19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

- If required, the packet filter should support dynamic packet filtration. This<br />

means that during the transmission of UDP packets, for example, the<br />

related context is stored for a particular time period and the corresponding<br />

response packets are allowed to pass through.<br />

Dynamic filters<br />

Based on the definition of a packet filter as a filter which uses the information<br />

of layers three and four as a check, the limits of this procedure soon become<br />

apparent. Although it is possible, in the case of TCP (Transmission Control<br />

Protocol) to recognise the establishment of a connection and thereby prohibit<br />

connections from the Internet to the network requiring protection, this is no<br />

longer possible in the case of UDP (User Datagram Protocol). In order to<br />

solve this problem, dynamic packet filters are used. If a UDP packet is sent<br />

from an internal computer to a DNS server in the Internet, the dynamic packet<br />

filter stores the data (source and destination address, source and destination<br />

port) and produces a new permission rule for the response packets. This rule is<br />

only valid for a certain period, which can be adjusted. If no response packets<br />

are received, it is deleted.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!