Secure Routing and Antispoofing

This chapter covers both antispoofing and securing the routing protocol your routers use to exchange information. Antispoofing filters prevent external users from sending forged packets that act as if they come from your internal network. Many security controls use a packet’s source IP address to allow or deny access. By sending spoofed packets that look as if they originated on your internal network, attackers can manipulate or bypass these security controls. | Page 83 Friday February 15 2002 2 54 PM CHAPTER 9 Secure Routing and Antispoofing This chapter covers both antispoofing and securing the routing protocol your routers use to exchange information. Antispoofing filters prevent external users from sending forged packets that act as if they come from your internal network. Many security controls use a packet s source IP address to allow or deny access. By sending spoofed packets that look as if they originated on your internal network attackers can manipulate or bypass these security controls. Your routers use routing protocols to exchange information. This information is used to determine what direction a router will send a packet once it is received. A functional network requires correct routing information so minimally an attacker can cause a denial-of-service DoS attack by inserting false routing information into your routers. A far more damaging attack can involve having all of your network traffic relayed through another system possibly one controlled by the attacker or one that allows him to bypass your firewall and intrusion detection systems. Protecting how routers exchange routing information is necessary to prevent such dangers. Antispoofing Antispoofing filters are usually implemented to protect the networks behind routers but they are equally important in protecting the routers themselves. These filters keep people from attempting to spoof connections to your routers. They also prevent numerous attacks that while not directed at the router must pass through the router and can overwhelm it with excessive traffic. This chapter will cover both inbound and outbound filters using traditional ACLs and Cisco s newer unicast reverse packet forwarding feature. Finally since filtering can cause some performance degradation the checklist ends with brief descriptions of methods used to reduce the performance impact of antispoofing filters. 83 Page 84 Friday February 15 2002 2 54 PM Ingress and .

Không thể tạo bản xem trước, hãy bấm tải xuống
TÀI LIỆU MỚI ĐĂNG
5    366    1    14-05-2024
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.