Home > Ask the Security Experts > Application Security Questions & Answers > The pros and cons of application firewalls
Ask The Security Expert: Questions & Answers
EMAIL THIS

The pros and cons of application firewalls

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 07 September 2005
Why is it that positive model application (layer 7) firewalls are NOT the default option?


BROWSE BY TAG
Application Security,   Application and Platform Security,   Database Security Management,   Web Security Tools and Best Practices,   Web Application Security,   Network Security: Tools, Products, Software,   Network Firewalls, Routers and Switches,   Enterprise Network Security,   Web Server Threats and Countermeasures,   Web Application and Web 2.0 Threats,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Application Security
Are Web application penetration tests still important?
What does 'invoked by uid 78' mean?
How secure are iPhone App Store mobile applications?
What security software should be installed on Internet café computers?
Are message stubs a secure part of email retention policies?
How does a Web server model differ from an application server model?
Can Google Earth and other mash-up applications threaten enterprise security?
Do European laws prevent a U.S. company from blocking spam?
Can one antivirus program be used to get rid of spyware?
How to prevent cross-site scripting (XSS) session hijacking

Database Security Management
Oracle to buy Sun Microsystems for $7.4 billion
Oracle issues 43 updates, fixes serious database flaws
Information security book excerpts and reviews
Kaspersky website hacked multiple times, expert says
Kaspersky website hacked, customer activation codes exposed
SQL injection attacks targeting Flash, JavaScript errors
Fuzzing tool helps Oracle DBAs defend against SQL injection
Oracle extends Audit Vault third-party database compatibility
When should a database application be placed in a DMZ?
Oracle patches dangerous WebLogic, Secure Backup vulnerabilities
Database Security Management Research

Web Application Security
nCircle statistics show rising Web application vulnerabilities
Twitter bugs, DNSSEC and broswer security
Month of Twitter Bugs project to document Twitter flaws
Are Web application penetration tests still important?
IT pros can detect, prevent website vulnerabilities, thwart attacks
PCI compliance requirement 6: Systems and applications
Trust eroding as social engineering attacks climb in 2009, says Kaspersky expert
US-CERT warns of Gumblar, Martuz drive-by exploits
XSS bugs, information leakage top list of website vulnerabilities
How to find and stop automated SQL injection attacks

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
data encryption/decryption IC  (SearchSecurity.com)
International Data Encryption Algorithm  (SearchSecurity.com)
link encryption  (SearchSecurity.com)
MD2  (SearchSecurity.com)
MD4  (SearchSecurity.com)
MD5  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Application firewalls or proxies certainly do offer several advantages over packet filter and stateful packet inspection firewalls. Although these types of firewalls can prevent various network-level attacks, they cannot block the gaping holes found in most Web applications that allow hackers to attack Web sites directly through URL manipulation. However, they can permit or deny specific applications or specific features of an application given a great degree of granular control. Application firewalls can also authenticate users directly. This means, for example, that they can allow or deny a specific incoming telnet command from a particular user, whereas other firewalls can only control general incoming requests from a particular host.

They also provide better content filtering capabilities as they have the ability to examine the payload of the packet and make decisions based on actual content. Having the ability to examine the entire network packet rather than just the network addresses and ports means they have more extensive logging capabilities too, such as application-specific commands, which provide valuable information for dealing with security incidents and policy implementation.

So, given these obvious security advantages why aren't application firewalls the default option? Well, the main reasons are cost and performance. Since all incoming and outgoing traffic is inspected at the application level, it must pass through all seven layers of the OSI model prior to being inspected, whereas packet filtering and stateful packet inspection methods just look at traffic at the network layer. Because the firewall must consume CPU cycles reading and interpreting each packet, the inspection process requires more processing power, which has the potential to become a bottleneck for the network. This means application firewalls are more susceptible to distributed denial-of-service attacks and therefore are less suited to high-bandwidth or real-time applications. The firewall can also be vulnerable to the security loopholes of the underlying operating system.

Another disadvantage of application firewalls is that each protocol, such as HTTP, SMTP, etc., requires its own proxy application, and support for new network applications and protocols tends to be limited. Although most firewall vendors provide generic proxy agents to support undefined network protocols or applications, they tend to allow traffic to tunnel through the firewall, negating many of the reasons for operating an application firewall. Alternatively, stateful packet inspection firewalls, like packet filtering firewalls, have very little impact on network performance, can be implemented transparently and are application independent. Scalability can also become a problem as the number of clients or the number of proxies increases. Application firewalls typically require clients on the network to install specialized software or make configuration changes to be able to connect to the application proxy. This can have quite an impact on larger networks. To reduce the load on the firewall, a dedicated proxy server may be needed to secure less time-sensitive services, such as e-mail and most Web traffic adding to the overall costs.

Hopefully you can see why an application firewall might not be the obvious choice for everyone, but what about the positive model you also mention in your question? The two approaches for an application firewall are a positive security model, which enforces positive behavior and a negative security model, which blocks recognized attacks by relying on a database of known attack signatures. The weakness in the negative model is that it provides no defense against newly discovered exploits and it tends to become an almost daily race against time to keep the signature database up-to-date. Unlike a negative security model, where all behaviors are legal except what is known to be illegal, the positive security model focuses instead on the allowed actions a user may perform, i.e. everything is illegal except what is known to be legal. Although the positive model is certainly the preferred approach, products that use this model are generally more expensive and sophisticated than those that don't. So again, it comes down to money and time.


Related Information

  • Visit our firewall resource center for news, tips and expert advice.
  • Learn how to lock down your Web applications





  • Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts