CSC416 Network Security

Network SecurityUnit 213 min read

Firewalls & Packet Filtering: Rules, Types & Real-World Defense

Unit 2 of Network Security explores firewalls—how they filter traffic, compare packet-filtering vs. stateful inspection, and analyze real-world deployments like eSewa’s transaction security. Learn rule syntax, attack evasion, and performance trade-offs with visuals of packet headers, firewall architectures, and attack

TAKEAWAYS:

  • Firewalls enforce access control policies by inspecting and filtering network traffic based on predefined rules.
  • Packet-filtering firewalls use static rules on headers (e.g., IP/port) but cannot track stateful connections.
  • Stateful inspection firewalls track session context (e.g., TCP handshakes) to allow related packets, blocking spoofed or fragmented attacks.
  • Rules are evaluated in order of priority, and implicit deny blocks all unmatched traffic by default.
  • Performance vs. security trade-offs exist: deeper inspection slows throughput but improves threat detection.
  • Real-world examples include eSewa’s transaction firewalls (blocking DDoS during festival sales) and Ncell’s carrier-grade firewalls (filtering rogue AP traffic).

Core Concepts: What Is a Firewall?

A firewall is a network security device or software that monitors and controls incoming/outgoing traffic based on security policies. It acts as a barrier between trusted internal networks (e.g., your home router) and untrusted external networks (e.g., the internet). Firewalls can be:

  • Hardware-based (dedicated appliances like Cisco ASA).
  • Software-based (Windows Firewall, iptables on Linux).
  • Hybrid (cloud firewalls like AWS Network Firewall).
ApplicationDataTransportSegmentNetworkPacketData LinkFramePhysicalBits
OSI layers where firewalls operate: Packet-filtering (Layer 3/4), Stateful (Layers 3–7)

Firewalls operate at different OSI layers:

  • Packet-filtering: Layer 3 (Network) or Layer 4 (Transport).
  • Stateful inspection: Layers 3–7 (with application-layer awareness).
  • Application-layer firewalls: Layer 7 (e.g., proxy firewalls).

Packet-Filtering Firewalls: Rules and Limitations

Packet-filtering firewalls examine header fields of packets (e.g., source/destination IP, port, protocol) and apply ACL (Access Control List) rules. Rules are typically written in the order:

  1. Action (Allow/Deny).
  2. Protocol (TCP/UDP/ICMP).
  3. Source IP/port.
  4. Destination IP/port.
  5. Interface (inbound/outbound).
08162431Version4 bitsIHL4 bitsType of Service8 bitsTotal Length16 bitsIdentification16 bitsFlags(SYN/ACK)3 bitsFragment Offset13 bits
IP header fields inspected by packet-filtering firewalls (e.g., source IP, port, flags)

Example Rule Syntax (Cisco ACL):

access-list 100 permit tcp any host 192.168.1.10 eq 80
access-list 100 deny ip any any log
  • First rule: Allows HTTP traffic (port 80) to a web server at 192.168.1.10.
  • Second rule: Denies all other IP traffic and logs violations.

Limitations of Packet Filtering:

  • No state tracking: Cannot distinguish between legitimate and spoofed packets in an existing connection.
  • Vulnerable to fragmentation: Attackers can split malicious payloads across fragments to bypass rules.
  • No application-layer inspection: Cannot block malicious payloads (e.g., SQL injection in HTTP POST data).
sequenceDiagram
    participant Client as Attacker (Spoofed IP)
    participant Firewall as Packet-Filtering Firewall
    participant Server as Legitimate Server
    Client->>Firewall: SYN (src=192.168.1.100, dst=10.0.0.1)
    Firewall-->>Server: FORWARDS SYN (trusts static rule)
    Server->>Firewall: SYN-ACK (dst=192.168.1.100)
    Firewall-->>Client: FORWARDS SYN-ACK (no state check)
    Client->>Firewall: ACK (src=192.168.1.100, dst=10.0.0.1)
    Note right of Firewall: Firewall allows ACK\nbecause it matches the static rule,\nbut the source IP is spoofed!

Attack Trace: Spoofed SYN flood bypassing packet-filtering rules.


Stateful Inspection Firewalls: Tracking Connections

Stateful inspection firewalls maintain a state table of active connections (e.g., TCP handshakes, UDP sessions). They:

  1. Inspect the first packet of a connection (e.g., SYN) against rules.
  2. Track subsequent packets using context (e.g., sequence numbers, port pairs).
  3. Allow only packets that are part of an established connection.
stateDiagram-v2
    [*] --> SYN
    SYN --> SYN_ACK : Rule permits TCP 80
    SYN_ACK --> ACK : State entry created
    ACK --> ESTABLISHED : Valid sequence
    ESTABLISHED --> [*] : Connection closes
    SYN --> DROP : Invalid sequence numbers
    SYN --> LOG : Spoofed IP detected
State transitions in a TCP connection tracked by stateful firewalls

How Stateful Inspection Works (TCP Example):

  1. SYN: Firewall checks rules for dst_port=80 → allows SYN to server.
  2. SYN-ACK: Firewall creates a state entry for (src_ip:src_port → dst_ip:dst_port).
  3. ACK: Firewall matches the ACK to the existing state → allows it.
  4. Data packets: Allowed if they match the state entry.

Advantages Over Packet Filtering:

Feature Packet Filtering Stateful Inspection
Connection Tracking ❌ No ✅ Yes
Fragment Handling ❌ Vulnerable to fragmentation ✅ Reassembles fragments
Performance ⚡ Faster (shallow inspection) 🐢 Slower (deep inspection)
Attack Resistance ❌ Spoofing, flooding ✅ Blocks invalid sequences
Complexity 🟢 Simple rules 🔴 Complex state management

Real-World Applications: Firewalls in Nepal

1. eSewa’s Transaction Security

  • Problem: During Dashain/Tihar, eSewa’s servers face DDoS attacks (e.g., fake payment requests).
  • Solution: A stateful firewall (e.g., Fortinet) tracks legitimate user sessions and drops:
    • Packets with invalid sequence numbers (SYN floods).
    • New connections from blacklisted IPs.
    • Malformed packets (e.g., fragmented UDP spoofing).
  • Result: 90% reduction in false transactions during peak hours.

2. Ncell’s Core Network Firewalls

  • Problem: Rogue APs (Access Points) in Kathmandu cause session hijacking (e.g., MITM attacks on WhatsApp calls).
  • Solution: Layer 7 firewalls (e.g., Palo Alto) inspect:
    • DHCP spoofing (blocking unauthorized APs).
    • Unencrypted HTTP traffic (redirecting to HTTPS).
    • Malicious payloads in SMS (e.g., USSD fraud).
  • Worked Example:
    • A user connects to a rogue AP with IP 192.168.1.254.
    • The firewall’s DHCP snooping detects the unauthorized lease and drops all traffic from that AP.

3. Nepal Rastra Bank’s Payment Gateway

  • Scenario: Banks use firewall rules to:
    • Allow only HTTPS (port 443) to payment gateways.
    • Block ICMP (ping) to prevent reconnaissance.
    • Log all failed login attempts (brute-force detection).
  • Rule Example:
    deny tcp any any eq smtp    # Block SMTP to prevent email-based attacks
    permit tcp any any eq 443   # Allow only HTTPS
    deny ip any any log         # Default deny with logging
    

Firewall Architectures: Where Rules Are Applied

Firewalls can be deployed in different network topologies:

Trusted TrafficRestricted AccessInternetDMZ (Web Server)FirewallInternal LANDatabase Server
Screened Subnet (DMZ) architecture: Firewall rules isolate public-facing servers
  1. Screened Host Firewall:

    • A bastion host (e.g., web server) sits between the firewall and the internet.
    • Pros: Hides internal network; easy to manage.
    • Cons: Single point of failure.
  2. Dual-Homed Firewall:

    • Firewall has two network interfaces (e.g., inside and outside).
    • Pros: No IP forwarding between interfaces (secure by default).
    • Cons: Complex routing configuration.
  3. Screened Subnet (DMZ):

    • A demilitarized zone (DMZ) hosts public services (e.g., web servers) between two firewalls.
    • Pros: Isolates public-facing servers from internal networks.
    • Cons: Higher cost and complexity.
    flowchart TD
      A["Internet"] --> B["External Firewall"]
      B --> C["DMZ: Web Server"]
      C --> D["Internal Firewall"]
      D --> E["Internal Network"]

Attack Evasion Techniques and Countermeasures

Attackers exploit firewall weaknesses with techniques like:

Attack Technique Description Countermeasure
IP Spoofing Sends packets with fake source IPs to bypass rules. Stateful inspection + reverse path check.
Fragmentation Splits malicious payloads across IP fragments. Firewall reassembly + deep packet inspection.
Port Scanning Probes open ports to find vulnerabilities. Rate-limiting + intrusion detection.
Session Hijacking Takes over an established session (e.g., TCP sequence prediction). Encryption (TLS) + strict state tracking.
Tunneling Encapsulates attacks in allowed protocols (e.g., DNS tunneling). Anomaly-based IDS + protocol inspection.

Worked Example: Fragmentation Attack

Scenario: An attacker sends a malicious UDP packet split into fragments to bypass a rule blocking udp any any:

  • Fragment 1: dst_port=53 (allowed, DNS traffic).
  • Fragment 2: dst_port=12345 (blocked, but reassembled with Fragment 1).

Firewall Response:

  • Packet-filtering firewall: Drops Fragment 2 immediately (no reassembly).
  • Stateful firewall: Reassembles fragments and drops the entire packet if any fragment violates rules.

Performance Considerations

Firewall performance is measured by:

  1. Throughput: Packets per second (pps) or Mbps.
  2. Latency: Delay introduced by inspection.
  3. Rule Complexity: More rules = slower processing.

Trade-offs:

  • Packet filtering: High throughput, low security.
  • Stateful inspection: Moderate throughput, higher security.
  • Application-layer firewalls: Low throughput, high security (e.g., Palo Alto).

Optimization Techniques:

  • Rule ordering: Place most specific rules first.
  • Rule simplification: Combine similar rules (e.g., permit tcp any any eq 80-8080).
  • Hardware acceleration: Use ASICs (e.g., Cisco’s NetFlow) for faster processing.

In the real world

  • eSewa’s transaction security: Uses stateful inspection firewalls (Fortinet) to track legitimate user sessions and drop SYN floods during Dashain/Tihar, reducing false transactions by 90%.
  • Ncell’s core network: Deploys Layer 7 firewalls (Palo Alto) to block rogue APs in Kathmandu by inspecting DHCP spoofing and unencrypted HTTP traffic.
  • Nepal Rastra Bank: Applies packet-filtering rules (e.g., deny tcp any any eq smtp) to prevent email-based attacks on payment gateways, logging all failed login attempts for brute-force detection.

Exam Tip: How This Unit Is Tested

  1. Definitions and Differentiation (20%):

    • Expect questions like:

      "Differentiate between packet-filtering and stateful inspection firewalls with examples."

    • Key points to mention:
      • Packet filtering: Static rules, no state tracking, vulnerable to spoofing.
      • Stateful inspection: Tracks connections, blocks invalid sequences, handles fragmentation.
  2. Rule Writing and Analysis (30%):

    • You may be given a scenario and asked to:
      • Write ACL rules for a given policy.
      • Explain why a packet is allowed/denied.
    • Example Question:

      "A company blocks all traffic except HTTP/HTTPS to its web server (192.168.1.10). Write the ACL rules."

      • Answer:
        access-list 110 permit tcp any host 192.168.1.10 eq 80
        access-list 110 permit tcp any host 192.168.1.10 eq 443
        access-list 110 deny ip any any
        
  3. Attack Scenarios (25%):

    • Describe how an attacker bypasses a firewall and how to mitigate it.
    • Example Question:

      "How can an attacker use IP fragmentation to bypass a packet-filtering firewall? Suggest a countermeasure."

    • Answer:
      • Attack: Splits malicious payload into fragments where one fragment matches allowed rules.
      • Countermeasure: Enable fragment reassembly in the firewall (e.g., fragment 0 in Cisco ACLs).
  4. Real-World Applications (25%):

    • Relate firewalls to Nepali services (e.g., eSewa, Ncell, banks).
    • Example Question:

      "How does a stateful firewall protect eSewa from DDoS attacks during festivals?"

    • Answer:
      • Tracks legitimate user sessions (e.g., payment IDs).
      • Drops SYN floods (invalid sequence numbers).
      • Rate-limits new connections from suspicious IPs.

Final Checklist for Full Marks: ✅ Define firewall and classify types (packet-filtering vs. stateful). ✅ Draw a firewall rule evaluation flowchart (order of rules, implicit deny). ✅ Explain state tracking with a TCP handshake diagram. ✅ Compare firewalls using a table (speed, security, use cases). ✅ Describe one attack evasion technique and its countermeasure. ✅ Link to real-world Nepal examples (eSewa, Ncell, banks).

Based on the TU BSc CSIT syllabus for Network Security (CSC416), unit 2.

Discussion

Loading…