19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 5.44 One-way connection setup<br />

Initiation responsibility: <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrators<br />

In most cases there is exactly one telephone line for one modem. <strong>The</strong> modem<br />

receives incoming calls and sends outgoing calls via this telephone line. To<br />

prevent an attacker from gaining unnoticed access to the connected <strong>IT</strong> system,<br />

at the very least one call-back mechanism should be installed (see also S 5.30<br />

Activating an existing call-back option).<br />

Despite an activated call-back mechanism, an incoming connection might not<br />

be terminated unless the caller hangs up. <strong>The</strong> public exchange switchboard<br />

only terminates such a connection after a certain amount of time has elapsed.<br />

<strong>The</strong> problem arises particularly if a PBX unit does not also terminate the<br />

connection.<br />

<strong>The</strong>refore, an attacker can initiate a call-back, but simultaneously keep the line<br />

open so that the modem correctly dials the stored call-back number but<br />

remains connected with the attacker as before.<br />

To prevent this, it should first be checked whether an incoming connection is<br />

terminated if the caller does not hang up. If this is not the case, and if it cannot<br />

be ensured that every modem connection is observed by one person, working<br />

with separate telephone lines and one-way connections should be considered,<br />

i.e. with one socket for incoming calls and one socket for outgoing calls. This<br />

requires a modem for every socket and the initiation of the call-back via the<br />

application. It must be ensured that the modem does not automatically receive<br />

any calls for outgoing connections (S0=0, i.e. no Auto-Answer). To prevent<br />

the receiving modem from creating any external connections, the modem<br />

socket should either be locked at the internal PBX unit or the relevant lock<br />

from the telephone provider should be applied for.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!