0% found this document useful (0 votes)
13 views28 pages

Network Security Fundamentals Explained

The document provides an overview of network security basics including: - Defining network security and its goals of confidentiality, integrity, and availability. - Describing the different domains of network security such as computer security, network security, application security, data security, physical security, and personnel security. - Explaining some fundamental security principles like authentication, authorization, non-repudiation, and the concepts of a secure object and security prevention, detection, and incident response. - Defining the key network security principles of confidentiality, integrity, and availability and the techniques used to achieve each one.

Uploaded by

tony09110
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views28 pages

Network Security Fundamentals Explained

The document provides an overview of network security basics including: - Defining network security and its goals of confidentiality, integrity, and availability. - Describing the different domains of network security such as computer security, network security, application security, data security, physical security, and personnel security. - Explaining some fundamental security principles like authentication, authorization, non-repudiation, and the concepts of a secure object and security prevention, detection, and incident response. - Defining the key network security principles of confidentiality, integrity, and availability and the techniques used to achieve each one.

Uploaded by

tony09110
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter 1: Network Security Basis

[Link]
Embrace Cyber Resilience

© 2022 Hillstone Networks | All rights reserved.


1
Hillstone Network Corporation
• A senior entrepreneurial team formed in 2007 by former Netscreen
technical experts, with 360+ granted patents and pending patent
applications.

• Hillstone has experienced rapid development. Hillstone has more


than 26,000+ customers in over 60 countries, covering various
industries such as finance, telecommunications, education, and
government.

• It leads research and development with over 2,000 employees


worldwide and three major R&D centers (Silicon Valley, Beijing,
and Suzhou). The proportion of research and development
personnel is over 35%.

2 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


About Hillstone
Become a first-class guardian of the digital world!

• In 2016, we received the NSS Labs "Next-Generation Firewall Recommended Level" honor.
• For nine consecutive years, we have been selected in the Gartner Network Firewall Magic Quadrant, and for two consecutive years, we
have entered the "Visionaries Quadrant.“
• For three consecutive years, we have been selected in Gartner's "IDPS Magic Quadrant" and Market Guide.
• Hillstone Cloud Hive was selected in the Gartner Cloud Workload Protection Platforms (CWPP) Global Market Guide.
• For four consecutive years, we have been awarded the Gartner Network Firewall "Customers' Choice" title (one of only two globally).
• For five consecutive years, we have been recognized as an outstanding security vendor through testing by ICSA Labs.
• In 2023, Hillstone was included in Gartner's "Voice of the Customer" NDR report, becoming one of Gartner's global Top 10 popular
NDR vendors.

3 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


For nine consecutive years, Hillstone have been
selected in the Gartner Network Firewall Magic
Quadrant
• Hillstone Networks has been selected in the report for the ninth consecutive year and has also
entered the "Visionaries Quadrant" for the following two consecutive year. We believe this
signifies that Hillstone Networks has made significant contributions to the world stage of
network security.
• Since the establishment of Hillstone in 2007, Hillstone Networks has been deeply involved in
the field of firewalls. Hillstone firewalls are widely applicable in various network application
scenarios such as enterprise networks, Internet gateways, VPN access, and public/private
clouds.
• In recent years, Hillstone Networks has continued the self-developed hardware innovation
strategy and introduced intelligent next-generation firewalls equipped with the Hillstone Mars
hardware acceleration engine, providing users with an ultimate security protection experience.

4 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


Hillstone was Selected in the Gartner IDPS (Intrusion
Detection and Prevention Systems) Market Guide.

• Gartner stated that Hillstone Networks


achieve the detection of malicious activities
to identify APT (Advanced Persistent Threat)
attacks based on the threat behavior
analytics and utilizing a library of thousands
of malicious software samples.
• And also, the integration of threat detection
and cloud sandbox allows effective response
to the growing number of APT attacks and
timely discovery of unknown threats. This
approach provides customers with
comprehensive threat detection and defense
capabilities against both known and
unknown attacks.

5 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


Network Security Basic Principles

Definition of Firewall
Agenda
Development of Firewall Detection Technology

Hillstone Security Products

6 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


1 Network Security Basic Principles

7 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


Network Security Basic Principles
• What is network security?
Ø Network security refers to the technologies, processes, and measures used to protect information and systems from
unauthorized access, disruption, theft, alteration, or destruction of computer networks. It aims to safeguard networks'
confidentiality, integrity, and availability while ensuring the connectivity of computer systems and networks. Network
security aims to prevent unauthorized access and attacks while providing secure access to data, applications, and other
resources. It encompasses various domains, including computer security, communication security, physical security, and
personnel security.
• Network security includes:
Ø Computer Security: Computer security focuses on using technical means to protect the security of computer systems. This
includes measures against viruses, trojans, and hacker attacks.
Ø Network Security: Network security aims to protect the security of computer networks through technical means and
security management measures. This includes securing network devices, network access controls, network traffic analysis,
etc.
Ø Application Security: Application security focuses on using technical means and security management measures to protect
the security of applications. This includes vulnerability scanning of applications, application access controls, etc.
Ø Data Security: Data security involves using technical means and security management measures to protect data security.
This includes data encryption, data backup, and recovery, data access controls, etc.
Ø Physical Security: Physical security involves using security management measures to protect the physical facilities of
computer systems and networks. This includes facility access controls, fire and theft prevention measures, etc.
Ø Personnel Security: Personnel security involves using security management measures to protect the security of
individuals. This includes employee security awareness training, employee background checks, personnel access controls,
etc.

8 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


Concept Distinction

Cybersecurity

Information security

network security

data security

9 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


Fundamental Security Principles
• Basic Principles: (CIA)
• Confidentiality Availability
• Integrity
• Availability
• Authentication
• Authorization
• Non-Repudiation Secure
• Security Object
• Prevention
• Detection
• Incident Response

Integrity Confidentiality

10 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


Network Security Basic Principles

• Confidentiality:
Ø Concept:
• Confidentiality refers to protecting data from unauthorized access.
Ø Protective measures:
• Confidentiality is achieved through techniques such as encryption and access control.
Ø Network security systems need to have confidentiality to protect sensitive information from theft and misuse.
• Integrity:
Ø Concept:
• Integrity ensures that data is not tampered, altered, or destroyed.
Ø Protective measures:
• Integrity is achieved through techniques such as digital signatures, data backups, and access control.
Ø Network security systems need to have integrity to ensure the accuracy and trustworthiness of data.

11 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


Network Security Basic Principles

• Availability:
Ø Concept:
• Availability refers to ensuring that systems and data are accessible and protected from
accidental or malicious interference.
Ø Protective measures:
• Availability is achieved through techniques such as backups, redundancy, fault tolerance, and
recovery.
Ø Network security systems need to have availability to ensure the availability of systems and data.
• CIA Priority Levels:
Ø Different information systems have different priorities for ensuring confidentiality, integrity, and
availability (CIA).
Ø For example, for sensitive data storage, confidentiality takes precedence.
Ø For industrial control systems on production lines, availability takes precedence.

12 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


The Root of security Problems

Trojans Virus and Worms


Hacker’s
Attacking External Threats
Malware/Logic Bomb
Internal Threats
Threats from internal individuals

Denial of service attack


(DoS)
System Network, Information system Vulnerabilities
vulnerabilities
Vulnerabilities Social Engineering Attack
Hardware
Failure

Network Communication Failure Thunderstorm Earthquake


On fire
Vulnerabilities Interruption of Natural Factors
power supply
13 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.
2
Definition of Firewall

14 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


Definition of Firewall

• Gartner defines a network firewall as an online control that enforces network security policies
in real-time between networks of different trust levels.

Internet
Internal External
Network Network

15 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


Development of Firewall Detection
3
Technology

16 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


Evolutionary History of Firewall
Application Layer Stage3 – NGFW
q Identify application via app signature
and app behavior
q Able to control the encrypted apps
q Role based user identification

Stage2
Session

–Stateful Inspection
Layer

q IP connection based
q Use ALG to track protocol stack, no
way to handle encrypted or HTTP
based application

Stage1
–Packet Filtering
Network
Layer

q Simple ACL

Before 1995 1996-2007 After 2008

17 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


Packet Filter Firewall
• Features of Packet Filter FW:
• Only check packet header:IP address and port
• Detected object is single packet, data connection requires bidirectional all permit policy, not able to correlate the
packets relation
• Filter packets via ACL

Only check packet header

IP TCP APP

Internet

18 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


State Inspection Technology

Source address [Link]

• Features of State Inspection FW: Destination address [Link]


1026
Source port
• Introduce “session” technology, Destination port 23
session connection is the detected 49091
Initial sequence number
object.
Ack
• Session is identified via 5 Flag SYN [Link]
tuple(source/destination IP and port, IP 1 [Link]
protocol number) 23 2
• Session maintains bidirectional traffic, 1026
one-way policy can control the access PC
3
32513
• For example:TCP [Link] [Link]
49092
[Link] Telnet
SYN+ACK
[Link]
1026

23

49092

32514

ACK

19 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


Next Generation FW

• DPI technology into application layer detection User、APP、Content


• Content identification
• User authentication
• IP 5 tuple + APP ID and User ID
IP Port

Port ≠ Application
IP ≠ User
Packet ≠ Content

20 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


NGFW Concept

• Next Generation Firewall (NGFW) is a


high-performance firewall that can
effectively address application-layer
threats. NGFW can be seen as the
equivalent of a well-equipped security
officer in real life. It inspects every traffic
flow and filters out unsafe or malicious
traffic.

21 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


Intelligent Firewall Concept

• The intelligent next-generation firewall adopts a new


hardware architecture design, featuring hardware
decryption engines, high-density interfaces, and
scalable storage. It possesses capabilities such as
intelligent perception, integrated intelligence,
converged security, and unlimited scalability. It can
effectively detect unknown threat events and identify
compromised hosts within the internal network. It
strengthens the management and protection of
Internet of Things (IoT) devices and is committed to
providing industry-leading network security
protection capabilities to customers across various
industries and scenarios.

22 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


NGFW Functions
VPN HA
Support IPSECVPN、 Support A/P、peer
SSLVPN、L2TPVPN mode,configuration、
session synchronization

Basic VSYS
Switch/Route, Session
management, Security
Network Logically divides the
physical firewall into
Policy several virtual firewalls.

IPV6 Monitor
Support IPv6/IPv4 dual
Monitor device status、
stack
traffic etc.

23 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


NGFW Functions

SSL Decryption
User Authentication
Support https decryption with APPID、
AD、Local、radius
IPS、AV、URL filtering

Link Load Balancing


QoS Intelligently route and dynamically
Two-level 8 layers pipe nesting of adjust the traffic load of each link by

APP
bandwidth control: based on user、 monitoring the quality of each link in
IP、APP、URL etc. real-time

Traffic Quota Server Load Balancing


Limit and control the allowable Based on weighted hashing、weighted
flow quota of users/user round robin、weighted least
groups per day or per month. connection
Endpoint Access
24 | See. Understand. Act. Monitor © 2022 Hillstone Networks | All rights reserved.
NGFW Functions – Threat Protection
Attack Defense Data Security: File/content filter

04 01
IPS 02 02 Botnet C&C Prevention

AV
06 03 IP Reputation

05 04
Cloud Sandbox Web access control,URL filter
25 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.
4
Hillstone Product Introduction

26 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


Hillstone’s Product Portfolio

27 | See. Understand. Act. © 2022 Hillstone Networks | All rights reserved.


+1 408 508 6750
inquiry@[Link]
5201 Great America Pkwy, #420
Santa Clara, CA 95054
[Link]

You might also like