Abstract
Building on the previous chapter, I will now examine attacks and defenses for networks and how they have evolved over time as network architectures and attack vectors have evolved. Because this chapter is about classical network security, I will focus on perimeter defenses built around firewalls, proxies, and other similar devices. Intrusion detection, including defensive deception, provides a second layer of security by identifying intruders if they get past the outer walls. I also discuss how attackers bypass network security systems.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Similar content being viewed by others
Notes
- 1.
This includes time setting up, configuring, and deploying the network architecture and security policy enforcement mechanisms. It also includes time monitoring the network for intrusion, audits to ensure changes remain compliant, and reconfiguring based on changing IT and security needs.
- 2.
In a historic irony, the view that network security is a bad idea and the only solution is secure hosts has returned in at least some form with the advent of zero trust security. Zero trust security is not considered in this book, which focuses on more classical security technologies. However, suffice it to say that in this zero trust model, the internal network is no longer trusted [279]. Unfortunately, most classical network security, the subject of this chapter, is quickly becoming obsolete. You have to start with the classic tech first, however, in order to understand what is changing and where computer security is going.
- 3.
These devices are, in fact, still implemented on general-purpose computer technologies, but the systems are (supposed to be) stripped down to only include components necessary for the security operations.
- 4.
Again, Appendix C provides an overview of the differences between UDP and TCP. Those differences are not particularly important here; the point is that a firewall that examines layer-4 data can tell the difference between layer-4 protocols.
- 5.
This is a specially reserved port number that should almost never be used but can return results in some circumstances.
- 6.
Please note, I am going to cite other papers and sources more heavily in this section than I have elsewhere. I am providing only a relatively brief overview of a very important technology. I figured it would be better to include a wide range of reference material here for those that want to investigate other sources instead of filling the “Further Reading” section with all of them.
- 7.
I will refer to this as Martha’s idea, not Stoll’s. Most references that I read do not properly attribute the idea to her. For example, see Bishop’s book on computer security [60, Chapter 27].
- 8.
I have very slightly edited this quote from the book for clarity.
- 9.
Again, you rarely see attribution when Stoll’s work is discussed.
- 10.
Each of these definitions comes from a different source. Refer to the survey [207] for attribution.
References
Cortex XDR incident handling v3.
Active deception to combat advanced threats. Technical report, Attivo Networks, 2019.
CVE-2021-44228. 11 2021.
Packet flow sequence in PAN-OS. 06 2021.
Ahmed, J., H.H. Gharakheili, Q. Raza, C. Russell, and V. Sivaraman. 2019. Real-time detection of DNS exfiltration and tunneling from enterprise networks. In 2019 IFIP/IEEE Symposium on Integrated Network and Service Management (IM), 649–653.
Alshamrani, A., S. Myneni, A. Chowdhary, and D. Huang. 2019. A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities. IEEE Communications Surveys and Tutorials 21(2): 1851–1877.
Alessandro Bulgarelli, M.A., and M.C. Francesca Mazzoni. 2005. Honeyspam: Honeypots fighting spam at the source. In Steps to Reducing Unwanted Traffic on the Internet Workshop (SRUTI’05), Cambridge, MA, ed. by D. Katabi and B. Krishnamurthy. USENIX Association.
Anderson, R.J. 2020. Security Engineering: A Guide to Building Dependable Distributed Systems, 3 ed. Wiley Publishing.
Bellovin, S.M., and W.R. Cheswick. 1994. Network firewalls. IEEE Communications Magazine 32(9): 50–57.
Beyer, B.A.E., C.M. Beske, J. Peck, and M. Saltonstall. 2017. Migrating to beyondcorp: Maintaining productivity while improving security. Login42(2). ISSN 1044-6397.
Bishop, M. 2019. Computer Security Art and Science, 2nd ed. Addison-Wesley Professional.
Braden, R., and J. Postel. 1987. Requirements for internet gateways (1009).
Chatel, M. 1996. Classical versus transparent IP proxies (1919).
Cheswick, W.R., S.M. Bellovin, and A.D. Rubin. 2003. Firewalls and Internet Security, 2nd ed. Addison Wesley Professional.
Cohen, F. 2004. The use of deception techniques: Honeypots and decoys.
Devlin, R. 2016. Data loss prevention—Devlin. Technical report, SANS Institute.
Economy, E.C. 2018. The great firewall of China: Xi Jinping’s internet shutdown. The Guardian
Findley, N. 1993. Shadowplay. Penguin Group.
Force, J.T. 2018. Risk management framework for information systems and organizations. Special Publication (NIST SP) 800-37r2, National Institute of Standards and Technology, Gaithersburg.
Garber, M. 2014. There are 64 tiananmen terms censored on China’s internet today. The Atlantic.
Group, J.T.F.T.I.I.W. 2020. Security and privacy controls for federal information systems and organizations. Special Publication (NIST SP) 800-53r5, National Institute of Standards and Technology, Gaithersburg.
Hernacki, B., J. Bennett, and T. Lofgren. 2004. Symantec deception server experience with a commercial deception system. In Recent Advances in Intrusion Detection, ed. E. Jonsson, A. Valdes, and M. Almgren, 188–202. Berlin/Heidelberg: Springer.
Karami, M., and D. McCoy. 2013. Understanding the emerging threat of DDoS-as-a-Service. In 6th USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET 13), Washington, DC. USENIX Association.
Luo, T., Z. Xu, X. Jin, Y. Jia, and X. Ouyang. 2017. Iotcandyjar: Towards an intelligent-interaction honeypot for IoT devices, 1–11.
Luotonen, A., and K. Altis. 1994. World-wide web proxies. Computer Networks and ISDN Systems 27(2): 147–154. Selected Papers of the First World-Wide Web Conference.
Mairh, A., D. Barik, K. Verma, and D. Jena. 2011. Honeypot in network security: A survey. In Proceedings of the 2011 International Conference on Communication, Computing and Security (ICCCS’11), New York, 600–605. Association for Computing Machinery.
Mann, D.E., and S.M. Christey. 1999. Towards a common enumeration of vulnerabilities. In 2nd Workshop on Research with Security Vulnerability Databases, West Lafayette.
McRae, C.M., and R.B. Vaughn. 2007. Phighting the phisher: Using web bugs and honeytokens to investigate the source of phishing attacks. In 2007 40th Annual Hawaii International Conference on System Sciences (HICSS’07), 270c.
Meadows, C. 1995. Applying the dependability paradigm to computer security. In Proceedings of 1995 New Security Paradigms Workshop, 75–79.
Moussaileb, R., B. Bouget, A. Palisse, H. Le Bouder, N. Cuppens, and J.-L. Lanet. 2018. Ransomware’s early mitigation mechanisms. In Proceedings of the 13th International Conference on Availability, Reliability and Security (ARES 2018), New York. Association for Computing Machinery.
Mphago, B., O. Bagwasi, B. Phofuetsile, and H. Hlomani. 2015. Deception in dynamic web application honeypots: Case of Glastopf. In Proceedings of the International Conference on Security and Management (SAM’15), Las Vegas, ed. by K. Daimi and H.R. Arabnia.
Osborn, B., J. McWilliams, B. Beyer, and M. Saltonstall. 2016. Beyondcorp: Design to deployment at Google. ;login: 41: 28–34.
Park, Y., and S.J. Stolfo. 2012. Software decoys for insider threat. In Proceedings of the 7th ACM Symposium on Information, Computer and Communications Security (ASIACCS’12), New York, 93–94. Association for Computing Machinery.
Peterson, L.L., and B.S. Davie. 2021. Computer Networks, 6th ed. Morgan Kaufmann.
Pouget, F., M. Dacier, and H. Debar. 2003. White paper: Honeypot, honeynet, honeytoken: Terminological issues. Technical Report RR-03-081, Eurecom.
Poulsen, K. 2003. Matrix sequel has hacker cred. The Register.
Provos, N. 2004 A virtual honeypot framework. In 13th USENIX Security Symposium (USENIX Security 04), San Diego. USENIX Association.
Ranum, M.J. 1994. Thinking about firewalls. In Proceedings of Second International Conference on Systems and Network Security and Management (SANS-II).
Rose, S., O. Borchert, S. Mitchell, and S. Connelly. 2020. Zero trust architecture. Special Publication (NIST SP) 800-207, National Institute of Standards and Technology, Gaithersburg.
Rowe, N.C., and J. Rrushi. 2016. Introduction to Cyberdeception, 1 ed. Springer International Publishing Switzerland.
Scarfone, K., and P. Mell. 2007. Guide to intrusion detection and prevention systems (IDPS). Special Publication (NIST SP) 800-94, National Institute of Standards and Technology, Gaithersburg.
Shinder, T.W. 2008. The Best Damn Firewall Book Period, 2nd ed. Syngress.
Spitzner, L. 2003. Honeypots: Catching the insider threat. In 19th Annual Computer Security Applications Conference, 2003, 170–179. IEEE.
Spitzner, L. 2003. Honeytokens: The other honeypot.
Stewart, J.M., and D. Kinsey. 2020. Network Security, Firewalls, and VPNs, 3rd ed. Jones & Bartlett Learning.
Stoll, C. 1989. The Cuckoo’s Egg: Tracking a Spy Through the Maze of Computer Espionage. New York: Doubleday.
Suljkanovic, S. 2005. Honeypots or honey delusions. Technical report, SANS Institute.
Tzu, S. 2002. Sun Tzu: Art of War. Trans. Ralph D. Sawyer. Basic Books.
Ward, R., and B. Beyer. 2014. Beyondcorp: A new approach to enterprise security. ;login: 39(6): 6–11.
Yang, S. 2022. As China shuts out the world, internet access from abroad gets harder too. LA Times.
Author information
Authors and Affiliations
Rights and permissions
Copyright information
© 2023 The Author(s), under exclusive license to APress Media, LLC, part of Springer Nature
About this chapter
Cite this chapter
Nielson, S.J. (2023). Classical Network Security Technology. In: Discovering Cybersecurity. Apress, Berkeley, CA. https://doi.org/10.1007/978-1-4842-9560-1_8
Download citation
DOI: https://doi.org/10.1007/978-1-4842-9560-1_8
Published:
Publisher Name: Apress, Berkeley, CA
Print ISBN: 978-1-4842-9559-5
Online ISBN: 978-1-4842-9560-1
eBook Packages: Professional and Applied ComputingApress Access BooksProfessional and Applied Computing (R0)