0% found this document useful (0 votes)
11 views29 pages

Module 5

The document discusses email security methods, focusing on Pretty Good Privacy (PGP) and Secure/Multipurpose Internet Mail Extension (S/MIME) for encrypting and signing emails. It highlights the importance of cyber security, the threats posed by intruders, and various techniques for intrusion detection and password management. Additionally, it emphasizes the need for strong passwords and two-factor authentication to protect sensitive information.

Uploaded by

salumolmr99
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views29 pages

Module 5

The document discusses email security methods, focusing on Pretty Good Privacy (PGP) and Secure/Multipurpose Internet Mail Extension (S/MIME) for encrypting and signing emails. It highlights the importance of cyber security, the threats posed by intruders, and various techniques for intrusion detection and password management. Additionally, it emphasizes the need for strong passwords and two-factor authentication to protect sensitive information.

Uploaded by

salumolmr99
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Module 5

Email security

Pretty Good Privacy

PGP stands for Pretty Good Privacy. It is an encryption program that uses
cryptographic privacy and authentication to online communications. PGP is most
generally used for maintaining contents of emails encrypted and private.
PGP needs a digital signature to support integrity, authentication, and
nonrepudiation. PGP uses a set of secret key encryption and public key encryption
to support privacy. Hence, it can say that the digital signature needs one hash
function, one secret key, and two private-public key [Link] can be used to sign
or encrypt e-mail messages with the simple click of the mouse. It is based upon the
version of PGP. The software needs SHA or MD5 for computing the message hash
such as CAST, Triple-DES, or IDEA for encryption and RSA or
DSS/Diffie-Hellman for key exchange and digital signatures.
In PGP, this message will not be maintain secret from an eavesdropper, but a
recipient can be guaranteed that the message has not been changed from what the
sender transmitted. In this example, the sender signs the message utilizing their
own private key. The receiver needs the sender’s public key to test the signature
and the public key is taken from the receiver’s keyring depends on the sender’s
e-mail address.

There are multiple reasons that PGP is widely used −

It is available free global in versions that run on some multiple platforms,


Windows, UNIX, Mac etc. Furthermore the commercial version satisfies those who
require vendor support.

It is based on algorithms that have keep broad public review and are considered
secure. Particularly, the package contains RSA, DSS and DiffieHellman for
public-key encryptions such as CAST-128, IDEA, and 3DES for symmetric
encryption and SHA-1 for hash coding.
It has a broad range of applicability, from corporations that need to select and
enforce a standardised scheme for encrypting documents and messages to
individuals who want to communicate securely with others worldwide over the
Internet.

It was not produced by, nor is it managed by, any government or standards
organisation. For those with an inherent distrust of “the establishment”, this creates
PGP attractive. In the last few years commercial versions have become applicable.

PGP is on an Internet standards track (RFC 3156). PGP has an aspect of an


antiestablishment endeavor.

S/MIME

Secure/Multipurpose Internet Mail Extension (S/MIME) is an industry-standard


for email encryption and signature that is commonly used by businesses to
improve email security. S/MIME is supported by the majority of corporate email
clients.
S/MIME encrypts and digitally signs emails to verify that they are verified and
that their contents have not been tampered with.
How Does S/MIME Address Email Security Problems?
An S/MIME certificate is an end-to-end encryption solution for MIME data, a.k.a.
email communications, as shown in the preceding sections. The use of asymmetric
cryptography by S/MIME certificates prevents the message's integrity from being
compromised by a third party. In basic English, a digital signature is used to hash
the message. The mail is then encrypted to protect the message's secrecy.
S/MIME employs public encryption to protect communications that can only be
decoded with the corresponding private key obtained by the authorized mail
receiver, according to GlobalSign, a company that provides specialized Public
Key Infrastructure (PKI) solutions to businesses.
Stepping back in time allows us to visualize the situation. Wax seals on letters
served as a unique identifying proof of the sender while also assisting the recipient
in determining whether the letters had been tampered with. S/MIME certificates
work on a similar principle.
The sender can use a private key to digitally sign the letter he is sending. The
email is then accompanied by a public key while in transit. The recipient will use
it to verify the sender's digital signature and decode the message using his own
private key. Using 'asymmetric cryptography,' this system uses two separate but
mathematically comparable cryptographic keys to provide end-to-end encryption.
The completely encrypted contents of the email will be nearly hard to crack
without both keys.
S/MIME Certificate Characteristics
You receive a slew of cryptographic security features when you use an S/MIME
certificate for email apps.
● Authentication − It refers to the verification of a computer user's or a
website's identity.
● Message consistency − This is a guarantee that the message's contents
and data have not been tampered with. The message's secrecy is
crucial. The decryption procedure entails checking the message's
original contents and guaranteeing that they have not been altered.
● Use of digital signatures that invoke non-repudiation − This is a
circumstance in which the original sender's identity and digital
signatures are validated so that there is no doubt about it.
● Protection of personal information − A data breach cannot be caused
by an unintentional third party.
● Encryption is used to protect data − It relates to the procedures
described above, in which data security is ensured by a mix of public
and private keys representing asymmetric cryptography.

The MIME type is designated by a S/MIME certificate. The enclosed data is


referred to by the MIME type. The MIME entity is completely prepared,
encrypted, and packaged inside a digital envelope.
Some of the most popular email programs that support S/MIME are listed below.
● iPhone iOS Mail
● Apple Mail
● Gmail IBM Notes
● Mozilla Thunderbird MailMate Microsoft Outlook or Outlook on the Web
● CipherMail

What is the Best Way to Send Encrypted Emails?


Secure email service providers are used by certain companies and individuals to
send secure emails. These services, such as ProtonMail, may allow you to send
and receive private messages for free, but the disadvantage is that both the sender
and the recipient must have the same account. This is a common disadvantage of
endto-end encryption services.
Aside from this issue, there is a far more serious one that limits the usability of
email services for businesses. These ostensibly safe email service companies are
nonetheless vulnerable to cyber-attacks. VFEMail is a classic example of a secure
email service provider that, after 20 years of operation, fell to a cyber-attack.
A method is to use a S/MIME certificate to digitally sign and send encrypted
emails. This technology is classified as secure public-key encryption by the
Internet Engineering Task Force (IETF), and it is also suggested by the National
Institute of Standards and Technology (NIST) as a "protocol for email end-to-end
authentication and secrecy".
Intruders

Cyber Security is the branch of technology that deals with the security of using the
internet. Technology is an essential part of today’s generation, it is hard to imagine
our lives without technology. Thus, it is very essential that the technology we use
in our daily lives is extremely secure and safe. Cyber technology is the branch of
technology, that takes care of this need.

Importance of Cyber Security:


● Protecting Identity: Cyber security ensures that individuals’ identity is
protected and authenticity is maintained while using technology.
● Maintaining Privacy: Cyber security caters to the requirement of
information or content that is confidential is extremely secure. Users can
trust the technology for use.
● Securing Confidential Content: Sensitive information is the most
vulnerable to security threats. Attack on sensitive information such as
bank information is most common and done for monetary frauds.

The most common threat to security is the attack by the intruder. Intruders are
often referred to as hackers and are the most harmful factors contributing to the
vulnerability of security. They have immense knowledge and an in-depth
understanding of technology and security. Intruders breach the privacy of users and
aim at stealing the confidential information of the users. The stolen information is
then sold to third-party, which aim at misusing the information for their own
personal or professional gains.

Intruders are divided into three categories:


● Masquerader: The category of individuals that are not authorized to use
the system but still exploit user’s privacy and confidential information by
possessing techniques that give them control over the system, such
category of intruders is referred to as Masquerader. Masqueraders are
outsiders and hence they don’t have direct access to the system, their aim
is to attack unethically to steal data/ information.
● Misfeasor: The category of individuals that are authorized to use the
system, but misuse the granted access and privilege. These are
individuals that take undue advantage of the permissions and access
given to them, such category of intruders is referred to as Misfeasor.
Misfeasors are insiders and they have direct access to the system, which
they aim to attack unethically for stealing data/ information.
● Clandestine User: The category of individuals those have
supervision/administrative control over the system and misuse the
authoritative power given to them. The misconduct of power is often
done by superlative authorities for financial gains, such a category of
intruders is referred to as Clandestine User. A Clandestine User can be
any of the two, insiders or outsiders, and accordingly, they can have
direct/ indirect access to the system, which they aim to attack unethically
by stealing data/ information.

different ways adopted by intruders for cracking passwords for stealing


confidential information:

● Regressively try all short passwords that may open the system for them.
● Try unlocking the system with default passwords, which will open the
system if the user has not made any change to the default password.
● Try unlocking the system by personal information of the user such as
their name, family member names, address, phone number in different
combinations.
● Making use of Trojan horse for getting access to the system of the user.
● Attacking the connection of the host and remote user and getting entry
through their connection gateway.
● Trying all the applicable information, relevant to the user such as plate
numbers, room numbers, locality info.

Intrusion Detection

Any illicit behavior on a digital network is known as a network intrusion. Network


incursions frequently include the theft of important network resources, which
virtually always compromise the network and/or data security. This can take the
shape of more dangerous and pervasive threats like ransomware or unintended
data leaks by workers or others on your network.
An illegal entrance into your network or an address in your assigned domain is
referred to as a network intrusion. An intrusion can be passive (in which access is
achieved quietly and undetected) or aggressive (in which access is gained overtly
and without detection) (in which changes to network resources are effected).
Intrusions might occur from the outside or from within your network structure (an
employee, customer, or business partner). Some intrusions are just aimed to alert
you that an intruder has entered your site and is defacing it with various messages
or obscene graphics. Others are more malevolent, attempting to harvest sensitive
data on a one-time basis or as part of a long-term parasitic connection that will
continue to siphon data until it is identified.
Some intruders will try to implant code that has been carefully developed. Others
will infiltrate the network, stealthily siphoning out data on a regular basis or
altering public-facing Web sites with varied messages.
An attacker can acquire physical access to your system (by physically accessing a
restricted computer and its hard drive and/or BIOS), externally (by assaulting your
Web servers or breaching your firewall), or internally (by physically accessing a
restricted machine and its hard disc and/or BIOS) (your own users, customers, or
partners).
Any of the following can be considered an intrusion −
● Malware, sometimes known as ransomware, is a type of computer
virus.
● Attempts to obtain unauthorized access to a system
● DDOS (Distributed Denial of Service) attacks
● Destruction of cyber-enabled equipment
● Employee security breaches that are unintentional (like moving a
secure file into a shared folder)
● Untrustworthy users, both within and external to your company
● Phishing campaigns and other methods of deceiving consumers with
ostensibly genuine communication are examples of social engineering
assaults.
Network Intrusion Attack Techniques
When it comes to compromising networks, attackers are increasingly relying on
existing tools and procedures as well as stolen credentials. Operating system
utilities, commercial productivity software, and scripting languages, for example,
are clearly not malware and have a wide range of lawful applications.
● Asymmetric Routing − Attackers will typically employ several routes
to gain access to the targeted device or network if the network allows
for asymmetric routing.
● Buffer Overwriting − Attackers can substitute regular data in specified
parts of computer memory on a network device with a barrage of
commands that can subsequently be utilized as a part of a network
incursion by overwriting certain memory locations.
● Covert CGI Scripts − The Common Gateway Interface (CGI), which
allows servers to relay user requests to appropriate programs and get
data back to then forward to users, unfortunately, provides an easy
mechanism for attackers to gain access to network system files.
● Enormous traffic loads − Attackers can cause chaos and congestion in
network settings by producing traffic loads that are too enormous for
systems to fully filter, allowing them to carry out assaults without being
discovered.
● Worms − The typical, isolated computer virus, or worm, is one of the easiest
and most dangerous network penetration tools. Worms, which are commonly
distributed by email attachments or instant messaging, use a considerable
amount of network resources, preventing permitted activities from taking
place.

How Does Intrusion Detection Work?


An intrusion detection system (IDS) is a monitor-only program that detects and
reports irregularities in your network architecture before hackers may do damage.
IDS can be set up on your network or on a client system (host-based IDS).
Intrusion detection systems often seek known attack signatures or aberrant
departures from predetermined standards. These anomalous network traffic
patterns are then transmitted up the stack to the OSI (Open Systems
Interconnection) model's protocol and application layers for further investigation.
An IDS is a detection system that is positioned outside of the real-time
communication band (a channel between the information transmitter and receiver)
within your network infrastructure. Instead, it uses a SPAN or TAP port to watch
the network and examines a copy of inline network packets (acquired through port
mirroring) to ensure that the streaming traffic is not fraudulent or faked in any
manner.
The IDS can readily identify malformed information packets, DNS poisonings,
Xmas scans, and other polluted materials, which can have a severe impact on your
overall network performance.
Intrusion detection systems employ two detection methods −
● Signature-based detection matches data activity to a signature or
pattern in a signatures database. A new harmful behavior that is not in
the database, for example, is overlooked when using signature-based
detection.
● Unlike signature-based detection, behavior-based detection recognizes
any abnormality and issues alarms, making it capable of identifying
new sorts of threats. It's referred to as an expert system since it learns
what regular behavior looks like in your system.

Password Management

With most of our lives is spent in front of screens nowadays, safety is a significant
concern, and passwords are the first line of defense for any login, be it your phone
screen, your social media account, or even your bank account. Even though we are
very aware that our passwords must be foolproof most of us don't take it as
seriously. Hackers are looking for a way to access your accounts, be it to steal
money or data; they are always on the run to do so. Here we will be discussing how
you can secure all your passwords.
How to Secure Your Passwords?

You can use the following methods to secure your passwords −

Use strong passwords


Many internet accounts are hacked and hijacked due to users using simple
passwords that are easy to remember or guess, making it easy for others to gain
access. Using strong passwords to safeguard your account is one approach to
avoid being worried about getting hacked. Using a password consisting of letters,
numbers, and special characters in your password is one approach to make it more
secure.
Making long passwords is another option. Longer passwords, while usually the
bare minimum, provide additional security.
Two-factor authentication
Everyone should utilize two-step authentication for their online accounts
whenever possible. This is an option that most banks and major social media
platforms provide. As the name implies, two-step authentication entails entering
your password and entering a number only you have access to. The number might
be reaching you through your registered email id or phone number.
Take advantage of biometrics if it is available
A fingerprint instead of a password is becoming more common on smartphones,
tablets, and laptops. This not only makes your password more secure but also
keeps you from forgetting it.
Use multiple passwords and update them regularly
Try to create a habit of using different passwords for each site or account. It's not
advisable since if hackers obtain a password from one site, they'll attempt it on all
of your other sites.
Using the same password for work and personal accounts is never a good idea. If
there is a breach, the invaders will have no trouble accessing all of your accounts.
Also, remember to change your passwords regularly.
Keep your password to yourself
You may be intimidated to share your passwords with others, your family, or
friends, do not share your passwords with anybody, be it your social media
account or your bank account; always make sure not to give away such sensitive
data.
Use a password manager
Password managers keep track of the many usernames and passwords you use on
different websites, increasing security and saving you time by automatically filling
in username/password boxes. They'll also sync your passwords across all of your
devices, so you won't be stumped if you log on to a site on your phone but register
on your desktop.
Update your software regularly
By allowing and auditing Automatic Updates, you can always guarantee that
you're running the most recent software versions. Older versions may not support
high encryption levels and may have other security vulnerabilities for remote
access.

Firewalls

Firewall is a barrier between Local Area Network (LAN) and the Internet. It allows
keeping private resources confidential and minimizes the security risks. It controls
network traffic, in both directions.
The following diagram depicts a sample firewall between LAN and the internet.
The connection between the two is the point of vulnerability. Both hardware and
the software can be used at this point to filter network traffic.
There are two types of Firewall system: One works by using filters at the
network layer and the other works by using proxy servers at the user,
application, or network layer.

Key Points
● Firewall management must be addressed by both system managers and
the network managers.
● The amount of filtering a firewall varies. For the same firewall, the
amount of filtering may be different in different directions.
What is a Firewall?
A firewall is a hardware or software device that can be set up to restrict data from
specific sites, programs, or ports while allowing relevant and necessary data to
come through.
Firewalls block unauthorized access to or from networks with varying levels of
trust. They prevent hostile actors from accessing private networks connected to
the Internet by implementing security policies. A firewall can be set up using
hardware, software, or a mix of the two.
Zero Trust policies can be used in conjunction with perimeter firewalls to ensure
that network access is allowed appropriately and securely at every access layer of
the OSI Model. Firewalls are sometimes dismissed as antiquated because they are
created to secure a network's perimeter, but in truth, they are critical components
of Zero Trust Architectures (ZTAs).

How does a firewall work?


A firewall is a network security solution that establishes a barrier between an
external network and the network it is protecting. It's installed in the middle of a
network connection and inspects all packets entering and exiting the protected
network. As it examines packets, it uses a set of pre- configured criteria to
distinguish between benign and malicious ones.
Data prepared for transmission over the Internet is called 'packets.' Data and
metadata about the data, such as where it originated, are contained in packets.
Firewalls can use this packet information to determine whether a given packet
complies with the ruleset. If it doesn't, the packet will be denied access to the
protected network.
Packet data can generate rule sets depending on various factors, such as the
source, destination, and content.
At different network layers, these features may be expressed in different ways. A
packet is reformatted numerous times as it travels through the network to notify
the protocol where to deliver it. Various types of firewalls can read packets at
different network levels.
What is the purpose of a firewall?
A firewall serves as a barrier between two networks. It detects and inhibits
attempts to obtain access to your operating system, as well as unwanted traffic
from unidentified sources.
How does it accomplish this? A firewall works as a barrier or filter between your
computer and another network, such as the Internet. A firewall can be compared
to a traffic controller. It manages network traffic to help safeguard your network
and information. This involves blocking unsolicited incoming network traffic and
authenticating access by scanning network traffic for unwanted content such as
hackers and viruses.
A firewall is usually preinstalled with your operating system and security
applications. It's a good idea to check if those options are enabled. Also,
double-check your security settings to ensure they're set to install updates
automatically.

Why do you need a firewall?


Now that you've learned what a firewall is, it should be obvious why you should
have one installed and operational. But, just in case you're still not convinced, here
are a few more reasons why you should use a firewall.
Prevent Unauthorized Remote Access with a Firewall
Someone attempting to take control of your computer remotely is one of the worst
things that might happen to it. You don't want a remote intruder to seize control of
your data and usurp your digital kingdom.
Remote desktop access should be disabled with a properly configured firewall
(and a current operating system). This will prevent hackers from gaining
unnoticed access to your machine.
However, this does not prevent the Windows tech support scammers from using
remote control tools. These are browser-based scams that rely on you being duped
into giving permission. You'll continue to be vulnerable to this danger because
your browser already has permission to send data past the firewall. Maintain your
vigilance!
Malware (Trojans, keyloggers, backdoors) is frequently preinstalled in illegal
copies of Windows found on BitTorrent networks. You're likely to encounter
security difficulties if you're operating one of these, even if you have a firewall
setup.
Firewalls Can protect old PCs temporarily.
Even though Windows XP and Windows 7 were released in 2001 and 2009,
respectively, people still use them. Worse, some of them are functioning without a
firewall. Yes, you read that correctly. There is a lot of malicious code roaming the
Internet, waiting to pounce on vulnerable computers. While your ISP can prevent
this, its ability to intervene is restricted.
So, if you're a Windows 7 user (14 percent of computers as of June 2019), do
yourself a favor and upgrade. To be safe, use a third-party firewall. After that, you
can begin the upgrade procedure. If possible, upgrade to Windows 10 or even
Linux.
Alternatively, you may get a new computer capable of running a modern, safe
operating system because you're an easy, live target for hackers right now.
To keep your online gaming safe, use a firewall.
Online gaming is one of the most popular activities on the Internet, but it also
poses a security risk. Various malware has been developed to target internet
gamers that use game servers that are either insecure or have recently been
compromised.
While most game publishers maintain their servers secure, a firewall is a good
idea. Any efforts by hackers to get access to your system via malware will be
denied, leaving your system safe.
The firewall will set things up according to the game's requirements, using
metadata information in most circumstances. It's worth noting that many security
suites come preinstalled with "Gaming Mode" or a similar feature. Before starting
your favorite game, use this to optimize your computer and get the best
performance possible. If you run into any issues, go to the game's support site and
change the firewall application settings.
If you need to change some settings on your console, you can use hardware
firewalls or routers.
To keep your online gaming safe, use a firewall.
Online gaming is one of the most popular activities on the Internet, but it also
poses a security risk. Various malware has been developed to target internet
gamers that use game servers that are either insecure or have recently been
compromised.
While most game publishers maintain their servers secure, a firewall is a good
idea. Any efforts by hackers to get access to your system via malware will be
denied, leaving your system safe.
The firewall will set things up according to the game's requirements, using
metadata information in most circumstances. It's worth noting that many security
suites come preinstalled with "Gaming Mode" or a similar feature. Before starting
your favorite game, use this to optimize your computer and get the best
performance possible. If you run into any issues, go to the game's support site and
change the firewall application settings.
If you need to change some settings on your console, you can use hardware
firewalls or routers.

Hardware or software firewalls are available.


Firewalls do not have to be software, as previously stated. Most homes have
hardware firewalls incorporated into their routers.
To access these firewall settings, you'll need the router's administrator credentials
(make sure you've changed the default password). You should be able to review
your options and make any necessary adjustments after you've signed in. You'll
need to make some adjustments from time to time, especially if you're playing
online with a games console. For example, on PlayStation 3 and PlayStation 4,
changing the NAT type is a typical cure for online gaming connectivity troubles.
Before saving any changes, double-check the documentation for your router to
acquaint yourself with the settings.
With that in mind, it's essential to think about what a firewall can't do. We've
already described malware, including Trojans, viruses, worms, and other threats.
While a firewall should prevent backdoor access with a Trojan, it's possible that
this can be circumvented.
Worse, firewalls are powerless to stop viruses, worms, keyloggers, and other
forms of malware. As a result, a firewall must be used in tandem with an antivirus
program. The antiviral market is becoming increasingly tough to navigate these
days. You'll need a list of the top security and antivirus software.

A firewall is a network security device; it is a protective layer for the server that
monitors and filters all the incoming and outgoing network traffic. It uses a set of
rules to determine whether to allow or block a specific network traffic. Firewalls
can prevent unauthorized use before reaching the servers. Firewalls can be
hardware or software-based.
Types of Firewall
● Packet Filters (Stateless Firewall) − In the packet filters, if a packet
matches then the packet filters set of rules and filters will drop or
accept it.
● Stateful firewall filters − It is also known as a network firewall; this
filter maintains a record of all the connections passing through. It can
determine if a packet is either the start of a new connection or a part of
an existing connection or is an invalid packet.
● Application firewall − A web application firewall is used for HTTP
applications. There are sets of rules that are applied to monitor or
block data packets from HTTP network traffic. For example, these
rules can help block cross-site scripting (XSS) and SQL injections.

Packet Filter Firewall


A packet filter firewall can forward or block packets based on the information in
the network layer and transport layer headers source and destination IP addresses,
source, and destination port address, and type of protocol (TCP and UDP).
A packet filter firewall is a router that uses a filtering table to decide which packet
must be discarded or not to forward. It filters at the network or transport layer.
Proxy Based Firewall
A proxy-based firewall acts as an intermediary between the requested data by the
end-users and the source servers. The proxy filters all the network traffic and will
block or allow the traffic based on its rules and policies.
The proxy can also examine the entire network packet besides the network address
and the port number. This type of firewall is labeled as the most secured, as it
prevents direct network contact between the systems.

Network Security – Firewalls

Almost every medium and large-scale organization has a presence on the Internet
and has an organizational network connected to it. Network partitioning at the
boundary between the outside Internet and the internal network is essential for
network security. Sometimes the inside network (intranet) is referred to as the
“trusted” side and the external Internet as the “un-trusted” side.
Types of Firewall
Firewall is a network device that isolates organization’s internal network from
larger outside network/Internet. It can be a hardware, software, or combined
system that prevents unauthorized access to or from internal network.
All data packets entering or leaving the internal network pass through the firewall,
which examines each packet and blocks those that do not meet the specified
security criteria.

Deploying firewall at network boundary is like aggregating the security at a single


point. It is analogous to locking an apartment at the entrance and not necessarily at
each door.
Firewall is considered as an essential element to achieve network security for the
following reasons −
● Internal network and hosts are unlikely to be properly secured.
● Internet is a dangerous place with criminals, users from competing
companies, disgruntled ex-employees, spies from unfriendly countries,
vandals, etc.
● To prevent an attacker from launching denial of service attacks on
network resource.
● To prevent illegal modification/access to internal data by an outsider
attacker.
Firewall is categorized into three basic types −
● Packet filter (Stateless & Stateful)
● Application-level gateway
● Circuit-level gateway

These three categories, however, are not mutually exclusive. Modern firewalls
have a mix of abilities that may place them in more than one of the three
categories.

Stateless & Stateful Packet Filtering Firewall


In this type of firewall deployment, the internal network is connected to the
external network/Internet via a router firewall. The firewall inspects and filters data
packet-by-packet.
Packet-filtering firewalls allow or block the packets mostly based on criteria such
as source and/or destination IP addresses, protocol, source and/or destination port
numbers, and various other parameters within the IP header.
The decision can be based on factors other than IP header fields such as ICMP
message type, TCP SYN and ACK bits, etc.
Packet filter rule has two parts −
● Selection criteria − It is a used as a condition and pattern matching for
decision making.
● Action field − This part specifies action to be taken if an IP packet
meets the selection criteria. The action could be either block (deny) or
permit (allow) the packet across the firewall.

Packet filtering is generally accomplished by configuring Access Control Lists


(ACL) on routers or switches. ACL is a table of packet filter rules.
As traffic enters or exits an interface, firewall applies ACLs from top to bottom to
each incoming packet, finds matching criteria and either permits or denies the
individual packets.

Stateless firewall is a kind of a rigid tool. It looks at packet and allows it if its
meets the criteria even if it is not part of any established ongoing communication.
Hence, such firewalls are replaced by stateful firewalls in modern networks. This
type of firewalls offer a more in-depth inspection method over the only ACL based
packet inspection methods of stateless firewalls.
Stateful firewall monitors the connection setup and teardown process to keep a
check on connections at the TCP/IP level. This allows them to keep track of
connections state and determine which hosts have open, authorized connections at
any given point in time.
They reference the rule base only when a new connection is requested. Packets
belonging to existing connections are compared to the firewall's state table of open
connections, and decision to allow or block is taken. This process saves time and
provides added security as well. No packet is allowed to trespass the firewall
unless it belongs to already established connection. It can timeout inactive
connections at firewall after which it no longer admit packets for that connection.

Application Gateways
An application-level gateway acts as a relay node for the application-level traffic.
They intercept incoming and outgoing packets, run proxies that copy and forward
information across the gateway, and function as a proxy server, preventing any
direct connection between a trusted server or client and an untrusted host.
The proxies are application specific. They can filter packets at the application layer
of the OSI model.
Application-specific Proxies
An application-specific proxy accepts packets generated by only specified
application for which they are designed to copy, forward, and filter. For example,
only a Telnet proxy can copy, forward, and filter Telnet traffic.
If a network relies only on an application-level gateway, incoming and outgoing
packets cannot access services that have no proxies configured. For example, if a
gateway runs FTP and Telnet proxies, only packets generated by these services can
pass through the firewall. All other services are blocked.
Application-level Filtering
An application-level proxy gateway, examines and filters individual packets, rather
than simply copying them and blindly forwarding them across the gateway.
Application-specific proxies check each packet that passes through the gateway,
verifying the contents of the packet up through the application layer. These proxies
can filter particular kinds of commands or information in the application protocols.
Application gateways can restrict specific actions from being performed. For
example, the gateway could be configured to prevent users from performing the
‘FTP put’ command. This can prevent modification of the information stored on
the server by an attacker.
Transparent
Although application-level gateways can be transparent, many implementations
require user authentication before users can access an untrusted network, a process
that reduces true transparency. Authentication may be different if the user is from
the internal network or from the Internet. For an internal network, a simple list of
IP addresses can be allowed to connect to external applications. But from the
Internet side a strong authentication should be implemented.
An application gateway actually relays TCP segments between the two TCP
connections in the two directions (Client ↔ Proxy ↔ Server).
For outbound packets, the gateway may replace the source IP address by its own IP
address. The process is referred to as Network Address Translation (NAT). It
ensures that internal IP addresses are not exposed to the Internet.

Circuit-Level Gateway
The circuit-level gateway is an intermediate solution between the packet filter and
the application gateway. It runs at the transport layer and hence can act as proxy for
any application.
Similar to an application gateway, the circuit-level gateway also does not permit an
end-to-end TCP connection across the gateway. It sets up two TCP connections
and relays the TCP segments from one network to the other. But, it does not
examine the application data like application gateway. Hence, sometime it is called
as ‘Pipe Proxy’.
SOCKS
SOCKS (RFC 1928) refers to a circuit-level gateway. It is a networking proxy
mechanism that enables hosts on one side of a SOCKS server to gain full access to
hosts on the other side without requiring direct IP reachability. The client connects
to the SOCKS server at the firewall. Then the client enters a negotiation for the
authentication method to be used, and authenticates with the chosen method.
The client sends a connection relay request to the SOCKS server, containing the
desired destination IP address and transport port. The server accepts the request
after checking that the client meets the basic filtering criteria. Then, on behalf of
the client, the gateway opens a connection to the requested untrusted host and then
closely monitors the TCP handshaking that follows.
The SOCKS server informs the client, and in case of success, starts relaying the
data between the two connections. Circuit level gateways are used when the
organization trusts the internal users, and does not want to inspect the contents or
application data sent on the Internet.

Firewall Deployment with DMZ


A firewall is a mechanism used to control network traffic ‘into’ and ‘out’ of an
organizational internal network. In most cases these systems have two network
interfaces, one for the external network such as the Internet and the other for the
internal side.
The firewall process can tightly control what is allowed to traverse from one side
to the other. An organization that wishes to provide external access to its web
server can restrict all traffic arriving at firewall expect for port 80 (the standard http
port). All other traffic such as mail traffic, FTP, SNMP, etc., is not allowed across
the firewall into the internal network. An example of a simple firewall is shown in
the following diagram.

In the above simple deployment, though all other accesses from outside are
blocked, it is possible for an attacker to contact not only a web server but any other
host on internal network that has left port 80 open by accident or otherwise.
Hence, the problem most organizations face is how to enable legitimate access to
public services such as web, FTP, and e-mail while maintaining tight security of
the internal network. The typical approach is deploying firewalls to provide a
Demilitarized Zone (DMZ) in the network.
In this setup (illustrated in following diagram), two firewalls are deployed; one
between the external network and the DMZ, and another between the DMZ and the
internal network. All public servers are placed in the DMZ.
With this setup, it is possible to have firewall rules which allow public access to
the public servers but the interior firewall can restrict all incoming connections. By
having the DMZ, the public servers are provided with adequate protection instead
of placing them directly on external network.
The packet filtering firewalls operate based on rules involving TCP/UDP/IP
headers only. They do not attempt to establish correlation checks among different
sessions.
Intrusion Detection/Prevention System (IDS/IPS) carry out Deep Packet Inspection
(DPI) by looking at the packet contents. For example, checking character strings in
packet against database of known virus, attack strings.
Application gateways do look at the packet contents but only for specific
applications. They do not look for suspicious data in the packet. IDS/IPS looks for
suspicious data contained in packets and tries to examine correlation among
multiple packets to identify any attacks such as port scanning, network mapping,
and denial of service and so on.
Difference between IDS and IPS
IDS and IPS are similar in detection of anomalies in the network. IDS is a
‘visibility’ tool whereas IPS is considered as a ‘control’ tool.
Intrusion Detection Systems sit off to the side of the network, monitoring traffic at
many different points, and provide visibility into the security state of the network.
In case of reporting of anomaly by IDS, the corrective actions are initiated by the
network administrator or other device on the network.
Intrusion Prevention System are like firewall and they sit in-line between two
networks and control the traffic going through them. It enforces a specified policy
on detection of anomaly in the network traffic. Generally, it drops all packets and
blocks the entire network traffic on noticing an anomaly till such time an anomaly
is addressed by the administrator.

You might also like