Files
notes/docs/lectures/security/11_network_security.md
2026-10-04 15:24:17 +01:00

161 lines
5.4 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Network Security
### TCP/IP
- Each protocol carries the protocol in the layer above by appending headers to it
![1647096411.png](img/1647096411.png)
- IP is connection-less and state-less
- Best effort service
- No delivery guarantee
- No order guarantee
- IPv4 No guaranteed security support
- IPv6 security support is guaranteed - IPSec
#### IPSec
- Optional in IPv4, mandatory support in IPv6
- Two major security mechanisms
- IP Authentication Header (AH)
- IP Encapsulation Security Payload (ESP)
- Does not contain any mechanisms to prevent traffic analysis
##### Encapsulation Security Payload
- Includes an additional header within the IP packet that describes what encryption and authentication is in use
![1647096765.png](img/1647096765.png)
##### Security Parameter Index
- Stores security parameters e.g. crypto protocol and keys
- Established by Internet Security association and key management protocol (ISAKMP) during the Internet Key Exchange (IKE) handshake
- Uses Diffie-Hellman for key exchange
- The SPI references the entry in a table that corresponds to this session’s parameters
- ESP uses either *transport* or *tunnel* modes
Transport mode
![1647096990.png](img/1647096990.png)
Tunnel mode
![1647097202.png](img/1647097202.png)
#### Transport vs Tunnel
- Transport mode simply encrypts packets, providing host-to-host encryption but using the original header
- Prevents contents being read, but does not stop traffic analysis or manipulation of the header
- Tunnel mode (usually gateway-to-gateway) protects some segment of a channel with encryption
- Provides some resistance to traffic analysis, and completely protects manipulation of the payload
- VPNs are commonly implemented this way
![1647097501.png](img/1647097501.png)
### Network Attacks
#### ARP
- ARP is a protocol used to obtain physical MAC addresses for given IPs
- It is used prior to constructing IP and TCP packets for communication
- Network layer
![1647097704.png](img/1647097704.png)
##### ARP Cache Poisoning
- We can simply send an unrequested ARP reply, and overwrite the MAC address in a host’s ARP cache with our own
![1647097845.png](img/1647097845.png)
##### ARP Protection
- Some OSs ignore unsolicited ARP requests, or can be configured to use ARP differently
- Some software, such as intrusion detection packages, will include ARP spoofing detection
- Maintain a log of current MAC:IP assignments and ARP requests / replies
#### DNS
- DNS translates domain names into IP addresses
- DNS packets are UDP
- Stateless on the transport layer
- DNS resolvers will cache the IP for a while
##### DNS Spoofing
- If we poison the cache of a nameserver people are using, we can replace a website lookup with our IP
- Can be achieved through prior ARP cache poisoning, a reply flood or a Kaminsky attack
![1647103405.png](img/1647103405.png)
###### DNS Protection
- *Random query numbers* help protect against spoof replies
- Since the Kaminsky attack, most resolvers now *randomise the source port* too
- DNSSEC aims to tackle DNS exploits by authenticating the name server and providing integrity for the messages
### Denial of Service
- A denial of service attack is an attempt to make a machine or network resource unavailable to its authorised / intended users
- This will usually involve flooding a machine with enough requests that it can’t serve its legitimate purpose
- ping flood
- A distributed denial of service occurs where there is more than one attacking machine
#### TCP Syn Flooding
- Attacker initiates a genuine connection but then immediately breaks it
- Attack never finishes 3-way handshake
- Victim is busy with the timeout
- Attack initiates large number of syn requests
- Victim reaches its half-open connection limit
![1647104111.png](img/1647104111.png)
#### Amplification Attacks
- Regular attacks are your bandwidth vs your target’s
- Amplification attacks utilise some aspect of a network protocol to *increase the bandwidth* of an attack
![1647104236.png](img/1647104236.png)
##### Smurf and Fraggle Attacks
- Smurf attacks broadcast an ICMP ping request to a router, but with a spoofed IP belonging to the victim
- A fraggle attack is identical in principle, using UDP echo packets
![1647104391.png](img/1647104391.png)
##### DNS Amplification
- Recursive resolvers respond to DNS queries then return a response
- This response can be many times larger than the query
![1647104517.png](img/1647104517.png)
- In an ideal world, all DNS resolvers would:
- Use an authorised list of requesters
- e.g. ISPs allowing requests from only their customers
- Egress filtering
- Many DNS servers are set up incorrectly, and will happily amplify your traffic - **Open resolvers**
- Botnets maintain lists of these open resolvers and there are projects attempting to shut these down
##### NTP Amplification
- NTP is a protocol for synchronising time between machines
- Extremely similar to DNS amplification
- `MON_GETLIST` request returns the list of the last 600 contacts
- Gives 200x amplification
- `MON_GETLIST` is deprecated because of this attack
##### Slow Loris
- Opens numerous connections to a server
- Begin an HTTP request
- Send just enough traffic to stop the connection from closing
- Apache2 creates a new thread for each connection
- More connections slow the server down significantly
- The attack only sends bytes of data at a time making it extremely easy to do