HACKER ATTACKS: Protecting Your Customers

author-image
DQC News Bureau
New Update

Not everyone connected to the Net can be trusted to keep to his own
legitimate transactions. Your customers are always at the risk of getting their
networks hacked into. This is where you step in and protect their networks and
their business.

Advertisment

Solution providers must help customers using the Internet extensively to
protect their confidential information from those who are not authorized to
access it. Every company wants to protect their networks from malicious attacks.

A fool-proof access control policy and a powerful firewall is becoming a must
for corporate networks. For a firewall to work efficiently, it must be a part of
a consistent overall organizational security architecture. Firewall policies
must be realistic and reflect the level of security in the entire network.

One must also make it very clear that only a firewall cannot completely
protect a network, especially from hackers who have some personal contacts in
the organization. Such attacks are called socially engineered attacks and utmost
care must be taken to protect the network from such attacks. Firewalls are good
enough for blocking attacks from unknown hackers.

Advertisment

FIRED UP

There are three varieties of firewalls, hardware, software, or a combination
of both. These are used to prevent unauthorized Internet users from accessing
private networks connected to the Internet, especially intranets. All messages
entering or leaving the intranet pass through the firewall, which examines each
message and blocks those that do not meet the specified security criteria.

Several techniques are used by firewalls to achieve their goal of detecting
and preventing unauthorized traffic. Here are some of them.

Packet filtering: Packet filtering looks at each
packet entering or leaving the network and accepts or rejects it based on
user-defined rules. Packet filtering is fairly effective and transparent to
users, but it is difficult to configure. In addition, it is susceptible to IP
spoofing when an attacker outside your network pretends to be a trusted computer
either by using an IP address that is within the range of IP addresses on your
network or by pretending to have an external IP address that

you trust.

Advertisment

Application gateway: Here, the firewall applies
security mechanisms to specific applications, such as FTP and Telnet servers.
This is very effective, but can result in performance degradation of these
applications by taking up system resources and slowing them down.

Circuit-level gateway: This applies to security
mechanisms where a TCP or UDP connection is established. Once the connection has
been made, packets can flow between the hosts without further checking.

Proxy server: This hardware intercepts all messages
entering and leaving the network. The proxy server effectively hides the true
network addresses from the hackers on the Internet.

Advertisment

Two or more of these techniques are generally used by
Firewalls to achieve better results.

WHAT SUITS BEST

A software-based firewall resides on top of an operating system in a
computer and monitors what is transferred in and out of it. It can be installed
separately or can be integrated into the operating system itself.

Once installed, the user must keep up with the latest patches. Otherwise, a
security hole will be left open within the system. How well the software works
depends on the speed of the computer, how much memory it has, and what the
computer is used for.

Advertisment
A
firewall is a system designed to prevent unauthorized access to or
from a private network
 SOFTWARE
HARDWARE
FIREWALL
FIREWALL
ADVANTAGESCheaper
and simpler to install and upgrade;

Requires no physical changes to the hardware or network;

Ideal for home or small businesses as it takes no physical space.
Very
fast in functioning as it uses very little system resources; Has
enhanced security control; Easy to disable or remove;

Works independently of the network operating system.
DISADVANTAGESPurely
software driven;

It may crash or be incompatible with the system; Can be difficult to
disable or remove;

Software bugs may compromise security;

Takes up computer resources and slows down the system
Takes
up physical space;

It is costlier;

Hardware upgrades and repair are difficult.

This type of firewall is good for a single computer connected to the
Internet. When the setup involves more than one PC, all PCs must be connected
through one machine to the Internet. The PC where the software firewall resides
can then act as the Internet gateway for all other PCs within that network.

A hardware-based firewall is a stand-alone box containing hardware that
connects your computer to the Internet, and monitors traffic flowing in and out
from the network. It can have a default configuration from the manufacturer,
which is good enough for most users.

Advertisment

All you have to do is plug in the box (usually a firewall router) between
your network and the Internet. When a security flaw is found, the user only has
to install one patch, making it easy to plug the security holes.

The speed of a hardware firewall can be very close to the operating speed of
your original network, as the processor within the firewall hardware does all
the filtering and security checks without loading the network operating system.
Thus making the firewall completely transparent to the network users.

Hardware firewalls can also provide a De-Militarized Zone port. It is a
separate Ethernet port on a hardware firewall that is used to connect publicly
accessed servers like mail, web or FTP servers to the Internet. The main
advantage of using a DMZ port is to isolate a private network from Internet
users by keeping it on a separate network segment.

Advertisment

Choice of firewall solution to use for your customer is a matter of corporate
needs, based on the security requirements and the budget for implementation.

Software based firewalls would probably be best for home or small business
use where you want some protection but don´t want to spend a lot of money to
get it.

However, if you want to provide extreme protection for your customers, using
a combination of hardware and software firewalls may be the best solution for
them!

Ashok Dongre is an independent consultant