Skip to main content
Top

2024 | OriginalPaper | Chapter

UDP State Manipulation: Description of a Packet Filtering Vulnerability in Stateful Firewalls

Authors : Wassim Koribeche, David Espes, Cédric Morin

Published in: Foundations and Practice of Security

Publisher: Springer Nature Switzerland

Activate our intelligent search to find suitable subject content or patents.

search-config
loading …

Abstract

Firewalls are essential components for security enforcement in a network, as they are the first layer of protection from unwanted traffic and cyber-attacks. While the requirements for efficiency led to the design of ever more complex systems, evolving from stateless to stateful firewalls, this complexity induced new vulnerabilities. In this paper, we discuss a new vulnerability present in Packet Filtering that we called Vulnerability on Firewall States (Von-FS). It is due to three factors: 1) once a state is up, traffic going through it is not checked anymore, 2) a state timeout is refreshed when a packet matches it, and 3) pushing a blocking/dropping rule in the firewall does not automatically delete obsolete states. This vulnerability can be used by legacy attacks to be more stealthy and more difficult to stop when detected. Our study shows that many commercial and open-source firewalls are subject to this vulnerability. We propose a mitigation solution that consists of deleting all obsolete states whenever a dropping rule is pushed. We evaluated this idea by patching a well-known open-source firewall, FreeBSD. Experiments show that the impact on firewall performance is very low.

Dont have a licence yet? Then find out more about our products and how to get one now:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literature
3.
go back to reference Gouda, M.G., Liu, A.X.: A model of stateful firewalls and its properties. In: 2005 International Conference on Dependable Systems and Networks (DSN’05), pp. 128–137. IEEE (2005) Gouda, M.G., Liu, A.X.: A model of stateful firewalls and its properties. In: 2005 International Conference on Dependable Systems and Networks (DSN’05), pp. 128–137. IEEE (2005)
5.
go back to reference Hussain, M.A., Jin, H., Hussien, Z.A., Abduljabbar, Z.A., Abbdal, S.H., Ibrahim, A.: DNS protection against spoofing and poisoning attacks. In: 2016 3rd International Conference on Information Science and Control Engineering (ICISCE), pp. 1308–1312 (2016). https://doi.org/10.1109/ICISCE.2016.279 Hussain, M.A., Jin, H., Hussien, Z.A., Abduljabbar, Z.A., Abbdal, S.H., Ibrahim, A.: DNS protection against spoofing and poisoning attacks. In: 2016 3rd International Conference on Information Science and Control Engineering (ICISCE), pp. 1308–1312 (2016). https://​doi.​org/​10.​1109/​ICISCE.​2016.​279
6.
go back to reference IBM whitepaper: An architectural blueprint for autonomic computing IBM whitepaper: An architectural blueprint for autonomic computing
7.
go back to reference Kim, H., Pak, W., Ju, H.: Correlation analysis between inference accuracy and inference parameters for stateless firewall policy. In: 2013 15th Asia-Pacific Network Operations and Management Symposium (APNOMS), pp. 1–6 (2013) Kim, H., Pak, W., Ju, H.: Correlation analysis between inference accuracy and inference parameters for stateless firewall policy. In: 2013 15th Asia-Pacific Network Operations and Management Symposium (APNOMS), pp. 1–6 (2013)
9.
go back to reference McCanne, S., Jacobson, V.: The BSD packet filter: a new architecture for user-level packet capture. In: USENIX Winter, vol. 46 (1993) McCanne, S., Jacobson, V.: The BSD packet filter: a new architecture for user-level packet capture. In: USENIX Winter, vol. 46 (1993)
10.
Metadata
Title
UDP State Manipulation: Description of a Packet Filtering Vulnerability in Stateful Firewalls
Authors
Wassim Koribeche
David Espes
Cédric Morin
Copyright Year
2024
DOI
https://doi.org/10.1007/978-3-031-57537-2_19

Premium Partner