5.9 KiB
5.9 KiB
Firewalls
- A hardware and/or software system
- Prevents unauthorised access of packets from one network to another
- All data leave any subnet must pass through it
Firewall Functions
- Implements single point security measures
- Security event monitoring through packet analysis and logging
- Network-based access control through implementation of a rules set
Network Firewalls - placed between a subnet and the internet
Host-based Firewalls - placed on individual machines
- A standard home router is a good example of a network firewall
DMZ
- A demilitarised zone is a small subnet that separates exrternally facing services from the internal network
- Imagine we have a web and email server running, these servers need different firewall rules to personal machines on the network
Basic Function
- Defends a network against parties accessing internal services
- Can also restrict access from inside to outside services
- Network Address Translation
- Hides the internal machines with private addresses
Firewalls are not enough
- Cannot protect against attacks that bypass the firewall
- e.g. tunneling
- Cannot protect against internal threats or insiders
- Might help a bit by egress filtering
- Network firewalls cannot always protect against the transfer of virus-infected programs or files
Packet Filters
- Specify which packets are allowed or dropped
- Rules based on:
- Source / destination IP
- TCP / UDP port numbers
- Possible for both inbound and outbound traffic
- Can be implemented in a router by only examining packet headers (IP / TCP)
Packet Filter Rules
- Rule execution depends on implementation
IPTABLES: First rule to match is appliedPF: All rules are examined, last match is applied
- Rules are organised in chains, which are logical subgroups of rules
- Depending on the packet, different chains are activated
IPTABLES
- An application that provides access to the Linux firewall rule tables
- Not actually a firewall, but configures the firewall
- The firewall is mostly implemented as
netfiltermodules
Tables and Chains
IPTABLESuses tables to store chains- Default is the filtering table
- Chains are ordered in lists of rules
- Rules match, or they don’t
- Matches result in a jump, else we check the next rule.
Default policy on this chain is DROP
- There can be multiple chains per table
- e.g. a
TCPhandling chain
- e.g. a
- Jumps can go to
ACCEPT,DROP,LOGor another chain - Complex behaviour can be built up
Defaults
- There are four built-in tables in
IPTABLES- Filter
NAT- Mangle - packet alteration
- Raw - skips connection tracking
- The default table is the filtering table, including input, output and forward chains
Rules Examples
- Using the command line, we add rules onto the end of chains
$ iptables -A INPUT -i eht0 -p tcp --dport 80 -j ACCEPT
$ iptables -A OUTPUT -i eht0 -p tcp --sport 80 -j ACCEPT
- Remember
httprequests are not sent from the client’s port 80, it is sent from a random high numbered port- This is how clients can have multiple web requests open at the same time
Policies
- Permissive - allow everything by default except dangerous services
- Make a black list
- Easy to make a mistake or forget something
iptables -p INPUT ACCEPT
iptables -p FORWARD ACCEPT
iptables -p OUTPUT ACCEPT
iptables -A INPUT -s X.X.X.X -j DROP
iptables -A OUTPUT -p tcp --dport ssh -j DROP
- Restrictive - block everything except designated useful services
- Make a white list
- More secure by default
iptables -p INPUT DROP
iptables -p FORWARD DROP
iptables -p OUTPUT DROP
iptables -A INPUT -p tcp --dport ssh -j ACCEPT
iptables -A OUTPUT -s 192.168.0.2 -j ACCEPT
Packet Filter Issues
- Packet filters are simple, low-level and have high assurance
- However they cannot:
- Prevent attacks that employ application specific vulnerabilities
- Do not support higher-level authentication schemes
- Easy to accidentally allow or deny packets incorrectly
Stateful Packet Filters
- Understand requests and replies (
ACK/SYN) - Dynamically generate rules
- Based on what it sees from TCP handshakes (can be FTP or SSH etc)
- Can support policies for a wider range or protocols
IPTABLEShas a module for stateful packet filtering- Allow incoming / outgoing SSH connections
Connection Tables
ACKpackets are used to keep track of the session - the connection is ongoing- Packets without the
ACKare the connection establishment messages
Application-level Gateways
- Packet filters have limited criteria that allow data in and out
- An application gateway considers the application-layer protocol that is in use
- For example if someone sends an
HTTPrequest to port 22, it is blocked
- For example if someone sends an
Proxy Server
- Proxy servers initiate a connection on our behalf
- They can block certain access, and scan for malicious files or web pages
Issues:
- Large overhead per connection
- More expensive than packet filtering
- Configuration is complex
- A separate server is required for each service
Network Address Translation
The shortage of IP addresses mean that most routers now perform NAT automatically
- The implicit advantage in NAT is that your machine is almost totally hidden from the internet
- Only established connections are forwarded to your internal machine
- Or, specific port forwarding rules
- This prevents any unsolicited attacks on random ports, but no other types of attack









