Published on

  • Be the first to comment

  • Be the first to like this

No Downloads
Total views
On SlideShare
From Embeds
Number of Embeds
Embeds 0
No embeds

No notes for slide


  1. 1. Firewalls CIT304 University of Sunderland Harry R. Erwin, PhD
  2. 2. Resources <ul><li>Garfinkel and Spafford, 1996, Practical UNIX and Internet Security, O’Reilly, ISBN: 1-56592-148-8 </li></ul><ul><li>Schneier, 2000, Secrets and Lies, Wiley, ISBN: 0-471-25311-1. </li></ul><ul><li>Anderson, 2001, Security Engineering, Wiley, ISBN:0-471-38922-6. </li></ul><ul><li>Zwicky, Cooper & Chapman, 2001, Building Internet Firewalls, O’Reilly. </li></ul>
  3. 3. Definition <ul><li>Firewall ( Schneier ) </li></ul><ul><ul><li>Originally an iron wall that protected train passengers from engine fires. Didn’t protect the engineer—there may be a lesson for sysadmins here. </li></ul></ul><ul><ul><li>In early networks, a device that protected a segment of a network from failures in other segments </li></ul></ul><ul><ul><li>Now a device that protects an internal network from malicious intruders. </li></ul></ul><ul><ul><ul><li>Does not deal with the 70+% of attacks that come from inside. </li></ul></ul></ul><ul><ul><ul><li>Does not deal with most vulnerabilities (see next slide)—only those associated with network connections. </li></ul></ul></ul>
  4. 4. Top 20 Vulnerabilities ( , 4 Dec 2006) <ul><li>Operating Systems </li></ul><ul><li>Internet Explorer </li></ul><ul><li>Windows Libraries </li></ul><ul><li>Microsoft Office and Outlook Express </li></ul><ul><li>Windows Services </li></ul><ul><li>Internet Explorer (IE) </li></ul><ul><li>Windows Configuration Weaknesses </li></ul><ul><li>Mac OS X </li></ul><ul><li>Unix Configuration Weaknesses </li></ul><ul><li>Network Devices </li></ul><ul><li>VoIP Servers and Phones </li></ul><ul><li>Network and Other Devices Common Configuration Weaknesses </li></ul><ul><li>Cross-Platform Applications </li></ul><ul><li>Web Applications </li></ul><ul><li>Database Software </li></ul><ul><li>P2P File Sharing Applications </li></ul><ul><li>Instant Messaging </li></ul><ul><li>Media Players </li></ul><ul><li>DNS Servers </li></ul><ul><li>Backup Software </li></ul><ul><li>Security, Enterprise, and Directory Management Servers </li></ul><ul><li>Security Policy and Personnel </li></ul><ul><li>Excessive User Rights and Unauthorized Devices </li></ul><ul><li>Users (Phishing/Spear Phishing) </li></ul><ul><li>Special Section </li></ul><ul><li>Zero Day Attacks and Prevention Strategies </li></ul>
  5. 5. Perimeter Defense <ul><li>No good against internal uprisings </li></ul><ul><li>Denial of service will remains threat </li></ul><ul><li>Must be complete—otherwise the hacker will go around it. </li></ul><ul><li>Must still contain gateways, which become the main vulnerabilities. </li></ul>
  6. 6. Boundary Protection <ul><li>The careful use of boundary mechanisms allows the designer to segment the network into protected domains, isolated from the internet and telephone service. </li></ul><ul><li>This limits damage and prevents malicious attackers from gaining entry. </li></ul>
  7. 7. Hub and Ring Architectures <ul><li>Hub architecture—packets transmitted by one device are reflected to all devices. Can be digital or analog. Analog hubs reduce signal strength, limiting the number of devices. Speed of light delays also limit the spatial extent of the LAN. </li></ul><ul><li>Ring architecture—each device connects to a ring of connections. One packet at a time circulates around the ring. If it arrives back at the device unchanged, it is deemed to have been successfully transmitted. Otherwise it is retransmitted. </li></ul>
  8. 8. Gateway <ul><li>Typically a router connected to the hub or ring. Has external connections. </li></ul><ul><li>Uses routing tables to find a route to a server. Sends the packet out that route. </li></ul><ul><li>If a server isn’t reachable, an ICMP DEST_UNREACH packet is generated and eventually returns to the source. </li></ul>
  9. 9. Switch <ul><li>‘ Smart’ hubs that transfer packets between networks. Fast switches are based on state machine architectures. </li></ul><ul><li>Can block a sniffer from accessing local traffic. </li></ul><ul><li>Virtual LANs can be isolated and connected via switches </li></ul><ul><li>Not a security mechanism. Performance is too important for switches to do much processing. </li></ul>
  10. 10. Virtual Private Network (VPN) <ul><li>Encrypted tunneling (stunnel or ssh) can be used to link distant LANs via switches. </li></ul><ul><li>Usually handled peer-to-peer with the routers and firewalls passing encrypted packets. This is message-level encryption. </li></ul><ul><li>Can also be handled using link-level or packet-level encryption. Link-level uses military COMSEC devices and has a high maintenance overhead. </li></ul>
  11. 11. Boundary Mechanisms Used to Secure Networks <ul><li>Note: Firewalls and routers are basic tools of network security. </li></ul><ul><li>Filtering routers </li></ul><ul><li>Firewalls: </li></ul><ul><ul><li>Packet Filters </li></ul></ul><ul><ul><li>Proxies </li></ul></ul><ul><ul><li>NAT (network address translation) </li></ul></ul><ul><ul><li>Screens </li></ul></ul><ul><li>Personal firewalls </li></ul><ul><li>“ Demilitarized Zones” (DMZs) </li></ul>
  12. 12. Attacks on Boundary Mechanisms <ul><li>Three approaches: </li></ul><ul><li>Go around it. </li></ul><ul><ul><li>Internet connections from photocopiers, soft drink machines, and other devices </li></ul></ul><ul><ul><li>Maintenance ports on network devices </li></ul></ul><ul><ul><li>Unauthorized modems </li></ul></ul><ul><ul><li>Attack trusted peers instead </li></ul></ul><ul><li>Sneak past it. </li></ul><ul><li>Take the firewall over. </li></ul><ul><ul><li>Buggy software </li></ul></ul><ul><ul><li>Insecure operating systems </li></ul></ul>
  13. 13. Filtering Router <ul><li>A basic router that provides stateless protection: </li></ul><ul><ul><li>Only passes legitimate packets, which is good. What packets are legitimate is a policy decision. Two basic strategies: </li></ul></ul><ul><ul><ul><li>Default permit —easier to configure but riskier </li></ul></ul></ul><ul><ul><ul><li>Default deny —safer but inflexible (UoS policy) </li></ul></ul></ul><ul><ul><li>Neither is a panacea. </li></ul></ul><ul><ul><li>A filtering router doesn’t connect SYN ACKs to the related SYN packets or other packets involved in the connection. This can be exploited by a smart attacker. </li></ul></ul>
  14. 14. Firewall <ul><li>Smarter than a simple filtering router. Enforces your chosen policies. May sniff traffic. </li></ul><ul><li>Blocks access as part of a defense in depth strategy. </li></ul><ul><li>Can serve as a proxy for the clients behind it. </li></ul><ul><li>Can encrypt traffic between separate locations. </li></ul><ul><li>Can even be stateful, tracking connections, not just packets—reducing throughput, but harder to fool. (Remains vulnerable to slow attacks.) </li></ul><ul><li>Note however, a filtering router plus strong endpoint security (hardened workstations) is more secure than an isolated firewall. </li></ul>
  15. 15. Firewall Anatomy <ul><li>Based on chokes and gates ( Garfinkel and Spafford ): </li></ul><ul><li>Choke </li></ul><ul><ul><li>A component that restricts the free flow of packets between networks based on some policy. </li></ul></ul><ul><li>Gate </li></ul><ul><ul><li>Handles port connections. </li></ul></ul><ul><ul><li>Single machines that handle all ports are “bastion hosts” </li></ul></ul><ul><ul><li>Programs that might be supported include </li></ul></ul><ul><ul><ul><li>network clients (undesirable), </li></ul></ul></ul><ul><ul><ul><li>proxy servers, and </li></ul></ul></ul><ul><ul><ul><li>network servers. </li></ul></ul></ul>
  16. 16. How to Program a Simple Packet Filtering Choke <ul><li>Block all packets for services not used. </li></ul><ul><li>Block all packets with IP source routing options </li></ul><ul><li>Allow incoming TCP connections to predetermined network servers. </li></ul><ul><li>Allow outgoing TCP connections. (You might want to some used by malware.) </li></ul>
  17. 17. Pros and Cons of Packet Filtering <ul><li>Pros </li></ul><ul><ul><li>Cheap and easy </li></ul></ul><ul><ul><li>Flexible </li></ul></ul><ul><li>Cons </li></ul><ul><ul><li>Usually lacks logging </li></ul></ul><ul><ul><li>Complex rulesets that are hard to configure and untestable </li></ul></ul><ul><ul><li>ftp not handled well unless passive mode is set (due to the high port numbers used by ftp) </li></ul></ul><ul><ul><li>Security can be silently compromised </li></ul></ul><ul><ul><li>Remote administration can be compromised </li></ul></ul><ul><ul><li>Insider attacks are easy </li></ul></ul><ul><ul><li>Packet contents are not monitored </li></ul></ul>
  18. 18. Firewall Types <ul><li>Packet filters </li></ul><ul><ul><li>Usually based on a filtering router, but stateful </li></ul></ul><ul><li>Proxy-based firewalls </li></ul><ul><ul><li>Services are provided by the visible firewall </li></ul></ul><ul><li>Packet-rewriting firewalls (NAT) </li></ul><ul><ul><li>Transparent to applications </li></ul></ul><ul><li>Screens </li></ul><ul><ul><li>No IP address; run in stealth mode </li></ul></ul>
  19. 19. How Network Address Translation (NAT) Works <ul><li>A server anonymises traffic by replacing the true address on the LAN with its own address and vice versa. </li></ul><ul><li>Incoming packets from inside addresses can be quietly dropped. </li></ul><ul><li>Aka “proxying with network address translation”. </li></ul><ul><li>Can also cache data received to save on network bandwidth </li></ul>
  20. 20. Personal Firewalls <ul><li>This is a router/firewall installed on your personal PC. </li></ul><ul><li>Usually a simple packet filter. </li></ul><ul><li>Now available for most modern operating systems. </li></ul><ul><li>MacOS X, BSD Unix, and Linux use ipfw. </li></ul><ul><li>Windows XP has a proprietary firewall. Mediocre. </li></ul><ul><li>Commercial firewalls either manage the firewall provided by the OS or replace it with their own. </li></ul><ul><li>Watch out for snake oil . </li></ul>
  21. 21. Personal Firewalls for Windows Machines <ul><li>Some Free Ones </li></ul><ul><ul><li>Microsoft Internet Connection Firewall (XP default) </li></ul></ul><ul><ul><li>ZoneAlarm (good, better than ipfw) </li></ul></ul><ul><ul><li>Tiny Firewall (good, USAF uses) </li></ul></ul><ul><ul><li>Sygate® Personal Firewall™ (good) </li></ul></ul><ul><li>More Expensive </li></ul><ul><ul><li>Black Ice Defender (well-regarded) </li></ul></ul><ul><ul><li>ZoneAlarm Pro (good) </li></ul></ul><ul><ul><li>Norton Personal Firewall (OK) </li></ul></ul><ul><ul><li>McAfee Personal Firewall (subscription) </li></ul></ul>
  22. 22. “ Demilitarized Zone” (DMZ) <ul><li>A place on your network where you put your public services. </li></ul><ul><li>Reduces the external threat, but protects your private network. </li></ul><ul><li>External firewall (to the internet) has a limited number of restrictions. </li></ul><ul><li>Internal firewall (to your private network) has more restrictions. </li></ul>
  23. 23. Running a Windows Firewall <ul><li>If you are responsible for a Windows firewall (incomplete): </li></ul><ul><ul><li>Enable auditing, accounting, and full logging. Monitor them. </li></ul></ul><ul><ul><li>Use strong authentication. Install a logon banner. </li></ul></ul><ul><ul><li>Rename the Administrator account. </li></ul></ul><ul><ul><li>No user or guest accounts. Generally, block all user access. </li></ul></ul><ul><ul><li>Manually configure the machine. Install all security patches. </li></ul></ul><ul><ul><li>Use NTFS. </li></ul></ul><ul><ul><li>Protect the bios configuration. </li></ul></ul><ul><ul><li>Block removable devices and unused ports. </li></ul></ul><ul><ul><li>Support only TCP/IP. You may need to enable SMNP. </li></ul></ul><ul><ul><li>Disable unneeded services, in particular WINS TCP/IP, Computer Browser, NetBIOS, RPC, Server, and Workstation. Check that patches/ hotfixes/updates don’t reenable them. </li></ul></ul>
  24. 24. Running a UNIX Firewall <ul><li>If you are responsible for a UNIX firewall: </li></ul><ul><ul><li>Enable auditing, accounting, and full logging. Monitor them. </li></ul></ul><ul><ul><li>Use strong authentication. </li></ul></ul><ul><ul><li>Firewall machines should not have user accounts. </li></ul></ul><ul><ul><li>Block X11 server ports. </li></ul></ul><ul><ul><li>Do not mount NFS (etc.). Export databases read-only. Disks should be mounted read-only where possible. </li></ul></ul><ul><ul><li>Remove binaries not needed for the firewall. Disable unneeded network services. </li></ul></ul><ul><ul><li>chmod all system directories to 711. </li></ul></ul><ul><ul><li>Remove /etc/hosts.equiv and /etc/hosts.lpd </li></ul></ul><ul><ul><li>Use process and disk quotas and monitor them. </li></ul></ul>
  25. 25. Conclusions <ul><li>You may need a firewall, but you will need a lot more and probably more urgently: </li></ul><ul><ul><li>Start by ensuring you have strong end-point security. Make sure you have the latest service pak installed. </li></ul></ul><ul><ul><li>Install/enable personal firewalls on all machines. </li></ul></ul><ul><ul><li>Use a filtering router as a minimum. </li></ul></ul><ul><ul><li>Finally consider using a firewall. </li></ul></ul><ul><li>Watch for snake oil! </li></ul><ul><li>Manage your security actively! </li></ul><ul><li>Good luck! </li></ul>