Bài giảng Mạng máy tính nâng cao - Chương 13: Firewall
Số trang: 16
Loại file: pdf
Dung lượng: 564.38 KB
Lượt xem: 24
Lượt tải: 0
Xem trước 2 trang đầu tiên của tài liệu này:
Thông tin tài liệu:
Bài giảng Mạng máy tính nâng cao - Chương 13: Firewall bao gồm những nội dung về Firewalls (Stateless packet filtering, Stateful packet filtering, Application Gateways); Intrusion Detection Systems (IDS), Denial of Service Attacks.
Nội dung trích xuất từ tài liệu:
Bài giảng Mạng máy tính nâng cao - Chương 13: FirewallMạng máy tính nâng cao-V11Firewalls & IDS OutlineFirewalls◦ Stateless packet filtering◦ Stateful packet filteringAccess Control Lists◦ Application GatewaysIntrusion Detection Systems (IDS)◦ Denial of Service Attacks2FirewallsFirewallisolates organization’s internal net from larger Internet, allowing somepackets to pass, blocking others.publicInternetadministerednetworkfirewall3Why Firewalls?prevent denial of service (DoS) attacks:• SYN flooding: attacker establishes many bogus TCPconnections, no resources left for “real” connections.prevent illegal modification/access of internal data.• e.g., attacker replaces CIA’s homepage with somethingelse.allow only authorized access to inside network (set ofauthenticated users/hosts)three types of firewalls:1. stateless packet filters2. stateful packet filters3. application gateways4Stateless Packet FilteringShould arriving packetbe allowed in?Departing packet letout?internal network connected to Internet via routerfirewall.router filters packet-by-packet, decision toforward/drop packet based on:◦◦◦◦source IP address, destination IP addressTCP/UDP source and destination port numbersICMP message typeTCP SYN and ACK bits.5
Nội dung trích xuất từ tài liệu:
Bài giảng Mạng máy tính nâng cao - Chương 13: FirewallMạng máy tính nâng cao-V11Firewalls & IDS OutlineFirewalls◦ Stateless packet filtering◦ Stateful packet filteringAccess Control Lists◦ Application GatewaysIntrusion Detection Systems (IDS)◦ Denial of Service Attacks2FirewallsFirewallisolates organization’s internal net from larger Internet, allowing somepackets to pass, blocking others.publicInternetadministerednetworkfirewall3Why Firewalls?prevent denial of service (DoS) attacks:• SYN flooding: attacker establishes many bogus TCPconnections, no resources left for “real” connections.prevent illegal modification/access of internal data.• e.g., attacker replaces CIA’s homepage with somethingelse.allow only authorized access to inside network (set ofauthenticated users/hosts)three types of firewalls:1. stateless packet filters2. stateful packet filters3. application gateways4Stateless Packet FilteringShould arriving packetbe allowed in?Departing packet letout?internal network connected to Internet via routerfirewall.router filters packet-by-packet, decision toforward/drop packet based on:◦◦◦◦source IP address, destination IP addressTCP/UDP source and destination port numbersICMP message typeTCP SYN and ACK bits.5
Tìm kiếm theo từ khóa liên quan:
Mạng máy tính nâng cao Bài giảng Mạng máy tính nâng cao Stateless packet filtering Stateful packet filtering Application Gateways Intrusion Detection SystemsTài liệu có liên quan:
-
Advanced Computer Networks: Lecture 7 - Dr. Amir Qayyum
29 trang 51 0 0 -
Advanced Computer Networks: Lecture 6 - Dr. Amir Qayyum
46 trang 45 0 0 -
Advanced Computer Networks: Lecture 35 - Dr. Amir Qayyum
16 trang 42 0 0 -
Advanced Computer Networks: Lecture 17 - Dr. Amir Qayyum
44 trang 39 0 0 -
Advanced Computer Networks: Lecture 8 - Dr. Amir Qayyum
34 trang 38 0 0 -
Advanced Computer Networks: Lecture 11 - Dr. Amir Qayyum
26 trang 37 0 0 -
Advanced Computer Networks: Lecture 40 - Dr. Amir Qayyum
31 trang 36 0 0 -
Advanced Computer Networks: Lecture 20 - Dr. Amir Qayyum
11 trang 35 0 0 -
Advanced Computer Networks: Lecture 34 - Dr. Amir Qayyum
21 trang 35 0 0 -
Advanced Computer Networks: Lecture 18 - Dr. Amir Qayyum
8 trang 35 0 0