Solved

stateful packet inspection -- relation to clients' computer security

Posted on 2009-07-02
2
265 Views
Last Modified: 2012-05-07
What does the "state" of a TCP/IP packet have to do with whether it is from a user-requested web site, or from a hacker trying to gain access to a client computer, with reagrd to the "stateful packet inspection" that presumably only hardware firewalls are capable of?
0
Comment
Question by:Casey Claassen
2 Comments
 
LVL 32

Accepted Solution

by:
rsivanandan earned 35 total points
Comment Utility
To simply look at it,

If the packet coming from outside

1. Has SYN and ACK bit set then it means that the connection was indeed originated from the inside machine and that is why acknowledgment is coming.

2. After that every packet passed has sequence numbers which are math bound and has relation with the packet sent.

So keeping the state information helps find it.

Now if a hacker sends a reply packet with 'syn' and 'ack' bit set, the machine won't entertain it since it didn't originate that traffic at all.

Does that help?

Cheers,
Rajesh
0
 

Author Closing Comment

by:Casey Claassen
Comment Utility
Yes, that does indeed help!
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now