part also covers multi-carrier MPLS VPN
deployments. Finally, Part IV provides a methodology for advanced MPLS VPN
troubleshooting.
MPLS and VPN Architectures, Volume II , also introduces the latest advances in customer
integration, security, and troubleshooting features essential to providing the advanced
Chapter 4. Virtual Router Connectivity
Configuring Virtual Routers on CE Routers
Linking the Virtual Router with the MPLS VPN Backbone
VRF Selection Based on Source IP Address
Performing NAT in a Virtual Router Environment
Summary
Part III. Advanced Deployment Scenarios
Chapter 5. Protecting the MPLS-VPN Backbone
Inherent Security Capabilities
Neighbor Authentication
CE-to-CE Authentication
Control of Routes That Are Injected into a VRF
PE to CE Circuits
Extranet Access
Internet Access
IPSec over MPLS
Summary
Chapter 6. Large-Scale Routing and Multiple Service Provider Connectivity
Large Scale Routing: Carrier's Carrier Solution Overview
Carrier Backbone Connectivity
Label Distribution Protocols on PE-CE Links
BGP-4 Between PE/CE Routers
Hierarchical VPNs: Carrier's Carrier MPLS VPNs
VPN Connectivity Between Different Service Providers
Summary
Chapter 7. Multicast VPN
Introduction to IP Multicast
Enterprise Multicast in a Service Provider Environment
mVPN Architecture
MDTs
Case Study of mVPN Operation in SuperCom
Summary
Chapter 8. IP Version 6 Transport Across an MPLS Backbone
IPv6 Business Drivers
Deployment of IPv6 in Existing Networks
Quick Introduction to IPv6
In-Depth 6PE Operation and Configuration
Complex 6PE Deployment Scenarios
Summary
Part IV. Troubleshooting
Chapter 9. Troubleshooting of MPLS-Based Solutions
Introduction to Troubleshooting of MPLS-Based Solutions
Troubleshooting the MPLS Backbone
Other Quick Checks
MPLS Control Plane Troubleshooting
MPLS Data Plane Troubleshooting
MPLS VPN Troubleshooting
In-Depth MPLS VPN Troubleshooting
Summary
Index

Another Network Books
Another VPN Books
Download

Sunday, October 2, 2011

IPSec VPN Design







By Vijay Bollapragada, Mohamed Khalid, Scott Wainner

Publisher : Cisco Press
Pub Date : April 07, 2005
ISBN : 1-58705-111-7
Pages : 384





Master IPSec-based Virtual Private Networks with guidance from the Cisco Systems® VPN Solutions group

Understand how IPSec VPNs are designed, built, and administered

Improve VPN performance through enabling of modern VPN services such as performance, scalability, QoS, packet processing, multicast, and security

Integrate IPSec VPNs with MPLS, Frame Relay, and ATM technologies

As the number of remote branches and work-from-home employees grows throughout corporate America, VPNs are becoming essential to both enterprise networks and service providers. IPSec is one of the more popular technologies for deploying IP-based VPNs. IPSec VPN Design provides a solid understanding of the design and architectural issues of IPSec VPNs. Some books cover IPSec protocols, but they do not address overall design issues. This book fills that void.

IPSec VPN Design consists of three main sections. The first section provides a comprehensive introduction to the IPSec protocol, including IPSec Peer Models. This section also includes an introduction to site-to-site, network-based, and remote access VPNs. The second section is dedicated to an analysis of IPSec VPN architecture and proper design methodologies. Peer relationships and fault tolerance models and architectures are examined in detail. Part three addresses enabling VPN services, such as performance, scalability, packet processing, QoS, multicast, and security. This book also covers the integration of IPSec VPNs with other Layer 3 (MPLS VPN) and Layer 2 (Frame Relay, ATM) technologies; and discusses management, provisioning, and troubleshooting techniques. Case studies highlight design, implementation, and management advice to be applied in both service provider and enterprise environments.


Copyright
About the Authors
About the Technical Editors
Acknowledgments
This Book Is Safari Enabled
Icons Used in This Book
Command Syntax Conventions
Introduction
Chapter 1. Introduction to VPNs
Motivations for Deploying a VPN
VPN Technologies
Summary
Chapter 2. IPSec Overview
Encryption Terminology
IPSec Security Protocols
Key Management and Security Associations
Summary
Chapter 3. Enhanced IPSec Features
IKE Keepalives
Dead Peer Detection
Idle Timeout
Reverse Route Injection
Stateful Failover
IPSec and Fragmentation
GRE and IPSec
IPSec and NAT
Summary
Chapter 4. IPSec Authentication and Authorization Models
Extended Authentication (XAUTH) and Mode Configuration (MODE-CFG)
Mode-Configuration (MODECFG)
Easy VPN (EzVPN)
Digital Certificates for IPSec VPNs
Summary
Chapter 5. IPSec VPN Architectures
IPSec VPN Connection Models
Hub-and-Spoke Architecture
Full-Mesh Architectures
Summary
Chapter 6. Designing Fault-Tolerant IPSec VPNs
Link Fault Tolerance
IPSec Peer Redundancy Using SLB
Intra-Chassis IPSec VPN Services Redundancy
Summary
Chapter 7. Auto-Configuration Architectures for Site-to-Site IPSec VPNs
IPSec Tunnel Endpoint Discovery
Dynamic Multipoint VPN
Summary
Chapter 8. IPSec and Application Interoperability
QoS-Enabled IPSec VPNs
VoIP Application Requirements for IPSec VPN Networks
IPSec VPN Architectural Considerations for VoIP
Multicast over IPSec VPNs
Summary
Chapter 9. Network-Based IPSec VPNs
Fundamentals of Network-Based VPNs
The Network-Based IPSec Solution: IOS Features
Operation of Network-Based IPSec VPNs
Network-Based VPN Deployment Scenarios
Summary
Index


Another Network Books
Download

Thursday, September 29, 2011

MPLS and VPN Architectures






MPLS and VPN Architectures
By Jim CCIE #2069 Guichard, Ivan CCIE #1354 Pepelnjak

Publisher : Cisco Press
Pub Date : October 31, 2000
ISBN : 1-58705-002-1
Pages : 448
Slots : 2



Multiprotocol Label Switching (MPLS) provides the mechanisms to perform label switching, which is an innovative technique for high-performance packet forwarding. This book provides an in-depth study of MPLS technology, including MPLS theory and configuration, network design issues, and case studies. The MPLS/VPN architecture and all of its mechanisms are explained with configuration examples and suggested deployment guidelines. MPLS and VPNs provides the first in-depth discussion particular to Ciscos MPLS architecture. Multiprotocol Label Switching and Virtual Private Networks covers MPLS theory and configuration, network design issues, and case studies as well as one major MPLS application: MPLS-based VPNs. The MPLS/VPN architecture and all of its mechanisms are explained with configuration examples, suggested design and deployment guidelines, and extensive case studies.

Copyright
About the Authors
About the Technical Reviewers
Acknowledgments
Part I: MPLS Technology and Configuration
Chapter 1. Multiprotocol Label Switching (MPLS) Architecture Overview
Scalability and Flexibility of IP-based Forwarding
Multiprotocol Label Switching (MPLS) Introduction
Other MPLS Applications
Summary

Chapter 2. Frame-mode MPLS Operation
Frame-mode MPLS Data Plane Operation
Label Bindings and Propagation in Frame-mode MPLS
Penultimate Hop Popping
MPLS Interaction with the Border Gateway Protocol
Summary

Chapter 3. Cell-mode MPLS Operation
Control-plane Connectivity Across an LC-ATM Interface
Labeled Packet Forwarding Across an ATM-LSR Domain
Label Allocation and Distribution Across an ATM-LSR Domain
Summary

Chapter 4. Running Frame-mode MPLS Across Switched WAN Media
Frame-mode MPLS Operation Across Frame Relay
Frame-mode MPLS Operation Across ATM PVCs
Summary

Chapter 5. Advanced MPLS Topics
Controlling the Distribution of Label Mappings
MPLS Encapsulation Across Ethernet Links
MPLS Loop Detection and Prevention
Traceroute Across an MPLS-enabled Network
Route Summarization Within an MPLS-enabled Network
Summary

Chapter 6. MPLS Migration and Configuration Case Study
Migration of the Backbone to a Frame-mode MPLS Solution
Pre-migration Infrastructure Checks
Addressing the Internal BGP Structure
Migration of Internal Links to MPLS
Removal of Unnecessary BGP Peering Sessions
Migration of an ATM-based Backbone to Frame-mode MPLS
Summary


Part 2: MPLS-based Virtual Private Networks
Chapter 7. Virtual Private Network (VPN) Implementation Options
Virtual Private Network Evolution
Business Problem-based VPN Classification
Overlay and Peer-to-peer VPN Model
Typical VPN Network Topologies
Summary

Chapter 8. MPLS/VPN Architecture Overview
Case Study: Virtual Private Networks in SuperCom Service Provider Network
VPN Routing and Forwarding Tables
Overlapping Virtual Private Networks
Route Targets
Propagation of VPN Routing Information in the Provider Network
VPN Packet Forwarding
Summary

Chapter 9. MPLS/VPN Architecture Operation
Case Study: Basic MPLS/VPN Intranet Service
Configuration of VRFs
Route Distinguishers and VPN-IPv4 Address Prefixes
BGP Extended Community Attribute
Basic PE to CE Link Configuration
Association of Interfaces to VRFs
Multiprotocol BGP Usage and Deployment
Outbound Route Filtering (ORF) and Route Refresh Features
MPLS/VPN Data Plane—Packet Forwarding
Summary

Chapter 10. Provider Edge (PE) to Customer Edge (CE) Connectivity Options
VPN Customer Access into the MPLS/VPN Backbone
BGP-4 Between Service Provider and Customer Networks
Open Shortest Path First (OSPF) Between PE- and CE-routers
Separation of VPN Customer Routing Information
Propagation of OSPF Routes Across the MPLS/VPN Backbone
PE-to-CE Connectivity—OSPF with Site Area 0 Support
PE-to-CE Connectivity—OSPF Without Site Area 0 Support
VPN Customer Connectivity—MPLS/VPN Design Choices
Summary

Chapter 11. Advanced MPLS/VPN Topologies
Intranet and Extranet Integration
Central Services Topology
MPLS/VPN Hub-and-spoke Topology
Summary

Chapter 12. Advanced MPLS/VPN Topics
MPLS/VPN: Scaling the Solution
Routing Convergence Within an MPLS-enabled VPN Network
Advertisement of Routes Across the Backbone
Introduction of Route Reflector Hierarchy
BGP Confederations Deployment
PE-router Provisioning and Scaling
Additional Connectivity Requirements—Internet Access
Internet Connectivity Through Firewalls
Internet Access—Static Default Routing
Separate BGP Session Between PE- and CE-routers
Internet Connectivity Through Dynamic Default Routing
Additional Lookup in the Global Routing Table
Internet Connectivity Through a Different Service Provider
Summary

Chapter 13. Guidelines for the Deployment of MPLS/VPN
Introduction to MPLS/VPN Deployment
IGP to BGP Migration of Customer Routes
Multiprotocol BGP Deployment in an MPLS/VPN Backbone
MPLS/VPN Deployment on LAN Interfaces
Network Management of Customer Links
Use of Traceroute Across an MPLS/VPN Backbone
Summary

Chapter 14. Carrier's Carrier and Inter-provider VPN Solutions
Carrier's Carrier Solution Overview
Carrier's Carrier Architecture—Topologies
Hierarchical Virtual Private Networks
Inter-provider VPN Solutions
Summary

Chapter 15. IP Tunneling to MPLS/VPN Migration Case Study
Existing VPN Solution Deployment—IP Tunneling
Definition of VPNs and Routing Policies for PE-routers
Definition of VRFs Within the Backbone Network
VRF and Routing Polices for SampleNet VPN Sites
VRF and Routing Policies for SampleNet Internet Access
VRF and Routing Policies for Internet Access Customers
MPLS/VPN Migration—Staging and Execution
Configuration of MP-iBGP on BGP Route Reflectors
Configuration of MP-iBGP on TransitNet PE-routers
Migration of VPN Sites onto the MPLS/VPN Solution
Summary

Appendix A. Tag-switching and MPLS Command Reference

Index


Another Network Books
Download

Monday, August 22, 2011

CCSP Cisco Secure VPN Exam Certification Guide






Contents at a Glance

Introduction xvii

Chapter 1

All About the Cisco Certified Security Professional 3

Chapter 2

Overview of VPN and IPSec Technologies 15

Chapter 3

Cisco VPN 3000 Concentrator Series Hardware Overview 79

Chapter 4

Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys 125

Chapter 5

Configuring Cisco VPN 3000 for Remote Access Using Digital
Certificates 215

Chapter 6

Configuring the Cisco VPN Client Firewall Feature 259

Chapter 7

Monitoring and Administering the VPN 3000 Series Concentrator 303

Chapter 8

Configuring Cisco 3002 Hardware Client for Remote Access 359

Chapter 9

Configuring Scalability Features of the VPN 3002 Hardware Client 399

Chapter 10

Cisco VPN 3000 LAN-to-LAN with Preshared Keys 443

Chapter 11

Scenarios 473

Appendix A

Answers to the “Do I Know This Already?” Quizzes and Q&A Sections 489

Index

551


Another VPN Books
Another Network Books
Download

Wednesday, August 17, 2011

Understanding SSL VPN





Language : English
Paperback : 212 pages [ 235mm x 191mm ]
Release Date : March 2005
ISBN : 1904811078
ISBN 13 : 978-1-904811-07-7
Author(s) : Joseph Steinberg, Tim Speed

This book provides a detailed technical and business introduction to SSL VPN. It explains how SSL VPN devices work along with their benefits and pitfalls. As well as covering SSL VPN technologies, the book also looks at how to authenticate and educate users - a vital element in ensuring that the security of remote locations is not compromised. The book also looks at strategies for making legacy applications accessible via the SSL VPN.


Virtual Private Networks (VPNs) provide remote workers with secure access to their company network via the internet by encrypting all data sent between the company network and the user?s machine (the client). Before SSL VPN this typically required the client machine to have special software installed, or at least be specially configured for the purpose.

Clientless SSL VPNs avoid the need for client machines to be specially configured. Any computer with a Web browser can access SSL VPN systems. This has several benefits:

Low admin costs, no remote configuration
Users can safely access the company network from any machine, be that a public workstation, a palmtop or mobile phone
By pass ISP restrictions on custom VPNs by using standard technologies

SSL VPN is usually provided by a hardware appliance that forms part of the company network. These appliances act as gateways, providing internal services such as file shares, email servers, and applications in a web based format encrypted using SSL. Existing players and new entrants, such as Nokia, Netilla, Symantec, Whale Communications, and NetScreen technologies, are rushing our SSL VPN products to meet growing demand.

This book provides a detailed technical and business introduction to SSL VPN. It explains how SSL VPN devices work along with their benefits and pitfalls. As well as covering SSL VPN technologies, the book also looks at how to authenticate and educate users ? a vital element in ensuring that the security of remote locations is not compromised. The book also looks at strategies for making legacy applications accessible via the SSL VPN.

This book is a business and technical overview of SSL VPN technology in a highly readable style. It provides a vendor-neutral introduction to SSL VPN technology for system architects, analysts and managers engaged in evaluating and planning an SSL VPN implementation.

Another Network Books
Another VPN Books
Download

Selecting MPLS VPN Services






Selecting MPLS VPN Services
By Chris Lewis, Steve Pickavance, Monique Morrow, John Monaghan, Craig Huegen
...............................................
Publisher: Cisco Press
Pub Date: February 13, 2006
Print ISBN-10: 1587051915
Print ISBN-13: 978-1-58705-191-3
Pages: 456


A guide to using and defining MPLS VPN services

Analyze strengths and weaknesses of TDM and Layer 2 WAN services
Understand the primary business and technical issues when evaluating IP/MPLS VPN offerings
Describe the IP addressing, routing, load balancing, convergence, and services capabilities of the IP VPN
Develop enterprise quality of service (QoS) policies and implementation guidelines
Achieve scalable support for multicast services
Learn the benefits and drawbacks of various security and encryption mechanisms
Ensure proper use of services and plan for future growth with monitoring and reporting services
Provide remote access, Internet access, and extranet connectivity to the VPN supported intranet
Provide a clear and concise set of steps to plan and execute a network migration from existing ATM/Frame Relay/leased line networks to an IP VPN

IP/MPLS VPNs are compelling for many reasons. For enterprises, they enable right-sourcing of WAN services and yield generous operational cost savings. For service providers, they offer a higher level of service to customers and lower costs for service deployment.

Migration comes with challenges, however. Enterprises must understand key migration issues, what the realistic benefits are, and how to optimize new services. Providers must know what aspects of their services give value to enterprises and how they can provide the best value to customers.

Selecting MPLS VPN Services helps you analyze migration options, anticipate migration issues, and properly deploy IP/MPLS VPNs. Detailed configurations illustrate effective deployment while case studies present available migration options and walk you through the process of selecting the best option for your network. Part I addresses the business case for moving to an IP/MPLS VPN network, with a chapter devoted to the business and technical issues you should review when evaluating IP/MPLS VPN offerings from major providers. Part II includes detailed deployment guidelines for the technologies used in the IP/MPLS VPN.

This book is part of the Networking Technology Series from Cisco Press®, which offers networking professionals valuable information for constructing efficient networks, understanding new technologies, and building successful careers.


Copyright
About the Authors
Acknowledgments
Icons Used in This Book
Command Syntax Conventions
Introduction
Part I: Business Analysis and Requirements of IP/MPLS VPN
Chapter 1. Assessing Enterprise Legacy WANs and IP/VPN Migration
Current State of Enterprise Networks
Evolutionary Change of Enterprise Networks
Acme, a Global Manufacturer
New WAN Technologies for Consideration by Acme
Convergence Services
Summary
Chapter 2. Assessing Service Provider WAN Offerings
Enterprise/Service Provider Relationship and Interface
Investigation Required in Selecting a Service Provider
Service Management
Summary
Chapter 3. Analyzing Service Requirements
Application/Bandwidth Requirements
Backup and Resiliency
Enterprise Segmentation Requirements
Access Technologies
QoS Requirements
Subscriber Network QoS Design
Security Requirements
Multiprovider Considerations
Extranets
Case Study: Analyzing Service Requirements for Acme, Inc.
Summary
References
Part II: Deployment Guidelines
Chapter 4. IP Routing with IP/MPLS VPNs
Introduction to Routing for the Enterprise MPLS VPN
Site Typifying WAN Access: Impact on Topology
Case Study: BGP and EIGRP Deployment in Acme, Inc.
Summary
References
Chapter 5. Implementing Quality of Service
Introduction to QoS
QoS Tool Chest: Understanding the Mechanisms
Building the Policy Framework
IP/VPN QoS Strategy
Identification of Traffic
QoS Requirements for Voice, Video, and Data
The LAN Edge: L2 Configurations
Case Study: QoS in the Acme, Inc. Network
QoS Reporting
Summary
References
Chapter 6. Multicast in an MPLS VPN
Introduction to Multicast for the Enterprise MPLS VPN
Mechanics of IP Multicast
Multicast Deployment Models
Multicast in an MPLS VPN Environment: Transparency
Case Study: Implementing Multicast over MPLS for Acme
What Happens When There Is No MVPN Support?
Summary
References
Chapter 7. Enterprise Security in an MPLS VPN Environment
Setting the Playing Field
Comparing MPLS VPN Security to Frame Relay Networks
Issues for Enterprises to Resolve When Connecting at Layer 3 to Provider Networks
Basic Security Techniques
Distributed DoS, Botnets, and Worms
Case Study Selections
Summary
References
Chapter 8. MPLS VPN Network Management
The Enterprise: Evaluating Service Provider Management Capabilities
The Enterprise: Managing the VPN
The Service Provider: How to Meet and Exceed Customer Expectations
Summary
References
Chapter 9. Off-Net Access to the VPN
Remote Access
IPsec Access
Supporting Internet Access in IP VPNs
Case Study Selections
Summary
References
Chapter 10. Migration Strategies
Network Planning
Implementation Planning
On-Site Implementation
Case Study Selections
Summary
Part III: Appendix
Appendix A. Questions to Ask Your Provider Regarding Layer 3 IP/MPLS VPN Capability
Coverage and Topology
Customer Edge Router Management
Network Access, Resiliency, and Load Balancing
QoS Capability
Multicast Capability
Routing Protocol Capability
Security
Software Deployment Processes
Inter-Provider IP/VPN
IPv6
MTU Considerations
Hosting Capability
IP Telephony PSTN Integration
IP Telephony Hosted Call Agent
Remote and Dial Access
Internet Access
Other Network Services
Index


Another Network Books
Another VPN Books
Download

Wednesday, July 27, 2011

Cisco IP Routing Fundamentals






Introduction l
An Introduction to Internetworking l
Understanding Internetwork Addresses l
Routers and LANs l
Routers and WANs l
Internet Protocols Versions l
Transmission Technologies l
The Mechanics of Routing Protocols l
RIP l
RIP V2 l
IGRP l
Enhanced IGRP l
OSPF l
Building Internetworks l
Internetworking with Dissimilar Protocols l
The Future of Routing l

Another Network Books
Download

Thursday, July 14, 2011

Java 2 Network Security






Contents
Foreword . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3
Preface. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xvii
The Team That Wrote This Redbook . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xvii
Comments Welcome . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xix
Part 1. Introduction to Java and Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1
Chapter 1. An Overview of Java and Security . . . . . . . . . . . . . . . . . . . . 3
1.1 Java Is Not Just a Language . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3
1.2 What Java Does . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3
1.3 Java Is Not an Island: Java as a Part of Security . . . . . . . . . . . . . . . . . 5
1.3.1 Safety and Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
1.3.2 Java as an Aid to Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
1.3.3 Java as a Threat to Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
1.3.4 Writing Secure Java . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
1.3.5 Staying One Jump Ahead . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
1.3.6 The Vigilant Web Site . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
1.4 Understanding Java 2 Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
1.4.1 An Example of Applet Security in Java 2 . . . . . . . . . . . . . . . . . . 14
1.4.2 An Example of Application Security in Java 2 . . . . . . . . . . . . . . . 26
1.5 Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
Chapter 2. Attack and Defense . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35
2.1 Components of Java . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35
2.1.1 The Development Environment. . . . . . . . . . . . . . . . . . . . . . . . . . 36
2.1.2 The Execution Environment . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44
2.1.3 Interfaces and Architectures . . . . . . . . . . . . . . . . . . . . . . . . . . . . 50
2.2 Java 2 and Cryptography . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 53
2.2.1 Cryptographic Tools in Brief . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54
2.2.2 Java Cryptography Architecture . . . . . . . . . . . . . . . . . . . . . . . . . 56
2.2.3 United States Export Rules for Encryption . . . . . . . . . . . . . . . . . 57
2.2.4 Signed Code. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58
2.2.5 The Other Side of the Coin – Access Control . . . . . . . . . . . . . . . 59
2.3 Attacking the World of Java . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59
2.3.1 Perils in the Life of Remote Code . . . . . . . . . . . . . . . . . . . . . . . . 59
2.3.2 Vulnerabilities in Java Applications . . . . . . . . . . . . . . . . . . . . . . . 66
2.4 Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68
Chapter 3. The New Java Security Model . . . . . . . . . . . . . . . . . . . . . . . 69
3.1 The Need for Java Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69
3.2 Evolution of the Java Security Model . . . . . . . . . . . . . . . . . . . . . . . . . 70
3.2.1 The JDK 1.0 Sandbox Security Model . . . . . . . . . . . . . . . . . . . . 70
3.2.2 The Concept of Trusted Code in JDK 1.1 . . . . . . . . . . . . . . . . . . 72
3.2.3 The Fine-Grained Access Control of Java 2 . . . . . . . . . . . . . . . . 74
3.2.4 A Comparison of the Three Java Security Models . . . . . . . . . . . 78
3.3 Java 2 Protection Domain and Permissions Model . . . . . . . . . . . . . . . 80
3.4 New Class Search Path . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 83
3.4.1 Boot Class Path . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84
3.4.2 Extensions Framework . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 86
3.4.3 Application Class Path . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 88
3.4.4 Class Search Paths in Summary . . . . . . . . . . . . . . . . . . . . . . . . 89
3.5 Java 2 Class Loading Mechanism . . . . . . . . . . . . . . . . . . . . . . . . . . . 89
3.5.1 Run-Time Access Controls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 91
3.6 The Policy File . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 93
3.6.1 The Default System-Wide Policy File . . . . . . . . . . . . . . . . . . . . . 96
3.7 Security Manager vs Access Controller . . . . . . . . . . . . . . . . . . . . . . . 98
3.8 Security Management with Java 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . 98
3.8.1 Applying a Security Manager to Applets and Applications. . . . . . 99
3.8.2 Applying a User-Defined Security Policy. . . . . . . . . . . . . . . . . . . 99
3.8.3 Java Security Debugging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 100
3.9 Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 106
Part 2. Under the Hood. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 107
Chapter 4. The Java Virtual Machine. . . . . . . . . . . . . . . . . . . . . . . . . . 109
4.1 The Java Virtual Machine, Close Up. . . . . . . . . . . . . . . . . . . . . . . . . 109
4.1.1 The Class Loader . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 110
4.1.2 The Class File Verifier . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 112
4.1.3 The Heap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 112
4.1.4 The Class Area. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 112
4.1.5 The Native Method Loader . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113
4.1.6 The Security Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113
4.1.7 The Execution Engine. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113
4.1.8 Just-in-Time Compilers. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113
4.2 Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 115
Chapter 5. Class Files in Java 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117
5.1 The Traditional Development Life Cycle . . . . . . . . . . . . . . . . . . . . . . 117
5.2 The Java Development Life Cycle . . . . . . . . . . . . . . . . . . . . . . . . . . 119
5.3 The Java 2 Class File Format. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 124
5.3.1 Decompilation Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 126
5.4 The Constant Pool . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 129
5.4.1 Beating the Decompilation Threat. . . . . . . . . . . . . . . . . . . . . . . 134
5.5 Java Bytecode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 136
5.5.1 A Bytecode Example . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 136
Chapter 6. The Class Loader and Class File Verifier . . . . . . . . . . . . . 145
6.1 Class Loaders . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 145
6.1.1 Loading Classes from Trusted Sources . . . . . . . . . . . . . . . . . . 146
6.1.2 Loading Classes from Untrusted Sources . . . . . . . . . . . . . . . . . 147
6.1.3 Beyond What the JVM Provides . . . . . . . . . . . . . . . . . . . . . . . . 148
6.1.4 The Class Loading Process . . . . . . . . . . . . . . . . . . . . . . . . . . . 150
6.1.5 Should You Build Your Own Class Loader . . . . . . . . . . . . . . . . 155
6.2 The Class File Verifier . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 168
6.2.1 An Example of Class File Verification . . . . . . . . . . . . . . . . . . . . 169
6.2.2 The Duties of the Class File Verifier . . . . . . . . . . . . . . . . . . . . . 175
6.2.3 The Four Passes of the Class File Verifier. . . . . . . . . . . . . . . . 176
6.3 The Bytecode Verifier in Detail . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 180
6.3.1 The Data Flow Analyzer . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 181
6.4 An Incompleteness Theorem for Bytecode Verifiers . . . . . . . . . . . . . 183
6.5 Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 184
Chapter 7. The Java 2 SecurityManager . . . . . . . . . . . . . . . . . . . . . . . 187
7.1 What SecurityManager Does . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 187
7.2 Operation of the Security Manager . . . . . . . . . . . . . . . . . . . . . . . . . . 190
7.2.1 Interdependence of the Three JVM Security Elements . . . . . . . 192
7.3 Attacking the Defenses of Java . . . . . . . . . . . . . . . . . . . . . . . . . . . . 192
7.3.1 Types of Attack. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 193
7.3.2 Malicious Applets . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 195
7.4 Avoiding Security Hazards . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 204
7.4.1 How to Test . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 205
7.5 Examples of Security Manager Extensions . . . . . . . . . . . . . . . . . . . . 206
7.5.1 First Example – Overriding checkWrite(). . . . . . . . . . . . . . . . . . 206
7.5.2 Second Example – Overriding checkPermission(). . . . . . . . . . . 211
7.5.3 Third Example – Overriding checkRead() and checkWrite() . . . 218
7.6 Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 224
Chapter 8. Security Configuration Files in the Java 2 SDK . . . . . . . . 225
8.1 A Note on java.home and the JRE Installation Directory. . . . . . . . . . 225
8.2 Keystores . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 230
8.2.1 The Certificates KeyStore File cacerts . . . . . . . . . . . . . . . . . . . 233
8.3 The Security Properties File, java.security . . . . . . . . . . . . . . . . . . . . 234
8.4 Security Policy Files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 242
8.4.1 keystore Entry . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 242
8.4.2 grant Entries . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 243
8.5 An Example of Security Settings in the Java 2 Platform . . . . . . . . . . 248
8.5.1 The Count Application Source Code . . . . . . . . . . . . . . . . . . . . . 248
8.5.2 A Sample Text File . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 249
8.5.3 Compiling the Application . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 249
8.5.4 Running the Application without a Security Manager . . . . . . . . 250
8.5.5 Running the Application with the Default Security Manager . . . 250
8.5.6 Policy File Modification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 250
8.6 File Read Access to Files in the Code Base URL Directory . . . . . . . 252
8.7 Security Properties and Policy File Protection . . . . . . . . . . . . . . . . . 252
8.8 How to Implement a Policy Server . . . . . . . . . . . . . . . . . . . . . . . . . . 252
Chapter 9. Java 2 SDK Security Tools. . . . . . . . . . . . . . . . . . . . . . . . . 259
9.1 Key and Certificate Management Tool . . . . . . . . . . . . . . . . . . . . . . . 259
9.1.1 keytool Syntax . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 259
9.1.2 Store and Private Key Password . . . . . . . . . . . . . . . . . . . . . . . 261
9.1.3 Commands and Options Associated with keytool . . . . . . . . . . . 262
9.1.4 An Example of keytool Usage . . . . . . . . . . . . . . . . . . . . . . . . . . 269
9.2 Java Archive Tool. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 270
9.2.1 Options of the jar Command . . . . . . . . . . . . . . . . . . . . . . . . . . . 271
9.2.2 Running a JAR File. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 274
9.3 JAR Signing and Verification Tool . . . . . . . . . . . . . . . . . . . . . . . . . . 275
9.3.1 jarsigner Scenario . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 280
9.3.2 Observations on the jarsigner Verification Process . . . . . . . . . . 284
9.3.3 Tampering with a Signed JAR File . . . . . . . . . . . . . . . . . . . . . . 286
9.4 Policy File Creation and Management Tool . . . . . . . . . . . . . . . . . . . 288
9.4.1 Observations on the Use of the Policy Tool . . . . . . . . . . . . . . . 295
Chapter 10. Security APIs in Java 2 . . . . . . . . . . . . . . . . . . . . . . . . . . 297
10.1 The Package java.security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 297
10.1.1 Principals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 297
10.1.2 Guard Interface and GuardedObject Class . . . . . . . . . . . . . . . 298
10.1.3 Providers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 299
10.1.4 The Security Class . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 301
10.1.5 Access Control APIs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 304
10.1.6 Key Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 305
10.1.7 Message Digests and DIgital Signatures. . . . . . . . . . . . . . . . . 311
10.1.8 Secure Random Number Generation . . . . . . . . . . . . . . . . . . . 316
10.1.9 The SignedObject Class . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 316
10.1.10 Permission APIs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 317
10.1.11 Code Source . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 318
10.1.12 Protection Domain . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 321
10.1.13 Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 321
10.1.14 Secure Class Loader . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 322
10.1.15 Algorithm Parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 322
10.2 The Package java.security.spec . . . . . . . . . . . . . . . . . . . . . . . . . . . 322
10.3 The Package java.security.cert. . . . . . . . . . . . . . . . . . . . . . . . . . . . 323
10.4 Package java.security.interfaces . . . . . . . . . . . . . . . . . . . . . . . . . . 324
10.5 The Package java.security.acl . . . . . . . . . . . . . . . . . . . . . . . . . . . . 324
10.6 Examples Using the Java 2 Security APIs . . . . . . . . . . . . . . . . . . . 325
10.6.1 Signature and Signature Verification. . . . . . . . . . . . . . . . . . . . 325
10.6.2 Using Keystores . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 332
10.7 The Permission Classes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 339
10.7.1 How to Create New Permissions. . . . . . . . . . . . . . . . . . . . . . . 344
10.7.2 Working with Signed Permissions . . . . . . . . . . . . . . . . . . . . . . 348
10.8 How to Write Privileged Code . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 350
10.8.1 First Case – No Return Value, No Exception Thrown . . . . . . . 351
10.8.2 Second Case – Return Value, No Exception Thrown . . . . . . . 352
10.8.3 Third Case – Return Value, Exception Thrown . . . . . . . . . . . . 353
10.8.4 Accessing Local Variables . . . . . . . . . . . . . . . . . . . . . . . . . . . 353
10.8.5 An Example of Privileged Blocks Usage . . . . . . . . . . . . . . . . . 354
10.8.6 General Recommendations on Using the Privileged Blocks . . 358
Chapter 11. The Java Plug-In. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 359
11.1 Main Features of Java Plug-In . . . . . . . . . . . . . . . . . . . . . . . . . . . . 360
11.2 What Does the Java Plug-In Do? . . . . . . . . . . . . . . . . . . . . . . . . . . 364
11.3 Java Plug-In HTML Changes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 364
11.3.1 Changes Supported by Navigator . . . . . . . . . . . . . . . . . . . . . . 364
11.3.2 Changes Supported by Internet Explorer . . . . . . . . . . . . . . . . 365
11.3.3 Changes Supported by Both Navigator and Internet Explorer . 366
11.3.4 All the Web Browsers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 367
11.3.5 Java Plug-in Software HTML Converter . . . . . . . . . . . . . . . . . 369
11.4 Java Plug-In Control Panel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 370
11.4.1 The Basic Panel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 370
11.4.2 The Advanced Panel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 371
11.4.3 The Proxies Panel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 373
11.5 Java Plug-In Security Scenario. . . . . . . . . . . . . . . . . . . . . . . . . . . . 374
11.5.1 First Step – Without Using the Java Plug-in . . . . . . . . . . . . . . 374
11.5.2 Second Step – Using the Java Plug-in . . . . . . . . . . . . . . . . . . 377
Chapter 12. Java Gets Out of Its Box . . . . . . . . . . . . . . . . . . . . . . . . . 385
12.1 JAR Files and Applet Signing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 385
12.1.1 Manifest File . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 387
12.1.2 Signature File . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 392
12.1.3 Signature Block File . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 392
12.2 Signed Code Scenario in JDK 1.1 and Sun HotJava. . . . . . . . . . . . 393
12.2.1 Creating the CA Key Database . . . . . . . . . . . . . . . . . . . . . . . . 393
12.2.2 Creating the Server Key Database . . . . . . . . . . . . . . . . . . . . . 395
12.2.3 Creating and Signing a JAR File . . . . . . . . . . . . . . . . . . . . . . . 397
12.2.4 Running the Applet . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 399
12.2.5 Creating the Client Key Database . . . . . . . . . . . . . . . . . . . . . . 399
12.3 Signed Code Scenario in Java 2 SDK, Standard Edition, V1.2 . . . . 400
12.3.1 Creating a Keystore for Certification Authorities . . . . . . . . . . . 401
12.3.2 Creating the Server Certificate . . . . . . . . . . . . . . . . . . . . . . . . 402
12.3.3 Creating and Signing a JAR file . . . . . . . . . . . . . . . . . . . . . . . 406
12.3.4 Granting the Permissions and Running the Applet . . . . . . . . . 407
12.4 Signed Code Scenario in Netscape Communicator. . . . . . . . . . . . . 409
12.4.1 Using the netscape.security Package . . . . . . . . . . . . . . . . . . . 410
12.4.2 Installing Keys and Certificates in Netscape Communicator . . 415
12.4.3 Signing JAR Files with Netscape Signing Tool . . . . . . . . . . . . 418
12.5 Signed Code Scenario in Microsoft Internet Explorer . . . . . . . . . . . 437
12.5.1 First Example with Signed CAB Files . . . . . . . . . . . . . . . . . . . 438
12.5.2 A More Complex Signed CAB File Example . . . . . . . . . . . . . . 450
12.6 The JAR Bug – Fixed In Java 2 SDK, Standard Edition, V1.2.1 . . . 461
12.6.1 The Solution in Java 2 SDK, Standard Edition, V1.2.1 . . . . . . 470
12.7 Future Developments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 470
Part 3. Beyond the Island of Java – Surfing into the Unknown . . . . . . . . . . . . . . . . . 473
Chapter 13. Cryptography in Java 2 . . . . . . . . . . . . . . . . . . . . . . . . . . 475
13.1 Security Questions, Cryptographic Answers . . . . . . . . . . . . . . . . . . 475
13.1.1 Public Key Certificates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 478
13.2 The Java Cryptography Architecture Framework . . . . . . . . . . . . . . 480
13.2.1 JCE and United States Export Considerations . . . . . . . . . . . . 481
13.2.2 Relationship between Java 2 SDK, JCA and JCE APIs. . . . . . 482
13.3 JCA Terms and Definitions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 483
13.3.1 The Provider Concept in the JCA . . . . . . . . . . . . . . . . . . . . . . 485
13.3.2 Engine Classes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 487
13.3.3 Algorithms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 489
13.4 Java Cryptography Extension . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 493
13.4.1 JCE – Packages and Their Contents . . . . . . . . . . . . . . . . . . . 493
13.4.2 The Cipher Class . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 495
13.4.3 The Cipher Stream Classes . . . . . . . . . . . . . . . . . . . . . . . . . . 495
13.4.4 Secret Key Interfaces and Classes . . . . . . . . . . . . . . . . . . . . . 495
13.4.5 The KeyGenerator Class . . . . . . . . . . . . . . . . . . . . . . . . . . . . 495
13.4.6 The KeyAgreement Class . . . . . . . . . . . . . . . . . . . . . . . . . . . . 496
13.4.7 The SealedObject Class . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 496
13.5 Java Cryptography in Practice . . . . . . . . . . . . . . . . . . . . . . . . . . . . 496
13.5.1 First Scenario . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 496
13.5.2 Second Scenario . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 496
13.6 Asymmetric Encryption with the Java 2 SDK and JCE 1.2 . . . . . . . 497
13.6.1 Using Asymmetric Encryption . . . . . . . . . . . . . . . . . . . . . . . . . 497
13.7 How to Implement Your Own Provider . . . . . . . . . . . . . . . . . . . . . . 497
13.7.1 Write the Service Implementation Code . . . . . . . . . . . . . . . . . 498
13.7.2 Give the Provider a Name. . . . . . . . . . . . . . . . . . . . . . . . . . . . 498
13.7.3 Write a Master Class . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 498
13.7.4 Compile the Code . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 498
13.7.5 Install and Configure the Provider. . . . . . . . . . . . . . . . . . . . . . 498
13.7.6 Test if the Provider Is Ready . . . . . . . . . . . . . . . . . . . . . . . . . 498
13.7.7 Algorithm Aliases . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 498
13.7.8 Dependencies on Other Algorithms . . . . . . . . . . . . . . . . . . . . 499
13.7.9 Default Initializations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 499
13.7.10 A Sample Master Class . . . . . . . . . . . . . . . . . . . . . . . . . . . . 499
Chapter 14. Enterprise Java . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 501
14.1 Browser Add-On Applets . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 501
14.2 Networked Architectures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 501
14.2.1 Applying the Java 2 Access Control Mechanisms . . . . . . . . . . 502
14.2.2 Two-Tier Architecture . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 503
14.2.3 Three-Tier Architecture. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 503
14.2.4 Network Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 506
14.3 Secure Clients and Network Computers . . . . . . . . . . . . . . . . . . . . . 509
14.4 Server-Side Java . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 510
14.4.1 The Cost of Server-Side Java . . . . . . . . . . . . . . . . . . . . . . . . . 511
14.5 Servlets . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 512
14.5.1 Advantages of Servlets . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 514
14.5.2 Servlets and CGI-BINs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 515
14.5.3 Java Servlet APIs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 516
14.5.4 Servlet Life Cycle . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 518
14.5.5 IBM WebSphere Application Server . . . . . . . . . . . . . . . . . . . . 520
14.5.6 A Sample Servlet . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 522
14.5.7 The Current Servlet Security Model . . . . . . . . . . . . . . . . . . . . 530
14.6 Distributed Object Architectures – RMI . . . . . . . . . . . . . . . . . . . . . . 537
14.6.1 Stubs and Skeletons. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 539
14.6.2 RMI Registry. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 540
14.6.3 A Sample RMI Program . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 542
14.6.4 The Security of RMI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 553
14.7 Enterprise JavaBeans . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 554
Chapter 15. Java and Firewalls – In and Out of the Net . . . . . . . . . . . 557
15.1 What Is a Firewall?. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 557
15.2 What Does a Firewall Do? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 558
15.2.1 Inside a TCP/IP Packet. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 558
15.2.2 How Can Programs Communicate through a Firewall? . . . . . . 561
15.3 Detailed Example of TCP/IP Protocol . . . . . . . . . . . . . . . . . . . . . . . 562
15.3.1 DNS Flow (UDP Example) . . . . . . . . . . . . . . . . . . . . . . . . . . . 562
15.3.2 HTTP Flow (TCP Example). . . . . . . . . . . . . . . . . . . . . . . . . . . 564
15.4 Proxy Servers and SOCKS Gateways . . . . . . . . . . . . . . . . . . . . . . 570
15.4.1 Proxy Servers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 570
15.4.2 What Is SOCKS? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 571
15.4.3 Using Proxy Servers or SOCKS Gateways . . . . . . . . . . . . . . . 574
15.5 The Effect of Firewalls on Java. . . . . . . . . . . . . . . . . . . . . . . . . . . . 575
15.5.1 Downloading an Applet Using HTTP . . . . . . . . . . . . . . . . . . . . 575
15.5.2 Stopping Java Downloads with a Firewall . . . . . . . . . . . . . . . . 575
15.5.3 Java Network Connections through the Firewall . . . . . . . . . . . 578
15.6 Java and Firewall Scenarios . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 580
15.6.1 URL Connection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 582
15.6.2 Socket Connection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 590
15.6.3 Conclusions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 598
15.7 Remote Method Invocation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 599
15.8 Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 602
Chapter 16. Java and SSL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 603
16.1 What Is SSL? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 603
16.2 Using SSL from an Applet . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 608
16.2.1 Using SSL URLs with Java . . . . . . . . . . . . . . . . . . . . . . . . . . . 609
16.3 Java and SSL with Sun Microsystems . . . . . . . . . . . . . . . . . . . . . . 609
16.3.1 The javax.net Package . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 610
16.3.2 The javax.net.ssl Package . . . . . . . . . . . . . . . . . . . . . . . . . . . 610
16.3.3 The javax.security.cert Package . . . . . . . . . . . . . . . . . . . . . . . 612
16.4 How to Use Java and SSL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 613
16.4.1 Skeleton Program without SSL . . . . . . . . . . . . . . . . . . . . . . . . 614
16.4.2 Using SSL with the Sun Microsystems API . . . . . . . . . . . . . . . 623
16.5 Java and SSL with IBM SSLite . . . . . . . . . . . . . . . . . . . . . . . . . . . . 625
16.5.1 Extensions to the SSL Protocol . . . . . . . . . . . . . . . . . . . . . . . 627
16.5.2 SSLite Key Ring Management Tools. . . . . . . . . . . . . . . . . . . . 627
16.5.3 SSL Server Authentication with IBM SSLite for Java. . . . . . . . 631
16.6 Conclusions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 633
16.7 Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 634
Chapter 17. Epilogue . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 635
17.1 Future Directions of Java . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 635
17.1.1 Java 2 SDK – The Path Ahead . . . . . . . . . . . . . . . . . . . . . . . . 635
17.1.2 Resource Consumption Management . . . . . . . . . . . . . . . . . . . 636
17.1.3 Java Authentication and Authorization Service . . . . . . . . . . . . 636
17.1.4 Java RMI Security Extension . . . . . . . . . . . . . . . . . . . . . . . . . 637
17.1.5 Arbitrary Grouping of Permissions . . . . . . . . . . . . . . . . . . . . . 637
17.1.6 Object-Level Protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 637
17.1.7 Subdividing Protection Domains . . . . . . . . . . . . . . . . . . . . . . . 638
17.1.8 Running Applets with Signed Content . . . . . . . . . . . . . . . . . . . 638
17.1.9 Java 2 Platform, Enterprise Edition. . . . . . . . . . . . . . . . . . . . . 639
17.2 Conclusion . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 639
Appendix A. Getting Internal System Properties . . . . . . . . . . . . . . . . . 641
A.1 Program GetAllProperties . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 641
A.2 Program GetProperty . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 644
Appendix B. Signature Formats . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 647
Appendix C. X.509 Certificates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 649
C.1 X.509 Certificate Versions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 650
Appendix D. Sources of Information about Java Security . . . . . . . . . 651
D.1 Companies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 651
D.1.1 JavaSoft . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 651
D.1.2 Sun . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 652
D.1.3 IBM . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 652
D.1.4 Microsoft . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 653
D.1.5 Reliable Software Technologies . . . . . . . . . . . . . . . . . . . . . . . . . . . 654
D.1.6 JavaWorld. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 654
D.1.7 JCE Providers outside the United States . . . . . . . . . . . . . . . . . . . . 654
D.2 Universities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 655
D.2.1 Princeton . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 655
D.2.2 Yale . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 655
D.2.3 Others. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 656
Appendix E. What’s on the Diskette? . . . . . . . . . . . . . . . . . . . . . . . . . . . 657
E.1 How to Access the Diskette . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 657
E.2 How to Get the Same Software Material from the Web . . . . . . . . . . . . . 657
Appendix F. Special Notices. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 659
Appendix G. Related Publications. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 663
G.1 International Technical Support Organization Publications . . . . . . . . . . 663
G.2 Redbooks on CD-ROMs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 663
G.3 Other Publications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 663
How to Get ITSO Redbooks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 665
IBM Redbook Fax Order Form . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 666
Glossary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 667
Index . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 669
ITSO Redbook Evaluation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 679

Another Computer Security Books
Another Java Books
Another Network Books
Download
Related Posts with Thumbnails

Put Your Ads Here!