Files
notes/docs/lectures/security/11_network_security.md
2026-10-04 15:24:17 +01:00

5.4 KiB
Raw Permalink Blame History

Network Security

TCP/IP

  • Each protocol carries the protocol in the layer above by appending headers to it

1647096411.png

  • IP is connection-less and state-less
    • Best effort service
    • No delivery guarantee
    • No order guarantee
  • IPv4 No guaranteed security support
  • IPv6 security support is guaranteed - IPSec

IPSec

  • Optional in IPv4, mandatory support in IPv6
  • Two major security mechanisms
    • IP Authentication Header (AH)
    • IP Encapsulation Security Payload (ESP)
  • Does not contain any mechanisms to prevent traffic analysis
Encapsulation Security Payload
  • Includes an additional header within the IP packet that describes what encryption and authentication is in use

1647096765.png

Security Parameter Index
  • Stores security parameters e.g. crypto protocol and keys

  • Established by Internet Security association and key management protocol (ISAKMP) during the Internet Key Exchange (IKE) handshake

    • Uses Diffie-Hellman for key exchange
  • The SPI references the entry in a table that corresponds to this session’s parameters

  • ESP uses either transport or tunnel modes

Transport mode

1647096990.png

Tunnel mode

1647097202.png

Transport vs Tunnel

  • Transport mode simply encrypts packets, providing host-to-host encryption but using the original header

  • Prevents contents being read, but does not stop traffic analysis or manipulation of the header

  • Tunnel mode (usually gateway-to-gateway) protects some segment of a channel with encryption

  • Provides some resistance to traffic analysis, and completely protects manipulation of the payload

  • VPNs are commonly implemented this way

1647097501.png

Network Attacks

ARP

  • ARP is a protocol used to obtain physical MAC addresses for given IPs
    • It is used prior to constructing IP and TCP packets for communication
    • Network layer

1647097704.png

ARP Cache Poisoning
  • We can simply send an unrequested ARP reply, and overwrite the MAC address in a host’s ARP cache with our own

1647097845.png

ARP Protection
  • Some OSs ignore unsolicited ARP requests, or can be configured to use ARP differently
  • Some software, such as intrusion detection packages, will include ARP spoofing detection
    • Maintain a log of current MAC:IP assignments and ARP requests / replies

DNS

  • DNS translates domain names into IP addresses
  • DNS packets are UDP
    • Stateless on the transport layer
  • DNS resolvers will cache the IP for a while
DNS Spoofing
  • If we poison the cache of a nameserver people are using, we can replace a website lookup with our IP
  • Can be achieved through prior ARP cache poisoning, a reply flood or a Kaminsky attack

1647103405.png

DNS Protection
  • Random query numbers help protect against spoof replies
  • Since the Kaminsky attack, most resolvers now randomise the source port too
  • DNSSEC aims to tackle DNS exploits by authenticating the name server and providing integrity for the messages

Denial of Service

  • A denial of service attack is an attempt to make a machine or network resource unavailable to its authorised / intended users
  • This will usually involve flooding a machine with enough requests that it can’t serve its legitimate purpose
    • ping flood
  • A distributed denial of service occurs where there is more than one attacking machine

TCP Syn Flooding

  • Attacker initiates a genuine connection but then immediately breaks it
  • Attack never finishes 3-way handshake
  • Victim is busy with the timeout
  • Attack initiates large number of syn requests
  • Victim reaches its half-open connection limit

1647104111.png

Amplification Attacks

  • Regular attacks are your bandwidth vs your target’s
  • Amplification attacks utilise some aspect of a network protocol to increase the bandwidth of an attack

1647104236.png

Smurf and Fraggle Attacks
  • Smurf attacks broadcast an ICMP ping request to a router, but with a spoofed IP belonging to the victim
  • A fraggle attack is identical in principle, using UDP echo packets

1647104391.png

DNS Amplification
  • Recursive resolvers respond to DNS queries then return a response
  • This response can be many times larger than the query

1647104517.png

  • In an ideal world, all DNS resolvers would:
    • Use an authorised list of requesters
      • e.g. ISPs allowing requests from only their customers
    • Egress filtering
  • Many DNS servers are set up incorrectly, and will happily amplify your traffic - Open resolvers
  • Botnets maintain lists of these open resolvers and there are projects attempting to shut these down
NTP Amplification
  • NTP is a protocol for synchronising time between machines
  • Extremely similar to DNS amplification
  • MON_GETLIST request returns the list of the last 600 contacts
    • Gives 200x amplification
    • MON_GETLIST is deprecated because of this attack
Slow Loris
  • Opens numerous connections to a server
  • Begin an HTTP request
    • Send just enough traffic to stop the connection from closing
    • Apache2 creates a new thread for each connection
    • More connections slow the server down significantly
  • The attack only sends bytes of data at a time making it extremely easy to do