PPRuNe Forums - View Single Post - Recommended security add-ons
View Single Post
Old 17th Oct 2011, 13:28
  #16 (permalink)  
mixture
 
Join Date: Aug 2002
Location: Earth
Posts: 3,663
Likes: 0
Received 0 Likes on 0 Posts
All about NAT.....

Let's start by addressing your statement that "nothing can get you when you're behind NAT".

Two irrefutable counter-arguments :

"Phone home" software that sends data/information about your computer/network to the outside world.

Software with mechanisms to bypass or work-around NAT (legitimate examples of this include Skype, GoToMyPC, Teamviewer etc.). Products such as Teamviewer provide you with full remote-control of your computer without any need to open any inbound ports on the firewall perimeter of your network.

It doesn't take much imagination to realise what can be done by people with malicious intent.

One source of further reading on this is the activities and presentations of the Jericho Forum.

The Jericho Forum began in 2003 when a group of global corporate CISOs came together informally to discuss an issue that no one was addressing – de-perimeterization – the erosion of the network perimeter. Concerned that the industry was valiantly trying to shore up an ever-crumbling corporate perimeter while trying to securely conduct business via the Internet.

I'll leave you with two facts :

(1) RFC1631 (aka NAT) was never designed as a security mechanism. It's role in life was always, and will always be to address the problem of address depletion and scaling in routing. That's it. The fact that your IP address gets masked in the process is a byproduct of the way the NAT mechanism was designed and consequently implemented.

(2) That today's internet is not a very pleasant place. There is an ever growing number of mechanisms at the disposal of the mischievous to bypass security, and the only way to address these effectively is to build a layered security model, not just relying on one piece of infrastructure to protect you.

You might be of the opinion that "oh, I'm just a boring home user, with no nuclear secrets on my ageing PC.... why should I bother". To that, I say remember zombie botnets and spam.... the miscreants want you to be a small piece in their large cog. It's your duty as an individual connected to the internet to do your small bit to help deflect the damage they cause. If you don't believe me on the damage front, I'll leave you with a little quote from a recent ticketing system notification message :

We experienced a large scale distributed denial of service attack
starting at 17:34 this evening targetted at one of our customers. This
attack resulted in an unprecendented load on our routers and some
interlinks.

The attack is still on-going but we have mitigated most of its effects
by way of filtering traffic on our network border.

As a result of the volume of traffic, customers will have seen some
packetloss until we put in place systems to filter the attack.

We are still seeing a high level of inbound traffic however the
filters which has been in place for over 40 minutes appears to
be successfully mitigating most of its impact. We are continuing
to monitor the network closely.
mixture is offline