38 38 votes A firewall is to be configured to allow hosts in a private network to freely open TCP connections and send packets on open connections. However, it will only allow external hosts to send packets on existing open TCP connections or connections that are being opened (by internal hosts) but not allow them to open TCP connections to hosts in the private network. To achieve this the minimum capability of the firewall should be that of A combinational circuit A finite automaton A pushdown automaton with one stack A pushdown automaton with two stacks Computer Networks gateit-2007 computer-networks theory-of-computation normal network-security out-of-gatecse-syllabus + – Ishrat Jahan 9.2k views answer comment Share Follow Print See 1 comment 1 1 comment reply Sumit1311 commented Nov 17, 2016 reply Follow flag It is not PDA+1 but PDA with one/two stacks. makes sense? 1 1 replyShare Please log in or register to add a comment.
Best answer 65 65 votes A combinational circuit$\Rightarrow$ Not possible, because we need memory in Firewall, Combinational ckt has none. A finite automaton$\Rightarrow$ We need infinite memory, there is no upper limit on Number of TCP ckt so Not this. A pushdown automaton with one stack$\Rightarrow$ Stack is infinite. Suppose we have $2$ connections, we have pushed details of those on stack we can not access the details of connection which was pushed first, without popping it off. So, Big NO. A pushdown automaton with two stacks$\Rightarrow$ This is TM. It can do everything our normal computer can do so Yes. A firewall can be created out of TM. Correct Answer: $D$ Akash Kanase answered Dec 18, 2015 • edited May 18, 2019 by Naveen Kumar 3 Akash Kanase comment Share Follow See all 13 Comments 13 13 Comments reply ravi_ssj4 commented Jul 17, 2016 reply Follow flag I think all the explanations are correct except the Finite Automation one. First of all, we don't need infinite memory here, because there could be only finite no. of TCP connections opened by a finite no. of internal hosts at a time. A FA also does not have any memory, but it can automate a pattern, but there is no pattern to the no. of TCP connections and the internal hosts which will open them. So a FA cannot work here. 32 32 replyShare Pankaj Joshi commented Jan 7, 2017 reply Follow flag can't we just block syn packets from outside no need for memory? 4 4 replyShare sushmita commented Aug 24, 2017 reply Follow flag Finite automata have finite amount of memory encoded in its states. 1 1 replyShare Chhotu commented Dec 18, 2017 reply Follow flag If somebody is thinking, why is @ravi_ssj4 ji saying --> number of TCP connection will be finite then answer is https://stackoverflow.com/questions/2332741/what-is-the-theoretical-maximum-number-of-open-tcp-connections-that-a-modern-lin OR in simple terms our main memory is finite. 1 1 replyShare Agnel A commented Jan 8, 2018 reply Follow flag why option C is not correct...we need to track of only the connection which is created by the private network.raise me if I'm wrong. 0 0 replyShare Rishabh Gupta 2 commented Jan 26, 2018 reply Follow flag Someone please answer this: can't we just block syn packets from outside no need for memory? 3 3 replyShare Sourav Basu commented Mar 11, 2018 reply Follow flag What if external host tries to send packets on not opened TCP connections, We need to block those packets as well. 0 0 replyShare Ayush Upadhyaya commented Aug 13, 2018 reply Follow flag For all outgoing packets, if the ACK bit of TCP segment is set to 0(which represents the first SYN) segment, these types of packets must be allowed to leave the network. For all packets coming from outside the network into the private network, all packets which have ACK bit set to 0 must be blocked(means ALL SYN packets from outside are blocked) but if ACK bit is set to 1, this means we are allowing our internal hosts to make TCP connections to the outside world and this is allowed. 2 2 replyShare Divy Kala commented Sep 20, 2018 reply Follow flag An attacker could send messages on a TCP connection that has not been established, but has the SYN bit set to 0. The question says that the firewall "will only allow external hosts to send packets on existing open TCP connections.... but not allow them to open TCP connections to hosts in the private network". Rejecting incoming packets with the SYN bit set will not help us achieve "will only allow external hosts to send packets on existing open TCP connections", but will allow us to achieve the second part of the question. 1 1 replyShare Markzuck commented Nov 27, 2018 reply Follow flag isnt TM= FA + 2 Stacks = PDA + 1 stack? and TM and all other TM with 1 or more stacks are equally powerful, so isnt option C and D same? 1 1 replyShare Matrix commented Dec 13, 2018 reply Follow flag @ Rishabh Gupta 2 If we block syn packet from outside wouldn't it also block SYN + ACK packet required during 3 way handshake in connection establishment phase ? 3 3 replyShare zeeshanmohnavi commented Dec 22, 2018 reply Follow flag @Akash Kanase You arguments make sense, but since the question mentions the word minimum, I think option $(C)$ could be correct as well if we assume that the TCP connections are accessed in the opposite order in which they are opened. Comments? 0 0 replyShare KartikGawande commented Sep 25, 2022 reply Follow flag Markzuck by “pda with one stack” we dont mean “pda with one additional stack” we mean “pda consisting of one stack” 0 0 replyShare Please log in or register to add a comment.
5 5 votes It should be D as it is equal to turing machine and since we need to keep track of all the open connections as they should only be connected with outside world(one to one matching) a PDA won't suffice.. Marv Patel answered Dec 31, 2014 Marv Patel comment Share Follow See 1 comment 1 1 comment reply Vicky Bajoria commented Jan 8, 2015 reply Follow flag Answer should be (D) It can be done by finite state machine only if it is allowed only one host to open connection at a time, becuase when the replying packet will come back, then NAT (network address translator) very much knowing who has asked for the packet.. but since more than one host can open connection simultaneously, so memory requirement may not be finite because we don't know how many host in the private network has asked for the network.. So it does require some memory capability.. And as per the options we have to use stack as the memory.. We will be requring two stack, because when a external packets coems as a reply then firewall pop each of the requiesting packet to see, who has ordred the packet and keep on pushing on the another stack, and once it is found, he forwards it to the requesting host.. else if not found the packet is discarded.. 15 15 replyShare Please log in or register to add a comment.
0 0 votes pushdown automata with two stacks which is the Turing machine. Turing machine can do everything as the normal computer can do, so firewall can be created by the TM. Utkarsh Pathak answered Nov 9, 2020 Utkarsh Pathak comment Share Follow 0 reply Please log in or register to add a comment.
0 0 votes COMMENT BELOW IF YOU HAVE ANY DOUBT akshay_123 answered May 2 akshay_123 comment Share Follow 0 reply Please log in or register to add a comment.