ENGLISH

Linux Firewalls: Attack Detection and Response

Book information

Publisher
No Starch Press
Year
2007
ISBN
1593271417, 9781593271411
Language
english
Format
PDF
Filesize
7 MB (7038744 bytes)
Edition
Pages
336\338
Time added
2021-03-19 15:43:24

Description

System administrators need to stay ahead of new security vulnerabilities that leave their networks exposed every day. A firewall and an intrusion detection systems (IDS) are two important weapons in that fight, enabling you to proactively deny access and monitor network traffic for signs of an attack. Linux Firewalls discusses the technical details of the iptables firewall and the Netfilter framework that are built into the Linux kernel, and it explains how they provide strong filtering, Network Address Translation (NAT), state tracking, and application layer inspection capabilities that rival many commercial tools. You'll learn how to deploy iptables as an IDS with psad and fwsnort and how to build a strong, passive authentication layer around iptables with fwknop. Concrete examples illustrate concepts such as firewall log analysis and policies, passive network authentication and authorization, exploit packet traces, Snort ruleset emulation, and more with coverage of these topics: Passive network authentication and OS fingerprinting iptables log analysis and policies Application layer attack detection with the iptables string match extension Building an iptables ruleset that emulates a Snort ruleset Port knocking vs. Single Packet Authorization (SPA) Tools for visualizing iptables logs Perl and C code snippets offer practical examples that will help you to maximize your deployment of Linux firewalls. If you're responsible for keeping a network secure, you'll find Linux Firewalls invaluable in your attempt to understand attacks and use iptables-along with psad and fwsnort-to detect and even prevent compromises. Acknowledgments Foreword Introduction Why Detect Attacks with iptables? What About Dedicated Network Intrusion Detection Systems? Defense in Depth Prerequisites Technical References About the Website Chapter Summaries 1: Care and Feeding of iptables iptables Packet Filtering with iptables Tables Chains Matches Targets Installing iptables Kernel Configuration Essential Netfilter Compilation Options Finishing the Kernel Configuration Loadable Kernel Modules vs. Built-in Compilation and Security Security and Minimal Compilation Kernel Compilation and Installation Installing the iptables Userland Binaries Default iptables Policy Policy Requirements iptables.sh Script Preamble The INPUT Chain The OUTPUT Chain The FORWARD Chain Network Address Translation Activating the Policy iptables-save and iptables-restore Testing the Policy: TCP Testing the Policy: UDP Testing the Policy: ICMP Concluding Thoughts 2: Network Layer Attacks and Defense Logging Network Layer Headers with iptables Logging the IP Header Network Layer Attack Definitions Abusing the Network Layer Nmap ICMP Ping IP Spoofing IP Fragmentation Low TTL Values The Smurf Attack DDoS Attacks Linux Kernel IGMP Attack Network Layer Responses Network Layer Filtering Response Network Layer Thresholding Response Combining Responses Across Layers 3: Transport Layer Attacks and Defense Logging Transport Layer Headers with iptables Logging the TCP Header Logging the UDP Header Transport Layer Attack Definitions Abusing the Transport Layer Port Scans Port Sweeps TCP Sequence Prediction Attacks SYN Floods Transport Layer Responses TCP Responses UDP Responses Firewall Rules and Router ACLs 4: Application Layer Attacks and Defense Application Layer String Matching with iptables Observing the String Match Extension in Action Matching Non-Printable Application Layer Data Application Layer Attack Definitions Abusing the Application Layer Snort Signatures Buffer Overflow Exploits SQL Injection Attacks Gray Matter Hacking Encryption and Application Encodings Application Layer Responses 5: Introducing psad: The Port Scan Attack Detector History Why Analyze Firewall Logs? psad Features psad Installation psad Administration Starting and Stopping psad Daemon Process Uniqueness iptables Policy Configuration syslog Configuration whois Client psad Configuration /etc/psad/psad.conf /etc/psad/auto_dl /etc/psad/signatures /etc/psad/snort_rule_dl /etc/psad/ip_options /etc/psad/pf.os Concluding Thoughts 6: psad Operations: Detecting Suspicious Traffic Port Scan Detection with psad TCP connect() Scan TCP SYN or Half-Open Scan TCP FIN, XMAS, and NULL Scans UDP Scan Alerts and Reporting with psad psad Email Alerts psad syslog Reporting Concluding Thoughts 7: Advanced psad Topics: From Signature Matching to OS Fingerprinting Attack Detection with Snort Rules Detecting the ipEye Port Scanner Detecting the LAND Attack Detecting TCP Port 0 Traffic Detecting Zero TTL Traffic Detecting the Naptha Denial of Service Attack Detecting Source Routing Attempts Detecting Windows Messenger Pop-up Spam psad Signature Updates OS Fingerprinting Active OS Fingerprinting with Nmap Passive OS Fingerprinting with p0f DShield Reporting DShield Reporting Format Sample DShield Report Viewing psad Status Output Forensics Mode Verbose/Debug Mode Concluding Thoughts 8: Active Response with psad Intrusion Prevention vs. Active Response Active Response Trade-offs Classes of Attacks False Positives Responding to Attacks with psad Features Configuration Variables Active Response Examples Active Response Configuration Settings SYN Scan Response UDP Scan Response Nmap Version Scan FIN Scan Response Maliciously Spoofing a Scan Integrating psad Active Response with Third-Party Tools Command-Line Interface Integrating with Swatch Integrating with Custom Scripts Concluding Thoughts 9: Translating Snort Rules into iptables Rules Why Run fwsnort? Defense in Depth Target-Based Intrusion Detection and Network Layer Defragmentation Lightweight Footprint Inline Responses Signature Translation Examples Nmap command attempt Signature Bleeding Snort “Bancos Trojan” Signature PGPNet connection attempt Signature The fwsnort Interpretation of Snort Rules Translating the Snort Rule Header Translating Snort Rule Options: iptables Packet Logging Snort Options and iptables Packet Filtering Unsupported Snort Rule Options Concluding Thoughts 10: Deploying fwsnort Installing fwsnort Running fwsnort Configuration File for fwsnort Structure of fwsnort.sh Command-Line Options for fwsnort Observing fwsnort in Action Detecting the Trin00 DDoS Tool Detecting Linux Shellcode Traffic Detecting and Reacting to the Dumador Trojan Detecting and Reacting to a DNS Cache-Poisoning Attack Setting Up Whitelists and Blacklists Concluding Thoughts 11: Combining psad and fwsnort Tying fwsnort Detection to psad Operations WEB-PHP Setup.php access Attack Revisiting Active Response psad vs. fwsnort Restricting psad Responses to Attacks Detected by fwsnort Combining fwsnort and psad Responses DROP vs. REJECT Targets Thwarting Metasploit Updates Metasploit Update Feature Signature Development Busting Metasploit Updates with fwsnort and psad Concluding Thoughts 12: Port Knocking vs. Single Packet Authorization Reducing the Attack Surface The Zero-Day Attack Problem Zero-Day Attack Discovery Implications for Signature-Based Intrusion Detection Defense in Depth Port Knocking Thwarting Nmap and the Target Identification Phase Shared Port-Knocking Sequences Encrypted Port-Knocking Sequences Architectural Limitations of Port Knocking Single Packet Authorization Addressing Limitations of Port Knocking Architectural Limitations of SPA Security Through Obscurity? Concluding Thoughts 13: Introducing fwknop fwknop Installation fwknop Configuration /etc/fwknop/fwknop.conf /etc/fwknop/access.conf Example /etc/fwknop/access.conf File fwknop SPA Packet Format Deploying fwknop SPA via Symmetric Encryption SPA via Asymmetric Encryption Detecting and Stopping a Replay Attack Spoofing the SPA Packet Source Address fwknop OpenSSH Integration Patch SPA over Tor Concluding Thoughts 14: Visualizing iptables Logs Seeing the Unusual Gnuplot Gnuplot Graphing Directives Combining psad and Gnuplot AfterGlow iptables Attack Visualizations Port Scans Port Sweeps Slammer Worm Nachi Worm Outbound Connections from Compromised Systems Concluding Thoughts A: Attack Spoofing Connection Tracking Spoofing exploit.rules Traffic Spoofed UDP Attacks B: A Complete fwsnort Script Index Updates

Similar books