Thursday, May 3, 2012

Network / Port Address Translation


In the case of Singapore, the number of internet user has raised from 1.2 million users in 2000 to 3.7 million users in 2010 (“Singapore internet,” 2010). This shows that the number internet users have risen significantly.

Hence to slow down IPv4 depletion, Network Address Translation (NAT) and Port Address Translation (PAT) come into play. In NAT (dynamic), a group of private addresses can be mapped to a set of public addresses. Normally, that set of private addresses is more than that set of public addresses. While PAT will be referring to mapping of a set of private addresses to one public address. As a result, it helps to slows down the depletion IP address (Tyson, n.d.).

Figure 1 (Using NAT (Dynamic) (Tyson, n.d.))


Figure 2 (Using PAT (Tyson, n.d.))

There are several benefits of using NAT/PAT. This includes conservation of IP address. Secondly, NAT/PAT will allow greater scalability since adding a new host will not affect the addressing a scheme of the public address. Lastly, NAT/PAT provides an additional layer of security since query can only be initiated by the internal host. Therefore it makes it difficult for people with malicious motive to enter the network (Kozierok, 2005).

However NAT/PAT also has disadvantage, this includes performance issue. It is because when address translation takes place, there is a need to recalculate the header checksum. As a result some time is lost to perform this task (Kozierok, 2005). Secondly, there is also problem in security protocol. For instance, IPSec might flag address translation process as datagram “hacking” since it has the capability of detecting header modification (Kozierok, 2005).

In conclusion, although NAT/PAT might have its disadvantage, it also brought many advantage such as scalability in private network. As a result, many organizations decide to use NAT/PAT because they feel that the advantages have outweighed the disadvantages.

Reference

Kozierok, C. M. (2005, September 20). IP NAT overview, motivation, advantages and disadvantages. Retrieved May 2, 2012, from The TCP/IP Guide: http://www.tcpipguide.com/free/t_IPNATOverviewMotivationAdvantagesandDisadvantages.htm
Singapore internet statistic and telecommunications. (2010, June 24). Retrieved May 2, 2012, from Internet World Stats: http://www.internetworldstats.com/asia/sg.htm
Tyson, J. (n.d.). How Network Address Translation Works. Retrieved May 2, 2012, from howstuffworks: http://computer.howstuffworks.com/nat1.htm


Perimeter Router, Internal Router and Firewall


Perimeter Router is also known as the border router. It is being used to connect between trusted and untrusted network. However if the perimeter router is not properly configured, it will adversely compromise the operations of the trusted network (Dunning, 2011).

For instance, a poorly secured perimeter router will result in denial of service (DoS), which will compromise the availability of the network (Dunning, 2011). It will happen when the router is ineffective in filtering redundant network traffic (Dunning, 2011). On the other hand, a well-secured perimeter router will be able to prevent any reconnaissance from taking place, hence reducing the risk of being attacked (Dunning, 2011).

Figure 1 (Network Diagram)

To prevent any attack from taking place, the perimeter router must filter all the incoming packets. One of way will be ensuring that the source IP address must not contain the IP address of the local network. This is one of the sign of IP spoofing (Dunning, 2011).

Internal router will be referring to router that is not between the trusted and untrusted network. It will help to divide the local area network of into smaller network. In this way it will help to speed up the speed of transfer since it will have smaller routing table than before (Cooney, n.d.).

A firewall is referring to filtering of unwanted packets in order to protect the host from any attack (Tyson, n.d.).

The following video will be explaining the uses of firewall:

There are several methods to control traffic in firewall. These include packet filtering and stateful inspection. In packet filtering, the packets must go through a set of filtering. Only those packets managed to make it will be sent to the system (Tyson, n.d.).

In stateful inspection, only key parts of the packets will be checked against the database. The characteristic of the outbound information will be checked against the inbound information. If it matches reasonably, the packet will be allowed (Tyson, n.d.).

Reference

 [Network diagram]. Retrieved May 1, 2012, from: http://www.aniltj.com/blog/2007/03/23/DesignPatternsAndSOARuntimeInfrastructure.aspx
Cooney, R. (n.d.). Subnet Addressing. Retrieved May 1, 2012, from NetworkComputing: http://www.networkcomputing.com/unixworld/tutorial/001.html
Dunning, D. (2011, November 13). What Is a Perimeter Router? Retrieved May 1, 2012, from eHow: http://www.ehow.com/info_12198351_perimeter-router.html
Tyson, J. (n.d.). How Firewalls Work. Retrieved May 1, 2012, from howstuffworks: http://computer.howstuffworks.com/firewall1.htm



Friday, April 27, 2012

Security Policy


In this network security policy, it is defined as a formal statement of rules for people who are granted access to the organization resources to abide (Temasek Polytechinc, n.d.). Since threats are ever-growing and ever-changing, hence network security policy is a continuous cycle. In this cycle, it is divided into 4 phase, namely secure, monitor, test and improve.

In secure stage, it will begin to implement things to prevent any possible loss of information (Temasek Polytechinc, n.d.). This includes requiring constant change of password and implementing firewall in the network.

In monitoring stage, it will be detecting any violation to the policy (Temasek Polytechinc, n.d.). It normally involves the use of the Intrusion Detection System (IDS) to flag any violations to network adminstrator.

In test stage, the organization will be performing penetration testing or auditing the network system (Temasek Polytechinc, n.d.).

After gathering information from both monitoring and test stage, the organization will be improving or create a new security policies based on any vulnerability that is being surfaced in the organization (Temasek Polytechinc, n.d.). This stage is also known as the improve stage.

Figure 1 (Security policy life cycle)

When developing security policy, the organization can decide in three ways according to RFC 2196. Firstly, "Services offered versus security provided." In this concept, the network administrator can decide whether to provide the service (carries more security risks) or not to provide the service (least benefits) (Tittel, 2003).

Secondly, "Ease of use versus security." Network administrator can also decide between the ease of use (less secure) or “user-unfriendly” interface (most secure). Hence, depending on the situation, the network administrator will be deciding between these two extremities (Tittel, 2003).

Lastly, "Cost of security versus risk of loss." Network administrator can decide between the costs of security (in terms of performance, ease of use and cost) and loss when they didn’t implement. These include the loss of information, privacy and service (Tittel, 2003).


References:

[Information security policy]. Retrieved April 27, 2012, from: http://trustedtoolkit.blogspot.com/2007/07/information-security-policy-101_03.html
Temasek Polytechinc. (n.d.). L02 - Laws and ethics. Singapore, Singapore, Singapore. Retrieved from SearchSecurity.
Temasek Polytechinc. (n.d.). Overview of internetworking security. Singapore, Singapore, Singapore.
Tittel, E. (2003, August). The security policy document library: site security handbook. Retrieved April 27, 2012, from SearchSecurity: http://searchsecurity.techtarget.com/tip/The-security-policy-document-library-Site-Security-Handbook

Common Networking Attacks Threats and Solution

In this highly globalized world, both threats in defense technologies are improving in a rapid pace. This led to a lot of disastrous problem such as unauthorized disclosure of information, including states secret.

One of the problems of network will be Ping of Death attack. In this attack, one of the hosts will be sending defected packet unintentionally or intentionally. As a result, instead of sending 32 bytes of data, the host will be sending 65,525 bytes of ping packet. This will result in buffer overflow, crashing the computer (“Ping of”, 2012). Ping of Death is also one of the methods for denial of service.

To solve the problem of denial of service, network administrator can implement Intrusion Prevention System (IPS). IPS will be able to detect any anomaly activities through signature, or “experience” of that normal network conditions (“Intrusion prevention,” 2012). Another method will be traffic rate limiting. In this method, they will be implementing a quota for the traffic allowed for the network (Temasek Polytechinc, n.d.).

Here is the video explaining the differences between IPS and Intrusion Prevention System (IDS):

Another common networking threat will be scanning phase of the attack. In that phase, the hacker will try to map the network of the victim’s system (“Types of,” 2011). One of the ways will be performing banner grabbing using Netcat to determine the victim’s Operating System (OS). By doing so, the hacker will be able to retrieve information about OS versions and begin to exploit the known vulnerability of that OS (Banner grabbing, 2012). After scanning is completed, it will normally mean that the hacker will be preparing for phase 3, which is gaining access to the network.


Figure 1 (Steps of hacking (Graves, 2010, p. 8))


Figure 2 (Phase of scanning (Graves, 2010, p. 67))

There are several ways to prevent any scanning from taking place. One of the ways will be disabling unused services on the network host (Banner grabbing, 2012). Another way will be using Intrusion Detection System (IDS) to notify the network administrator when reconnaissance is taking place (Temasek Polytechinc, n.d.).

In conclusion, these networking threats cannot be thoroughly eliminated since ‘older’ threats are ever-changing and ‘new’ threats are emerging. Therefore being a network administrator, it is important for them to keep themselves updated through visiting the advisories that is made by the manufacturer and update the latest security patches from the manufacturer.




References:


Types of network attacks: four primary classes. (2011, July 17). Retrieved April 27, 2012, from CCNAanswers-khim: http://ccnaanswers-khim.blogspot.com/2011/07/types-of-network-attacks-four-primary.html
Banner grabbing. (2012, February 22). Retrieved April 27, 2012, from Wikipedia: http://en.wikipedia.org/wiki/Banner_grabbing
Intrusion prevention system. (2012, March 25). Retrieved April 26, 2012, from Wikipedia: http://en.wikipedia.org/wiki/Intrusion-prevention_system
Ping of death. (2012, March 16). Retrieved April 2012, 2012, from Wikipedia: http://en.wikipedia.org/wiki/Ping_of_death`
Graves, K. (2010, April 26). Certified ethical hacker. Sybex.
Temasek Polytechinc. (n.d.). Overview of internetworking security. Singapore, Singapore, Singapore.