Files
2026-10-04 15:24:17 +01:00

6.0 KiB
Raw Permalink Blame History

Firewalls

  • A hardware and/or software system
  • Prevents unauthorised access of packets from one network to another
  • All data leaving any subnet must pass through it

1647287782.png

Firewall Functions

  • Implements single point security measures
  • Security event monitoring through packet analysis and logging
  • Network-based access control through implementation of a rules set

Network Firewalls - placed between a subnet and the internet

Host-based Firewalls - placed on individual machines

  • A standard home router is a good example of a network firewall

1647288145.png

DMZ

  • A demilitarised zone is a small subnet that separates externally facing services from the internal network

1647288286.png

  • Imagine we have a web and email server running, these servers need different firewall rules to personal machines on the network
Basic Function
  • Defends a network against parties accessing internal services
  • Can also restrict access from inside to outside services
  • Network Address Translation
    • Hides the internal machines with private addresses

Firewalls are not enough

  • Cannot protect against attacks that bypass the firewall
    • e.g. tunnelling
  • Cannot protect against internal threats or insiders
    • Might help a bit by egress filtering
  • Network firewalls cannot always protect against the transfer of virus-infected programs or files

Packet Filters

  • Specify which packets are allowed or dropped
  • Rules based on:
    • Source / destination IP
    • TCP / UDP port numbers
  • Possible for both inbound and outbound traffic
  • Can be implemented in a router by only examining packet headers (IP / TCP)
Packet Filter Rules
  • Rule execution depends on implementation
    • IPTABLES: First rule to match is applied
    • PF: All rules are examined, last match is applied
  • Rules are organised in chains, which are logical subgroups of rules
  • Depending on the packet, different chains are activated
IPTABLES
  • An application that provides access to the Linux firewall rule tables
    • Not actually a firewall, but configures the firewall
    • The firewall is mostly implemented as netfilter modules
Tables and Chains
  • IPTABLES uses tables to store chains
    • Default is the filtering table
  • Chains are ordered in lists of rules
    • Rules match, or they don’t
  • Matches result in a jump, else we check the next rule.

1647289401.png

Default policy on this chain is DROP

  • There can be multiple chains per table
    • e.g. a TCP handling chain
  • Jumps can go to ACCEPT, DROP, LOG or another chain
  • Complex behaviour can be built up

1647289523.png

Defaults
  • There are four built-in tables in IPTABLES
    • Filter
    • NAT
    • Mangle - packet alteration
    • Raw - skips connection tracking
  • The default table is the filtering table, including input, output and forward chains

1647289692.png

Rules Examples
  • Using the command line, we add rules onto the end of chains
$ iptables -A INPUT  -i eht0 -p tcp --dport 80 -j ACCEPT
$ iptables -A OUTPUT -i eht0 -p tcp --sport 80 -j ACCEPT
  • Remember http requests are not sent from the client’s port 80; they are sent from a random high-numbered port
    • This is how clients can have multiple web requests open at the same time
Policies
  • Permissive - allow everything by default except dangerous services
    • Make a black list
    • Easy to make a mistake or forget something
iptables -p INPUT ACCEPT
iptables -p FORWARD ACCEPT
iptables -p OUTPUT ACCEPT

iptables -A INPUT -s X.X.X.X -j DROP
iptables -A OUTPUT -p tcp --dport ssh -j DROP
  • Restrictive - block everything except designated useful services
    • Make a white list
    • More secure by default
iptables -p INPUT DROP
iptables -p FORWARD DROP
iptables -p OUTPUT DROP

iptables -A INPUT -p tcp --dport ssh -j ACCEPT
iptables -A OUTPUT -s 192.168.0.2 -j ACCEPT

Packet Filter Issues

  • Packet filters are simple, low-level and have high assurance
  • However:
    • They cannot prevent attacks that employ application-specific vulnerabilities
    • Do not support higher-level authentication schemes
    • Easy to accidentally allow or deny packets incorrectly

Stateful Packet Filters

  • Understand requests and replies (ACK/SYN)
  • Dynamically generate rules
    • Based on what it sees from TCP handshakes (can be FTP or SSH etc)
  • Can support policies for a wider range of protocols
  • IPTABLES has a module for stateful packet filtering
  • Allow incoming / outgoing SSH connections

1647290573.png

Connection Tables

1647290603.png

  • ACK packets are used to keep track of the session - the connection is ongoing
  • Packets without the ACK are the connection establishment messages

Application-level Gateways

  • Packet filters have limited criteria that allow data in and out
  • An application gateway considers the application-layer protocol that is in use
    • For example if someone sends an HTTP request to port 22, it is blocked
Proxy Server
  • Proxy servers initiate a connection on our behalf
  • They can block certain access, and scan for malicious files or web pages

1647290781.png

Issues:

  • Large overhead per connection
  • More expensive than packet filtering
  • Configuration is complex
  • A separate server is required for each service

Network Address Translation

The shortage of IP addresses means that most routers now perform NAT automatically

1647290897.png

  • The implicit advantage in NAT is that your machine is almost totally hidden from the internet
  • Only established connections are forwarded to your internal machine
    • Or, specific port forwarding rules
  • This prevents any unsolicited attacks on random ports, but no other types of attack