Home > Ask the Security Experts > Network Security Questions & Answers > How well do content filtering tools limit network traffic?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How well do content filtering tools limit network traffic?

Mike Chapple EXPERT RESPONSE FROM: Mike Chapple

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 20 December 2006
How do content monitoring and filtering tools work? How well do they monitor outbound traffic?

>
EXPERT RESPONSE
Content filters are an evolving area of security technology. Essentially, they monitor all traffic on a network and compare it to a set of rules that define unacceptable activity. Content monitors alert administrators to the unwanted activity, while content filters block the objectionable traffic from entering the network.

The technology behind content filtering is fairly simple. If the device is set up to be a monitor, technicians can attach it to the network by using a network tap, span port or similar replication technology, ensuring that the network has a copy of all traffic. If it is designed to serve as a filter, it can be placed at a choke point in the network.

The important criteria to evaluate when deciding if a content filter meets your business requirements is how the filter decides which traffic is allowed and which is denied. Most of the current generation of content filters use whitelist/blacklist technology to build lists of acceptable and unacceptable content. Depending upon the organization's security requirements, either a default "allow" or "deny" rule is applied. This approach is often seen in Web content filtering, where users are blocked from accessing inappropriate Web sites. While maintaining these lists can be quite a chore, filter manufacturers often provide a subscription service that offers access to a centrally maintained site categorization scheme.

Some companies are experimenting with newer content-filtering technologies. Using document signatures, traffic profiles and other techniques, these approaches seek to identify leaks of confidential information and other inappropriate content. While they hold promise, they're probably only useful if you have extremely high security requirements or a desire to be on the cutting edge of security technology. Otherwise, I'd recommend waiting a couple of years until these technologies mature.

More information:

  • Use IPsec rules to filter network traffic.
  • A content filtering tool is only one of the important intrusion defense technologies. Learn about the others in SearchSecurity.com's Intrusion Defense School.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Network Security
    Will Cisco's plan to open access to the IOS improve network security?
    Will VoIP attacks result in more than just spam?
    Should enterprises implement a mandatory iPhone VPN?
    Will organizations that lag behind on IPv6 adoption have greater security risks?
    Should iPhone email be sent without SSL encryption?
    How to secure an FTP connection
    DMVPN configuration: Is an additional firewall needed between the router and the Internet?
    Is centralized logging worth all the effort?
    What are the pros and cons of shaping P2P packets?
    Should an ISP keep corrupted machines off of a network?

    Monitoring Network Traffic and Network Forensics
    Windows registry forensics guide: Investigating hacker activities
    More built-in Windows commands for system analysis
    Is security improved when the number of Internet gateways is reduced?
    Screencast: Using Nessus to scan for vulnerabilities
    What are the pros and cons of shaping P2P packets?
    Built-in Windows commands to determine if a system has been hacked
    How will the centralized logging of network flow data benefit an enterprise?
    The forensics mindset: Making life easier for investigators
    Data Loss Prevention Tools Offer Insight into Where Data Lives
    vPro: Making the case for network security on a chip

    URL Filtering
    Web security gateways keep Web-based malware at bay
    Web security gateways meet rising malware threats
    Can watching online videos present enterprise security risks?
    How can hackers bypass proxy servers?
    What are the best ways to block proxy server sites?
    At Your Service
    Blocking Web anonymizers in the enterprise
    Mozilla fixes nearly two dozen Firefox flaws
    Blocking online music access
    Review: StoneGate SG-4000 'hard to beat'

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    computer forensics  (SearchSecurity.com)
    Einstein  (SearchSecurity.com)
    footprinting  (SearchSecurity.com)
    information signature  (SearchSecurity.com)
    intrusion detection  (SearchSecurity.com)
    network forensics  (SearchSecurity.com)
    port scan  (SearchSecurity.com)
    probe  (SearchSecurity.com)
    promiscuous mode  (SearchSecurity.com)
    snoop server  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts