5.4 KiB
Network Security
TCP/IP
- Each protocol carries the protocol in the layer above by appending headers to it
- IP is connection-less and state-less
- Best effort service
- No delivery guarantee
- No order guarantee
- IPv4 No guaranteed security support
- IPv6 security support is guaranteed - IPSec
IPSec
- Optional in IPv4, mandatory support in IPv6
- Two major security mechanisms
- IP Authentication Header (AH)
- IP Encapsulation Security Payload (ESP)
- Does not contain any mechanisms to prevent traffic analysis
Encapsulation Security Payload
- Includes an additional header within the IP packet that describes what encryption and authentication is in use
Security Parameter Index
-
Stores security parameters e.g. crypto protocol and keys
-
Established by Internet Security association and key management protocol (ISAKMP) during the Internet Key Exchange (IKE) handshake
- Uses Diffie-Hellman for key exchange
-
The SPI references the entry in a table that corresponds to this session’s parameters
-
ESP uses either transport or tunnel modes
Transport mode
Tunnel mode
Transport vs Tunnel
-
Transport mode simply encrypts packets, providing host-to-host encryption but using the original header
-
Prevents contents being read, but does not stop traffic analysis or manipulation of the header
-
Tunnel mode (usually gateway-to-gateway) protects some segment of a channel with encryption
-
Provides some resistance to traffic analysis, and completely protects manipulation of the payload
-
VPNs are commonly implemented this way
Network Attacks
ARP
- ARP is a protocol used to obtain physical MAC addresses for given IPs
- It is used prior to constructing IP and TCP packets for communication
- Network layer
ARP Cache Poisoning
- We can simply send an unrequested ARP reply, and overwrite the MAC address in a host’s ARP cache with our own
ARP Protection
- Some OSs ignore unsolicited ARP requests, or can be configured to use ARP differently
- Some software, such as intrusion detection packages, will include ARP spoofing detection
- Maintain a log of current MAC:IP assignments and ARP requests / replies
DNS
- DNS translates domain names into IP addresses
- DNS packets are UDP
- Stateless on the transport layer
- DNS resolvers will cache the IP for a while
DNS Spoofing
- If we poison the cache of a nameserver people are using, we can replace a website lookup with our IP
- Can be achieved through prior ARP cache poisoning, a reply flood or a Kaminsky attack
DNS Protection
- Random query numbers help protect against spoof replies
- Since the Kaminsky attack, most resolvers now randomise the source port too
- DNSSEC aims to tackle DNS exploits by authenticating the name server and providing integrity for the messages
Denial of Service
- A denial of service attack is an attempt to make a machine or network resource unavailable to its authorised / intended users
- This will usually involve flooding a machine with enough requests that it can’t serve its legitimate purpose
- ping flood
- A distributed denial of service occurs where there is more than one attacking machine
TCP Syn Flooding
- Attacker initiates a genuine connection but then immediately breaks it
- Attack never finishes 3-way handshake
- Victim is busy with the timeout
- Attack initiates large number of syn requests
- Victim reaches its half-open connection limit
Amplification Attacks
- Regular attacks are your bandwidth vs your target’s
- Amplification attacks utilise some aspect of a network protocol to increase the bandwidth of an attack
Smurf and Fraggle Attacks
- Smurf attacks broadcast an ICMP ping request to a router, but with a spoofed IP belonging to the victim
- A fraggle attack is identical in principle, using UDP echo packets
DNS Amplification
- Recursive resolvers respond to DNS queries then return a response
- This response can be many times larger than the query
- In an ideal world, all DNS resolvers would:
- Use an authorised list of requesters
- e.g. ISPs allowing requests from only their customers
- Egress filtering
- Use an authorised list of requesters
- Many DNS servers are set up incorrectly, and will happily amplify your traffic - Open resolvers
- Botnets maintain lists of these open resolvers and there are projects attempting to shut these down
NTP Amplification
- NTP is a protocol for synchronising time between machines
- Extremely similar to DNS amplification
MON_GETLISTrequest returns the list of the last 600 contacts- Gives 200x amplification
MON_GETLISTis deprecated because of this attack
Slow Loris
- Opens numerous connections to a server
- Begin an HTTP request
- Send just enough traffic to stop the connection from closing
- Apache2 creates a new thread for each connection
- More connections slow the server down significantly
- The attack only sends bytes of data at a time making it extremely easy to do











