munotes®

Firewall and Filter Detection

Get access to whole semester resourcesSemester Pass

Chapter Forty-One

Syllabus topic Module 1, "Network Scanning and Port Scanning Techniques: ... along with firewall detection logic"

Pages 196 to 200 of 578

In one line

A firewall cannot hide completely: the way it interferes with replies tells you it is there and roughly what it is doing. A firewall that rejects announces itself; one that drops makes the scanner guess, which is why dropping is the better default.

In examination wording: firewall detection is the inference, from the pattern of responses and non-responses to crafted probes, of whether traffic is being filtered, by what kind of device, and according to what rules; a filtering device that returns an explicit refusal discloses its presence and rule, whereas one that silently discards traffic denies the scanner the information it seeks.

The logic in one idea

The handshake chapter established that a direct TCP exchange has only two lawful outcomes: SYN/ACK or RST. Silence is impossible between two hosts talking directly.

Therefore any third outcome is evidence of a third party. That is the whole of firewall detection logic, and everything below refines it: which third outcome, on which ports, with what timing, tells you what kind of device is in the path and what rule it is applying.

Reject against drop

A filtering device meeting unwanted traffic has two choices, and the difference governs everything.

Reject. Send back an explicit refusal: a TCP RST, or an ICMP destination unreachable message, often with the code meaning administratively prohibited. The sender learns immediately that the connection will not happen.

Drop. Discard the packet and send nothing. The sender waits, retransmits, and eventually times out.

RejectDrop
Scanner learnsA filter exists, and this port is blockedOnly that no answer came
Reported stateFiltered, with the firewall confirmedFiltered, cause unproven
Speed of failureImmediateA full timeout, then retries
Effect on scan timeFastSlow, which is itself a defence
Legitimate misrouted trafficFails fast and clearlyHangs, which frustrates diagnosis

The security conclusion: drop is the better default for internet-facing filters, because it gives an attacker less information and makes scanning expensive in time. The ICMP administratively prohibited message is a particularly generous disclosure, since it names the cause, and it should not be sent to untrusted networks.

The counter-argument deserves a fair hearing: dropping makes legitimate misconfiguration hard to diagnose, because a client with a wrong setting hangs instead of failing cleanly. The usual resolution is to drop at the perimeter and reject internally, so outsiders learn nothing while staff get useful errors.

What each observation lets you infer

This is the "logic" MU asks for, set out as inferences rather than tools.

RST from every port, open and closed alike. No filtering on those ports, or a device that rejects uniformly. Compare with an ACK scan to distinguish.

munotes.in196

Firewall and Filter Detection

Some ports answer, others are silent. A firewall with per-port rules. The boundary between answering and silent ports is the rule set, and mapping it is the single most useful output of this work.

Every port silent, but the host is known to be alive (from an ARP reply or another route): a default-deny firewall dropping everything not explicitly permitted. This is the secure posture, and the fact that it is recognisable is not a weakness.

Silence on a SYN scan but RST on an ACK scan. A stateless filter: it blocks connection attempts but passes segments that resemble established traffic. This is the comparison developed in the ACK-scan chapter and it is the most technically informative single observation in the block.

Silence on both. A stateful firewall tracking connections.

ICMP administratively prohibited. A rejecting filter, and the message frequently reveals the filtering device's own address, which is a further disclosure.

Timing differences. A dropped packet times out; a rejected one fails at once. Consistent slow failures across a range indicate dropping.

Different results by source port or protocol. Some rule sets permit traffic that appears to come from a trusted service port, or treat UDP differently from TCP. Testing from varied source ports can reveal a rule written more loosely than intended, which is a genuine finding.

Hop-count differences. A traceroute that stops at a consistent hop before the target locates the filtering device in the path and reveals the perimeter's structure.

The kinds of firewall

The inference depends on what is in the path, so the vocabulary is needed.

Packet filter (stateless). Judges each packet alone against rules on addresses, ports and flags. Fast, simple, and unable to tell whether a packet belongs to a real conversation, which is why bare ACK probes pass it.

Stateful inspection firewall. Maintains a table of active connections and permits only packets that fit one, or that legitimately start one. Defeats the ACK scan and the inverse TCP scans in one stroke, and is the modern baseline.

Application-layer firewall or proxy. Understands the protocol it is carrying and can inspect content, not just headers. A web application firewall is this kind specialised for HTTP, and it reappears in the SQL injection and cross-site scripting chapters as an outer net.

Next-generation firewall. Stateful inspection combined with application awareness, identity, and intrusion prevention in one device.

Host-based firewall. On the machine itself. Its importance for this book is that it makes a host unreachable without being absent, which is why the host-discovery chapter insisted that silence is not absence and why ARP finds hosts nothing else does.

Turning the logic into a configuration

Everything above, read as instructions:

  • Default deny. Permit what is needed and drop the rest, rather than blocking known-bad and permitting the rest.
  • Drop, do not reject, at the perimeter. Deny scanners the confirmation and make scanning slow. Reject internally, where diagnosis matters more than obscurity.
  • Do not send administratively-prohibited messages to untrusted networks, since they name the cause and often the device.
  • Be stateful. One change defeats ACK scanning and the FIN, NULL and XMAS scans together.
  • Filter UDP as deliberately as TCP. Rule sets are routinely careful for TCP and permissive for UDP, and the previous chapter showed what lives there.
  • Do not trust source ports. A rule permitting traffic that claims to come from a trusted service port is trivially satisfied by an attacker who chooses that source port.
  • Filter egress as well as ingress. Controlling what may leave breaks command-and-control and data exfiltration, and the Log4Shell case showed it can break an exploit chain outright. It is the most commonly omitted control on this list.
  • Match IPv6 to IPv4. A carefully filtered IPv4 perimeter with an unfiltered IPv6 path is a recurring real finding.
  • Audit the rules against intent, with an ACK scan from outside, and remove rules nobody can justify. Rule sets accumulate.
munotes.in197

Firewall and Filter Detection

A worked example

An assessor audits a perimeter, with authorisation, and reasons from observations to conclusions.

ObservationInference
SYN scan: 80 and 443 answer SYN/ACK; all other ports silent; no port returns RSTDefault-deny firewall that drops. The secure posture, and the absence of any closed port is the tell
ACK scan: only 80 and 443 return RST; the rest silentStateful, since a stateless filter would have passed the bare ACKs
No ICMP administratively-prohibited messages anywhereCorrectly configured not to disclose the cause
Traceroute stops two hops before the hostThe filtering device sits there; the perimeter's structure is visible
Repeating the SYN scan with source port 53Port 3306 now answers. A rule permits traffic claiming to come from DNS
IPv6 scan of the same service names22 and 3306 open over IPv6 with no equivalent filtering

The first four findings are positive and should be reported as such. The last two are serious:

  1. A source-port rule permits access to the database port. Anyone choosing source port 53 reaches it. Remove the rule or make it stateful and address-restricted.
  2. The IPv6 path is unfiltered. The carefully built IPv4 posture is bypassed entirely by using IPv6, which is the more serious of the two because it exposes SSH as well.

The example makes the chapter's point: the firewall was well configured in the ways people usually check, and the failures were in the two places people usually do not, a permissive source-port rule and an unmatched IPv6 policy.

munotes.in198

Firewall and Filter Detection

What beginners get wrong

  • Thinking a firewall makes a host invisible. It changes what the scan learns; open ports you publish are still found, and silence itself is a signal.
  • Assuming reject is friendlier and therefore better. It is friendlier to misrouted legitimate traffic and gives an attacker a clear map. Drop at the perimeter.
  • Reading filtered as closed. Filtered means a device intervened and the service state is unknown.
  • Using an ACK scan to find services. It maps filtered against unfiltered; use SYN for services.
  • Forgetting egress filtering. Controlling outbound traffic breaks command-and-control and exfiltration and can defeat an exploit that needs to fetch a payload.
  • Auditing IPv4 only. An unfiltered IPv6 path silently bypasses the whole rule set.
  • Trusting source ports. Any attacker can choose a source port; a rule based on one is not a control.

Quick revision

  • The logic: a direct TCP exchange must yield SYN/ACK or RST, so any other outcome proves a third party is in the path.
  • Reject (RST or ICMP administratively prohibited) confirms a filter and fails fast; drop yields silence and slow timeouts. Drop at the perimeter, reject internally.
  • Inferences: mixed answering and silent ports mean per-port rules; all silent with the host known alive means default deny; silent to SYN but RST to ACK means stateless; silent to both means stateful; timing and hop counts locate the device; varying the source port can expose a loose rule.
  • Kinds: packet filter (stateless), stateful inspection (the baseline, defeats ACK and inverse scans), application-layer or proxy (including web application firewalls), next-generation, and host-based (makes a host unreachable without being absent).
  • Configuration: default deny, drop at the perimeter, no prohibited messages outward, stateful, deliberate UDP rules, no source-port trust, egress filtering, IPv6 matching IPv4, and periodic rule audits against intent.

Test yourself

  1. State the single principle on which firewall detection rests.

That a direct TCP exchange between two hosts can only produce SYN/ACK or RST, so any other outcome, especially silence or an ICMP error, is evidence that a third device intervened. What kind of outcome, on which ports, with what timing, then indicates the type of device and its rules.

  1. Compare reject and drop, and say which belongs at an internet-facing perimeter and why.

Reject returns an explicit refusal (RST or ICMP administratively prohibited), confirming a filter and failing immediately; drop discards silently, producing timeouts. Drop belongs at the perimeter because it denies the scanner confirmation and makes scanning slow, whereas reject is preferable internally where fast, clear diagnosis of misconfiguration matters more than withholding information.

  1. A host returns SYN/ACK on two ports and silence on every other port, with no port ever returning RST. What do you conclude?
munotes.in199

Firewall and Filter Detection

That a default-deny firewall is dropping all traffic other than the two permitted services. The absence of any closed port is the decisive observation, since a directly reachable host would return RST on ports with no listener.

  1. How is a stateless filter distinguished from a stateful firewall by scanning?

By comparing a SYN scan with an ACK scan. If ports are filtered to SYN but return RST to a bare ACK, the filter is judging packets individually and letting through segments that resemble established traffic, so it is stateless. If both scans are filtered, the device is tracking connections and dropping segments belonging to none, so it is stateful.

  1. Name two commonly omitted firewall controls and explain the risk of each.

Egress filtering, whose absence permits command-and-control traffic and data exfiltration and allows exploits that must fetch a remote payload to complete; and IPv6 rules matching IPv4, whose absence leaves an unfiltered parallel path that bypasses the entire carefully built IPv4 policy. A third acceptable answer is source-port trust, since an attacker can freely choose a source port, so a rule permitting traffic claiming to come from a trusted service port is not a control at all.

munotes.in200

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.

Issue
Done!