A student of mine confronted me with a project problem that has to do with programming, unfortunately I am not into programming. But I told him to relax that I will make it a family problem by bringing it to this family.
Here is the problem
His supervisor wants him to develope a software that will solve any particular network security issue of his choice.
my first response
I asked him what security issue he has in mind, and he said something like writing a software that will encrypt a packet in transit in a pair to pair network.
My second response
I told him lets substitute the word SOFTWARE with the word SCRIPT. My thinking is that if he stick to developing a software, then it might probably be bigger than what they are thinking as he is not deeply into programming.
Also, I told him there are lots of scripts flying around the internet that he can break down and reassemble in a slightly different way. Using C will be a good idea .
I told him to consider isssues with sniffing and writing scripts for antisniffing. Issues like writing script to check ARP poisoning, like tweeking ARPwatcher, or writing a script that will do static ARP binding as systems boot in a network, or writing a script that will do source address authentication in a TCP/IP packet.
The bottom line is that any popular product in the market has a huge security team working 24/7 with millions of dollars invested to detect vulnerabilities. S the issue is not writing a script/software to solve a security issue but detecting a new security issue.
Hello Sose follow @nigroeneveld on twitter or check him out, he is one of my connections on linkedin. He is a security professional... he will have somethng for u and since u also love the security line, it will help u a gr8 deal...
I need some materials on Layer3 Addressing...
I AM MADE TO SHINE... BORN TO BE GREAT
C0dE - 3
Take Responsibility! Don't let failures define you