In this thread the security issue will be discussed from various aspects. The ultimate goal is to ensure the safety of the GeneNetwork major portal and back office databases/development platforms.

1: Root exploit (very dangerous but unlikely happen)

2: DOS/DDOS (smart DOS such as IP fragmentation attack can be avoided , capacity-based DOS can only be avoided by specifying network structure)

3: Vulnerability Scan (I usually ban those IPs who initiated a Vulnerability scan to my host, sometimes junior hackers cause more damage than senior hackers)

4: Spoofing

I guess the DOS/DDOS is the most critical issue apparently at the moment.

Setting up an offline alert system with short message notification through Modem should be economic and effective.

-- FanZhang - 24 May 2007

Topic revision: r2 - 24 May 2007 - 12:58:35 - FanZhang
GeneNetwork.SecurityNotes moved from GeneNetwork.GNSecurityNotes on 24 May 2007 - 12:57 by FanZhang - put it back
 
This site is powered by the TWiki collaboration platformCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback