194 lines
5.9 KiB
Markdown
194 lines
5.9 KiB
Markdown
# Firewalls
|
||
|
||
- A hardware and/or software system
|
||
- Prevents unauthorised access of packets from one network to another
|
||
- All data leave any subnet must pass through it
|
||
|
||

|
||
|
||
### Firewall Functions
|
||
|
||
- Implements *single point* security measures
|
||
- Security event monitoring through packet analysis and *logging*
|
||
- Network-based access control through implementation of a rules set
|
||
|
||
**Network Firewalls** - placed between a subnet and the internet
|
||
|
||
**Host-based Firewalls** - placed on individual machines
|
||
|
||
- A standard home router is a good example of a network firewall
|
||
|
||

|
||
|
||
#### DMZ
|
||
|
||
- A demilitarised zone is a small subnet that separates exrternally facing services from the internal network
|
||
|
||

|
||
|
||
- Imagine we have a web and email server running, these servers need different firewall rules to personal machines on the network
|
||
|
||
##### Basic Function
|
||
|
||
- Defends a network against parties accessing *internal services*
|
||
- Can also restrict access from *inside to outside* services
|
||
- Network Address Translation
|
||
- Hides the internal machines with private addresses
|
||
|
||
**Firewalls are not enough**
|
||
|
||
- Cannot protect against attacks that bypass the firewall
|
||
- e.g. tunneling
|
||
- Cannot protect against internal threats or insiders
|
||
- Might help a bit by egress filtering
|
||
- Network firewalls cannot always protect against the transfer of virus-infected programs or files
|
||
|
||
#### Packet Filters
|
||
|
||
- Specify which packets are *allowed or dropped*
|
||
- Rules based on:
|
||
- Source / destination IP
|
||
- TCP / UDP port numbers
|
||
- Possible for both *inbound* and *outbound* traffic
|
||
- Can be implemented in a router by only examining packet headers (**IP / TCP**)
|
||
|
||
##### Packet Filter Rules
|
||
|
||
- Rule execution depends on implementation
|
||
- `IPTABLES`: **First** rule to match is applied
|
||
- `PF`: All rules are examined, **last** match is applied
|
||
- Rules are organised in *chains*, which are logical subgroups of rules
|
||
- Depending on the packet, different chains are activated
|
||
|
||
###### IPTABLES
|
||
|
||
- An application that provides access to the Linux firewall rule tables
|
||
- Not actually a firewall, but configures the firewall
|
||
- The firewall is mostly implemented as `netfilter` modules
|
||
|
||
###### Tables and Chains
|
||
|
||
- `IPTABLES` uses tables to store chains
|
||
- Default is the filtering table
|
||
- Chains are ordered in lists of rules
|
||
- Rules match, or they don’t
|
||
- Matches result in a **jump**, else we check the next rule.
|
||
|
||

|
||
|
||
Default policy on this chain is `DROP`
|
||
|
||
- There can be multiple chains per table
|
||
- e.g. a `TCP` handling chain
|
||
- Jumps can go to `ACCEPT`, `DROP`, `LOG` or another chain
|
||
- Complex behaviour can be built up
|
||
|
||

|
||
|
||
##### Defaults
|
||
|
||
- There are four built-in tables in `IPTABLES`
|
||
- Filter
|
||
- `NAT`
|
||
- Mangle - packet alteration
|
||
- Raw - skips connection tracking
|
||
- The default table is the filtering table, including input, output and forward chains
|
||
|
||

|
||
|
||
###### Rules Examples
|
||
|
||
- Using the command line, we add rules onto the end of chains
|
||
|
||
```bash
|
||
$ iptables -A INPUT -i eht0 -p tcp --dport 80 -j ACCEPT
|
||
$ iptables -A OUTPUT -i eht0 -p tcp --sport 80 -j ACCEPT
|
||
```
|
||
|
||
- Remember `http` requests are not sent from the client’s port 80, it is sent from a random high numbered port
|
||
- This is how clients can have multiple web requests open at the same time
|
||
|
||
##### Policies
|
||
|
||
- **Permissive** - allow everything by default except dangerous services
|
||
- Make a black list
|
||
- Easy to make a mistake or forget something
|
||
|
||
```bash
|
||
iptables -p INPUT ACCEPT
|
||
iptables -p FORWARD ACCEPT
|
||
iptables -p OUTPUT ACCEPT
|
||
|
||
iptables -A INPUT -s X.X.X.X -j DROP
|
||
iptables -A OUTPUT -p tcp --dport ssh -j DROP
|
||
```
|
||
|
||
- **Restrictive** - block everything except designated useful services
|
||
- Make a white list
|
||
- More secure by default
|
||
|
||
```bash
|
||
iptables -p INPUT DROP
|
||
iptables -p FORWARD DROP
|
||
iptables -p OUTPUT DROP
|
||
|
||
iptables -A INPUT -p tcp --dport ssh -j ACCEPT
|
||
iptables -A OUTPUT -s 192.168.0.2 -j ACCEPT
|
||
```
|
||
|
||
#### Packet Filter Issues
|
||
|
||
- Packet filters are simple, low-level and have high assurance
|
||
- However they cannot:
|
||
- Prevent attacks that employ application specific vulnerabilities
|
||
- Do not support higher-level authentication schemes
|
||
- Easy to accidentally allow or deny packets incorrectly
|
||
|
||
### Stateful Packet Filters
|
||
|
||
- Understand requests and replies (`ACK/SYN`)
|
||
- Dynamically generate rules
|
||
- Based on what it sees from TCP handshakes (can be FTP or SSH etc)
|
||
- Can support policies for a wider range or protocols
|
||
- `IPTABLES` has a module for stateful packet filtering
|
||
- Allow incoming / outgoing SSH connections
|
||
|
||

|
||
|
||
#### Connection Tables
|
||
|
||

|
||
|
||
- `ACK` packets are used to keep track of the session - the connection is ongoing
|
||
- Packets without the `ACK` are the connection establishment messages
|
||
|
||
#### Application-level Gateways
|
||
|
||
- Packet filters have limited criteria that allow data in and out
|
||
- An application gateway considers the *application-layer* protocol that is in use
|
||
- For example if someone sends an `HTTP` request to port 22, it is blocked
|
||
|
||
##### Proxy Server
|
||
|
||
- Proxy servers initiate a connection on our behalf
|
||
- They can block certain access, and scan for malicious files or web pages
|
||
|
||

|
||
|
||
**Issues**:
|
||
|
||
- Large overhead per connection
|
||
- More expensive than packet filtering
|
||
- Configuration is complex
|
||
- A separate server is required for each service
|
||
|
||
### Network Address Translation
|
||
|
||
The shortage of IP addresses mean that most routers now perform NAT automatically
|
||
|
||

|
||
|
||
- The implicit advantage in NAT is that your machine is almost totally hidden from the internet
|
||
- Only **established connections** are forwarded to your internal machine
|
||
- Or, specific **port forwarding** rules
|
||
- This prevents any unsolicited attacks on random ports, but no other types of attack |