City University of Hong Kong · FACULTY OF INFORMATION TECHNOLOGY

IS6523 Chap.5 Access Control, Firewalls and Perimeter Architecture

- one subject, every graph, every model, every mark
10 Chapters5-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 5 of 10 · IS6523

Access Control, Firewalls and Perimeter Architecture

Enforcement instruments, each with a stated reach

The session opens by conceding its own limits: technical controls cannot secure an environment alone, and people inside an organisation often have direct access to information and can circumvent the most potent of them. What technical controls do is enforce policy where human behaviour is hard to regulate.

Read the whole chapter as a catalogue of enforcement instruments with published blind spots rather than as a list of defences, because the examinable question is always which instrument was in a position to see the failure described.

Four processes in sequence, and three models separated by who decides

Access control runs through identification, where an unverified entity proposes a label, authentication, where that claim is validated, authorisation, where an authenticated entity is matched to assets and access levels, and accountability, where every action is attributable to an identity through logs and journals.

Each depends on the one before it, so skipping any of the four produces a characteristic failure.

The models differ only in who sets the rule: mandatory controls follow a data classification scheme, nondiscretionary controls are a strictly enforced version managed centrally, and discretionary controls are implemented at the option of the data user, which scales best and audits worst.

Generations, architectures and the limits the session prints

Four firewall generations are distinguished by what each can observe, from packet header fields through an application layer proxy and a stateful connection table to deep inspection of content, with the caution that a stateful device falls back to plain packet filtering whenever it cannot match an incoming packet.

Three implementation architectures follow, and the difference between the second and the third is a second filtering stage rather than a better device. The session then prints a list of what firewalls cannot do, all of it about programming, patterns and people, which is what makes buying a larger device an answer to almost nothing on the list.

In this chapter

What this chapter covers

  • 01

    Technical controls as policy enforcement, and their stated limit

  • 02

    Identification, authentication, authorisation and accountability in sequence

  • 03

    Mandatory, nondiscretionary and discretionary models

  • 04

    Four firewall generations and what each can observe

  • 05

    The fallback behaviour of a stateful device

  • 06

    Proxy servers, cache servers and the demilitarised zone

  • 07

    Bastion host, screened host and screened subnet

  • 08

    Address and port translation, and the non-routable ranges

  • 09

    Virtual private networks in transport and tunnel mode

  • 10

    Wireless footprint as a management variable

Worked example · free

Decide whether the device or the topology failed

Q [6 marks]. AskSia-authored practice. An attacker reaches a distributor's internal order database through its public web shop. Firewall logs show the traffic was allowed: it arrived on the shop's port, from an address with no history, carrying a request the shop itself forwarded inward. Would a better firewall have changed the outcome? The marks shown are an AskSia study allocation, not a University marking scheme.
  • 3Say why packet filtering and stateful inspection both pass this traffic.
  • 3Name the architectural change and what it adds.
A better device would not have changed it. The traffic was well formed and arrived on an allowed port, so a packet filter had nothing to object to, and a stateful device would have found a matching state table entry because the connection was genuinely initiated from outside to a service meant to be reachable. What changes the outcome is placement. Under a screened subnet architecture the shop sits on its own segment behind an external filtering router, with a second filtering stage between that segment and the trusted network, so a connection into the internal order system is permitted only from the segment's own hosts and only where the interior rule set allows it. The instrument that failed was the topology.
Sia tip — State where the device sits before you state what it catches. A control named without a position is unassessable, and half the diagnostic questions in this area are answered entirely by the sentence that names the segment the device is on.
Glossary

Key terms

Supplicant
The entity seeking access to a resource, which proposes an identifier during the identification process before anything has been validated.
Discretionary Access Control
A model in which access is granted at the discretion of the data user rather than by classification or central authority. It scales well and audits poorly.
Bastion Host
A single device filtering packets as the sole security point between two networks, usually dual homed with one interface on each. The course notes it is a rich target.
Stateful Packet Inspection
Firewall behaviour that tracks the state and context of each connection in a state table, falling back to plain packet filtering against the rule base when a packet cannot be matched.
Screened Subnet
An architecture placing public facing hosts on a separate segment behind a filtering router, with further packet filtering between that segment and the trusted network.
Port Address Translation
The conversion of one routable external address to a range of internal addresses by adding a unique port number to traffic leaving the private network.
Tunnel Mode
A virtual private network arrangement in which two perimeter servers act as encryption points for all traffic crossing an unsecured network, so an intercepted packet reveals nothing about the true destination.
Content Filter
A tool that restricts what enters a network, most commonly access to material unrelated to business. The course notes it is technically not a firewall.
FAQ

Access Control, Firewalls and Perimeter Architecture FAQ

Which of the four access processes does a stale permissions audit finding actually indict?

Authorisation, not authentication. Everyone holding a stale permission is who they claim to be; what failed is that the matching of an authenticated entity to assets and access levels was never revisited. The distinction matters because it selects the remedy: periodic re-attestation rather than stronger credentials, and it also usually identifies discretionary access control as the model in use.

Is a stateful firewall always stronger than a packet filter?

Not in the case the course singles out. When a stateful device receives an incoming packet it cannot match to its state table it falls back to plain packet filtering against the rule base, and writes a new table entry where that rule base permits the packet.

That means the weakest configured rule sets the real behaviour of the device, so a poorly written rule base makes the two generations equivalent in exactly the situation you most want them to differ.

What can deep inspection at the perimeter not see?

Two things the course names elsewhere. Anything that never crosses the boundary, such as a file copied to removable media or moved between machines on a segment the device does not observe. And anything encrypted before it leaves, since an inspector without the key cannot read it, which is why the detection material states plainly that network placed sensors cannot analyse encrypted packets.

Why does the course call the size of a wireless footprint a management requirement?

Because it is the one control variable in this area that is set by a physical decision rather than by configuration. The footprint depends on the power the access points emit, so placement and strength determine how far outside the building the network is reachable at all. Protocol choice matters too, and the guidance is explicit that the older privacy protocol is considered insecure and easily breached.

Study strategy

Exam move

List the four access processes in order and write beside each the failure that results from skipping it, because that mapping answers most diagnostic questions in this area on its own. Then sketch the three architectures and mark, on each, the point an attacker who has compromised a public facing host would have to cross next. Finally read the list of firewall limitations and pick the two that no purchase could remove.

Working through Access Control, Firewalls and Perimeter Architecture in IS6523? Sia is AskSia’s AI Information Technology tutor — ask any IS6523 Access Control, Firewalls and Perimeter Architecture question and get a clear, step-by-step explanation grounded in how IS6523 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 6 of your City University of Hong Kong subjects - and 1,000+ Bibles across every Australian university.
Sia - your IS6523 tutor, unlimited, worked the way the exam marks it
The full 5-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works