
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 40
inspectiontechnology.Aformofdynamicpacketfiltering,statefulinspectionworks
atthenetworklayerandtrackseachconnectiontraversingallinterfacesofthefirewall
tomakesuretheyarevalid.
Statefulinspectionis“superior”asitexaminesnotonlythepacketheaderbutalsothe
packetcontents.Suchinspectionisdoneallthewayuptotheapplicationlayer,
makingitpossibleforfilteringdecisionstobemadebasedoncontextthathasbeen
establishedbypriorpassedpackets.Asameasureagainstportscanning,stateful
inspectionfirewallsalwayscloseoffportsuntilconnectiontothespecificportis
requested.
ForthisprojectIusedFW1version4.0forx86,whichisnotcurrentbutiswhatI
haveonhand.ItrunsonWindowsNTServer4.0.Tomakethisfirewallsystemtruly
secure,thethingsthatneedtobedoneare:
n HardeningNTitself –applyallthelatestservicepacks,patchesandfixes;and
disablealltheunnecessaryservicesandcomponents.
n SecuringFW1–again,applyallthelatestpatchesandfixesforversion4.
Hardeni ngtheNTInstallation
AccordingtoCERT’sNTconfigurationguidelines,therearetwotypesofpatches
fromMicrosoft:ServicePacksandHotfixes.Servicepacksareforpatchingawide
rangeofvulnerabilitiesandbugs,whilehotfixesarereleasedmorefrequentlythan
servicepacksandareforpatchingmorespecificproblems
5
.
Keepinmindthough,thatservicepacksarecumulative,meaningweonlyneedto
installthelatestServicePack.Forfixes,however,weneedtodeterminewhatto
install(aswewon’tneedallofthem).ServicePackmustbeinstalledbeforethe
Hotfixes.
Wemayaccessalltheseservicepacksandupdatesfromacentrallocation:
http://www.microsoft.com/ntserver/nts/downloads/default.asp#RecommendedUpdates.
5
http://www.cert.org/tech_tips/win_configuration_guidelines.html
Comentarios a estos manuales