- Treat open ports as attack surface and close the unnecessary ones
- Build firewall rules on the “first match wins” principle
- Know what VPNs and Wi-Fi standards do and do not protect against
- Recognise MITM, DNS spoofing and DDoS and choose defences
Murad set up a small web server at home for the school club. The next morning the log showed thousands of connection attempts on ports 22 and 3389 from addresses he had never seen. Nobody had picked him as a target: scanners probe the whole internet non-stop. In this lesson we learn how to defend a network.
Ports and the attack surface
An IP address is like a building and a port like a door number (0–65535). Behind every open port a service is running, and every service is a potential way in. The sum of all entry points reachable from outside is called the attack surface. The golden rule: close everything you do not need.
| Port | Service | Recommendation |
|---|---|---|
| 22 | SSH | only via VPN or allow-listed addresses; keys instead of passwords |
| 23 | Telnet | unencrypted — switch it off |
| 80 | HTTP | only to redirect to HTTPS |
| 443 | HTTPS | open for a public website |
| 3306 | MySQL | must never be open to the internet |
| 3389 | RDP | never directly on the internet, only behind a VPN |
Firewalls
A firewall filters traffic by rules: direction, protocol, port, source and destination address. Rules are checked from top to bottom, the first matching rule wins, and the last rule is “deny everything else”. A stateful firewall remembers established connections, so replies to requests you sent get through without extra rules.
import ipaddress
RULES = [
('allow', 'tcp', 443, '0.0.0.0/0'), # HTTPS from anywhere
('allow', 'tcp', 22, '10.0.0.0/24'), # SSH only from the office LAN
('deny', 'any', None, '0.0.0.0/0'), # everything else
]
def decide(proto, port, src):
for action, r_proto, r_port, r_net in RULES:
if r_proto not in ('any', proto):
continue
if r_port is not None and r_port != port:
continue
if ipaddress.ip_address(src) in ipaddress.ip_network(r_net):
return action
return 'deny'
for packet in [('tcp', 443, '203.0.113.7'), ('tcp', 22, '10.0.0.15'),
('tcp', 22, '203.0.113.7'), ('tcp', 3306, '10.0.0.15')]:
print(packet, '->', decide(*packet))▸ Expected output
('tcp', 443, '203.0.113.7') -> allow
('tcp', 22, '10.0.0.15') -> allow
('tcp', 22, '203.0.113.7') -> deny
('tcp', 3306, '10.0.0.15') -> deny203.0.113.x addresses are reserved for documentation examples, and 10.0.0.0/24 is the internal office network.VPNs and Wi-Fi
A VPN builds an encrypted tunnel between your device and a VPN server (or a company network): it protects traffic on an untrusted network and gives remote access to internal resources. But a VPN does not make you anonymous and does not protect you from phishing or malware; it simply moves your trust from the internet provider to the VPN service. Modern protocols: WireGuard, IPsec, OpenVPN.
| Wi-Fi mode | Verdict |
|---|---|
| Open network | the radio link is not encrypted — only with HTTPS and a VPN |
| WEP | broken long ago, never use it |
| WPA2 (AES) | acceptable with a long passphrase |
| WPA3 (SAE) | best: resists offline password guessing |
In larger networks another key technique is segmentation: the network is split into separate zones (office computers, servers, cameras, guests), and only the traffic that is really needed may cross between zones. Even if a camera is hijacked, the attacker cannot jump from it to the accounting server. At zone borders, IDS/IPS systems detect or block suspicious traffic.
Common attacks and defences
| Attack | The idea | Defence |
|---|---|---|
| Man-in-the-middle (MITM) | the attacker slips between you and the site, for example with a fake “Free_WiFi” hotspot, and reads or alters the traffic | HTTPS and HSTS, taking certificate warnings seriously, a VPN on public networks |
| DNS spoofing | a DNS resolver receives a forged answer, so the domain points to the attacker's IP | DNSSEC, encrypted DNS (DoH, DoT), a trusted resolver; TLS certificate checks expose the fake site |
| DDoS | thousands of hijacked devices (a botnet) flood a service with requests | CDNs and scrubbing services, rate limiting, spare capacity, a plan agreed with the provider |
The school's internet link is 1 Gbit/s. A botnet has 10,000 devices, each sending 2 Mbit/s. How many times is the link overloaded?
Show solutionHide solution
Ratio: 20 Gbit/s ÷ 1 Gbit/s = 20 times.
Conclusion: the link is full before packets even reach the server, so a firewall on the server does not help. Filtering must happen upstream — at the provider or a CDN.
The office computers cannot reach the DNS server (UDP, port 53). Add a rule to RULES that allows UDP 53 only from the 10.0.0.0/24 network. Put the rule in the right place so that the output is allow, deny, deny.
import ipaddress
RULES = [
('allow', 'tcp', 443, '0.0.0.0/0'),
('allow', 'tcp', 22, '10.0.0.0/24'),
('deny', 'any', None, '0.0.0.0/0'),
]
# add a rule for DNS: udp, port 53, office LAN only
def decide(proto, port, src):
for action, r_proto, r_port, r_net in RULES:
if r_proto not in ('any', proto):
continue
if r_port is not None and r_port != port:
continue
if ipaddress.ip_address(src) in ipaddress.ip_network(r_net):
return action
return 'deny'
print(decide('udp', 53, '10.0.0.15'))
print(decide('udp', 53, '198.51.100.4'))
print(decide('tcp', 23, '10.0.0.15'))▸ Expected output
allow deny deny
Key points
- Every open port is part of the attack surface; close the ones you don't need and never expose management ports to the internet.
- Firewall rules are checked top to bottom, the first match wins, and “deny everything” comes last.
- A VPN protects traffic inside a tunnel but gives no anonymity and no protection from phishing.
- For Wi-Fi, WPA3 is best, WPA2 is acceptable with a long passphrase and WEP is useless.
- HTTPS and certificate checks defeat MITM, DNSSEC fights DNS spoofing, and upstream filtering handles DDoS.
Check yourself
10 questions. Every correct answer earns XP.