SlideShare a Scribd company logo
1 of 15
SNA, Step 2, 10/31
Survivable Network Analysis
Oracle Financial Management
Services
Ali Ardalan
Qianming “Michelle” Chen
Yi Hu
Jason Milletary
Jian Song
SNA, Step 2, 10/31
Overview
 Essential User Capabilities
 Summary of Essential Components
 Firewall Type
 Essential Components Diagram
 Essential Scenarios
 Essential Component Details
 Next Steps
SNA, Step 2, 10/31
Essential User Capabilities
 Essential Capabilities performed by 300 dedicated
users
 Dedicated users must have access to financial
service applications
 Core Financial Applications
 Application Desktop Integrator Applications
 Feeder systems must integrate with financial
applications
 Primary actions performed by users are:
 Billing, reporting & reconciliation of budgets and expenses
SNA, Step 2, 10/31
Summary of Essential Components
 Kerberos Domain Controller (authentication)
 Acis.as.cmu.edu (public access points)
 Mistral (db server)
 Tandem (print & e-mail)
 Chinook (backup server)
SNA, Step 2, 10/31
Logical Proxy (Application Gateway) Firewall
SCP
HTTPS …
Oracle
Connection Mgr.
Acis.as. cmu.edu (Sun Sparc Cluster)
LPR
(print)
SSH
SSH
SMTP
(e-mail)
Tandem
CAMPUS
NETWORK
PRIVATE
NETWORK
(External) (Internal)
1. Restricts
traffic based
upon packet
content
2. Application
specific
SNA, Step 2, 10/31
Essential Components Diagram
Kerberos
SCP
HTTPS …
Oracle
Connection Mgr.
Kerberos Domain Contriller
Acis.as. cmu.edu (Sun Sparc Cluster)
LPR
(print)
SSH
SSH
SMTP
(e-mail)
Tandem
O. DB
HTTP
…
O. Listener
Mistral (databse server)
SQL Net
O. Forms
CITRIX
FTP LPR
(print)
SSH
SMTP
(e-mail)
O. DB
HTTP
…
O. Listener
Chinook (Backup)
SQL Net
O. Forms
CITRIX
FTP LPR
(print)
SSH
SMTP
(e-mail)
CAMPUS
NETWORK
Cyert Computer Center 6555 Penn Ave
FIBER
SNA, Step 2, 10/31
Essential Components [1]
 Acis.as.cmu.edu:
 Cluster of Sun Sparc Servers
 Public Access Points
 Support services
 Oracle Connection Manager
 HTTP, Telnet, FTP, HTTPS(some Kerberos
authenticated)
 SCP (Secure Copy Protocol – unix)
 SSH
 Web DB, Big Brother (Monitoring software), …
SNA, Step 2, 10/31
Essential Components [2]
 Mistral: Database Server
 Hosts main Oracle Server:
 HTTP
 Oracle Listeners, Names, Database
 CITRIX Application Server
 NFS(data sharing),
 SMTP (e-mail)
 LPR (printer) & Fs (other printer)
 SQL net, FTP, SSH(file upload)…
SNA, Step 2, 10/31
Essential Components [3]
 Tandem
 Print & E-mail gateway
 No user accounts on this machine
 Services provided:
 SSH (Administrator Connections)
 LPD (Printing)
 SMTP (email)
SNA, Step 2, 10/31
Essential Components [4]
 Chinook
 Disaster Recovery Machine: standby database
 Located offsite at 6555 Penn Ave.
 Test & Development machine
 Mirroring of Development database every
5-minutes
 Existing passive fiber link between campus and
this location.
 Exact Same HW & SW as Mistral
SNA, Step 2, 10/31
Essential Scenarios – Budget Spreadsheet
Kerberos
SCP
HTTPS
Oracle
Connection
Mgr.
Kerberos Domain Contriller
Acis.as. cmu.edu (Sun Sparc Cluster)
LPR
(print)
SSH
SMTP
(e-mail)
Tandem
O. DB
HTTP O. Listener
Mistral (Databse Server)
O. Forms
CITRIX
CAMPUS
NETWORK
(out)
SNA, Step 2, 10/31
Essential Scenarios – Feeder System
Kerberos
SCP
HTTPS
Oracle
Connection
Mgr.
Kerberos Domain Contriller
Acis.as. cmu.edu (Sun Sparc Cluster)
LPR
(print)
SSH
SMTP
(e-mail)
Tandem
O. DB
HTTP O. Listener
Mistral (Database Server)
O. Forms
Secure
Directory
CAMPUS
NETWORK
LPR
(print)
SMTP
(e-mail)
SNA, Step 2, 10/31
Essential Components – DB Mirroring
O. DB
O. Mirroring
Software
Mistral (Database Server) Chinook (Backup)
O. DB
O. Mirroring
Software
Automatic mirroring of development
database changes every 5-minutes
SNA, Step 2, 10/31
Ongoing Steps
 Client & Users
 3rd client meeting to verify essential services and
components
 On-going interviews of Business Managers with
and w/o feeder systems
 Within Our Group
 Development of potential intrusion detection
scenarios & attacker profiles
 Identify compromisable components
 Physical visit to 6555 Penn Ave. Backup facility
SNA, Step 2, 10/31
A potential security threat
 Business Managers:
 30+ business managers
 SCS, MCS, CIT, etc…
 Determine exactly who is able to obtain various
forms of access to areas of the oracle financial
system
 For example, MCS:
 College Manager
 7 Business Managers
 Provide access to 2-3 individuals (regular users)

More Related Content

Similar to SNA_Pres2.ppt

Better Network Management Through Network Programmability
Better Network Management Through Network ProgrammabilityBetter Network Management Through Network Programmability
Better Network Management Through Network ProgrammabilityCisco Canada
 
Sector Sphere 2009
Sector Sphere 2009Sector Sphere 2009
Sector Sphere 2009lilyco
 
sector-sphere
sector-spheresector-sphere
sector-spherexlight
 
Splunk App for Stream
Splunk App for StreamSplunk App for Stream
Splunk App for StreamSplunk
 
Seattle spark-meetup-032317
Seattle spark-meetup-032317Seattle spark-meetup-032317
Seattle spark-meetup-032317Nan Zhu
 
Lightbend Fast Data Platform
Lightbend Fast Data PlatformLightbend Fast Data Platform
Lightbend Fast Data PlatformLightbend
 
Virtual Distro Dispatcher - A costless distributed virtual environment from T...
Virtual Distro Dispatcher - A costless distributed virtual environment from T...Virtual Distro Dispatcher - A costless distributed virtual environment from T...
Virtual Distro Dispatcher - A costless distributed virtual environment from T...Flavio Bertini
 
Modern real-time streaming architectures
Modern real-time streaming architecturesModern real-time streaming architectures
Modern real-time streaming architecturesArun Kejariwal
 
ReactiveSummeriserAkka-ScalaByBay2016
ReactiveSummeriserAkka-ScalaByBay2016ReactiveSummeriserAkka-ScalaByBay2016
ReactiveSummeriserAkka-ScalaByBay2016Ho Tien VU
 
[ScalaByTheBay2016] Implement a scalable statistical aggregation system using...
[ScalaByTheBay2016] Implement a scalable statistical aggregation system using...[ScalaByTheBay2016] Implement a scalable statistical aggregation system using...
[ScalaByTheBay2016] Implement a scalable statistical aggregation system using...Stanley Nguyen Xuan Tuong
 
Designing High Availability Networks, Systems, and Software for the Universit...
Designing High Availability Networks, Systems, and Softwarefor the Universit...Designing High Availability Networks, Systems, and Softwarefor the Universit...
Designing High Availability Networks, Systems, and Software for the Universit...Shumon Huque
 
Enterprise wide information systems - SAP R3 overview & basis technology
Enterprise wide information systems - SAP R3 overview & basis technologyEnterprise wide information systems - SAP R3 overview & basis technology
Enterprise wide information systems - SAP R3 overview & basis technologySapFico Training
 
C19013010 the tutorial to build shared ai services session 2
C19013010 the tutorial to build shared ai services session 2C19013010 the tutorial to build shared ai services session 2
C19013010 the tutorial to build shared ai services session 2Bill Liu
 
Kafka Multi-Tenancy—160 Billion Daily Messages on One Shared Cluster at LINE
Kafka Multi-Tenancy—160 Billion Daily Messages on One Shared Cluster at LINE Kafka Multi-Tenancy—160 Billion Daily Messages on One Shared Cluster at LINE
Kafka Multi-Tenancy—160 Billion Daily Messages on One Shared Cluster at LINE confluent
 
Kafka Multi-Tenancy - 160 Billion Daily Messages on One Shared Cluster at LINE
Kafka Multi-Tenancy - 160 Billion Daily Messages on One Shared Cluster at LINEKafka Multi-Tenancy - 160 Billion Daily Messages on One Shared Cluster at LINE
Kafka Multi-Tenancy - 160 Billion Daily Messages on One Shared Cluster at LINEkawamuray
 
Lightbend Fast Data Platform
Lightbend Fast Data PlatformLightbend Fast Data Platform
Lightbend Fast Data PlatformLightbend
 
YOW2018 Cloud Performance Root Cause Analysis at Netflix
YOW2018 Cloud Performance Root Cause Analysis at NetflixYOW2018 Cloud Performance Root Cause Analysis at Netflix
YOW2018 Cloud Performance Root Cause Analysis at NetflixBrendan Gregg
 

Similar to SNA_Pres2.ppt (20)

Linux capacity planning
Linux capacity planningLinux capacity planning
Linux capacity planning
 
iiwas2009
iiwas2009iiwas2009
iiwas2009
 
Better Network Management Through Network Programmability
Better Network Management Through Network ProgrammabilityBetter Network Management Through Network Programmability
Better Network Management Through Network Programmability
 
Sector Sphere 2009
Sector Sphere 2009Sector Sphere 2009
Sector Sphere 2009
 
sector-sphere
sector-spheresector-sphere
sector-sphere
 
Splunk App for Stream
Splunk App for StreamSplunk App for Stream
Splunk App for Stream
 
Seattle spark-meetup-032317
Seattle spark-meetup-032317Seattle spark-meetup-032317
Seattle spark-meetup-032317
 
Lightbend Fast Data Platform
Lightbend Fast Data PlatformLightbend Fast Data Platform
Lightbend Fast Data Platform
 
Virtual Distro Dispatcher - A costless distributed virtual environment from T...
Virtual Distro Dispatcher - A costless distributed virtual environment from T...Virtual Distro Dispatcher - A costless distributed virtual environment from T...
Virtual Distro Dispatcher - A costless distributed virtual environment from T...
 
Modern real-time streaming architectures
Modern real-time streaming architecturesModern real-time streaming architectures
Modern real-time streaming architectures
 
ReactiveSummeriserAkka-ScalaByBay2016
ReactiveSummeriserAkka-ScalaByBay2016ReactiveSummeriserAkka-ScalaByBay2016
ReactiveSummeriserAkka-ScalaByBay2016
 
[ScalaByTheBay2016] Implement a scalable statistical aggregation system using...
[ScalaByTheBay2016] Implement a scalable statistical aggregation system using...[ScalaByTheBay2016] Implement a scalable statistical aggregation system using...
[ScalaByTheBay2016] Implement a scalable statistical aggregation system using...
 
Designing High Availability Networks, Systems, and Software for the Universit...
Designing High Availability Networks, Systems, and Softwarefor the Universit...Designing High Availability Networks, Systems, and Softwarefor the Universit...
Designing High Availability Networks, Systems, and Software for the Universit...
 
Enterprise wide information systems - SAP R3 overview & basis technology
Enterprise wide information systems - SAP R3 overview & basis technologyEnterprise wide information systems - SAP R3 overview & basis technology
Enterprise wide information systems - SAP R3 overview & basis technology
 
C19013010 the tutorial to build shared ai services session 2
C19013010 the tutorial to build shared ai services session 2C19013010 the tutorial to build shared ai services session 2
C19013010 the tutorial to build shared ai services session 2
 
Fundamentals
FundamentalsFundamentals
Fundamentals
 
Kafka Multi-Tenancy—160 Billion Daily Messages on One Shared Cluster at LINE
Kafka Multi-Tenancy—160 Billion Daily Messages on One Shared Cluster at LINE Kafka Multi-Tenancy—160 Billion Daily Messages on One Shared Cluster at LINE
Kafka Multi-Tenancy—160 Billion Daily Messages on One Shared Cluster at LINE
 
Kafka Multi-Tenancy - 160 Billion Daily Messages on One Shared Cluster at LINE
Kafka Multi-Tenancy - 160 Billion Daily Messages on One Shared Cluster at LINEKafka Multi-Tenancy - 160 Billion Daily Messages on One Shared Cluster at LINE
Kafka Multi-Tenancy - 160 Billion Daily Messages on One Shared Cluster at LINE
 
Lightbend Fast Data Platform
Lightbend Fast Data PlatformLightbend Fast Data Platform
Lightbend Fast Data Platform
 
YOW2018 Cloud Performance Root Cause Analysis at Netflix
YOW2018 Cloud Performance Root Cause Analysis at NetflixYOW2018 Cloud Performance Root Cause Analysis at Netflix
YOW2018 Cloud Performance Root Cause Analysis at Netflix
 

Recently uploaded

Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.soniya singh
 
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts servicesonalikaur4
 
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort ServiceEnjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort ServiceDelhi Call girls
 
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Sheetaleventcompany
 
AlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsAlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsThierry TROUIN ☁
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGAPNIC
 
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607dollysharma2066
 
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls KolkataLow Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
Russian Call girls in Dubai +971563133746 Dubai Call girls
Russian  Call girls in Dubai +971563133746 Dubai  Call girlsRussian  Call girls in Dubai +971563133746 Dubai  Call girls
Russian Call girls in Dubai +971563133746 Dubai Call girlsstephieert
 
VIP Kolkata Call Girls Salt Lake 8250192130 Available With Room
VIP Kolkata Call Girls Salt Lake 8250192130 Available With RoomVIP Kolkata Call Girls Salt Lake 8250192130 Available With Room
VIP Kolkata Call Girls Salt Lake 8250192130 Available With Roomgirls4nights
 
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Challengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya Shirtrahman018755
 
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130  Available With RoomVIP Kolkata Call Girl Kestopur 👉 8250192130  Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Roomdivyansh0kumar0
 
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Delhi Call girls
 
Russian Call Girls in Kolkata Samaira 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Samaira 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls in Kolkata Samaira 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Samaira 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 

Recently uploaded (20)

Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
 
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
 
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
 
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
 
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort ServiceEnjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
 
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
 
AlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsAlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with Flows
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOG
 
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
 
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls KolkataLow Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
Russian Call girls in Dubai +971563133746 Dubai Call girls
Russian  Call girls in Dubai +971563133746 Dubai  Call girlsRussian  Call girls in Dubai +971563133746 Dubai  Call girls
Russian Call girls in Dubai +971563133746 Dubai Call girls
 
VIP Kolkata Call Girls Salt Lake 8250192130 Available With Room
VIP Kolkata Call Girls Salt Lake 8250192130 Available With RoomVIP Kolkata Call Girls Salt Lake 8250192130 Available With Room
VIP Kolkata Call Girls Salt Lake 8250192130 Available With Room
 
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Sukhdev Vihar Delhi 💯Call Us 🔝8264348440🔝
 
Challengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya ShirtChallengers I Told Ya Shirt
Challengers I Told Ya ShirtChallengers I Told Ya Shirt
 
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130  Available With RoomVIP Kolkata Call Girl Kestopur 👉 8250192130  Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
 
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
Best VIP Call Girls Noida Sector 75 Call Me: 8448380779
 
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
Russian Call Girls in Kolkata Samaira 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Samaira 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls in Kolkata Samaira 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Samaira 🤌 8250192130 🚀 Vip Call Girls Kolkata
 

SNA_Pres2.ppt

  • 1. SNA, Step 2, 10/31 Survivable Network Analysis Oracle Financial Management Services Ali Ardalan Qianming “Michelle” Chen Yi Hu Jason Milletary Jian Song
  • 2. SNA, Step 2, 10/31 Overview  Essential User Capabilities  Summary of Essential Components  Firewall Type  Essential Components Diagram  Essential Scenarios  Essential Component Details  Next Steps
  • 3. SNA, Step 2, 10/31 Essential User Capabilities  Essential Capabilities performed by 300 dedicated users  Dedicated users must have access to financial service applications  Core Financial Applications  Application Desktop Integrator Applications  Feeder systems must integrate with financial applications  Primary actions performed by users are:  Billing, reporting & reconciliation of budgets and expenses
  • 4. SNA, Step 2, 10/31 Summary of Essential Components  Kerberos Domain Controller (authentication)  Acis.as.cmu.edu (public access points)  Mistral (db server)  Tandem (print & e-mail)  Chinook (backup server)
  • 5. SNA, Step 2, 10/31 Logical Proxy (Application Gateway) Firewall SCP HTTPS … Oracle Connection Mgr. Acis.as. cmu.edu (Sun Sparc Cluster) LPR (print) SSH SSH SMTP (e-mail) Tandem CAMPUS NETWORK PRIVATE NETWORK (External) (Internal) 1. Restricts traffic based upon packet content 2. Application specific
  • 6. SNA, Step 2, 10/31 Essential Components Diagram Kerberos SCP HTTPS … Oracle Connection Mgr. Kerberos Domain Contriller Acis.as. cmu.edu (Sun Sparc Cluster) LPR (print) SSH SSH SMTP (e-mail) Tandem O. DB HTTP … O. Listener Mistral (databse server) SQL Net O. Forms CITRIX FTP LPR (print) SSH SMTP (e-mail) O. DB HTTP … O. Listener Chinook (Backup) SQL Net O. Forms CITRIX FTP LPR (print) SSH SMTP (e-mail) CAMPUS NETWORK Cyert Computer Center 6555 Penn Ave FIBER
  • 7. SNA, Step 2, 10/31 Essential Components [1]  Acis.as.cmu.edu:  Cluster of Sun Sparc Servers  Public Access Points  Support services  Oracle Connection Manager  HTTP, Telnet, FTP, HTTPS(some Kerberos authenticated)  SCP (Secure Copy Protocol – unix)  SSH  Web DB, Big Brother (Monitoring software), …
  • 8. SNA, Step 2, 10/31 Essential Components [2]  Mistral: Database Server  Hosts main Oracle Server:  HTTP  Oracle Listeners, Names, Database  CITRIX Application Server  NFS(data sharing),  SMTP (e-mail)  LPR (printer) & Fs (other printer)  SQL net, FTP, SSH(file upload)…
  • 9. SNA, Step 2, 10/31 Essential Components [3]  Tandem  Print & E-mail gateway  No user accounts on this machine  Services provided:  SSH (Administrator Connections)  LPD (Printing)  SMTP (email)
  • 10. SNA, Step 2, 10/31 Essential Components [4]  Chinook  Disaster Recovery Machine: standby database  Located offsite at 6555 Penn Ave.  Test & Development machine  Mirroring of Development database every 5-minutes  Existing passive fiber link between campus and this location.  Exact Same HW & SW as Mistral
  • 11. SNA, Step 2, 10/31 Essential Scenarios – Budget Spreadsheet Kerberos SCP HTTPS Oracle Connection Mgr. Kerberos Domain Contriller Acis.as. cmu.edu (Sun Sparc Cluster) LPR (print) SSH SMTP (e-mail) Tandem O. DB HTTP O. Listener Mistral (Databse Server) O. Forms CITRIX CAMPUS NETWORK (out)
  • 12. SNA, Step 2, 10/31 Essential Scenarios – Feeder System Kerberos SCP HTTPS Oracle Connection Mgr. Kerberos Domain Contriller Acis.as. cmu.edu (Sun Sparc Cluster) LPR (print) SSH SMTP (e-mail) Tandem O. DB HTTP O. Listener Mistral (Database Server) O. Forms Secure Directory CAMPUS NETWORK LPR (print) SMTP (e-mail)
  • 13. SNA, Step 2, 10/31 Essential Components – DB Mirroring O. DB O. Mirroring Software Mistral (Database Server) Chinook (Backup) O. DB O. Mirroring Software Automatic mirroring of development database changes every 5-minutes
  • 14. SNA, Step 2, 10/31 Ongoing Steps  Client & Users  3rd client meeting to verify essential services and components  On-going interviews of Business Managers with and w/o feeder systems  Within Our Group  Development of potential intrusion detection scenarios & attacker profiles  Identify compromisable components  Physical visit to 6555 Penn Ave. Backup facility
  • 15. SNA, Step 2, 10/31 A potential security threat  Business Managers:  30+ business managers  SCS, MCS, CIT, etc…  Determine exactly who is able to obtain various forms of access to areas of the oracle financial system  For example, MCS:  College Manager  7 Business Managers  Provide access to 2-3 individuals (regular users)