Files
2026-10-04 15:24:17 +01:00

195 lines
6.0 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Firewalls
- A hardware and/or software system
- Prevents unauthorised access of packets from one network to another
- All data leaving any subnet must pass through it
![1647287782.png](img/1647287782.png)
### Firewall Functions
- Implements *single point* security measures
- Security event monitoring through packet analysis and *logging*
- Network-based access control through implementation of a rules set
**Network Firewalls** - placed between a subnet and the internet
**Host-based Firewalls** - placed on individual machines
- A standard home router is a good example of a network firewall
![1647288145.png](img/1647288145.png)
#### DMZ
- A demilitarised zone is a small subnet that separates externally facing services from the internal network
![1647288286.png](img/1647288286.png)
- Imagine we have a web and email server running, these servers need different firewall rules to personal machines on the network
##### Basic Function
- Defends a network against parties accessing *internal services*
- Can also restrict access from *inside to outside* services
- Network Address Translation
- Hides the internal machines with private addresses
**Firewalls are not enough**
- Cannot protect against attacks that bypass the firewall
- e.g. tunnelling
- Cannot protect against internal threats or insiders
- Might help a bit by egress filtering
- Network firewalls cannot always protect against the transfer of virus-infected programs or files
#### Packet Filters
- Specify which packets are *allowed or dropped*
- Rules based on:
- Source / destination IP
- TCP / UDP port numbers
- Possible for both *inbound* and *outbound* traffic
- Can be implemented in a router by only examining packet headers (**IP / TCP**)
##### Packet Filter Rules
- Rule execution depends on implementation
- `IPTABLES`: **First** rule to match is applied
- `PF`: All rules are examined, **last** match is applied
- Rules are organised in *chains*, which are logical subgroups of rules
- Depending on the packet, different chains are activated
###### IPTABLES
- An application that provides access to the Linux firewall rule tables
- Not actually a firewall, but configures the firewall
- The firewall is mostly implemented as `netfilter` modules
###### Tables and Chains
- `IPTABLES` uses tables to store chains
- Default is the filtering table
- Chains are ordered in lists of rules
- Rules match, or they don’t
- Matches result in a **jump**, else we check the next rule.
![1647289401.png](img/1647289401.png)
Default policy on this chain is `DROP`
- There can be multiple chains per table
- e.g. a `TCP` handling chain
- Jumps can go to `ACCEPT`, `DROP`, `LOG` or another chain
- Complex behaviour can be built up
![1647289523.png](img/1647289523.png)
##### Defaults
- There are four built-in tables in `IPTABLES`
- Filter
- `NAT`
- Mangle - packet alteration
- Raw - skips connection tracking
- The default table is the filtering table, including input, output and forward chains
![1647289692.png](img/1647289692.png)
###### Rules Examples
- Using the command line, we add rules onto the end of chains
```bash
$ iptables -A INPUT -i eht0 -p tcp --dport 80 -j ACCEPT
$ iptables -A OUTPUT -i eht0 -p tcp --sport 80 -j ACCEPT
```
- Remember `http` requests are not sent from the client’s port 80; they are sent from a random high-numbered port
- This is how clients can have multiple web requests open at the same time
##### Policies
- **Permissive** - allow everything by default except dangerous services
- Make a black list
- Easy to make a mistake or forget something
```bash
iptables -p INPUT ACCEPT
iptables -p FORWARD ACCEPT
iptables -p OUTPUT ACCEPT
iptables -A INPUT -s X.X.X.X -j DROP
iptables -A OUTPUT -p tcp --dport ssh -j DROP
```
- **Restrictive** - block everything except designated useful services
- Make a white list
- More secure by default
```bash
iptables -p INPUT DROP
iptables -p FORWARD DROP
iptables -p OUTPUT DROP
iptables -A INPUT -p tcp --dport ssh -j ACCEPT
iptables -A OUTPUT -s 192.168.0.2 -j ACCEPT
```
#### Packet Filter Issues
- Packet filters are simple, low-level and have high assurance
- However:
- They cannot prevent attacks that employ application-specific vulnerabilities
- Do not support higher-level authentication schemes
- Easy to accidentally allow or deny packets incorrectly
### Stateful Packet Filters
- Understand requests and replies (`ACK/SYN`)
- Dynamically generate rules
- Based on what it sees from TCP handshakes (can be FTP or SSH etc)
- Can support policies for a wider range of protocols
- `IPTABLES` has a module for stateful packet filtering
- Allow incoming / outgoing SSH connections
![1647290573.png](img/1647290573.png)
#### Connection Tables
![1647290603.png](img/1647290603.png)
- `ACK` packets are used to keep track of the session - the connection is ongoing
- Packets without the `ACK` are the connection establishment messages
#### Application-level Gateways
- Packet filters have limited criteria that allow data in and out
- An application gateway considers the *application-layer* protocol that is in use
- For example if someone sends an `HTTP` request to port 22, it is blocked
##### Proxy Server
- Proxy servers initiate a connection on our behalf
- They can block certain access, and scan for malicious files or web pages
![1647290781.png](img/1647290781.png)
**Issues**:
- Large overhead per connection
- More expensive than packet filtering
- Configuration is complex
- A separate server is required for each service
### Network Address Translation
The shortage of IP addresses means that most routers now perform NAT automatically
![1647290897.png](img/1647290897.png)
- The implicit advantage in NAT is that your machine is almost totally hidden from the internet
- Only **established connections** are forwarded to your internal machine
- Or, specific **port forwarding** rules
- This prevents any unsolicited attacks on random ports, but no other types of attack