# Network Security ### TCP/IP - Each protocol carries the protocol in the layer above by appending headers to it ![1647096411.png](img/1647096411.png) - IP is connection-less and state-less - Best effort service - No delivery guarantee - No order guarantee - IPv4 No guaranteed security support - IPv6 security support is guaranteed - IPSec #### IPSec - Optional in IPv4, mandatory support in IPv6 - Two major security mechanisms - IP Authentication Header (AH) - IP Encapsulation Security Payload (ESP) - Does not contain any mechanisms to prevent traffic analysis ##### Encapsulation Security Payload - Includes an additional header within the IP packet that describes what encryption and authentication is in use ![1647096765.png](img/1647096765.png) ##### Security Parameter Index - Stores security parameters e.g. crypto protocol and keys - Established by Internet Security association and key management protocol (ISAKMP) during the Internet Key Exchange (IKE) handshake - Uses Diffie-Hellman for key exchange - The SPI references the entry in a table that corresponds to this session’s parameters - ESP uses either *transport* or *tunnel* modes Transport mode ![1647096990.png](img/1647096990.png) Tunnel mode ![1647097202.png](img/1647097202.png) #### Transport vs Tunnel - Transport mode simply encrypts packets, providing host-to-host encryption but using the original header - Prevents contents being read, but does not stop traffic analysis or manipulation of the header - Tunnel mode (usually gateway-to-gateway) protects some segment of a channel with encryption - Provides some resistance to traffic analysis, and completely protects manipulation of the payload - VPNs are commonly implemented this way ![1647097501.png](img/1647097501.png) ### Network Attacks #### ARP - ARP is a protocol used to obtain physical MAC addresses for given IPs - It is used prior to constructing IP and TCP packets for communication - Network layer ![1647097704.png](img/1647097704.png) ##### ARP Cache Poisoning - We can simply send an unrequested ARP reply, and overwrite the MAC address in a host’s ARP cache with our own ![1647097845.png](img/1647097845.png) ##### ARP Protection - Some OSs ignore unsolicited ARP requests, or can be configured to use ARP differently - Some software, such as intrusion detection packages, will include ARP spoofing detection - Maintain a log of current MAC:IP assignments and ARP requests / replies #### DNS - DNS translates domain names into IP addresses - DNS packets are UDP - Stateless on the transport layer - DNS resolvers will cache the IP for a while ##### DNS Spoofing - If we poison the cache of a nameserver people are using, we can replace a website lookup with our IP - Can be achieved through prior ARP cache poisoning, a reply flood or a Kaminsky attack ![1647103405.png](img/1647103405.png) ###### DNS Protection - *Random query numbers* help protect against spoof replies - Since the Kaminsky attack, most resolvers now *randomise the source port* too - DNSSEC aims to tackle DNS exploits by authenticating the name server and providing integrity for the messages ### Denial of Service - A denial of service attack is an attempt to make a machine or network resource unavailable to its authorised / intended users - This will usually involve flooding a machine with enough requests that it can’t serve its legitimate purpose - ping flood - A distributed denial of service occurs where there is more than one attacking machine #### TCP Syn Flooding - Attacker initiates a genuine connection but then immediately breaks it - Attack never finishes 3-way handshake - Victim is busy with the timeout - Attack initiates large number of syn requests - Victim reaches its half-open connection limit ![1647104111.png](img/1647104111.png) #### Amplification Attacks - Regular attacks are your bandwidth vs your target’s - Amplification attacks utilise some aspect of a network protocol to *increase the bandwidth* of an attack ![1647104236.png](img/1647104236.png) ##### Smurf and Fraggle Attacks - Smurf attacks broadcast an ICMP ping request to a router, but with a spoofed IP belonging to the victim - A fraggle attack is identical in principle, using UDP echo packets ![1647104391.png](img/1647104391.png) ##### DNS Amplification - Recursive resolvers respond to DNS queries then return a response - This response can be many times larger than the query ![1647104517.png](img/1647104517.png) - In an ideal world, all DNS resolvers would: - Use an authorised list of requesters - e.g. ISPs allowing requests from only their customers - Egress filtering - Many DNS servers are set up incorrectly, and will happily amplify your traffic - **Open resolvers** - Botnets maintain lists of these open resolvers and there are projects attempting to shut these down ##### NTP Amplification - NTP is a protocol for synchronising time between machines - Extremely similar to DNS amplification - `MON_GETLIST` request returns the list of the last 600 contacts - Gives 200x amplification - `MON_GETLIST` is deprecated because of this attack ##### Slow Loris - Opens numerous connections to a server - Begin an HTTP request - Send just enough traffic to stop the connection from closing - Apache2 creates a new thread for each connection - More connections slow the server down significantly - The attack only sends bytes of data at a time making it extremely easy to do