Examining Firewalls And IPSs Flashcards
What are network firewalls?
These devices act as a security barrier between internal and external networks, controlling incoming and outgoing network traffic based on predetermined security rules. The primary purpose is to prevent unauthorized access while permitting outward communication.
What are a few different types of firewalls and their associated functionality?
- Packet-filtering: Examines packets entering or leaving the network, either accepting or rejecting the packet based on user-defined rules.
- Stateful packet inspection: Monitors the state of active connections, making decisions based on the context of the traffic and state of the network.
- Application-level: Filters incoming traffic between the network and the traffic source, operating at the application layer.
- Circuit-level: Monitors TCP handshakes across the firewall to determine if the session is legitimate.
What is a Next-Generation Firewall (NGFW)?
NGFW incorporates features of traditional firewalls with quality of service (QoS) functionalities, including additional features like application awareness, integrated intrusion prevention, and cloud-delivered threat intelligence.
What is an Intrusion Detection System (IDS)?
IDS monitors networks or systems for malicious activity or policy violations. It can be network-based (NIDS) or host-based (HIDS).
What is an Intrusion Prevention System (IPS)?
IPS is similar to IDS but with the ability to prevent detected threats, actively blocking or preventing intrusions in real-time.
What is Unified Threat Management (UTM)?
UTM combines and integrates various security services and features, including Firewall, IDS/IPS, Antivirus, Gateway anti-spam, and Content filtering.
What is a stateful firewall?
A stateful firewall keeps track of the state of active connections, making decisions based on the context of the traffic and the state of the network.
How do stateful firewalls operate?
Stateful firewalls operate by inspecting both the header information and the contents of data packets.
What do stateful inspections monitor?
Stateful inspections monitor ongoing connections to ensure that the traffic is associated with a known connection.
What advantage do stateful firewalls offer?
Stateful firewalls provide more awareness of communications occurring over a network, offering a higher level of security.
How do stateful firewalls make security decisions?
Stateful firewalls remember previous communications and make security decisions based on past packets and the state of connections.
What are circuit-level gateways?
Circuit-level gateways operate at layer 5 of the OSI model, making security decisions based on the handshaking protocols.
What do circuit-level gateways monitor?
Circuit-level gateways monitor TCP handshaking between packets, determining whether a session request is legitimate.
What can circuit-level gateways do with packet information?
Circuit-level gateways can hide information about the packets.