CMP426 Network and Cyber Security

Network and Cyber SecurityUnit 717 min read

Firewalls & Intrusion Detection: Rules, IDS/IPS, Honeypots & Logs

Unit 7 of Network and Cyber Security covers firewalls (types, rules, packet filtering), intrusion detection systems (signature-based vs anomaly-based), honeypots, and log analysis—explaining how they protect networks from attacks like DDoS, malware, and unauthorized access, with real-world examples from Nepali and glob

TAKEAWAYS:

  • Firewalls filter traffic using rules (ACL, stateful inspection) and can be network-based (hardware) or host-based (software).
  • Intrusion Detection Systems (IDS) monitor signatures (known attacks) or anomalies (unusual behavior), while IPS actively blocks threats.
  • Honeypots decoy systems lure attackers to study their tactics, while SIEM tools correlate logs to detect breaches.
  • False positives/negatives are critical trade-offs in IDS/IPS design, affecting performance and security.
  • Log analysis (syslog, SIEM) helps reconstruct attacks and enforce compliance (e.g., GDPR, Nepali cyber laws).
  • Real-world use: Banks (e.g., NMB) use firewalls to block SQL injection; Pathao’s servers rely on IDS to detect fraudulent ride requests.

1. Firewalls: The First Line of Defense

Firewalls act as gatekeepers between trusted internal networks and untrusted external ones (e.g., the internet). They enforce access control policies by inspecting and filtering traffic based on predefined rules.

1.1 Types of Firewalls

Firewalls are classified based on their inspection method and placement in the network. Below is a comparison table:

Type How It Works Pros Cons Example Use Case
Packet Filtering Checks headers (source/dest IP, port, protocol) against ACL rules. Fast, low overhead. No state tracking; vulnerable to spoofing. Basic router ACLs in NTC networks.
Stateful Inspection Tracks connection state (e.g., TCP handshake) to allow return traffic. Better security than packet filtering. Higher CPU usage. Corporate networks (e.g., Ncell HQ).
Application-Level (Proxy) Inspects application data (e.g., HTTP, FTP) by acting as a proxy. Deep inspection (e.g., block malicious URLs). Slow; complex setup. Web application firewalls (e.g., Cloudflare).
Next-Gen (NGFW) Combines stateful inspection + deep packet inspection (DPI) + IPS. Blocks advanced threats (e.g., malware in emails). Expensive; resource-intensive. Government networks (e.g., NEPSE).
Host-Based Runs on end devices (e.g., Windows Firewall, iptables on Linux). Protects individual machines. No network-wide visibility. Laptops in universities (PU, TU).

1.2 How Firewalls Work: Rule Processing

Firewalls use Access Control Lists (ACL) to decide whether to allow or deny traffic. Rules are processed in order, and the first match determines the action.

Example: ACL Rule Processing

Assume the following rules for a small office network (IP range: 192.168.1.0/24):

Rule # Action Source IP Dest IP Port/Protocol Description
1 Allow 192.168.1.0/24 Any Any Internal traffic allowed.
2 Deny Any 192.168.1.10 TCP 22 (SSH) Block external SSH to server.
3 Allow Any 192.168.1.0/24 TCP 80 (HTTP) Allow web traffic to internal sites.
4 Deny Any Any Any Default: Block all else.

Worked Example: Traffic Flow

  1. Packet A: From 192.168.1.5 (internal) to 10.0.0.1 (external) on TCP 80.
    • Rule 1 matches → Allowed.
  2. Packet B: From 192.168.0.100 (external) to 192.168.1.10 (internal) on TCP 22.
    • Rule 2 matches → Denied (blocked SSH).
  3. Packet C: From 192.168.1.20 (internal) to 192.168.1.10 (internal) on TCP 443.
    • Rule 1 matches → Allowed (internal traffic).

Mermaid Diagram: Firewall Rule Processing

flowchart TD
    A["Packet Arrives"] --> B["Check Rule 1: Allow Internal"]
    B -->|"Match"| C["ALLOW"]
    B -->|"No Match"| D["Check Rule 2: Deny SSH to Server"]
    D -->|"Match"| E["DENY"]
    D -->|"No Match"| F["Check Rule 3: Allow HTTP"]
    F -->|"Match"| G["ALLOW"]
    F -->|"No Match"| H["Check Rule 4: DENY ALL"]
    H --> I["DENY"]

1.3 Firewall Placement in Networks

Firewalls are deployed at strategic points to maximize security:

Key Placements:

  1. Perimeter Firewall: Between the internet and the internal network (e.g., Firewall 1 above).
  2. DMZ Firewall: Protects public servers (e.g., web, mail) from internal networks.
  3. Internal Firewall: Segments sensitive data (e.g., databases) from less secure zones.

Real-World Example: Daraz’s Firewall Strategy

  • Perimeter Firewall: Blocks DDoS attacks targeting Daraz’s checkout servers.
  • DMZ: Hosts public APIs (e.g., product catalog) but restricts access to internal inventory systems.
  • Internal Segmentation: Separates payment processing (PCI-DSS compliant) from customer support.

1.4 Firewall Limitations

Limitation Explanation Mitigation
No Application Awareness Packet filters can’t inspect payloads (e.g., SQL injection in HTTP). Use application-layer firewalls (e.g., ModSecurity).
Stateful Overhead Tracking connections consumes CPU/memory. Deploy hardware firewalls (e.g., Cisco ASA).
Misconfigured Rules Overly permissive rules (e.g., allowing RDP from the internet). Least privilege principle; audit logs.
Encrypted Traffic Bypass TLS/SSL hides payloads from inspection. Use SSL inspection (but risks privacy).

2. Intrusion Detection and Prevention Systems (IDS/IPS)

While firewalls prevent unauthorized access, IDS/IPS detect and respond to active attacks.

2.1 Intrusion Detection Systems (IDS)

IDS monitors network/host activity for suspicious patterns and alerts admins. It does not block traffic.

Types of IDS

Type How It Works Pros Cons Example
Signature-Based Matches traffic against a database of known attack signatures (e.g., malware hashes). Fast, accurate for known threats. Fails against zero-day attacks. Snort, Suricata.
Anomaly-Based Uses ML/AI to detect deviations from normal behavior (e.g., sudden spike in outbound traffic). Catches new/unseen attacks. High false positives. Darktrace, Cisco Stealthwatch.
Hybrid Combines signature + anomaly detection. Balanced security and performance. Complex to tune. Palo Alto Traps.

Worked Example: Signature-Based IDS

  • Attack: A SQL injection attempt on a web server:
    http://example.com/login.php?id=1' OR '1'='1
    
  • Signature Rule (Snort):
    alert tcp any any -> 192.168.1.10 80 (msg:"SQL Injection Attempt"; content:"' OR '"; nocase;)
    
    • Action: IDS logs the alert but does not block the traffic (that’s IPS’s job).

Mermaid Diagram: IDS vs. IPS Response

sequenceDiagram
    participant Attacker as Attacker
    participant IDS as IDS (Detects)
    participant IPS as IPS (Blocks)
    participant Firewall as Firewall

    Attacker->>IDS: Malicious Packet (SQLi)
    IDS->>Admin: Alert (Signature Match)
    Admin->>IPS: Configure Rule to Block
    IPS->>Firewall: Drop Traffic Matching Pattern
    Firewall->>Attacker: Packet Dropped

2.2 Intrusion Prevention Systems (IPS)

Unlike IDS, IPS actively blocks malicious traffic in real-time. It is inline with the network traffic.

Feature IDS IPS
Placement Passive (monitor only). Inline (must process all traffic).
Action on Detection Alerts admins. Drops/Resets connections.
Performance Impact Low (monitoring only). High (active filtering).
False Positives Tolerable (just alerts). Critical (blocks legitimate traffic).

Real-World Example: Ncell’s IPS Against Fraud

  • Threat: SIM-box fraud (unauthorized international calls).
  • Solution: IPS detects anomalous call patterns (e.g., sudden spike in calls to a single country) and blocks the suspicious SIM before calls are routed.

2.3 Honeypots: Decoy Systems to Trap Attackers

A honeypot is a fake system designed to attract attackers, allowing security teams to:

  • Study attacker tactics (e.g., malware behavior).
  • Distract attackers from real systems.
  • Collect intelligence on new threats.
InternetDMZ (Honeypot)Internal Network
Honeypot placement: Isolated in DMZ to lure attackers away from real systems.

Types of Honeypots

Type Description Example
Low-Interaction Simulates basic services (e.g., fake SSH, HTTP). Cowrie (SSH honeypot).
High-Interaction Fully functional fake OS/applications (riskier but more realistic). HoneyDrive (full VM honeypot).
Research Honeypot Used by security researchers (e.g., tracking APT groups). Canary Tokens.

Worked Example: Honeypot in a Bank (NMB)

  • Setup: A fake ATM server exposed to the internet.
  • Attack: An attacker tries to exploit a known SQLi vulnerability in the ATM interface.
  • Outcome:
    • The bank’s SIEM detects the attack from the honeypot.
    • Security team updates real ATM systems with the patch.
    • Attacker’s IP is blacklisted before they reach real systems.

3. Log Analysis and SIEM

Firewalls and IDS/IPS generate logs, but raw logs are useless without analysis. SIEM (Security Information and Event Management) tools correlate logs to detect advanced threats.

3.1 Key Log Sources

Source Example Log Entry Purpose
Firewall Logs 2023-10-01 12:34:56 DENY TCP 192.168.1.10:22 -> 203.0.113.45:54321 (SSH Blocked) Track blocked attacks.
IDS/IPS Logs ALERT: Signature matched (SQL Injection) - Source: 203.0.113.45 Identify attack patterns.
System Logs (syslog) Oct 1 12:35:00 server sshd[1234]: Failed password for root from 203.0.113.45 Detect brute-force attempts.
Application Logs ERROR: Database query failed: ' OR '1'='1 in login.php` Find exploited vulnerabilities.

Mermaid Diagram: SIEM Log Correlation

Firewall LogsIDS/IPS LogsSystem LogsApplication LogsSIEM Correlation
SIEM correlates logs to detect coordinated attacks (e.g., brute force + exploit).

3.2 SIEM Tools in Action

Example: Detecting a Data Exfiltration Attack

  1. Step 1: IDS detects unusual outbound traffic from a database server to a cloud storage bucket.
  2. Step 2: SIEM correlates this with:
    • Firewall logs: Multiple new outbound connections to an unknown IP.
    • Database logs: A user (admin) ran SELECT * FROM customers (unusual at 3 AM).
  3. Step 3: SIEM triggers an alert and blocks the IP via the firewall.
12:35:00IDS: Brute ForceAlert (203.0.113.45)12:36:00Firewall: BlockedSSH from 203.0.113.4512:37:00SIEM: CorrelatedEvent → Admin Alert12:38:00AutomatedResponse: Block IP Glo
SIEM-driven incident response timeline for a brute-force attack.

Real-World Example: NEPSE’s SIEM for Market Manipulation

  • Threat: Insider trading via unauthorized API access.
  • Solution: SIEM monitors:
    • Failed login attempts (brute force).
    • Unusual data downloads (e.g., bulk stock price history).
  • Action: Automatically locks the account and notifies compliance officers.

4. False Positives and False Negatives

A major challenge in IDS/IPS is balancing security and usability.

Term Definition Impact Mitigation
False Positive Legitimate traffic wrongly flagged as malicious. User frustration; wasted time investigating. Tune rules; use anomaly detection carefully.
False Negative Actual attack goes undetected. Security breach. Use hybrid IDS (signature + anomaly).

Example: False Positive in a University (TU)

  • Scenario: A student downloads a legitimate security tool (e.g., Wireshark).
  • Problem: IDS flags it as malware (based on file hash).
  • Solution: Whitelist known-good tools in the IDS rules.

Example: False Negative in a Bank (GlobalPay)

  • Scenario: A zero-day exploit in a payment gateway.
  • Problem: Signature-based IDS misses it (no known signature).
  • Solution: Deploy anomaly-based detection (e.g., sudden spike in transaction volume).

5. Exam Tip: How to Score Full Marks

What Examiners Look For

  1. Definitions: Clearly distinguish between IDS vs. IPS, firewall types, and honeypot categories.
  2. Diagrams: Draw network topologies (e.g., DMZ placement) and rule processing flows.
  3. Real-World Applications: Link concepts to Nepali companies (e.g., Ncell’s IPS, Daraz’s firewall).
  4. Worked Examples: Show step-by-step rule matching or log analysis.
  5. Trade-offs: Discuss false positives/negatives and performance vs. security.

Common Mistakes to Avoid

  • Confusing IDS and IPS: Remember, IDS detects, IPS prevents.
  • Ignoring Rule Order: Firewall rules are top-down; the first match wins.
  • Overlooking Honeypots: They are not firewalls but decoy systems.
  • Not Drawing Diagrams: Always include network layouts or Mermaid sequences for protocol flows.

Sample Exam Questions & How to Answer

Q1: "Explain how a stateful firewall differs from a packet-filtering firewall with an example." Answer Structure:

  1. Definition: Packet filtering = header-only; stateful = tracks connections.
  2. Example: Show a TCP handshake where packet filtering allows SYN but drops ACK (if no rule), while stateful allows both.
  3. Diagram: Use a Mermaid sequence for the handshake.

Q2: "Describe how a SIEM tool would detect a data exfiltration attack in a corporate network." Answer Structure:

  1. Log Sources: Firewall (unusual outbound), IDS (anomalous traffic), database (bulk queries).
  2. Correlation: SIEM matches time, IP, and user across logs.
  3. Response: Alert admin + block IP via firewall.

Based on the PU BE Computer (PU) syllabus for Network and Cyber Security (CMP426), unit 7.

Discussion

Loading…