Firewalls, IDS & IPS Explained: Network Security Devices Fundamentals
HELLO FRIENDS
WELCOME TO MY CYPHER LOG
We all hear a lot about Firewall in our field and we also know the overview of it but in this blog we are going to know little more than we already knew.
In today's blog we are going to see about the Firewall, IDS and IPS.
Let's dive into it
FIREWALLS
As we know firewalls work like security guards who monitor the incoming and outgoing network traffic and devices in our systems and whether to block or allow based on the set of security rules.
It had three types they are
PACKET FILTERING FIREWALL
It will look only at the header of the packet, like IP addresses.
It acts like a security guard who stands in front of our college main gate who would permit us if we have a proper ID card, they won't ask many questions to let us in right because we have an ID card otherwise they won't let us in.
It had a biggest drawback that if an attacker hides a malware inside a legitimate looking packet it won't think twice to block it because it had a legitimate header.
STATEFUL INSPECTION FIREWALL
It will remember the State of active connections. It knows if a packet is relevant to the conversation or a random one.
To understand it clearly,
If there is a meeting conducted by the principal of your college for the professor then students won't be allowed to enter there right that's how it works.
NEXT GENERATION FIREWALL
It is a modern standard of firewall which combines traditional Firewall rules with deep packet inspection.
It won't just check the header to let the packet in, it would analyse the packet payload, like if you went to airports they would check your bags before they let you board the flight.
It works in the application layer which is the 7th layer in OSI model.
IDS and IPS
Both works like a guard and camera, here the IDS is the camera and IPS is the guard.
IDS [ Intrusion detection system ]
It monitors network traffic to identify if there is any anonymous behaviour and compares it against a data base of known attack signatures to find a attack, if there is any then they would alert, it can't stop that but it would log everything.
IPS [ Intrusion prevention system ]
It does everything that IDS does and it is placed directly in the path of the traffic, if it find any anonymous behaviour they would tend to block or drop the packets in real time.
It had a drawback to if it configured too aggressively they can cause false positives which leads to block the legitimate users too.
So that's all guys today's lesson.
I hope you guys understand it well. Stay tuned for future blogs.
If you want to know more about this you can get the study material through this link.

Comments
Post a Comment