Security Information Information Research

Tell a Friend about this Site

Personal Firewalls for Home Users


What is a Firewall?

The term "firewall" illustrates a system that protects a network and the machines on them from various types of attack. Firewalls are geared towards keeping the server up all the time and protecting the entire network.

The primary goal of a firewall is to implement a desired security policy; controlling access in both directions through the firewall, and to protect the firewall itself from compromise. It wards off intrusion attempts, Trojans and other malicious attacks.

Personal Firewalls:

They are meant for the home user in a networked environment. They aim to block simple attacks, unlike the enterprise level firewalls that the corporate world uses at the server or router end. There are many ways to implement a firewall, each with specific advantages and disadvantages.

Are they really needed?

Nowadays organizations and professionals use Internet technology to establish their online presence and showcase their products and services globally. Their endeavor is to leverage digital technology to make their business work for them.

All the organizations and professionals are shifting from Dialup to broadband and getting a fixed IP. It has led to an increase in security attacks, bugs in everyday working. This does not mean that Dialup being anonymous dynamic link or the firewall of the ISP network make you pretty safe.

Now if your machine was under attack, you must have wondered what went wrong making your system crash suddenly. So I would rather like to say, it's not necessary for anyone to actually know about you or your IP address to gain access to your system.

If you system is infected or prone to intrusions, then beyond the anonymity of your Dialup connection or a dynamic IP, your system can be hacked.

Types of Attacks

Intrusion:

There are many ways to gain unauthorized access to a system. Operating system vulnerabilities, cracked or guessed passwords are some of the more common. Once access is attained, the intruder can send email, tamper with data, or use the system privileges to attack another system.

Information Theft and Tampering:

Data theft and tampering do not always require that the system be compromised. There have been many bugs with FTP servers that allow attackers to download password files or upload Trojan horses.

Service Attacks:

Any attack that keeps the intended user from being able to use the services provided by their servers is considered a denial of service attack. There are many types of denial of service attacks, and unfortunately are very difficult to defend against. "Mail bombs" are one example in which an attacker repeatedly sends large mail files in the attempt at filling the server's disk filesystem thus preventing legitimate mail from being received.

Types of Attackers

Joyrider:

Not all attacks on computer systems are malicious. Joyriders are just looking for fun. Your system may be broken into just because it was easy, or to use the machine as a platform to attack others. It may be difficult to detect intrusion on a system that is used for this purpose. If the log files are modified, and if everything appears to be working, you may never know.

Vandals:

A vandal is malicious. They break in to delete files or crash computer systems either because they don't like you, or because they enjoy destroying things. If a vandal breaks into your computer, you will know about it right away. Vandals may also steal secrets and target your privacy.

"In an incident a Trojan was being used to operate the web cam. All the activities being done in the house were being telecasted on the websites."

Spies:

Spies are out to get secret information. It may be difficult to detect break-ins by spies since they will probably leave no trace if they get what they are looking for.

A personal firewall, therefore, is one of the methods you can use to deny such intrusions.

How Firewalls work?

Firewalls basically work as a filter between your application and network connection. They act as gatekeepers and as per your settings, show a port as open or closed for communication. You can grant rights for different applications to gain access to the internet and also in a reverse manner by blocking outside applications trying to use ports and protocols and preventing attacks. Hence you can block ports that you don't use or even block common ports used by Trojans.

Using Firewalls you can also block protocols, so restricting access to NetBIOS will prevent computers on the network from accessing your data. Firewalls often use a combination of ports, protocols, and application level security to give you the desired security.

Firewalls are configured to discard packets with particular attributes such as:

  • Specific source or destination IP addresses.

  • Specific protocol types

  • TCP flags set/clear in the packet header.

Choosing a firewall:

Choose the firewalls which have the ability to ward of all intrusion attempts, control applications that can access the internet, preventing the malicious scripts or controls from stealing information or uploading files and prevent Trojans and other backdoor agents from running as servers.

The purpose of having a firewall cannot be diminished in order to gain speed. However, secure, high-performance firewalls are required to remove the bottleneck when using high speed Internet connections. The World-Wide-Web makes possible the generation of enormous amounts of traffic at the click of a mouse.

Some of the good firewall performers available in the market are below:

  • BlackICE Defender

  • eSafe Desktop

  • McAfee Personal Firewall

  • Neowatch

  • Norton Personal Firewall

  • PGP Desktop Security

  • Sygate Personal Firewalls

  • Tiny Personal Firewall

  • Zone Alarm

  • Zone Alarm Pro

Most of these firewalls are free for personal use or offer a free trial period. All the personal firewalls available can't ensure 100% security for your machine. Regular maintenance of the machine is needed for ensuring safety.

Some of the tasks advised for maintaining system not prone to intrusions:

  • Disable file and print sharing if you are not going to be on network.

  • Update your antivirus signature files regularly.

  • Use a specialized Trojan cleaner.

  • Regular apply security patches to your software and operating system.

  • Don't open email attachments if you have don't know the contents it may contain.

  • Don't allow unknown applications to access to the internet or to your system.

  • Regularly check log files of your personal firewall and antivirus software.

  • Disable ActiveX and java and uninstall windows scripting host if not required.

  • Turn off Macros in Applications like Microsoft Office and turn macro protection on.

  • Check the open ports of your system and see them against the common list of Trojans ports to see if they are being used by some Trojan.

  • Log Off from your internet connection if not required. Being online on the internet for long duration gives any intruder more and sufficient time to breach system security.

  • Unplug peripherals like web cam, microphone if they are not being used.

About The Author

Pawan Bangar,
Technical Director,
Birbals,India
ebirbals@gmail.com


MORE RESOURCES:

ABC News

McCain, Obama Tout Competing Social Security Plans (Update2)
Bloomberg - 13 hours ago
6 (Bloomberg) -- Presidential candidates John McCain and Barack Obama made dueling pitches to the nation's elderly, each vowing to bolster Social Security ...
Obama and McCain spar over Social Security Reuters
McCain, Obama Split Over Social Security Wall Street Journal
Candidates zero in on social security Minneapolis Star Tribune
Voice of America - The Associated Press
all 344 news articles


New choice for Social Security
San Diego Union Tribune, United States - 54 minutes ago
By Norma de la Vega Retired people who get Social Security checks by mail but don't have bank accounts have a new option for receiving their benefits. ...
Social Security debit card not a hit Carlsbad Current Argus
Debit Card Makes Social Security Easier NewsChannel5.com
Social Security debit card introduced Bizjournals.com
all 7 news articles


New poll: Voters see GOP-McCain surge on national security over ...
Los Angeles Times, CA - 16 hours ago
The national security gap has reopened. Democrats are regaining their reputation with voters as wimps. Greenberg, Quinlan, Rosner has just released a survey ...


ABC News

Rice hails business, security ties with Morocco
Jerusalem Post, Israel - 52 minutes ago
By AP US Secretary of State Condoleezza Rice held talks with her Moroccan counterpart on Sunday to expand on their countries' close business and security ...
In Morocco, Rice cites business, security ties The Associated Press
Algeria trip amid tight security Gulf Times
Discussing security with leaders of Tunisia and Algeria Al-Arabiya
Reuters - elEconomista.es
all 228 news articles


Biggest Security Challenges
PC World - Sep 6, 2008
Edward Amoroso is the chief security officer at AT&T in Florham Park, NJ, as well as a professor who has written several textbooks on information security. ...


GulfNews

Police likely to review VIP routes security
Daily Times, Pakistan - 17 hours ago
By Imran Asghar RAWALPINDI: Rawalpindi and Islamabad police in collaboration with other law-enforcement agencies are likely to review security arrangements ...
Security fears for Pakistan presidential election Radio Australia
Pak funding Mujahideen in Kashmir Hindustan Times
Attack on PM motorcade The Post
The News International - Irish Times
all 1,230 news articles


CNET News

Security firm spots Chrome 'SaveAs' flaw
CNET News, CA - 20 hours ago
It's been only a few days since Google released its Chrome browser, and security researchers are still digging into the software in search of the first few ...


Seattle Post Intelligencer

Iraqis protest against US security pact
PRESS TV, Iran - Sep 6, 2008
Thousands have protested in Iraq after Friday prayers against the controversial Washington-Baghdad security pact and the occupation in Iraq. ...
How to Exit Iraq New York Times
Lingering tensions slow Iraqi withdrawal plans International Herald Tribune
One down, seven to go Al-Ahram Weekly
Middle East Times - The Eureka Reporter
all 177 news articles


Mass. maximum security prison installing bunk beds
Worcester Telegram, MA - 1 hour ago
AP BOSTON— Prison officials are installing bunk beds for the first time at the maximum-security Souza-Baranowski Correctional Center in Shirley. ...
State sets record high for inmates Boston Herald
all 3 news articles


ABS CBN News

National security adviser: ‘Give Chavit a chance’
Inquirer.net, Philippines - 2 hours ago
MANILA, Philippines -- National Security Adviser Noberto Gonzales does not mind the entry of former Ilocos governor Luis "Chavit” Singson into the ...
Singson qualified as deputy nat'l security adviser - Palace GMA news.tv
Palace: Singson appointment is Arroyo's prerogative Sun.Star
Singson NSA posting ‘better than Gov Palin’s’ Inquirer.net
Inquirer.net - GMA news.tv
all 14 news articles

Security - Google News



MaineBannerExchange

home | site map
© 2006