CSEC3616Cybersecurity Engineering

    Rule tables, first match and default policy

    How a firewall rule is built from a match condition and an action, why the list is read top to bottom until one rule matches, and the difference between whitelisting and blacklisting.

    • Describe a firewall rule as a match condition plus an action, and name the actions the lecture lists.
    • Explain that the ruleset is processed sequentially until the first matching rule.
    • Distinguish whitelisting from blacklisting and say which one the lecture recommends.
    • Read the lecture's outgoing-HTTP rule table and say what each rule permits.

    15 min read

    Intuition

    A firewall has no judgement. It has a list. For each packet it starts at the top of the list, finds the first entry that describes the packet, and does what that entry says. Everything about firewall design is therefore about what to write on the list, and in what order.

    The other decision is what happens to a packet that nobody described. Either the answer is no, and every permitted thing must be written down, or the answer is yes, and every forbidden thing must be.

    Mechanism

    A firewall is configured by a list of rules. For every packet, the ruleset is processed sequentially until a matching rule is found. A rule has two parts: a match condition and an action.

    Actions the lecture names:

    • Accept permits the traffic through.
    • Drop blocks the traffic with no reply.
    • Reject blocks the traffic and replies with an unreachable error.
    • Log records details about the traffic and does not affect its flow.

    Match conditions can use the incoming interface, packet fields at different layers, stateful matches where the firewall tracks connections for you, and further conditions such as rate limits.

    Mechanism

    The packet fields a rule can match on, by layer:

    LayerFieldsNote from the lecture
    Link (L2, Ethernet)MAC addressEasily spoofable
    Network (L3, IPv4)IP addresses, transport protocol (TCP, UDP, ICMP)
    Transport (L4, TCP/UDP)Ports, flagsPorts identify the sending or receiving application

    Ports fall into ranges. Well-known ports are 0 to 1023, for example HTTP on 80, DNS on 53 and HTTPS on 443. Registered ports are 1024 to 49151, for example IRC on 6667 and a BitTorrent tracker on 6969. Ephemeral ports are 49152 to 65535.

    Three TCP flags matter for filtering. ACK is set in every segment of a connection except the first. SYN is only set in the first two segments. RST is an ungraceful close of the connection.

    A * in a rule field is a wildcard: the field can hold any value and it does not affect whether the rule applies.

    Compare

    Everything not explicitly permitted is denied. Increased security. The lecture names it best practice, while noting it may not be practical in many situations. The list needs constant updating as new legitimate entities appear, which is expensive in large or changing environments.

    Everything not explicitly forbidden is permitted. Less hassle with users, because nothing legitimate is blocked by an omission. The cost is that any threat nobody thought to list gets through.

    Mechanism

    The lecture’s worked configuration implements the policy allow outgoing HTTP (TCP port 80), deny the rest on a LAN of 192.168.0.0/16. It is a whitelist, and its last rule is the default deny.

    RuleInterfaceSource IPDestination IPProtocolSource portDestination portStateAction
    Alan192.168.0.0/160.0.0.0/0TCP> 102380New, Est.Accept
    Binet0.0.0.0/0192.168.0.0/16TCP80> 1023Est.Accept
    C*0.0.0.0/00.0.0.0/0****Drop

    Each rule exists for one piece of the policy.

    • The LAN can initiate outgoing HTTP connections. Rule A with state New covers the first packet, for example a SYN.
    • The Internet may respond on established connections. Rule B covers the reply, for example SYN,ACK.
    • The LAN may keep using established connections. Rule A with state Est. covers the later packets, for example ACK and HTTP GET / HTTP/1.0.
    • Everything else is prohibited. Rule C drops it. A DNS lookup is the lecture’s example of what this blocks.

    Pitfall

    Rule B in the lecture’s table is only correct for replies. Its source port is 80 and its destination port is above 1023, which is a server answering a client. Swapping those fields gives a rule that admits traffic the policy never allowed. When you read a rule table, say in words who is sending, to whom, and on which side of the firewall the packet arrived.

    Exam detail

    Know four things cold. A rule is a match condition plus an action. The ruleset is processed sequentially and stops at the first match. Whitelisting is default deny and is the best practice, while blacklisting is default permit. The usual way to get whitelisting in a rule table is a final rule that matches everything and drops.

    For any rule table, translate each row into a sentence about the policy it serves before judging the table. The practice-quiz questions that give you a table ask you to say what a rule permits and whether an earlier rule makes a later one unreachable.

    Aside

    The slide table for this example shows rule A’s state as New, Est. and rule B’s as Est., which is what the page reproduces. The accompanying text also says the replies on rule B carry SYN and/or ACK, which is how the firewall recognises them as part of a connection already started from inside.

    Recall

    In the outgoing-HTTP table, a packet from a LAN host to port 53 on an outside server arrives on the `lan` interface. Which rule decides what happens to it, and what is the action?

    Rule A does not match, because its destination port is 80. Rule B does not match, because it applies to the inet interface. Rule C matches everything, so it decides, and the action is Drop. The lecture uses a DNS lookup as its example of traffic this policy prohibits.

    Recall

    • A rule is a match condition plus an action. The actions are Accept, Drop, Reject and Log.
    • Rules are read in order and the first match wins.
    • Whitelisting is default deny and is the lecture’s best practice. Blacklisting is default permit.
    • A MAC address is easily spoofed. Well-known ports are 0 to 1023, registered 1024 to 49151, ephemeral 49152 to 65535.