Add the rest of university notes

This commit is contained in:
John Gatward committed 2026-10-04 14:02:35 +01:00
1 parent c1b84c7f7d
commit d0f27f276b
366 files changed
+9844 -110

No files matched your search

+194
View File
@@ -0,0 +1,194 @@
# Firewalls
- A hardware and/or software system
- Prevents unauthorised access of packets from one network to another
- All data leave any subnet must pass through it
![1647287782.png](img/1647287782.png)
### Firewall Functions
- Implements *single point* security measures
- Security event monitoring through packet analysis and *logging*
- Network-based access control through implementation of a rules set
**Network Firewalls** - placed between a subnet and the internet
**Host-based Firewalls** - placed on individual machines
- A standard home router is a good example of a network firewall
![1647288145.png](img/1647288145.png)
#### DMZ
- A demilitarised zone is a small subnet that separates exrternally facing services from the internal network
![1647288286.png](img/1647288286.png)
- Imagine we have a web and email server running, these servers need different firewall rules to personal machines on the network
##### Basic Function
- Defends a network against parties accessing *internal services*
- Can also restrict access from *inside to outside* services
- Network Address Translation
- Hides the internal machines with private addresses
**Firewalls are not enough**
- Cannot protect against attacks that bypass the firewall
- e.g. tunneling
- Cannot protect against internal threats or insiders
- Might help a bit by egress filtering
- Network firewalls cannot always protect against the transfer of virus-infected programs or files
#### Packet Filters
- Specify which packets are *allowed or dropped*
- Rules based on:
- Source / destination IP
- TCP / UDP port numbers
- Possible for both *inbound* and *outbound* traffic
- Can be implemented in a router by only examining packet headers (**IP / TCP**)
##### Packet Filter Rules
- Rule execution depends on implementation
- `IPTABLES`: **First** rule to match is applied
- `PF`: All rules are examined, **last** match is applied
- Rules are organised in *chains*, which are logical subgroups of rules
- Depending on the packet, different chains are activated
###### IPTABLES
- An application that provides access to the Linux firewall rule tables
- Not actually a firewall, but configures the firewall
- The firewall is mostly implemented as `netfilter` modules
###### Tables and Chains
- `IPTABLES` uses tables to store chains
- Default is the filtering table
- Chains are ordered in lists of rules
- Rules match, or they don’t
- Matches result in a **jump**, else we check the next rule.
![1647289401.png](img/1647289401.png)
Default policy on this chain is `DROP`
- There can be multiple chains per table
- e.g. a `TCP` handling chain
- Jumps can go to `ACCEPT`, `DROP`, `LOG` or another chain
- Complex behaviour can be built up
![1647289523.png](img/1647289523.png)
##### Defaults
- There are four built-in tables in `IPTABLES`
- Filter
- `NAT`
- Mangle - packet alteration
- Raw - skips connection tracking
- The default table is the filtering table, including input, output and forward chains
![1647289692.png](img/1647289692.png)
###### Rules Examples
- Using the command line, we add rules onto the end of chains
```bash
$ iptables -A INPUT -i eht0 -p tcp --dport 80 -j ACCEPT
$ iptables -A OUTPUT -i eht0 -p tcp --sport 80 -j ACCEPT
```
- Remember `http` requests are not sent from the client’s port 80, it is sent from a random high numbered port
- This is how clients can have multiple web requests open at the same time
##### Policies
- **Permissive** - allow everything by default except dangerous services
- Make a black list
- Easy to make a mistake or forget something
```bash
iptables -p INPUT ACCEPT
iptables -p FORWARD ACCEPT
iptables -p OUTPUT ACCEPT
iptables -A INPUT -s X.X.X.X -j DROP
iptables -A OUTPUT -p tcp --dport ssh -j DROP
```
- **Restrictive** - block everything except designated useful services
- Make a white list
- More secure by default
```bash
iptables -p INPUT DROP
iptables -p FORWARD DROP
iptables -p OUTPUT DROP
iptables -A INPUT -p tcp --dport ssh -j ACCEPT
iptables -A OUTPUT -s 192.168.0.2 -j ACCEPT
```
#### Packet Filter Issues
- Packet filters are simple, low-level and have high assurance
- However they cannot:
- Prevent attacks that employ application specific vulnerabilities
- Do not support higher-level authentication schemes
- Easy to accidentally allow or deny packets incorrectly
### Stateful Packet Filters
- Understand requests and replies (`ACK/SYN`)
- Dynamically generate rules
- Based on what it sees from TCP handshakes (can be FTP or SSH etc)
- Can support policies for a wider range or protocols
- `IPTABLES` has a module for stateful packet filtering
- Allow incoming / outgoing SSH connections
![1647290573.png](img/1647290573.png)
#### Connection Tables
![1647290603.png](img/1647290603.png)
- `ACK` packets are used to keep track of the session - the connection is ongoing
- Packets without the `ACK` are the connection establishment messages
#### Application-level Gateways
- Packet filters have limited criteria that allow data in and out
- An application gateway considers the *application-layer* protocol that is in use
- For example if someone sends an `HTTP` request to port 22, it is blocked
##### Proxy Server
- Proxy servers initiate a connection on our behalf
- They can block certain access, and scan for malicious files or web pages
![1647290781.png](img/1647290781.png)
**Issues**:
- Large overhead per connection
- More expensive than packet filtering
- Configuration is complex
- A separate server is required for each service
### Network Address Translation
The shortage of IP addresses mean that most routers now perform NAT automatically
![1647290897.png](img/1647290897.png)
- The implicit advantage in NAT is that your machine is almost totally hidden from the internet
- Only **established connections** are forwarded to your internal machine
- Or, specific **port forwarding** rules
- This prevents any unsolicited attacks on random ports, but no other types of attack