tailieunhanh - Bài giảng Mạng máy tính nâng cao - Chương 13: Firewall
Bài giảng Mạng máy tính nâng cao - Chương 13: Firewall bao gồm những nội dung về Firewalls (Stateless packet filtering, Stateful packet filtering, Application Gateways); Intrusion Detection Systems (IDS), Denial of Service Attacks. | Mạng máy tính nâng cao-V1 1 Firewalls & IDS Outline Firewalls ◦ Stateless packet filtering ◦ Stateful packet filtering Access Control Lists ◦ Application Gateways Intrusion Detection Systems (IDS) ◦ Denial of Service Attacks 2 Firewalls Firewall isolates organization’s internal net from larger Internet, allowing some packets to pass, blocking others. public Internet administered network firewall 3 Why Firewalls? prevent denial of service (DoS) attacks: • SYN flooding: attacker establishes many bogus TCP connections, no resources left for “real” connections. prevent illegal modification/access of internal data. • ., attacker replaces CIA’s homepage with something else. allow only authorized access to inside network (set of authenticated users/hosts) three types of firewalls: 1. stateless packet filters 2. stateful packet filters 3. application gateways 4 Stateless Packet Filtering Should arriving packet be allowed in? Departing packet let out? internal network connected to Internet via router firewall. router filters packet-by-packet, decision to forward/drop packet based on: ◦ ◦ ◦ ◦ source IP address, destination IP address TCP/UDP source and destination port numbers ICMP message type TCP SYN and ACK .
đang nạp các trang xem trước