Network Security - Network Aspects and Fundamentals

Internet Communication and Autonomous Systems

The Internet is fundamentally a "network of networks," composed of numerous logically separated networks known as Autonomous Systems (AS). Each AS is responsible for autonomously managing communications within its own boundaries using specific protocols.

  • Interior Gateway Protocols (IGP): These are used to route traffic within a single AS. Common examples include:
    • Routing Information Protocol (RIP)
    • Open Shortest Path First (OSPF)
  • Exterior Gateway Protocols (EGP): These are employed to route traffic between different Autonomous Systems. The most prominent example is the Border Gateway Protocol (BGP).

The OSI Reference Model

The Open Systems Interconnection (OSI) model organizes network communication into layers. The transcript provides examples for various layers:

  • Application Layer (Data): HTTP, Mail, Chat protocols, encoding information, RPC, Telnet.
  • Session Layer (Data): TLS, SSL.
  • Transport Layer (Segments or Datagrams): TCP, UDP.
  • Network Layer (Packet): IPv4, IPv6.
  • Data Link Layer (Frame): Ethernet, PPP.
  • Physical Layer (Bit): Ethernet cable, optical fiber.

Data Link Layer and MAC Addressing

The Data Link Layer is the lowest "logical" level, interconnecting physical interfaces. Every physical interface is uniquely identified by a Media Access Control (MAC) address, often referred to as an "Ethernet address."

  • Structure: MAC addresses are 4848-bit identifiers.
  • Notation: They are represented in Hexadecimal (HEX) notation as HH−HH−HH−HH−HH−HHHH-HH-HH-HH-HH-HH.
  • Function: They represent the final destination of a frame and are used to route packets within local networks.
  • Assignment: These addresses are fixed and assigned by the hardware producer according to the IEEE 802 standard.
MAC Address Composition and Identification
  • Organizationally Unique Identifier (OUI): The first 2424 bits are set by the IEEE standard and identify the producer of the network interface. For example, the prefix 00−10−BC00-10-BC identifies Aastra Telecom.
  • Host Logic: When a frame is sent to a specific MAC address (e.g., 00−10−BC−2c−11−5600-10-BC-2c-11-56), the interface with that address keeps the frame, while others drop it.
System Commands for Network Interfaces
  • Unix/Mac: ifconfig (lists interfaces) or networksetup -listallhardwareports.
  • Windows: ipconfig.

Network Layer and IP Addressing

The Network Layer provides the necessary information to reach other systems via addressing functionalities. The Internet Protocol (IP) operates at this layer.

  • Function: It provides a high-level representation of a host's address and conveys the information needed to route datagrams.
  • Connectionless Nature: IP is a stateless protocol. It has no notion of an "established connection"; it simply provides the means for a packet to reach its destination.
  • Address Assignment: Unlike MAC addresses which are fixed by vendors, most IP addresses are dynamically assigned by an authority, such as an Internet Service Provider's (ISP) DHCP server.
Comparison: IPv4 vs. IPv6
  • IPv4: The most common version currently in use. It utilizes 3232 bits for addressing.
  • IPv6: Increasing in adoption; will be common in the future. It utilizes 128128 bits for addressing.
Address Space Considerations

With a 4848-bit MAC address system, there are 2482^{48} possible addresses, which equals 281,474,976,710,656281,474,976,710,656 (approximately 15361536 Terabytes if each address were a byte). IP addresses abstract host addresses away from physical properties to manage issues like hardware substitution (revoking/replacing an Ethernet card) and global routing between Autonomous Systems.

Address Resolution Protocol (ARP)

ARP allows systems to associate a known IP address with a corresponding MAC address. This is essential for local network delivery where IP packets must be encapsulated in Ethernet frames.

ARP Mechanism
  • ARP Tables: These tables contain mapping information (IP address to MAC address), along with other data like Time to Live (TTL) and interface details.
  • ARP Query (Discovery): If a system (System A) wants to send data to an IP (System D) but does not have the MAC address in its table, it initiates a discovery process.
    • Broadcast: System A sends a broadcast message to the L2 Ethernet address FF−FF−FF−FF−FF−FFFF-FF-FF-FF-FF-FF.
    • Request-Reply: The message asks "who has [IP address]? tell [My IP]." All hosts receive the broadcast; those whose IP does not match drop the request. The host with the matching IP replies with its MAC address.
  • Gratuitous ARP: A system can preemptively announce its IP-to-MAC mapping to the network.
ARP Frame Header Structure (3232 bits wide)
  1. Hardware Type (1616 bits)
  2. Protocol Type (1616 bits)
  3. Hardware Address Length (88 bits)
  4. Protocol Address Length (88 bits)
  5. Operation (Opcode): 11 for request, 22 for reply (1616 bits)
  6. Sender Hardware Address (Octets 0−50-5)
  7. Sender IP Address (Octets 0−30-3)
  8. Target Hardware Address (Octets 0−50-5)
  9. Target IP Address (Octets 0−30-3)

Network Security: ARP Poisoning

ARP is a declarative, non-authenticated protocol. Nodes are not required to provide proof of identity.

  • The Attack: An attacker (System C) can send unsolicited ARP messages (or replies to queries not intended for them) telling System B that "System A is at [C's MAC address]" and telling System A that "System B is at [C's MAC address]."
  • Result: This establishes a Man-in-the-Middle (MitM) position. Every communication between A and B passes through C.
  • Limitations: This attack only works on local networks where MAC addresses are meaningful. However, since routers and DNS servers also have MAC addresses, they can be targeted to intercept outgoing traffic.
  • Mitigation: Some third-party tools can monitor for anomalies, although the protocol's lack of authentication remains a core vulnerability.

Subnets and CIDR

Subnets are logical divisions of IP address ranges. An IP address is divided into network bits, subnet bits, and host bits.

  • Subnet Mask: Indicates which part of the IP address belongs to the network/subnet versus the host (e.g., 255.255.255.0255.255.255.0 means 2424 bits for the network/subnet and 88 bits for hosts).
  • CIDR (Classless Inter-Domain Routing): A synthetic notation representing the number of bits in the mask. For example, 192.168.10.1/24192.168.10.1/24 is equivalent to a mask of 255.255.255.0255.255.255.0.
Calculation Example

For an IP address 132.134.15.96132.134.15.96 with a mask of 255.255.0.0255.255.0.0:

  • CIDR: 132.134.15.96/16132.134.15.96/16
  • Binary Operation:
    • Network = IP AND SubnetIP\text{ AND }Subnet
    • Host = IP AND complement(Subnet)IP\text{ AND }\text{complement}(Subnet)
  • Total Hosts: 216−1=65,536−1=65,5352^{16} - 1 = 65,536 - 1 = 65,535

IP Classes and Private Addresses

IPv4 Classes
  • Class A: 0.0.0.0/80.0.0.0/8 to 127.255.255.255/8127.255.255.255/8 (Standard)
  • Class B: 128.0.0.0/16128.0.0.0/16 to 191.255.255.255/16191.255.255.255/16 (Standard)
  • Class C: 192.0.0.0/24192.0.0.0/24 to 223.255.255.255/24223.255.255.255/24 (Standard)
  • Class D: 224.0.0.0224.0.0.0 to 239.255.255.255239.255.255.255 (Multicast)
  • Class E: 240.0.0.0240.0.0.0 to 254.255.255.254254.255.255.254 (Experimental)
Reserved Private Address Ranges

These IPs are not routed on the public Internet; gateways should drop datagrams with these destinations:

  • 10.0.0.010.0.0.0 to 10.255.255.25510.255.255.255
  • 192.168.0.0192.168.0.0 to 192.168.255.255192.168.255.255
  • 172.16.0.0172.16.0.0 to 172.31.255.255172.31.255.255

IP Header and Fragmentation

IP Header Fields
  • Version: Identifying IPv4 or IPv6.
  • IHL (Internet Header Length): Length of the header.
  • Type of Service: Priority/Quality of Service info.
  • Total Length: Total size of the datagram (max 216−1=65,5352^{16}-1 = 65,535 bytes).
  • Identification (1616 bits): Unique ID for the datagram; all fragments of one datagram share this ID.
  • Flags (33 bits):
    • Bit 0: Reserved (must be 0).
    • DF (Don't Fragment): 00 = can fragment; 11 = do not fragment (drop if fragmentation is required).
    • MF (More Fragments): 00 = last fragment; 11 = more fragments coming.
  • Fragment Offset (1313 bits): The position of the fragment relative to the start of the original datagram, measured in blocks of 88 bytes.
  • Time to Live (TTL): Hop count limit.
  • Protocol: Identifying the next level protocol (TCP, UDP, ICMP).
  • Header Checksum: For error detection.
  • Source/Destination Addresses: 3232-bit IP addresses.
Fragmentation Example

If sending 42004200 bytes of data over Ethernet (MTU = 15001500 bytes):

  • Fragment 1: 2020 bytes header + 14801480 bytes data (15001500 total), offset = 00, MF=1.
  • Fragment 2: 2020 bytes header + 14801480 bytes data (15001500 total), offset = 185185 (calculated as 1480/81480/8), MF=1.
  • Fragment 3: 2020 bytes header + remainder data (12601260 bytes), offset = 370370 (calculated as 185×2185 \times 2), MF=0.

Internet Control Message Protocol (ICMP)

Defined in RFC 792, ICMP is an integral part of the IP suite used for status and error reporting.

Common ICMP Message Types
  • Type 3 (Destination Unreachable): Codes include 00 (net), 11 (host), 22 (protocol), 33 (port), 44 (fragmentation needed but DF set).
  • Type 11 (Time Exceeded): Used when TTL reaches 00. This is the basis for the Traceroute tool, which sends packets with increasing TTL values (1,2,3...1, 2, 3...) to map the path to a destination.
  • Type 8 (Echo Message) & Type 0 (Echo Reply): Used by the Ping utility.

Denial of Service (DoS) Attacks

DoS attacks aim to overpower a system's capacity by generating requests, leading to performance degradation or crashes.

Ping Flood

An attacker with high bandwidth sends a flood of ICMP Echo requests (Type 8) to a target. The target's bandwidth is exhausted by both receiving the requests and attempting to send Echo replies (Type 0).

Ping of Death

A classic attack involving oversized ICMP packets.

  • The maximum length of an IP packet (including header) is 65,53565,535 bytes.
  • The maximum offset is 81918191 blocks (8191×8=65,5288191 \times 8 = 65,528 bytes).
  • An attacker can craft fragments that, when reassembled, exceed the 65,53565,535 byte limit (e.g., a final fragment at the max offset with enough data to push the total size to 66,60066,600 bytes).
  • Early implementations failed to handle this, resulting in buffer overflows and system crashes.
  • Note: Modern versions of this mistake exist, such as CVE-2013-3183 (ICMPv6) and CVE-2020-16898.

Useful Network Tools

  • Wireshark / tcpdump: Used for traffic monitoring (ARP, DNS, TCP 3-way handshakes).
  • Nmap: Used for network scanning (TCP, UDP ports).
  • Scapy: A Python interface for manual packet crafting at any level of the stack.
  • Ettercap: Specifically designed for MitM attacks, including ARP poisoning.
  • Netcat: A legacy tool for generating UDP/TCP traffic.