Firewalls, IDS & IPS Explained: Network Security Devices Fundamentals

 

HELLO FRIENDS

WELCOME TO MY CYPHER LOG

   We all hear a lot about Firewall in our field and we also know the overview of it but in this blog we are going to know little more than we already knew.
In today's blog we are going to see about the Firewall, IDS and IPS.

Let's dive into it

FIREWALLS

         As we know firewalls work like security guards who monitor the incoming and outgoing network traffic and devices in our systems and whether to block or allow based on the set of security rules.
It had three types they are

PACKET FILTERING FIREWALL

    It will look only at the header of the packet, like IP addresses.
It acts like a security guard who stands in front of our college main gate who would permit us if we have a proper ID card, they won't ask many questions to let us in right because we have an ID card otherwise they won't let us in.
It had a biggest drawback that if an attacker hides a malware inside a legitimate looking packet it won't think twice to block it because it had a legitimate header.

STATEFUL INSPECTION FIREWALL

     It will remember the State of active connections. It knows if a packet is relevant to the conversation or a random one.
To understand it clearly, 
If there is a meeting conducted by the principal of your college for the professor then students won't be allowed to enter there right that's how it works.

NEXT GENERATION FIREWALL

   It is a modern standard of firewall which combines traditional Firewall rules with deep packet inspection.
It won't just check the header to let the packet in, it would analyse the packet payload, like if you went to airports they would check your bags before they let you board the flight.
It works in the application layer which is the 7th layer in OSI model.

IDS and IPS

  Both works like a guard and camera, here the IDS is the camera and IPS is the guard.

IDS [ Intrusion detection system ]

   It monitors network traffic to identify if there is any anonymous behaviour and compares it against a data base of known attack signatures to find a attack, if there is any then they would alert, it can't stop that but it would log everything.

IPS [ Intrusion prevention system ]

    It does everything that IDS does and it is placed directly in the path of the traffic, if it find any anonymous behaviour they would tend to block or drop the packets in real time.
It had a drawback to if it configured too aggressively they can cause false positives which leads to block the legitimate users too.

So that's all guys today's lesson.
I hope you guys understand it well. Stay tuned for future blogs.

If you want to know more about this you can get the study material through this link.

THANK YOU

Comments

Popular posts from this blog

Day 2: Understanding the CIA Triad, AAA

Cryptography Basics: Encryption Types & Hashing Explained

Cyber Security Day 4: Understanding Layered Security & Defence in Depth