Add the rest of university notes
This commit is contained in:
366 files changed
+9844
-110
No files matched your search
@@ -0,0 +1,194 @@
|
||||
# Firewalls
|
||||
|
||||
- A hardware and/or software system
|
||||
- Prevents unauthorised access of packets from one network to another
|
||||
- All data leave any subnet must pass through it
|
||||
|
||||

|
||||
|
||||
### Firewall Functions
|
||||
|
||||
- Implements *single point* security measures
|
||||
- Security event monitoring through packet analysis and *logging*
|
||||
- Network-based access control through implementation of a rules set
|
||||
|
||||
**Network Firewalls** - placed between a subnet and the internet
|
||||
|
||||
**Host-based Firewalls** - placed on individual machines
|
||||
|
||||
- A standard home router is a good example of a network firewall
|
||||
|
||||

|
||||
|
||||
#### DMZ
|
||||
|
||||
- A demilitarised zone is a small subnet that separates exrternally facing services from the internal network
|
||||
|
||||

|
||||
|
||||
- Imagine we have a web and email server running, these servers need different firewall rules to personal machines on the network
|
||||
|
||||
##### Basic Function
|
||||
|
||||
- Defends a network against parties accessing *internal services*
|
||||
- Can also restrict access from *inside to outside* services
|
||||
- Network Address Translation
|
||||
- Hides the internal machines with private addresses
|
||||
|
||||
**Firewalls are not enough**
|
||||
|
||||
- Cannot protect against attacks that bypass the firewall
|
||||
- e.g. tunneling
|
||||
- Cannot protect against internal threats or insiders
|
||||
- Might help a bit by egress filtering
|
||||
- Network firewalls cannot always protect against the transfer of virus-infected programs or files
|
||||
|
||||
#### Packet Filters
|
||||
|
||||
- Specify which packets are *allowed or dropped*
|
||||
- Rules based on:
|
||||
- Source / destination IP
|
||||
- TCP / UDP port numbers
|
||||
- Possible for both *inbound* and *outbound* traffic
|
||||
- Can be implemented in a router by only examining packet headers (**IP / TCP**)
|
||||
|
||||
##### Packet Filter Rules
|
||||
|
||||
- Rule execution depends on implementation
|
||||
- `IPTABLES`: **First** rule to match is applied
|
||||
- `PF`: All rules are examined, **last** match is applied
|
||||
- Rules are organised in *chains*, which are logical subgroups of rules
|
||||
- Depending on the packet, different chains are activated
|
||||
|
||||
###### IPTABLES
|
||||
|
||||
- An application that provides access to the Linux firewall rule tables
|
||||
- Not actually a firewall, but configures the firewall
|
||||
- The firewall is mostly implemented as `netfilter` modules
|
||||
|
||||
###### Tables and Chains
|
||||
|
||||
- `IPTABLES` uses tables to store chains
|
||||
- Default is the filtering table
|
||||
- Chains are ordered in lists of rules
|
||||
- Rules match, or they don’t
|
||||
- Matches result in a **jump**, else we check the next rule.
|
||||
|
||||

|
||||
|
||||
Default policy on this chain is `DROP`
|
||||
|
||||
- There can be multiple chains per table
|
||||
- e.g. a `TCP` handling chain
|
||||
- Jumps can go to `ACCEPT`, `DROP`, `LOG` or another chain
|
||||
- Complex behaviour can be built up
|
||||
|
||||

|
||||
|
||||
##### Defaults
|
||||
|
||||
- There are four built-in tables in `IPTABLES`
|
||||
- Filter
|
||||
- `NAT`
|
||||
- Mangle - packet alteration
|
||||
- Raw - skips connection tracking
|
||||
- The default table is the filtering table, including input, output and forward chains
|
||||
|
||||

|
||||
|
||||
###### Rules Examples
|
||||
|
||||
- Using the command line, we add rules onto the end of chains
|
||||
|
||||
```bash
|
||||
$ iptables -A INPUT -i eht0 -p tcp --dport 80 -j ACCEPT
|
||||
$ iptables -A OUTPUT -i eht0 -p tcp --sport 80 -j ACCEPT
|
||||
```
|
||||
|
||||
- Remember `http` requests are not sent from the client’s port 80, it is sent from a random high numbered port
|
||||
- This is how clients can have multiple web requests open at the same time
|
||||
|
||||
##### Policies
|
||||
|
||||
- **Permissive** - allow everything by default except dangerous services
|
||||
- Make a black list
|
||||
- Easy to make a mistake or forget something
|
||||
|
||||
```bash
|
||||
iptables -p INPUT ACCEPT
|
||||
iptables -p FORWARD ACCEPT
|
||||
iptables -p OUTPUT ACCEPT
|
||||
|
||||
iptables -A INPUT -s X.X.X.X -j DROP
|
||||
iptables -A OUTPUT -p tcp --dport ssh -j DROP
|
||||
```
|
||||
|
||||
- **Restrictive** - block everything except designated useful services
|
||||
- Make a white list
|
||||
- More secure by default
|
||||
|
||||
```bash
|
||||
iptables -p INPUT DROP
|
||||
iptables -p FORWARD DROP
|
||||
iptables -p OUTPUT DROP
|
||||
|
||||
iptables -A INPUT -p tcp --dport ssh -j ACCEPT
|
||||
iptables -A OUTPUT -s 192.168.0.2 -j ACCEPT
|
||||
```
|
||||
|
||||
#### Packet Filter Issues
|
||||
|
||||
- Packet filters are simple, low-level and have high assurance
|
||||
- However they cannot:
|
||||
- Prevent attacks that employ application specific vulnerabilities
|
||||
- Do not support higher-level authentication schemes
|
||||
- Easy to accidentally allow or deny packets incorrectly
|
||||
|
||||
### Stateful Packet Filters
|
||||
|
||||
- Understand requests and replies (`ACK/SYN`)
|
||||
- Dynamically generate rules
|
||||
- Based on what it sees from TCP handshakes (can be FTP or SSH etc)
|
||||
- Can support policies for a wider range or protocols
|
||||
- `IPTABLES` has a module for stateful packet filtering
|
||||
- Allow incoming / outgoing SSH connections
|
||||
|
||||

|
||||
|
||||
#### Connection Tables
|
||||
|
||||

|
||||
|
||||
- `ACK` packets are used to keep track of the session - the connection is ongoing
|
||||
- Packets without the `ACK` are the connection establishment messages
|
||||
|
||||
#### Application-level Gateways
|
||||
|
||||
- Packet filters have limited criteria that allow data in and out
|
||||
- An application gateway considers the *application-layer* protocol that is in use
|
||||
- For example if someone sends an `HTTP` request to port 22, it is blocked
|
||||
|
||||
##### Proxy Server
|
||||
|
||||
- Proxy servers initiate a connection on our behalf
|
||||
- They can block certain access, and scan for malicious files or web pages
|
||||
|
||||

|
||||
|
||||
**Issues**:
|
||||
|
||||
- Large overhead per connection
|
||||
- More expensive than packet filtering
|
||||
- Configuration is complex
|
||||
- A separate server is required for each service
|
||||
|
||||
### Network Address Translation
|
||||
|
||||
The shortage of IP addresses mean that most routers now perform NAT automatically
|
||||
|
||||

|
||||
|
||||
- The implicit advantage in NAT is that your machine is almost totally hidden from the internet
|
||||
- Only **established connections** are forwarded to your internal machine
|
||||
- Or, specific **port forwarding** rules
|
||||
- This prevents any unsolicited attacks on random ports, but no other types of attack
|
||||
Reference in new issue
Block a user