{"id":464,"date":"2018-07-24T11:57:06","date_gmt":"2018-07-24T11:57:06","guid":{"rendered":"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/?post_type=chapter&#038;p=464"},"modified":"2018-12-28T09:36:57","modified_gmt":"2018-12-28T09:36:57","slug":"firewalls","status":"publish","type":"chapter","link":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/chapter\/firewalls\/","title":{"rendered":"Firewalls"},"content":{"raw":"<div><span style=\"float: right\"><a href=\"https:\/\/youtu.be\/VMCT1U8xVcE\" target=\"_blank\" rel=\"noopener\"><img src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a>\r\n<\/span><\/div>\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n<strong>Learning Objectives<\/strong>\r\n<ul>\r\n \t<li><strong>Outlined the purpose of Firewalls.<\/strong><\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li><strong>Discuss about the basic firewall components.<\/strong><\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li><strong>Discuss about the firewall architecture and various types of firewalls.<\/strong><\/li>\r\n<\/ul>\r\n<div>\r\n\r\n<strong>1.\u00a0\u00a0 <\/strong><strong>Introduction<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Firewalls are computer security systems that protect your office\/home PCs or your network from intruders, hackers &amp; malicious code. Firewalls protect you from offensive software that may come to reside on your systems or from prying hackers. In a day and age when online security concerns are the top priority of the computer users, Firewalls provide you with the necessary safety and protection. Firewalls are software programs or hardware devices that filter the traffic that flows into you PC or your network through an internet connection. They shift through the data flow &amp; block that which they deem (based on how &amp; for what you have tuned the firewall) harmful\u00a0<span style=\"text-align: initial;font-size: 1em\">to your network or computer system. When connected to the internet, even a standalone PC or a network of interconnected computers make easy targets for malicious software &amp; unscrupulous hackers. A firewall can offer the security that makes you less vulnerable and also protect your data from being compromised or your computers being taken <\/span>hostage<span style=\"text-align: initial;font-size: 1em\">.<\/span><\/p>\r\n\r\n<\/div>\r\n<strong>1.1 What do Firewalls Protect?<\/strong>\r\n\r\n&nbsp;\r\n<ul>\r\n \t<li><strong>Data<\/strong>\r\n<ul>\r\n \t<li><strong>Proprietary corporate information<\/strong>.<\/li>\r\n \t<li><strong>Financial information<\/strong><\/li>\r\n \t<li><strong>Sensitive employee or customer data<\/strong><\/li>\r\n<\/ul>\r\n<\/li>\r\n \t<li><strong>Resources<\/strong>\r\n<ul>\r\n \t<li style=\"text-align: justify\"><strong>Computing resources <\/strong>consists of any physical or virtual part of constrained accessibility inside a computer framework. Each device associated with a computer framework is an asset.<\/li>\r\n \t<li style=\"text-align: justify\"><strong>Time resources <\/strong>includes asset that reports new forms on a designed interval. The level of interval can be subjectively long. This asset is worked to fulfill \"trigger this work in any event once at regular intervals,\" not \"trigger this expand on the tenth hour of each Sunday.\"<\/li>\r\n \t<li style=\"text-align: justify\"><strong>Reputation<\/strong>:When the Intruder uses an organization\u2019s network to attack other sites, leads to loss of confidence in an organization.<\/li>\r\n<\/ul>\r\n<\/li>\r\n<\/ul>\r\n<strong>1.2 Who do Firewalls Guard Against?<\/strong>\r\n<ul>\r\n \t<li>Internal Users<\/li>\r\n \t<li>Hackers<\/li>\r\n \t<li>Corporate Espionage<\/li>\r\n \t<li>\u00a0Cyber Terrorists<\/li>\r\n<\/ul>\r\n<ol start=\"2\">\r\n \t<li><strong>Basic Firewall Components<\/strong><\/li>\r\n<\/ol>\r\n<strong>\u00a0 \u00a0 2.1 Policy: <\/strong>Building a secure strategy.\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>2.2 Advanced authentication (<\/strong>or) \"<strong>Two-Factor Authentication<\/strong>\": requires an extra separate factor or accreditation with a specific end goal to finish the sign in process. This second qualification is regularly sent as a one time PIN (OTP) that is gotten by something that the client physically has in his or her ownership (e.g. an application or SMS content to a PDA, a hard token or a paper token)<\/p>\r\n\r\n<div>\r\n<p style=\"text-align: justify\"><strong>\u00a0 2.3 Packet inspection<\/strong>:Deep Packet Inspection and filtering enables advanced network management, user service, and security functions as well as internet data mining, eavesdropping, and internet censorship.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>2.4 Application gateway: <\/strong>is an application program that keeps running on a firewall framework between two systems. When a client program establishes a connection to a destination service, it connects to an application gateway, or proxy.<\/p>\r\n\r\n<\/div>\r\n<strong>2.5 Common Internet Threats:<\/strong>Some of the common internet threats are given below:\r\n<ul>\r\n \t<li>\u00a0Malware<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>Computer Virus<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>Rogue Security Software<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>Trojan horse<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>Malicious spyware<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>Computer worm<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>Botnet<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>\u00a0Spam<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>\u00a0Rootkit<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>\u00a0Phishing<\/li>\r\n<\/ul>\r\n<ol start=\"2\">\r\n \t<li><strong>Denial of service attacks<\/strong><\/li>\r\n<\/ol>\r\n<p style=\"text-align: justify\">The Specific attacks that can cause a server crash or Flooding the server with traffic to disrupt or deny service.<\/p>\r\n\r\n<ul>\r\n \t<li>\u00a0Intrusion threats<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>\u00a0Attacks on services\/exploits<\/li>\r\n<\/ul>\r\n<p style=\"text-align: justify\">The backend server may not be hardened enough for adequate protection, but the firewall can block external attacks.<\/p>\r\n\r\n<ul>\r\n \t<li>\u00a0Information threats<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>\u201cViral\u201d threats<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>\u00a0Defacement<\/li>\r\n<\/ul>\r\n<ol start=\"3\">\r\n \t<li><strong>How Vulnerable are Internet Services?<\/strong><\/li>\r\n<\/ol>\r\n<strong>3.1 E-mail or smtp \u2013 Simple Mail Transfer Protocol<\/strong>\r\n<ul>\r\n \t<li style=\"text-align: justify\">TCP\/IP based port 25 (POP 110) In processing, the Post Office Protocol (POP) is an application-layer Internet standard convention utilized by neighborhood email customers to recover email from a remote server over a TCP\/IP association.<\/li>\r\n \t<li style=\"text-align: justify\">E-mail bombing (stalking): In Internet use, an email bomb is a type of net manhandle comprising of sending enormous volumes of email to a deliver trying to flood the letter drop or overpower the server where the email address is facilitated in a dissent of-benefit assault.<\/li>\r\n<\/ul>\r\n<p style=\"text-align: justify\"><strong>Anonymous harassment<\/strong>: Work environment badgering is a difficult issue that must not be messed with not withstanding when the complainant does not know the wellspring of the provocation and the annoying behavior is unknown.<\/p>\r\n&nbsp;\r\n\r\nLarge amounts of e-mail to a single user address\r\n<ul>\r\n \t<li>Spamming<\/li>\r\n<\/ul>\r\nMessages sent to numerous different users from a host\r\n<ul>\r\n \t<li><strong>Virus download mechanism<\/strong><\/li>\r\n<\/ul>\r\n<div>\r\n<p style=\"text-align: justify\"><strong>Code Red<\/strong>: \"Code Red\" and \"Code Blue\" are the two terms that are regularly used to allude to a cardiopulmonary capture, yet different sorts of crises (for instance bomb dangers, psychological\u00a0<span style=\"text-align: initial;font-size: 1em\">militant movement, kid kidnappings, or mass setbacks) might be given \"Code\" assignments as well.<\/span><\/p>\r\n\r\n<\/div>\r\n<p style=\"text-align: justify\"><strong>Nimda: <\/strong>Nimda is a malignant document contaminating PC worm. It spreads, outperforming the monetary harm caused by past flare-ups, for example, Code Red.<\/p>\r\n&nbsp;\r\n\r\nTCP\/IP based port 25 (POP 110) are not always traceable and can be very insecure.\r\n\r\n&nbsp;\r\n\r\n<strong>4.2 FTP - File Transfer Protocol<\/strong>\r\n<ul>\r\n \t<li>TCP\/IP based port 20\/21:<\/li>\r\n \t<li style=\"text-align: justify\">Risks include\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 the\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Unencrypted authentication and data transfers.The<span style=\"text-align: initial;font-size: 1em\"> usernames and the passwords can be \u201dsniffed<\/span>\u201d .<span style=\"text-align: initial;font-size: 1em\">Unencrypted data transfer happens<\/span>.Data<span style=\"text-align: initial;font-size: 1em\"> can be viewed <\/span>oftenas<span style=\"text-align: initial;font-size: 1em\"> the part of default installations<\/span>.Anonymous<span style=\"text-align: initial;font-size: 1em\"> ftp is possible.<\/span><\/li>\r\n \t<li>\r\n<div>\r\n\r\n<strong>4.3 HTTP \u2013 Hypertext Transfer Protocol<\/strong>\r\n\r\n&nbsp;\r\n\r\nTCP\/IP based port 80\r\n\r\n&nbsp;\r\n\r\nRisks Include\r\n\r\n&nbsp;\r\n\r\nBrowsers can be used to run dangerous commands\r\n\r\n&nbsp;\r\n\r\nProtocol can be used between user agents and other protocols i.e.. smtp, nntp, ftp\r\n\r\n&nbsp;\r\n\r\nDifficult to secure\r\n\r\n&nbsp;\r\n\r\nRemote execution of commands and execution (server side)\r\n\r\n&nbsp;\r\n\r\nNon-secure add-on applications\r\n\r\n<\/div>\r\n<ul>\r\n \t<li>Java<\/li>\r\n<\/ul>\r\n&nbsp;\r\n<ul>\r\n \t<li>Cookies<\/li>\r\n<\/ul>\r\n&nbsp;\r\n<ul>\r\n \t<li>soap<\/li>\r\n<\/ul>\r\n<\/li>\r\n<\/ul>\r\n<strong>4.4 HTTPS \u2013 Secure Hypertext Transfer Protocol<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">TCP\/IP based port 443: TCP port 443 is the standard TCP port that is utilized for site which utilize SSL. When you go to a site which utilizes the https towards the starting you are associating with port 443.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>Risks<\/strong>: Includes the browsers can be used to run dangerous commands. Remote execution of commands and execution (server side), becomes a tunnel for any data.This can be used to subvert firewall\/security controls.<\/p>\r\n&nbsp;\r\n\r\n<strong>4.5 DNS<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">The DNS service uses the port number 53 for both TCP and UDP in the transport layer. One of the major risks include DNS cache poisoning. Attacker link used to redirect valid connections to the unkown server this called DNS spoofing.Absolutely needed for network services<\/p>\r\n&nbsp;\r\n<div>\r\n\r\n<strong>5. Firewall Architecture Overview<\/strong>\r\n\r\n&nbsp;\r\n\r\nThe configuration that works best for a particular organization depends on three factors:\r\n\r\n<\/div>\r\n<p style=\"text-align: justify\">\u00a0 \u00a0The objectives of the network, the organization\u2018s ability to develop and implement the architectures, and the budget available for the function.<\/p>\r\n&nbsp;\r\n\r\nThere are four common architectural implementations of firewalls.These implementations are\r\n\r\na) Packet Filtering routers,\r\n\r\nb) Screened host firewalls,\r\n\r\nc) Dual-homed firewalls,and\r\n\r\nd) Screened subnet firewalls.\r\n\r\n&nbsp;\r\n<div>\r\n\r\n<strong>Packet Filtering Routers<\/strong>\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">The organizations uses Internet connections should have the router as an interface at the perimeter between the internal networks and the external service provider. Therouters can be configured with access control list (ACL) to reject packets that does not allow into the network. This kind of firewall reduceses the risk from external attack.<\/p>\r\n&nbsp;\r\n\r\n<strong>Screened host firewalls<\/strong>\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">This Firewall combines the packet filtering router with a separate, dedicated firewall, such as an application proxy server. This technique allows the router to pre-screen packets to minimize the network traffic and loads on the internal proxy.The application proxy verifies the application layer protocol, such as HTTP, and provides the proxy services. This type of host is often termed as a bastion host and should be very highly secured.This bastion host\/application proxy actually contains only cached copies of the internal Web documents, it can still present a promising target, because compromise of the bastion host can disclose the configuration of internal network. To its advantage, this configuration requires the external attack to compromise two separate systems, before the attack can access internal data.<\/p>\r\n&nbsp;\r\n\r\n<strong>Dual-Homed Host Firewalls<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">The Dual-Homed Host Firewall architectural approach is used, the bastion host contains two NICs (Network Interface Cards) rather than one, as in the bastion host configuration. One NIC is connected to the external network, and one is connected to the internal network, providing an additional layer of protection. With 2 NICs , all traffic must physically go through the firewall to move between the internal and external networks. NAT is a method of mapping real, valid, external IP addresses to special ranges of non-routable internal IP addresses, thereby creating yet another barrier to intrusion from external attackers.<\/p>\r\n\r\n<\/div>\r\n&nbsp;\r\n\r\n<strong>Screened Subnet Firewalls<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">The most common architecture used in firewall is the screened subnet firewall. The architecture of a screened subnet firewall provides a DMZ. The DMZ uses a dedicated port on the firewall to link a single bastion host, or a screened subnet. The DMZ is commonly placed in untrusted network where the servers provides various services.<\/p>\r\n&nbsp;\r\n<div>\r\n\r\n<strong>Basic Firewall Components consists of<\/strong>\r\n\r\n<\/div>\r\n<ul>\r\n \t<li>\u00a0Software<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>\u00a0Hardware<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>Purpose Built\/Appliance based<\/li>\r\n<\/ul>\r\n<ol start=\"5\">\r\n \t<li><strong>Problems related to Firewall<\/strong><\/li>\r\n<\/ol>\r\n<p style=\"text-align: justify\">There are some problems related with implementation and maintenance of the firewall which are,<\/p>\r\n\r\n<ul>\r\n \t<li>Administrative limitations\r\n<ul>\r\n \t<li>Access<\/li>\r\n \t<li>Monitoring<\/li>\r\n \t<li>logging<\/li>\r\n<\/ul>\r\n<\/li>\r\n \t<li>Management requirements\r\n<ul>\r\n \t<li>Additional control points<\/li>\r\n \t<li>Additional non-secure applications required<\/li>\r\n<\/ul>\r\n<\/li>\r\n \t<li>Software limitations\r\n<ul>\r\n \t<li>Capacity<\/li>\r\n \t<li>Availability<\/li>\r\n \t<li>Hardware<\/li>\r\n<\/ul>\r\n<\/li>\r\n<\/ul>\r\n<ol start=\"5\">\r\n \t<li><strong>1 Packet Filtering Firewalls<\/strong><\/li>\r\n<\/ol>\r\n<strong>Products<\/strong>\r\n<ul>\r\n \t<li>\u00a0First Generation Firewalls<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>\u00a0Typically routers<\/li>\r\n<\/ul>\r\n<strong>First Generation Firewall Technology<\/strong>\r\n<p style=\"text-align: justify\">Most organizations has an Internet connections uses router as the interface at the perimeter between the organization\u2018s internal networks and the external service provider. Most of these routers can be configured to reject packets that the organization does not allow into the network. This is a simple but effective way to protect the organization\u2018s risk from external attack. The drawbacks to this type of firewall include a lack of auditing and strong authentication<\/p>\r\n&nbsp;\r\n\r\n<strong>Application Level Firewalls:<\/strong>\r\n\r\n&nbsp;\r\n\r\n<strong>Web Proxy Severs<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">A web proxy server is a computer is used between the computer and a website server when a data\/webpage is requested. There are two common reasons for using a web proxy:<\/p>\r\n&nbsp;\r\n<ul>\r\n \t<li>To speed up browsing by caching webpage data (a Web cache).<\/li>\r\n \t<li>To remain anonymous towards the website while visiting whereby the web proxy acts as a go between the user and the server.<\/li>\r\n<\/ul>\r\n<div>\r\n\r\n<strong>Application Proxy Servers<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Web Application Proxy provides organizations with the ability to provide selective access to applications running on servers inside the organization to end users located outside of the organization.<\/p>\r\n\r\n<\/div>\r\nThe process to make the application available externally is known as publishing.\r\n\r\n&nbsp;\r\n\r\n<strong>Products<\/strong>\r\n\r\n&nbsp;\r\n\r\nNone that are strictly Proxy based\r\n\r\n&nbsp;\r\n\r\n\u201cGateway Servers\u201d\r\n\r\n&nbsp;\r\n\r\n<strong>Second Generation Firewall Technology<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">In 1989-1990 from AT&amp;T Bell Labs developed second generation firewall calling it circuit level gateway. This operates up to Layer 4 (Transport Layer). To achieved by retaining enough packets in the buffer until enough information is availabe to make a judgement about its state. Thus, it records all connections passing through it and determines if a packet is a part of current connection or new connection. This firewall also known as stateful packet inspection.<\/p>\r\n&nbsp;\r\n\r\n<strong>Hybrid Firewalls<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">This hybrid firewall provides bith Packet Filtering functions and Application Proxy functions.This type belongs to the third Generation Firewall. The key benefit is that it can understand certain Application Layer protocols (FTP, HTTP, DNS). This generation of firewall is very useful to detect if unwanted protocol is trying to use standard port from known applications (e.g. HTTP) to bypass firewall. This firewall can inspect if packet contains virus signatures. Hooks into socket calls automatically. Disadvantages are that it is quite slow\u00a0and that rules can get complicated. It also can\u2019t possibly support of applications at application layer.<\/p>\r\n&nbsp;\r\n\r\n<strong>Products<\/strong>\r\n<ul>\r\n \t<li>\u00a0Raptor Firewall by Symantec .<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>\u00a0Firewall by Checkpoint.<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>Sidewinder Firewall by Secure Computing.<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>\u00a0Lucent Brick by Lucent<\/li>\r\n<\/ul>\r\n<div>\r\n\r\n<strong>6.2 Firewall Hardware Types<\/strong>\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n<strong>Three basic hardware options<\/strong>\r\n\r\n&nbsp;\r\n<ul>\r\n \t<li>\u00a0 \u00a0Appliance based systems<\/li>\r\n<\/ul>\r\n&nbsp;\r\n\r\nThey are Purpose built and Simply Highl integrated.\r\n\r\n&nbsp;\r\n<ul>\r\n \t<li>\u00a0 \u00a03rd Party servers<\/li>\r\n<\/ul>\r\n&nbsp;\r\n<p style=\"text-align: justify\">They are generaly useful systems and the additionally support the channel with g areater flexibility.Hybrid servers are purpose built for a limited product line.They are often closely integrated with software offerings and may have separate support channel. Most of the components are highly integrated.<\/p>\r\n\r\n<\/div>\r\n<ol start=\"7\">\r\n \t<li><strong> Network Firewall Architectures<\/strong><\/li>\r\n<\/ol>\r\n<strong>Screening Router<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Access Lists provide security against attacker in the network layer.Routers are not aware of application layer. This router only inspects network level information. The packet at the layer 3 of the OSI model.<\/p>\r\n&nbsp;\r\n\r\n<strong>Disadvantages:<\/strong>\r\n<ul>\r\n \t<li>\u00a0Does not provide a great deal of security<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>\u00a0Very fast<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>\u00a0Not commonly used alone for security<\/li>\r\n<\/ul>\r\n<p style=\"text-align: justify\"><strong>Simple Firewall: <\/strong>Simple Fire wall is a simple to utilize program for Microsoft Windows gadgets to permit, or piece programs from associating with the Internet<strong>.<\/strong><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>Multi-Legged Firewall: <\/strong>This is utilized in Small to large sized business.Security requirement is expanded. Provides stronger security and creates a secure sandbox for semi-trusted servicesFlexible and secure.<\/p>\r\n&nbsp;\r\n<div>\r\n\r\n<strong>Firewall Sandwich<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">These are Layered Firewall Approaches with large enterprises and low risk tolerance.It Separates the internal environments and\u00a0<span style=\"text-align: initial;font-size: 1em\">reduces the most happening computer crimes<\/span>.Mostly<span style=\"text-align: initial;font-size: 1em\"> the attacks are internally based.<\/span><\/p>\r\n\r\n<\/div>\r\n<p style=\"text-align: justify\"><strong>Advantages:<\/strong>Layered security is considered the best providing strong security controls coupled with audit, administrative reviews, and an effective security response plans will provide a strong holistic defense.<\/p>\r\n&nbsp;\r\n\r\n<strong>Summary<\/strong>\r\n<ul>\r\n \t<li>Outlined the purpose of Firewalls.<\/li>\r\n \t<li>Discussed about the basic firewall components.<\/li>\r\n \t<li>Discussed about the firewall architecture and various types of firewalls.<\/li>\r\n<\/ul>\r\n<table>\r\n<tbody>\r\n<tr>\r\n<td><strong>you can view video on Firewalls<\/strong><\/td>\r\n<td><a href=\"https:\/\/youtu.be\/VMCT1U8xVcE\" target=\"_blank\" rel=\"noopener\"><img class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n\r\n\r\n<img class=\"alignnone size-full wp-image-465\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-159.jpg\" alt=\"\" width=\"684\" height=\"503\" \/>","rendered":"<div><span style=\"float: right\"><a href=\"https:\/\/youtu.be\/VMCT1U8xVcE\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a><br \/>\n<\/span><\/div>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Learning Objectives<\/strong><\/p>\n<ul>\n<li><strong>Outlined the purpose of Firewalls.<\/strong><\/li>\n<\/ul>\n<ul>\n<li><strong>Discuss about the basic firewall components.<\/strong><\/li>\n<\/ul>\n<ul>\n<li><strong>Discuss about the firewall architecture and various types of firewalls.<\/strong><\/li>\n<\/ul>\n<div>\n<p><strong>1.\u00a0\u00a0 <\/strong><strong>Introduction<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Firewalls are computer security systems that protect your office\/home PCs or your network from intruders, hackers &amp; malicious code. Firewalls protect you from offensive software that may come to reside on your systems or from prying hackers. In a day and age when online security concerns are the top priority of the computer users, Firewalls provide you with the necessary safety and protection. Firewalls are software programs or hardware devices that filter the traffic that flows into you PC or your network through an internet connection. They shift through the data flow &amp; block that which they deem (based on how &amp; for what you have tuned the firewall) harmful\u00a0<span style=\"text-align: initial;font-size: 1em\">to your network or computer system. When connected to the internet, even a standalone PC or a network of interconnected computers make easy targets for malicious software &amp; unscrupulous hackers. A firewall can offer the security that makes you less vulnerable and also protect your data from being compromised or your computers being taken <\/span>hostage<span style=\"text-align: initial;font-size: 1em\">.<\/span><\/p>\n<\/div>\n<p><strong>1.1 What do Firewalls Protect?<\/strong><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li><strong>Data<\/strong>\n<ul>\n<li><strong>Proprietary corporate information<\/strong>.<\/li>\n<li><strong>Financial information<\/strong><\/li>\n<li><strong>Sensitive employee or customer data<\/strong><\/li>\n<\/ul>\n<\/li>\n<li><strong>Resources<\/strong>\n<ul>\n<li style=\"text-align: justify\"><strong>Computing resources <\/strong>consists of any physical or virtual part of constrained accessibility inside a computer framework. Each device associated with a computer framework is an asset.<\/li>\n<li style=\"text-align: justify\"><strong>Time resources <\/strong>includes asset that reports new forms on a designed interval. The level of interval can be subjectively long. This asset is worked to fulfill &#8220;trigger this work in any event once at regular intervals,&#8221; not &#8220;trigger this expand on the tenth hour of each Sunday.&#8221;<\/li>\n<li style=\"text-align: justify\"><strong>Reputation<\/strong>:When the Intruder uses an organization\u2019s network to attack other sites, leads to loss of confidence in an organization.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>1.2 Who do Firewalls Guard Against?<\/strong><\/p>\n<ul>\n<li>Internal Users<\/li>\n<li>Hackers<\/li>\n<li>Corporate Espionage<\/li>\n<li>\u00a0Cyber Terrorists<\/li>\n<\/ul>\n<ol start=\"2\">\n<li><strong>Basic Firewall Components<\/strong><\/li>\n<\/ol>\n<p><strong>\u00a0 \u00a0 2.1 Policy: <\/strong>Building a secure strategy.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>2.2 Advanced authentication (<\/strong>or) &#8220;<strong>Two-Factor Authentication<\/strong>&#8220;: requires an extra separate factor or accreditation with a specific end goal to finish the sign in process. This second qualification is regularly sent as a one time PIN (OTP) that is gotten by something that the client physically has in his or her ownership (e.g. an application or SMS content to a PDA, a hard token or a paper token)<\/p>\n<div>\n<p style=\"text-align: justify\"><strong>\u00a0 2.3 Packet inspection<\/strong>:Deep Packet Inspection and filtering enables advanced network management, user service, and security functions as well as internet data mining, eavesdropping, and internet censorship.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>2.4 Application gateway: <\/strong>is an application program that keeps running on a firewall framework between two systems. When a client program establishes a connection to a destination service, it connects to an application gateway, or proxy.<\/p>\n<\/div>\n<p><strong>2.5 Common Internet Threats:<\/strong>Some of the common internet threats are given below:<\/p>\n<ul>\n<li>\u00a0Malware<\/li>\n<\/ul>\n<ul>\n<li>Computer Virus<\/li>\n<\/ul>\n<ul>\n<li>Rogue Security Software<\/li>\n<\/ul>\n<ul>\n<li>Trojan horse<\/li>\n<\/ul>\n<ul>\n<li>Malicious spyware<\/li>\n<\/ul>\n<ul>\n<li>Computer worm<\/li>\n<\/ul>\n<ul>\n<li>Botnet<\/li>\n<\/ul>\n<ul>\n<li>\u00a0Spam<\/li>\n<\/ul>\n<ul>\n<li>\u00a0Rootkit<\/li>\n<\/ul>\n<ul>\n<li>\u00a0Phishing<\/li>\n<\/ul>\n<ol start=\"2\">\n<li><strong>Denial of service attacks<\/strong><\/li>\n<\/ol>\n<p style=\"text-align: justify\">The Specific attacks that can cause a server crash or Flooding the server with traffic to disrupt or deny service.<\/p>\n<ul>\n<li>\u00a0Intrusion threats<\/li>\n<\/ul>\n<ul>\n<li>\u00a0Attacks on services\/exploits<\/li>\n<\/ul>\n<p style=\"text-align: justify\">The backend server may not be hardened enough for adequate protection, but the firewall can block external attacks.<\/p>\n<ul>\n<li>\u00a0Information threats<\/li>\n<\/ul>\n<ul>\n<li>\u201cViral\u201d threats<\/li>\n<\/ul>\n<ul>\n<li>\u00a0Defacement<\/li>\n<\/ul>\n<ol start=\"3\">\n<li><strong>How Vulnerable are Internet Services?<\/strong><\/li>\n<\/ol>\n<p><strong>3.1 E-mail or smtp \u2013 Simple Mail Transfer Protocol<\/strong><\/p>\n<ul>\n<li style=\"text-align: justify\">TCP\/IP based port 25 (POP 110) In processing, the Post Office Protocol (POP) is an application-layer Internet standard convention utilized by neighborhood email customers to recover email from a remote server over a TCP\/IP association.<\/li>\n<li style=\"text-align: justify\">E-mail bombing (stalking): In Internet use, an email bomb is a type of net manhandle comprising of sending enormous volumes of email to a deliver trying to flood the letter drop or overpower the server where the email address is facilitated in a dissent of-benefit assault.<\/li>\n<\/ul>\n<p style=\"text-align: justify\"><strong>Anonymous harassment<\/strong>: Work environment badgering is a difficult issue that must not be messed with not withstanding when the complainant does not know the wellspring of the provocation and the annoying behavior is unknown.<\/p>\n<p>&nbsp;<\/p>\n<p>Large amounts of e-mail to a single user address<\/p>\n<ul>\n<li>Spamming<\/li>\n<\/ul>\n<p>Messages sent to numerous different users from a host<\/p>\n<ul>\n<li><strong>Virus download mechanism<\/strong><\/li>\n<\/ul>\n<div>\n<p style=\"text-align: justify\"><strong>Code Red<\/strong>: &#8220;Code Red&#8221; and &#8220;Code Blue&#8221; are the two terms that are regularly used to allude to a cardiopulmonary capture, yet different sorts of crises (for instance bomb dangers, psychological\u00a0<span style=\"text-align: initial;font-size: 1em\">militant movement, kid kidnappings, or mass setbacks) might be given &#8220;Code&#8221; assignments as well.<\/span><\/p>\n<\/div>\n<p style=\"text-align: justify\"><strong>Nimda: <\/strong>Nimda is a malignant document contaminating PC worm. It spreads, outperforming the monetary harm caused by past flare-ups, for example, Code Red.<\/p>\n<p>&nbsp;<\/p>\n<p>TCP\/IP based port 25 (POP 110) are not always traceable and can be very insecure.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>4.2 FTP &#8211; File Transfer Protocol<\/strong><\/p>\n<ul>\n<li>TCP\/IP based port 20\/21:<\/li>\n<li style=\"text-align: justify\">Risks include\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 the\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Unencrypted authentication and data transfers.The<span style=\"text-align: initial;font-size: 1em\"> usernames and the passwords can be \u201dsniffed<\/span>\u201d .<span style=\"text-align: initial;font-size: 1em\">Unencrypted data transfer happens<\/span>.Data<span style=\"text-align: initial;font-size: 1em\"> can be viewed <\/span>oftenas<span style=\"text-align: initial;font-size: 1em\"> the part of default installations<\/span>.Anonymous<span style=\"text-align: initial;font-size: 1em\"> ftp is possible.<\/span><\/li>\n<li>\n<div>\n<p><strong>4.3 HTTP \u2013 Hypertext Transfer Protocol<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>TCP\/IP based port 80<\/p>\n<p>&nbsp;<\/p>\n<p>Risks Include<\/p>\n<p>&nbsp;<\/p>\n<p>Browsers can be used to run dangerous commands<\/p>\n<p>&nbsp;<\/p>\n<p>Protocol can be used between user agents and other protocols i.e.. smtp, nntp, ftp<\/p>\n<p>&nbsp;<\/p>\n<p>Difficult to secure<\/p>\n<p>&nbsp;<\/p>\n<p>Remote execution of commands and execution (server side)<\/p>\n<p>&nbsp;<\/p>\n<p>Non-secure add-on applications<\/p>\n<\/div>\n<ul>\n<li>Java<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul>\n<li>Cookies<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul>\n<li>soap<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>4.4 HTTPS \u2013 Secure Hypertext Transfer Protocol<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">TCP\/IP based port 443: TCP port 443 is the standard TCP port that is utilized for site which utilize SSL. When you go to a site which utilizes the https towards the starting you are associating with port 443.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>Risks<\/strong>: Includes the browsers can be used to run dangerous commands. Remote execution of commands and execution (server side), becomes a tunnel for any data.This can be used to subvert firewall\/security controls.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>4.5 DNS<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The DNS service uses the port number 53 for both TCP and UDP in the transport layer. One of the major risks include DNS cache poisoning. Attacker link used to redirect valid connections to the unkown server this called DNS spoofing.Absolutely needed for network services<\/p>\n<p>&nbsp;<\/p>\n<div>\n<p><strong>5. Firewall Architecture Overview<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>The configuration that works best for a particular organization depends on three factors:<\/p>\n<\/div>\n<p style=\"text-align: justify\">\u00a0 \u00a0The objectives of the network, the organization\u2018s ability to develop and implement the architectures, and the budget available for the function.<\/p>\n<p>&nbsp;<\/p>\n<p>There are four common architectural implementations of firewalls.These implementations are<\/p>\n<p>a) Packet Filtering routers,<\/p>\n<p>b) Screened host firewalls,<\/p>\n<p>c) Dual-homed firewalls,and<\/p>\n<p>d) Screened subnet firewalls.<\/p>\n<p>&nbsp;<\/p>\n<div>\n<p><strong>Packet Filtering Routers<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The organizations uses Internet connections should have the router as an interface at the perimeter between the internal networks and the external service provider. Therouters can be configured with access control list (ACL) to reject packets that does not allow into the network. This kind of firewall reduceses the risk from external attack.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Screened host firewalls<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">This Firewall combines the packet filtering router with a separate, dedicated firewall, such as an application proxy server. This technique allows the router to pre-screen packets to minimize the network traffic and loads on the internal proxy.The application proxy verifies the application layer protocol, such as HTTP, and provides the proxy services. This type of host is often termed as a bastion host and should be very highly secured.This bastion host\/application proxy actually contains only cached copies of the internal Web documents, it can still present a promising target, because compromise of the bastion host can disclose the configuration of internal network. To its advantage, this configuration requires the external attack to compromise two separate systems, before the attack can access internal data.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Dual-Homed Host Firewalls<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The Dual-Homed Host Firewall architectural approach is used, the bastion host contains two NICs (Network Interface Cards) rather than one, as in the bastion host configuration. One NIC is connected to the external network, and one is connected to the internal network, providing an additional layer of protection. With 2 NICs , all traffic must physically go through the firewall to move between the internal and external networks. NAT is a method of mapping real, valid, external IP addresses to special ranges of non-routable internal IP addresses, thereby creating yet another barrier to intrusion from external attackers.<\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p><strong>Screened Subnet Firewalls<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The most common architecture used in firewall is the screened subnet firewall. The architecture of a screened subnet firewall provides a DMZ. The DMZ uses a dedicated port on the firewall to link a single bastion host, or a screened subnet. The DMZ is commonly placed in untrusted network where the servers provides various services.<\/p>\n<p>&nbsp;<\/p>\n<div>\n<p><strong>Basic Firewall Components consists of<\/strong><\/p>\n<\/div>\n<ul>\n<li>\u00a0Software<\/li>\n<\/ul>\n<ul>\n<li>\u00a0Hardware<\/li>\n<\/ul>\n<ul>\n<li>Purpose Built\/Appliance based<\/li>\n<\/ul>\n<ol start=\"5\">\n<li><strong>Problems related to Firewall<\/strong><\/li>\n<\/ol>\n<p style=\"text-align: justify\">There are some problems related with implementation and maintenance of the firewall which are,<\/p>\n<ul>\n<li>Administrative limitations\n<ul>\n<li>Access<\/li>\n<li>Monitoring<\/li>\n<li>logging<\/li>\n<\/ul>\n<\/li>\n<li>Management requirements\n<ul>\n<li>Additional control points<\/li>\n<li>Additional non-secure applications required<\/li>\n<\/ul>\n<\/li>\n<li>Software limitations\n<ul>\n<li>Capacity<\/li>\n<li>Availability<\/li>\n<li>Hardware<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol start=\"5\">\n<li><strong>1 Packet Filtering Firewalls<\/strong><\/li>\n<\/ol>\n<p><strong>Products<\/strong><\/p>\n<ul>\n<li>\u00a0First Generation Firewalls<\/li>\n<\/ul>\n<ul>\n<li>\u00a0Typically routers<\/li>\n<\/ul>\n<p><strong>First Generation Firewall Technology<\/strong><\/p>\n<p style=\"text-align: justify\">Most organizations has an Internet connections uses router as the interface at the perimeter between the organization\u2018s internal networks and the external service provider. Most of these routers can be configured to reject packets that the organization does not allow into the network. This is a simple but effective way to protect the organization\u2018s risk from external attack. The drawbacks to this type of firewall include a lack of auditing and strong authentication<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Application Level Firewalls:<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Web Proxy Severs<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">A web proxy server is a computer is used between the computer and a website server when a data\/webpage is requested. There are two common reasons for using a web proxy:<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>To speed up browsing by caching webpage data (a Web cache).<\/li>\n<li>To remain anonymous towards the website while visiting whereby the web proxy acts as a go between the user and the server.<\/li>\n<\/ul>\n<div>\n<p><strong>Application Proxy Servers<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Web Application Proxy provides organizations with the ability to provide selective access to applications running on servers inside the organization to end users located outside of the organization.<\/p>\n<\/div>\n<p>The process to make the application available externally is known as publishing.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Products<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>None that are strictly Proxy based<\/p>\n<p>&nbsp;<\/p>\n<p>\u201cGateway Servers\u201d<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Second Generation Firewall Technology<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">In 1989-1990 from AT&amp;T Bell Labs developed second generation firewall calling it circuit level gateway. This operates up to Layer 4 (Transport Layer). To achieved by retaining enough packets in the buffer until enough information is availabe to make a judgement about its state. Thus, it records all connections passing through it and determines if a packet is a part of current connection or new connection. This firewall also known as stateful packet inspection.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Hybrid Firewalls<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">This hybrid firewall provides bith Packet Filtering functions and Application Proxy functions.This type belongs to the third Generation Firewall. The key benefit is that it can understand certain Application Layer protocols (FTP, HTTP, DNS). This generation of firewall is very useful to detect if unwanted protocol is trying to use standard port from known applications (e.g. HTTP) to bypass firewall. This firewall can inspect if packet contains virus signatures. Hooks into socket calls automatically. Disadvantages are that it is quite slow\u00a0and that rules can get complicated. It also can\u2019t possibly support of applications at application layer.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Products<\/strong><\/p>\n<ul>\n<li>\u00a0Raptor Firewall by Symantec .<\/li>\n<\/ul>\n<ul>\n<li>\u00a0Firewall by Checkpoint.<\/li>\n<\/ul>\n<ul>\n<li>Sidewinder Firewall by Secure Computing.<\/li>\n<\/ul>\n<ul>\n<li>\u00a0Lucent Brick by Lucent<\/li>\n<\/ul>\n<div>\n<p><strong>6.2 Firewall Hardware Types<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Three basic hardware options<\/strong><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>\u00a0 \u00a0Appliance based systems<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>They are Purpose built and Simply Highl integrated.<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>\u00a0 \u00a03rd Party servers<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">They are generaly useful systems and the additionally support the channel with g areater flexibility.Hybrid servers are purpose built for a limited product line.They are often closely integrated with software offerings and may have separate support channel. Most of the components are highly integrated.<\/p>\n<\/div>\n<ol start=\"7\">\n<li><strong> Network Firewall Architectures<\/strong><\/li>\n<\/ol>\n<p><strong>Screening Router<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Access Lists provide security against attacker in the network layer.Routers are not aware of application layer. This router only inspects network level information. The packet at the layer 3 of the OSI model.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Disadvantages:<\/strong><\/p>\n<ul>\n<li>\u00a0Does not provide a great deal of security<\/li>\n<\/ul>\n<ul>\n<li>\u00a0Very fast<\/li>\n<\/ul>\n<ul>\n<li>\u00a0Not commonly used alone for security<\/li>\n<\/ul>\n<p style=\"text-align: justify\"><strong>Simple Firewall: <\/strong>Simple Fire wall is a simple to utilize program for Microsoft Windows gadgets to permit, or piece programs from associating with the Internet<strong>.<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>Multi-Legged Firewall: <\/strong>This is utilized in Small to large sized business.Security requirement is expanded. Provides stronger security and creates a secure sandbox for semi-trusted servicesFlexible and secure.<\/p>\n<p>&nbsp;<\/p>\n<div>\n<p><strong>Firewall Sandwich<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">These are Layered Firewall Approaches with large enterprises and low risk tolerance.It Separates the internal environments and\u00a0<span style=\"text-align: initial;font-size: 1em\">reduces the most happening computer crimes<\/span>.Mostly<span style=\"text-align: initial;font-size: 1em\"> the attacks are internally based.<\/span><\/p>\n<\/div>\n<p style=\"text-align: justify\"><strong>Advantages:<\/strong>Layered security is considered the best providing strong security controls coupled with audit, administrative reviews, and an effective security response plans will provide a strong holistic defense.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Summary<\/strong><\/p>\n<ul>\n<li>Outlined the purpose of Firewalls.<\/li>\n<li>Discussed about the basic firewall components.<\/li>\n<li>Discussed about the firewall architecture and various types of firewalls.<\/li>\n<\/ul>\n<table>\n<tbody>\n<tr>\n<td><strong>you can view video on Firewalls<\/strong><\/td>\n<td><a href=\"https:\/\/youtu.be\/VMCT1U8xVcE\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-465\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-159.jpg\" alt=\"\" width=\"684\" height=\"503\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-159.jpg 684w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-159-300x221.jpg 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-159-65x48.jpg 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-159-225x165.jpg 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-159-350x257.jpg 350w\" sizes=\"auto, (max-width: 684px) 100vw, 684px\" \/><\/p>\n","protected":false},"author":3,"menu_order":36,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":[],"pb_section_license":""},"chapter-type":[],"contributor":[],"license":[],"class_list":["post-464","chapter","type-chapter","status-publish","hentry"],"part":3,"_links":{"self":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters\/464","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/users\/3"}],"version-history":[{"count":5,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters\/464\/revisions"}],"predecessor-version":[{"id":629,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters\/464\/revisions\/629"}],"part":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/parts\/3"}],"metadata":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters\/464\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/media?parent=464"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapter-type?post=464"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/contributor?post=464"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/license?post=464"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}