Skip to content

Blog

Blog

How to use the Tor darknet to protect your information system?

In the article about the issue of service exposure and 10 cyber-attacks that have exploited the principle of exposure, we highlighted the risks associated with exposing services on the internet.

But what if we could conceal these services, preventing them from being discovered by just anyone?

One way to achieve this is by using the Chimera network and its hidden services mechanism it offers. However, if you have only a few services and users to manage, performance is not a concern, and you enjoy getting your hands dirty, why not directly use the Tor network? This method is particularly interesting for individuals or small enterprise information systems.

Let's see how to protect an SSH service and avoid becoming a target for attacks. Let's dive in!

3 strategies to protect your information system from internet scans (and resulting attacks)

In the previous two articles, we presented the issue of service exposure on the internet (Information System security: understanding the issue of exposure and 10 cyberattacks that exploited the principle of exposure), as well as 10 cyber attacks that exploited the principle of exposure. Today, we want to revisit three common strategies that companies use to address this problem. As remote access needs and teleworking have particularly increased in recent years, what are the common strategies that companies choose to prevent their exposed services from becoming a gateway for hackers?

10 cyberattacks that exploited the principle of exposure

In the previous article (Information System security: understanding the issue of exposure), we highlighted the exposure of services on the internet, its origin, and the associated risks. In this article, we revisit ten cyberattacks that took advantage of the principle of exposure to succeed. Whether it was exploiting vulnerabilities, configuration defects, phishing techniques, or a combination of these different vectors, these are the elements that the targeted companies or investigative commissions were able to reveal following a post-mortem analysis of the attacks.

Information System security: understanding the issue of exposure

One of the weaknesses of TCP/IP is still not solved today: the exposure of services.

If there is a network and security issue as old as the Internet, it is certainly the issue of service exposure. The internet network allows anyone to make services accessible through two pieces of information: an IP address, usually encoded on 4 bytes, and a port encoded on 2 bytes. Most of the time, knowledge of this information is sufficient to establish a connection with the associated application, regardless of the user's profile, whether legitimate or an attacker.

By delving a little deeper, one realizes that it is the cause of the majority of intrusions within information systems.

Let's take a closer look at a mechanism that is ubiquitous on the Internet and within private networks.

Forum International de la Cybersécurité

Lille, France

FIC
Nous serons présents au Forum International de la Cybersécurité du 5 au 7 avril à Lille dans le Village Innovation. Venez nous rencontrer et échanger autour de Chimere. Rendez-vous sur le stand F19-10 !

Thales Media Day

In Paris, France

darknet Chimere
During the THALES MEDIA DAY in Paris, the team had the chance to present the concept of cyberstealth and the solution to a group of national and international journalists.

Loading...