Добавил:
Upload Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

Internet.Security

.pdf
Скачиваний:
47
Добавлен:
10.02.2015
Размер:
3.75 Mб
Скачать

400

 

 

 

 

 

 

 

 

 

 

 

 

INDEX

 

 

 

 

 

 

 

 

 

 

packet filter

339, 341, 343, 344, 345

 

message packet

315, 319

 

 

packet filtering router

351

 

 

 

 

session key packet

317, 318, 319

packet filtering rule

346

 

 

 

 

 

 

signature packet

316, 318, 319

 

packet header

348

 

 

 

 

 

 

 

phase 1 exchange

263, 270

 

 

packet length

314

 

 

 

 

 

 

 

P-hash

296

 

 

 

 

 

 

packet mode terminal

4

 

 

 

 

 

physical address

 

10, 22, 28

 

 

packet tag

 

313

 

 

 

 

 

 

 

 

physical layer

4, 9, 10

 

 

 

packet-by-packet basis

 

 

 

 

 

 

PKI

201, 210

 

 

 

 

 

 

packet-filtering firewall

 

344, 349

 

PKIX

219, 222, 332

 

 

 

packet-switching network

 

 

5, 16

 

plaintext

58

 

 

 

 

 

 

packet-switching protocol

 

 

4

 

 

P-MD5 297

 

 

 

 

 

 

 

padded message

138

 

 

 

 

 

 

 

Y

191, 192, 193

 

 

 

 

 

 

 

point at infinity

 

 

parity bit

58

 

 

 

 

 

 

 

 

 

point-to-point encryption

 

 

 

passphrase

 

322

 

 

 

 

 

 

 

 

L

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Point-to-Point Protocol 3

 

 

 

path validation algorithm

 

240

 

F

 

 

 

 

 

 

 

344

 

 

Point-to-Point Tunnelling Protocol

path validation module

240

 

 

Policy Approval Authority

210, 217

Path-vector routing

55

 

 

 

 

 

M

 

 

 

 

 

 

 

 

201

 

 

 

 

 

 

 

Policy Certification Authority

 

payload length

38

 

 

 

 

 

 

 

policy constrains extension

232, 240

payment authorization

374

 

 

policy mapping extension

230, 232, 239

payment authorization service

357

 

policy-making state variable

240

 

payment capture

376

 

 

 

 

E

polynomial modulo

109

 

 

 

 

 

 

 

 

 

 

 

 

payment card

356

 

 

 

 

 

 

 

POP3 14, 51, 52, 325

 

 

 

payment card account

357

 

 

 

port number

42

 

 

 

 

 

payment card authorisation

357

A Post Office Protocol

14

 

 

 

payment card brand

356

 

 

 

 

Post Office Protocol version

3 52

 

payment card certificate

 

 

357

 

 

PostScript

327

 

 

 

 

 

 

payment card transaction

 

T357

PPP

3

 

 

 

 

 

 

 

 

payment digest

359

 

 

 

 

 

 

PPP frame

3

 

 

 

 

 

 

payment gateway

 

357, 373, 374

 

PPTP

344

 

 

 

 

 

 

 

payment gateway public key

376

 

PRBS state transition function

133

 

payment gateway’s key

 

 

374

 

 

precedence

17, 18

 

 

 

 

payment integrity

 

359

 

 

 

 

 

 

premaster secret

 

288, 290, 292

 

payment message

 

359, 374

 

 

preoutput block

 

68, 70

 

 

 

payment processing

 

 

 

 

 

 

 

presentation layer

11

 

 

 

PCA name

241

 

 

 

 

 

 

 

 

Pretty Good Privacy

14, 76, 208, 305

PCA

201, 210, 211, 212, 213, 217

PRF

296

 

 

 

 

 

 

 

PCMCIA card

222

 

 

 

 

 

 

primary ring

3

 

 

 

 

 

 

peer-to-peer communication

 

12

 

prime factor

179, 182, 185

 

 

PEM CRL format

 

203

 

 

 

 

 

 

Prime factorisation

172

 

 

 

pending read state

 

278

 

 

 

 

 

prime field

162, 187

 

 

 

pending write state

278

 

 

 

 

 

prime number

161, 165

 

 

 

perimeter

 

339

 

 

 

 

 

 

 

 

primitive element

161

 

 

 

perimeter network

 

343

 

 

 

 

 

priority

37

 

 

 

 

 

 

 

periodic timer

55

 

 

 

 

 

 

 

Privacy Enhanced Mail(PEM)

14

 

Perl

49

 

 

 

 

 

 

 

 

 

 

 

private key

166, 172, 198

 

 

 

PGP

14, 71, 76, 208, 305, 306, 308, 310

private-key usage period extension

229

PGP 5.x

323

 

 

 

 

 

 

 

 

 

proposal # field

 

264

 

 

 

PGP 5.x key

319

 

 

 

 

 

 

 

proposal payload

264

 

 

 

PGP packet structure 315

 

 

 

proposal-id field

 

264

 

 

 

Team-Fly®

INDEX

401

protocol suite

12

 

 

 

protocol-id field

269, 272, 275, 276

protocol-version

301

 

 

proxy ARP

29

 

 

 

 

proxy module

342

 

 

 

proxy server

 

48, 51, 341, 342, 348, 349

pseudocode

92, 114, 116, 118, 121

pseudo-random binary sequence 133

pseudo-random function

296

P-SHA-1 297

 

 

 

 

public key

166, 172, 198

public-key algorithm

 

161

public-key certificate

 

201, 213, 214

public-key Infrastructure

201

public-key packet

319

 

purchase request

373, 374

purchase response

373, 374

quadratic nonresidue

 

190, 191

quadratic residue

190, 191

query message

41, 42

 

queue

30, 31

 

 

 

 

 

Quoted-printable

327, 328

RA 201, 213, 214, 218

 

radix-64 conversion

208, 309

radix-64 encoding

310, 312, 319

Random symmetric key

370, 371, 372, 374

RARP

15, 27, 31

 

 

 

RC5 decryption algorithm

92, 93

RC5 encryption algorithm

84, 91

RC6 decryption algorithm

100

RC6 encryption algorithm

97

Rcon[i]

112

 

 

 

 

 

RDN

221

 

 

 

 

 

 

recompressed message

308

record route option

21

 

record-overflow

301

 

 

Registration Authority

201, 214

registration authority

 

357

registration form

372

 

 

registration form process

370, 372

registration form request

370

registration information (name, address and ID) 372

registration request 366, 372

registration request process

366

registration response process

366, 373

relative distinguished name

221

relatively prime 162, 166, 168

remote access

13

 

 

 

 

 

Remote Login

 

56

 

 

 

 

remote server

349

 

 

 

 

repository

202, 218, 220

 

 

 

required explicit policy field

232

 

Reserve Address Resolution Protocol 27, 31

resource sharing

 

13

 

 

 

 

RFC

 

202

 

 

 

 

 

 

 

 

Rijndael algorithm

58, 107

 

 

RIP

 

7, 54

 

 

 

 

 

 

 

RIPEMD-16

248

 

 

 

 

 

Rlogin

45, 56, 340

 

 

 

 

root CA

201, 216, 287, 358

 

 

RotWord()

112

 

 

 

 

 

 

round constant word array

112, 113

round key

133, 136

 

 

 

 

router

 

27, 28, 29

 

 

 

 

 

Routing Information Protocol

7, 54

routing module

7

 

 

 

 

routing table

7, 28, 34, 353

 

 

row/column-wise permutations

126, 127

row-wise permutation

126

 

 

RPC

 

50

 

 

 

 

 

 

 

 

RSA encryption algorithm

165

 

RSA public-key cryptosystem

165

 

RSA signature scheme

170

 

 

S/MIME

14, 71, 209, 223, 305, 324

S/MIME version

 

3 agents

331

 

S2K specifier

322, 323

 

 

 

SA

243, 246, 247, 252, 259, 260, 261

SA attributes field

265

 

 

 

SAD

 

246, 247

 

 

 

 

 

 

salted S2K

322

 

 

 

 

 

S-box

 

58, 63, 64, 67

 

 

 

 

Schnorr’s authentication algorithm

179, 180

Schnorr’s public-key cryptosystem

179

Schnorr’s signature algorithm

181

 

screened host firewall

350, 351

 

screened subnet firewall

350, 353

 

screening router

344, 345, 352, 353

SDLC

 

10

 

 

 

 

 

 

 

 

secondary ring

 

3

 

 

 

 

 

secret key parameter 91

 

 

 

secret-key packet

320

 

 

 

 

Secure Electronic Transaction

209, 355, 357

Secure Hash Algorithm

149, 165, 183

Secure Hash Standard

149

 

 

Secure Multimedia Internet Mail

 

 

Extension(S/MIME)

14

 

 

402

INDEX

secure payment processing

 

355, 366

secure payment transaction

356

Secure Socket Layer version

 

3 277

Secure/Multipurpose Internet Mail Extension

305, 324

 

 

 

 

 

 

 

Security Association

243, 246

Security Association Database

246, 247

security association payload

263

security gateway

244, 247, 253

security multiparts

330

 

 

 

security option

21

 

 

 

 

Security Parameter Index

246

Security Policy Database

244, 246

security protocol identifier

 

246

self-signed certificate

239, 240

sendmail 51, 347

 

 

 

 

 

sequence number

 

43

 

 

 

 

server certificate

287

 

 

 

 

server hello done message

 

286, 288

server key exchange message

256, 287

server socket address

42

 

 

 

Serverhello.random

290, 291

 

session layer

11

 

 

 

 

 

session state

278

 

 

 

 

 

cipher spec

278

 

 

 

 

compression method

278

 

is resumable

279

 

 

 

 

master secret

279

 

 

 

 

peer certificate

 

278

 

 

 

session identifier

278

 

 

 

SET

209, 223

 

 

 

 

 

 

SET payment instruction

 

 

 

SHA

183, 210

 

 

 

 

 

 

SHA primitive functions

150

 

SHA-1 149, 155, 248

 

 

 

 

SHA-1 algorithm

 

171

 

 

 

shared secret data

148

 

 

 

ShiftRows()

114, 117

 

 

 

SHS

149

 

 

 

 

 

 

 

Signaling System #7

8

 

 

 

signature payload

268, 274

 

 

signed-data content type

333

 

Simple Mail Transfer Protocol

14, 51, 347

Simple Network Management Protocol 13,

53

 

 

 

 

 

 

 

single-homed bastion host

341, 350, 351

sliding window protocol

45

 

SMI

53

 

 

 

 

 

 

 

SMTP

14, 45, 48, 51, 325, 339, 340, 347

SMTP packet filtering

347

SMTP server

51, 347

 

SNMP

13, 47, 53

 

 

 

socket address

45

 

 

 

socket pair

43

 

 

 

 

SOCKS

339, 340

 

 

 

tri-homing

 

 

 

 

 

SOCKS port

342

 

 

 

SOCKS protocol version 4

342

SOCKS server

342

 

 

source address

40

 

 

 

source host

28

 

 

 

 

source IP address

16, 19, 21

source port number

42, 43

source routing

33, 353

 

source routing option

21

 

SPD

244, 246

 

 

 

 

SPE

11

 

 

 

 

 

 

SPI

246, 247, 252, 255, 260, 264

SPI field

264, 269

 

 

 

SPI size

264, 269

 

 

 

SS7

8

 

 

 

 

 

 

SSD

148

 

 

 

 

 

SSL Alert Protocol

279, 283

bad-certificate

284

 

 

bad-record-mac 283

 

certificate-expired

284

 

certificate-revoked

284

 

certificate-unknown

284

close-notify

284

 

 

decompression-failure 283

illegal-parameter

284

 

no-certificate

283

 

 

unexpected-message

283

unsupported certificate

284

SSL Change Cipher Spec Protocol 279, 282 change cipher spec message 283

current state

283

 

 

padding state

283

 

 

SSL connection

279

 

 

client write key

279

 

client write MAC secret

279

initialisation vectors

279

sequence numbers

279

 

server and client random

279

server write key

279

 

server write MAC secret

279

SSL Handshake Protocol

279, 284, 285

cipher suites

286

 

 

client hello message

284

 

 

 

client hello

285

 

 

 

 

 

 

client version

285

 

 

 

 

 

ClientHello.cipher-suite

286

 

 

ClientHello.compression-method

286

ClientHello.session-id

286

 

 

 

compression method

286

 

 

 

handshake failure alert

 

286

 

 

 

hello request

284

 

 

 

 

 

 

server hello message

284, 285, 290

server hello message

286, 287

 

 

server version

286

 

 

 

 

 

session ID

286

 

 

 

 

 

 

SSL Record Protocol

277, 279, 284

 

appended SSL record header

282

 

compression and decompression

280

Fragmentation

279

 

 

 

 

 

MAC

280

 

 

 

 

 

 

 

 

SSL session

 

278

 

 

 

 

 

 

SSL v3

277

 

 

 

 

 

 

 

 

SSL v3 protocol

293

 

 

 

 

 

SSL/TLS

223

 

 

 

 

 

 

 

stand-alone signature

317

 

 

 

 

state

108, 114, 117, 119

 

 

 

 

state array

108, 114, 118

 

 

 

 

static mapping

27, 28

 

 

 

 

 

static table

7

 

 

 

 

 

 

 

 

string-to-key (S2K)

321

 

 

 

 

Structure of Management Information

53

stub link

55

 

 

 

 

 

 

 

 

SubBytes()

114, 116

 

 

 

 

 

subject alternative name

239

 

 

 

subject directory attributes extension

231

subject distinguished name

239

 

 

subject domain policy 230

 

 

 

subject identification information

223

 

subject key identifier

227, 228

 

 

subject key identifier extension

228

 

subkey

 

76

 

 

 

 

 

 

 

 

 

subkey binding signature

 

317

 

 

 

subnet

24

 

 

 

 

 

 

 

 

 

subnet addressing

26, 34

 

 

 

 

subnetid

24, 25

 

 

 

 

 

 

 

subnetting

24, 25, 26, 34

 

 

 

 

SubWord()

112

 

 

 

 

 

 

 

Sun’s Remote Procedure Call

50

 

 

supernetting

 

24, 25, 26, 34

 

 

 

swapped output

137

 

 

 

 

 

 

swapping operation

79

 

 

 

 

 

INDEX

 

 

 

 

 

 

 

403

switching mechanisms

5

 

circuit switching

5, 6

 

 

message switching

5, 6

 

packet switching

5, 6

 

 

symmetric block cipher

 

58, 107

 

Synchronous Data Link Control

10

syntax selection

11

 

 

 

 

System Packet Exchange

11

 

tampering

277

 

 

 

 

 

TCP

11, 13, 15, 42

 

 

 

 

TCP data

42, 43, 44

 

 

 

TCP header

43, 44

 

 

 

 

TCP packet format

42, 43

 

TCP port

345

 

 

 

 

 

TCP port 20

347

 

 

 

 

TCP port 21

347

 

 

 

 

TCP port 23

245

 

 

 

 

TCP port 25

347

 

 

 

 

TCP port number

340

 

 

 

TCP segment

42, 43, 44

 

TCP/IP four-layer model

12

 

TCP/IP protocol

11

 

 

 

 

TELNET

22, 45, 56

 

 

 

TELNET packet filtering

345

 

Telnet server

23

 

 

 

 

 

TFTP

23, 47, 50

 

 

 

 

 

Thicknet

8

 

 

 

 

 

 

Thinnet

8

 

 

 

 

 

 

Time to live (TTL)

20

 

 

 

timestamp option

21

 

 

 

timestamp signature

317

 

TLS certificate verify message 302

TLS change cipher spec message

302

TLS finished message

302

 

TLS handshake protocol

 

300

 

TLS handshake-message

302

 

TLS master-secret

303

 

 

 

TLS premaster-secret

303

 

TLS record layer

300

 

 

 

TLS record protocol

302

 

TLS server hello message

303

 

TLS v1

277

 

 

 

 

 

 

TLS v1 protocol

293

 

 

 

token

1

 

 

 

 

 

 

 

Token Ring

2

 

 

 

 

 

ToS field

18

 

 

 

 

 

 

trace

191

 

 

 

 

 

 

traffic control

10

 

 

 

 

transaction protocol

366

 

 

404

INDEX

transform # field

264, 273

transform payload

264

transform-id field

265, 273

Transmission Control Protocol 11, 13, 42

transparent data

290

Transport Layer Protocols 42

Transport Layer Security version 1 277

transport layer

4, 11, 13

transport mode

253, 256, 259

transport mode SA

247, 251

tri-homed firewall

341

 

triple DES

71, 72, 258

 

3DES 306

 

 

 

 

3DES-CBC mode

258

 

triple DES-EDE mode

73, 74

triple wrapped message

335, 336

triple wrapping

336

 

Trivial File Transfer Protocol 23, 47, 50

Trojan horse

51

 

 

Trojan horse sniffer

342

trust chain to the root key 366, 370, 372,

373, 375

 

trust chaining

358

truth table 139, 150

TTL 20, 41, 42

tunnel mode

251, 253, 256, 259

tunnel mode SA 247, 251,

tunneling protocol, Point-to-Point Tunneling

Protocol (PPTP)

 

 

Twisted Ethernet

8

 

 

twisted-pair cable

2

 

 

two-key cryptosystem

173

Type of service (ToS)

17

 

UDP

13, 15, 42, 45, 342

 

UDP header

45

 

 

 

Destination port number

46

ephemeral port number

45, 46

pseudoheader

46, 47

 

source port number

45

 

UDP checksum

46

 

 

UDP length

46

 

 

universal port number

46

UDP packet

45

 

 

 

UDP port 345

 

 

 

uncompressed message

308

unicast

22

 

 

 

 

unicast address 35

 

 

uniform resource identifier

230

universal addressing system 22

unknown-ca

301

 

URG flag

44

 

 

urgent pointer

44

 

URI

230, 231, 232, 233

URL

48

 

 

 

user authentication

205

User Datagram Protocol 13, 45

user key

102, 105

 

user-canceled

301

 

UTF-8 311

 

 

v3 key fingerprint

320

v4 key fingerprint

320

variable number of rounds

85

variable-length secret key

85

VCI 5

 

 

 

vendor ID payload

270

 

version

37

 

 

 

version

2 packet

320

 

version

3 packet

320

 

version

4 packet

320

 

version field(VER)

17

 

 

Virtual Channel Identifier

5

Virtual Path Identifier

5

 

Virtual Private Network

340

virus

51, 340

 

 

 

virus-infected programs or files 340 VPI 5

VPN

340, 344

 

 

VPN protocol 344

 

WAN

2, 3

 

 

 

Web page

47, 48. 49

 

Web server

48, 49

 

Web traffic

48

 

 

Website

1

 

 

 

Wide Area Network

2, 3

window NT

344

 

 

window scale factor

45

window size

44

 

 

word size

85

 

 

World Wide Web

13, 47

WWW

13, 47

 

 

X.25

4

 

 

 

 

X.400

52

 

 

 

X.500 directory

223

 

X.500 name

202, 221, 224

X.509 AC

 

332

 

 

X.509

certificate format

223

 

 

certification path constraint

227

extensions related to CRL

227

issuer 224

 

 

 

 

 

 

issuer unique identifier

225

 

issuer’s signature

225

 

 

 

key and policy information

226, 227

serial number

223

 

 

 

 

signature algorithm

224

 

 

subject and issuer attribute

227

subject name

224

 

 

 

 

subject public-key information

224

subject unique identifier

226

 

validity period

224

 

 

 

 

version number

 

223

 

 

 

 

X.509

certificate

218

 

 

 

 

X.509

certificate format

203, 222

X.509

CRL format

203, 233

 

 

X.509

Public-Key Infrastructure

219

X.509 v1 certificate

221, 223

 

 

X.509 v2 certificate

221, 225

 

 

X.509 v2 CRL format

203, 234, 235, 237

INDEX

 

 

 

 

 

405

issuer name field

235

 

 

UTC Time, Generalised Time 235

X.509 distinguished name

235

X.509 type name

235

 

next update field

235

 

 

revoked certificates field

235

 

signature field 235

 

 

 

algorithm identifier

235

 

hash functions – MD5 and SHA-1 235

signature algorithm – RSA and DSA

 

235

 

 

 

 

 

this update field

235

 

 

issue date of CRL

235

 

version field (optional)

234, 235, 237

X.509 v3 certificate

203, 223, 226, 287

X.509 v3 certificate format

234

 

X.509 v3 public-key certificate

357

XDR

51

 

 

 

 

 

Xerox Wire

8

 

 

 

 

xtime()

109

 

 

 

 

 

ZIP algorithm

308, 316

 

 

Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]