Network Security - Network Aspects and Fundamentals
Internet Communication and Autonomous Systems
The Internet is fundamentally a "network of networks," composed of numerous logically separated networks known as Autonomous Systems (AS). Each AS is responsible for autonomously managing communications within its own boundaries using specific protocols.
- Interior Gateway Protocols (IGP): These are used to route traffic within a single AS. Common examples include:
- Routing Information Protocol (RIP)
- Open Shortest Path First (OSPF)
- Exterior Gateway Protocols (EGP): These are employed to route traffic between different Autonomous Systems. The most prominent example is the Border Gateway Protocol (BGP).
The OSI Reference Model
The Open Systems Interconnection (OSI) model organizes network communication into layers. The transcript provides examples for various layers:
- Application Layer (Data): HTTP, Mail, Chat protocols, encoding information, RPC, Telnet.
- Session Layer (Data): TLS, SSL.
- Transport Layer (Segments or Datagrams): TCP, UDP.
- Network Layer (Packet): IPv4, IPv6.
- Data Link Layer (Frame): Ethernet, PPP.
- Physical Layer (Bit): Ethernet cable, optical fiber.
Data Link Layer and MAC Addressing
The Data Link Layer is the lowest "logical" level, interconnecting physical interfaces. Every physical interface is uniquely identified by a Media Access Control (MAC) address, often referred to as an "Ethernet address."
- Structure: MAC addresses are -bit identifiers.
- Notation: They are represented in Hexadecimal (HEX) notation as .
- Function: They represent the final destination of a frame and are used to route packets within local networks.
- Assignment: These addresses are fixed and assigned by the hardware producer according to the IEEE 802 standard.
MAC Address Composition and Identification
- Organizationally Unique Identifier (OUI): The first bits are set by the IEEE standard and identify the producer of the network interface. For example, the prefix identifies Aastra Telecom.
- Host Logic: When a frame is sent to a specific MAC address (e.g., ), the interface with that address keeps the frame, while others drop it.
System Commands for Network Interfaces
- Unix/Mac:
ifconfig(lists interfaces) ornetworksetup -listallhardwareports. - Windows:
ipconfig.
Network Layer and IP Addressing
The Network Layer provides the necessary information to reach other systems via addressing functionalities. The Internet Protocol (IP) operates at this layer.
- Function: It provides a high-level representation of a host's address and conveys the information needed to route datagrams.
- Connectionless Nature: IP is a stateless protocol. It has no notion of an "established connection"; it simply provides the means for a packet to reach its destination.
- Address Assignment: Unlike MAC addresses which are fixed by vendors, most IP addresses are dynamically assigned by an authority, such as an Internet Service Provider's (ISP) DHCP server.
Comparison: IPv4 vs. IPv6
- IPv4: The most common version currently in use. It utilizes bits for addressing.
- IPv6: Increasing in adoption; will be common in the future. It utilizes bits for addressing.
Address Space Considerations
With a -bit MAC address system, there are possible addresses, which equals (approximately Terabytes if each address were a byte). IP addresses abstract host addresses away from physical properties to manage issues like hardware substitution (revoking/replacing an Ethernet card) and global routing between Autonomous Systems.
Address Resolution Protocol (ARP)
ARP allows systems to associate a known IP address with a corresponding MAC address. This is essential for local network delivery where IP packets must be encapsulated in Ethernet frames.
ARP Mechanism
- ARP Tables: These tables contain mapping information (IP address to MAC address), along with other data like Time to Live (TTL) and interface details.
- ARP Query (Discovery): If a system (System A) wants to send data to an IP (System D) but does not have the MAC address in its table, it initiates a discovery process.
- Broadcast: System A sends a broadcast message to the L2 Ethernet address .
- Request-Reply: The message asks "who has [IP address]? tell [My IP]." All hosts receive the broadcast; those whose IP does not match drop the request. The host with the matching IP replies with its MAC address.
- Gratuitous ARP: A system can preemptively announce its IP-to-MAC mapping to the network.
ARP Frame Header Structure ( bits wide)
- Hardware Type ( bits)
- Protocol Type ( bits)
- Hardware Address Length ( bits)
- Protocol Address Length ( bits)
- Operation (Opcode): for request, for reply ( bits)
- Sender Hardware Address (Octets )
- Sender IP Address (Octets )
- Target Hardware Address (Octets )
- Target IP Address (Octets )
Network Security: ARP Poisoning
ARP is a declarative, non-authenticated protocol. Nodes are not required to provide proof of identity.
- The Attack: An attacker (System C) can send unsolicited ARP messages (or replies to queries not intended for them) telling System B that "System A is at [C's MAC address]" and telling System A that "System B is at [C's MAC address]."
- Result: This establishes a Man-in-the-Middle (MitM) position. Every communication between A and B passes through C.
- Limitations: This attack only works on local networks where MAC addresses are meaningful. However, since routers and DNS servers also have MAC addresses, they can be targeted to intercept outgoing traffic.
- Mitigation: Some third-party tools can monitor for anomalies, although the protocol's lack of authentication remains a core vulnerability.
Subnets and CIDR
Subnets are logical divisions of IP address ranges. An IP address is divided into network bits, subnet bits, and host bits.
- Subnet Mask: Indicates which part of the IP address belongs to the network/subnet versus the host (e.g., means bits for the network/subnet and bits for hosts).
- CIDR (Classless Inter-Domain Routing): A synthetic notation representing the number of bits in the mask. For example, is equivalent to a mask of .
Calculation Example
For an IP address with a mask of :
- CIDR:
- Binary Operation:
- Network =
- Host =
- Total Hosts:
IP Classes and Private Addresses
IPv4 Classes
- Class A: to (Standard)
- Class B: to (Standard)
- Class C: to (Standard)
- Class D: to (Multicast)
- Class E: to (Experimental)
Reserved Private Address Ranges
These IPs are not routed on the public Internet; gateways should drop datagrams with these destinations:
- to
- to
- to
IP Header and Fragmentation
IP Header Fields
- Version: Identifying IPv4 or IPv6.
- IHL (Internet Header Length): Length of the header.
- Type of Service: Priority/Quality of Service info.
- Total Length: Total size of the datagram (max bytes).
- Identification ( bits): Unique ID for the datagram; all fragments of one datagram share this ID.
- Flags ( bits):
- Bit 0: Reserved (must be 0).
- DF (Don't Fragment): = can fragment; = do not fragment (drop if fragmentation is required).
- MF (More Fragments): = last fragment; = more fragments coming.
- Fragment Offset ( bits): The position of the fragment relative to the start of the original datagram, measured in blocks of bytes.
- Time to Live (TTL): Hop count limit.
- Protocol: Identifying the next level protocol (TCP, UDP, ICMP).
- Header Checksum: For error detection.
- Source/Destination Addresses: -bit IP addresses.
Fragmentation Example
If sending bytes of data over Ethernet (MTU = bytes):
- Fragment 1: bytes header + bytes data ( total), offset = , MF=1.
- Fragment 2: bytes header + bytes data ( total), offset = (calculated as ), MF=1.
- Fragment 3: bytes header + remainder data ( bytes), offset = (calculated as ), MF=0.
Internet Control Message Protocol (ICMP)
Defined in RFC 792, ICMP is an integral part of the IP suite used for status and error reporting.
Common ICMP Message Types
- Type 3 (Destination Unreachable): Codes include (net), (host), (protocol), (port), (fragmentation needed but DF set).
- Type 11 (Time Exceeded): Used when TTL reaches . This is the basis for the Traceroute tool, which sends packets with increasing TTL values () to map the path to a destination.
- Type 8 (Echo Message) & Type 0 (Echo Reply): Used by the Ping utility.
Denial of Service (DoS) Attacks
DoS attacks aim to overpower a system's capacity by generating requests, leading to performance degradation or crashes.
Ping Flood
An attacker with high bandwidth sends a flood of ICMP Echo requests (Type 8) to a target. The target's bandwidth is exhausted by both receiving the requests and attempting to send Echo replies (Type 0).
Ping of Death
A classic attack involving oversized ICMP packets.
- The maximum length of an IP packet (including header) is bytes.
- The maximum offset is blocks ( bytes).
- An attacker can craft fragments that, when reassembled, exceed the byte limit (e.g., a final fragment at the max offset with enough data to push the total size to bytes).
- Early implementations failed to handle this, resulting in buffer overflows and system crashes.
- Note: Modern versions of this mistake exist, such as CVE-2013-3183 (ICMPv6) and CVE-2020-16898.
Useful Network Tools
- Wireshark / tcpdump: Used for traffic monitoring (ARP, DNS, TCP 3-way handshakes).
- Nmap: Used for network scanning (TCP, UDP ports).
- Scapy: A Python interface for manual packet crafting at any level of the stack.
- Ettercap: Specifically designed for MitM attacks, including ARP poisoning.
- Netcat: A legacy tool for generating UDP/TCP traffic.