0% found this document useful (0 votes)
3 views31 pages

Understanding VPN Insecurity Risks

This document discusses VPN security risks and mitigation strategies. It begins with an overview of VPN technologies like IPSec and how they establish encrypted tunnels between networks. It then covers common VPN deployment types and their security implications. The document warns about risks like unencrypted header data and implied access. It concludes by recommending mitigation best practices like firewalling VPN segments, limiting privileged access, and clearly defining security policies between connected networks.
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views31 pages

Understanding VPN Insecurity Risks

This document discusses VPN security risks and mitigation strategies. It begins with an overview of VPN technologies like IPSec and how they establish encrypted tunnels between networks. It then covers common VPN deployment types and their security implications. The document warns about risks like unencrypted header data and implied access. It concludes by recommending mitigation best practices like firewalling VPN segments, limiting privileged access, and clearly defining security policies between connected networks.
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

VPNInsecurity

DanGoldberg MADJiCConsulting,Inc
[Link] dan@[Link]

VPNInsecurity Agenda

WhatareVPNs HowdoVPNswork Abriefcryptosidetrip VPNanatomy BasicWANdesigns VPNrisks Riskmitigation

Whatisa VirtualPrivateNetwork(VPN)

Twoworkingdefinitions

Privatecommunicationsoveranonprivate medium Anetworktransportingtrusteddataoveran untrustednetwork(Internet) Hosttohost Hosttogateway(Remoteaccess) Gatewaytogateway(Sitetosite)

VPNformats

VPNImplementations

SSHSecureShell SSLSecureSocketsLayer

OpenSSL&Stunnel OpenVPN CommercialSSLVPN

Cryptcat(netcatwithcrypto) L2TPLayer2transportprotocol PPTPPointtopointtunnelingprotocol IPSecInternetProtocolSecurity

VPNLimitations

SSH,supportsTCPtrafficonly

DependonClientPortforwarding

SSHSecureShell SSLSecureSocketsLayer Cryptcat L2TPLayer2transportprotocol PPTPPointtopointtunnelingprotocol IPSecInternetProtocolSecurity

SymmetricorweakCrypto

Unicasttrafficonly

Theleastyouneedtoknow aboutcrypto

CryptographyisusedtopermitAlicetotalk toBob Elviscanlisteninbutnotchangeor understandthemessage Therearetwotoolsusedtoproducethisend inIPSecVPNsandPublicKeyCrypto


Encryptionalgorithm CryptographicHashalgorithm

Encryptionandhashes

Encryptionexample:

plaintext>|<agfoel23.!0clw

CryptographicHash
MD5createsa128bitchecksum SHA1creates160bytechecksum [dbg@madjicbox~]$[Link] 07f775c5982e14ed7e8840016a0cf0f15bea599e [Link] Usedasachecksumtovalidatetwoinputsare thesame

Acryptographicsideshow

Hey!Iheardthathashesarebroken!?! [Link] Hashesarenotsupposedtocollide

Notwoinputsaresupposedtoproducethe sameoutput

Somedo! ThelinkabovetellsthestoryofAliceandher Boss(Bob)inwhichBosssignsadocument withaknowncollision;ouch!

WhyInternetProtocolSecurity (IPSec)?

InternetProtocolversion4offersnopayload security

Simplechecksummingonheaders Transportmode(AuthenticationheaderAH)

IPSecprovides

Tunnelmode(EncapsulatingSecurityProtocol ESP)

AddsauthenticationtoexistingIPheader

EncryptsandpackagesoriginalIPpacketinsidea newIPheadertransmittedbysecuritygateway Receivinggatewayreversestheprocess

[Link]

TunnelmodeusesIPinIP

EncapsulatedSecurityProtocol(ESP) Encryptsentirepacketatsecuritygateway includingoriginalheader AddsentireIPnewheadertopacket Transportstosecuritygatewaybasedonpolicy ProtectsdataandIPaddressesofhostsbehind securitygateway

[Link]

TransportmodeaddstooriginalIPheader

Signspayloadandtransportstonexthop

InsertsadditionalheadersinIPheaderwithhash /checksum Protectsdatafrommaninthemiddle DoesnotprovideprivacyofdatainpayloadorIP addresses! NATbreakstransportmode

Doesnotincludedynamicheaderdatainsignature (TTLetc)

IPSecAnatomy

IKEInternetkeyexchange ISAKMPInternetSecurityAssociationand KeyManagementProtocol AHAuthenticationHeader ESPEncapsulatingSecurityProtocol

Authentication&KeyExchange

ISAKMP(IKE) Authenticationmethod

Policy

certificate sharedsecret DES 3DES MD5 SHA1

Encryptionalgorithm

Hashingalgorithm

IdentifyendpointsbyDNSorIP KeyLifetimemeasuredinmegabytesandortime (minutesorhours)

SecurityAssociations

Policymustmatchonbothends

Onesideinitiatescommunications;aSecurity PolicyIdentifier(SPI)iscreatedwhichidentifies aSecurityAssociation(SA)inaSecurityPolicy Database(SPD). SPDholdsalltheSPIsahostknowsabout

TheSecurityassociationidentifiesthe instanceofIPSecanditsparameters

Keys!Keys!Who'sgotthe

Cryptokeymaterialissensitive Howdoweexchangekeys IKEInternetkeyexchange


keys?

HybridISAKMP,andOakley UDPport500 Managekeyexchange,securityassociations, andkeymanagement

Itiscriticaltorekeyperiodically

IPSecPolicyrequirements

IPSecPolicy

Encryptionalgorithm

DES 3DES SHA1 MD5

Hashingalgorithm

Keylifetime

Bytes(manyimplementationsdefaultto8megabytes) Minutesorhours(manyimplementationsdefaultto24 hours)

Somethingstolookoutfor

IPSecasaTunnel

CombineAHandESP

Site2siteVPNs RemoteAccess

Maninthemiddleattacks ModifyunencryptedportionsofIPheaderintransit

See[Link]
[Link]

IPSecasaTransport

CombineAHandESPtoprotectpayload

Hosttohostcommunications Validatecommunicationsonaprivatenetwork

SomepacketswithIPSec

ThreepacketsandtheIPSectransforms
AnIPPacket IPheader Protocolheader
Payload

AnIPPacketintransportmode IPheader
AHheader Protocolheader Payload

AnIPPacketintunnelmode ESPIPheader IPheader Protocolheader


Payload

Hosttohost

Inhosttohostmodecommunications betweenspecifiedhostsuseIPSec Usefulinservertoserverconnections Typicallydoesnotrequireadditionalsecurity atupperlayerssuchasAAA Allothercommunicationsareclear

Hosttogateway

Commonlyusedforremoteaccesssystems RequiresAAAforaccess DoesnotreplaceAAAforsystemsonthe network Splittunnelingunintendedaccess

Gatewaytogateway (Sitetosite)

CommonlyusedforWAN DoesnotrequireAAAforaccess DoesnotreplaceAAAforsystemsonthe network Networkcontrolsmustbeimplemented

SomeWANdesigns

HubandSpoke Ring Mesh WANconsider:


Routing complexityandnumberoflinks ImpactofcryptoonCPUutilization PertunnelimpactonVPNgateway

VPNspecific

Site2siteVPNRisks

TreatVPNtunnelsasWANlinks Determinetrustlevel

TrustedInternal Semitrustedremoteusers,businesspartners withcommonriskmodel Untrustedeveryoneelse

Note:researchshowsthatsome85%of attacksareinternal

WhereareVPNsused?

Connectiontypes

Internal Businesstobusiness Businesstocustomer Remoteusers


Remoteworkers Contractors

RiskMitigation

Considertheriskmodelforeachlocationthat isconnectedand; Foreachnetwork,host,&servicelevel considerappropriate


Authentication Accesscontrol

Logging Virusvectors

Portsandprotocols Services

Mitigationexample

AlwaysconsiderImpliedAccess SiteAandSiteBshareasitetositeVPN PolicypermitsallhostsatsiteAtoaccess FTPserverbyIPaddress FTPserverhasFTPd,andSSHdrunning FTPuseraccountsarestoredin/etc/passwd Whatistheactualaccessbetweenthetwo sites?

PartneringandConnecting

Priortobuildinganylinkbetweentwoentities determine:

Whoarethecontactpointsoneachend Whatpolicywillgoverntheconnection Whocontrolsandmanagesthepoliciesoneach device Thechangemanagementprocess

MitigationexampleII

CompanyAandCompanyBshareasiteto siteVPN CompanyA'spacketfilterpolicylimits accessbetweenhosts(byIP)andports whicharepermittedbetweenthem CompanyBpermitsalltrafficbetweenboth sites Duringatechnicalconcallnoonecan identifythepolicyowneratcompanyB

Additionalmitigation

TerminateallVPNsonaseparateLAN segment FirewalltheVPNsegmentfromtheinternal LAN PermitaccessbysourceanddestinationIP andport/protocolasrequired Thisrequiresplanningandunderstanding whatthecommunicationneedsofallgroups Beawareofimpliedaccessviasplittunnels

RecentVPNProduct

Cisco'sVPNconcentrator:

Vulnerabilities

[Link] [Link]?lang=en Nortelvpncleartextpasswordissue:[Link] [Link]/[Link]?id=4065 NortelmalformedIKEpacketvulnerability: [Link] urity&ID=4094 Cisco'smalformedIKEpacketvulnerability: [Link] [Link]

Conclusion

TreatVPNslikeanyWANlink Employtheprincipleofleastprivilege WhendeployingVPNsdeterminesecurity andaccessrequirementsinadvance LimitaccessbetweenVPNsegmentsand LANsegmentsthenpermittrafficasneeded

You might also like