Home > Security Tips > Network Security Tactics > Q&A: Developments in firewalls
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

Q&A: Developments in firewalls


Crystal I. Ferraro, Editor
03.15.2004
Rating: -4.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


In a recent SearchSecurity webcast, speaker Joel Snyder, Senior Partner for Opus One, addressed technological developments in application-layer firewalls based on his research for sister publication Information Security magazine. Here he answers a few of the user-submitted questions he didn't have time to answer during the broadcast. If you missed our webcast, Application-layer firewalling: Raise your perimeter IQ, or would like to review it, you may listen to the webcast on-demand or download Joel's presentation without audio.


Why aren't firewalls blocking spyware?

Well, depending on your definition of spyware, they are. Firewalls give you the granular control you need to block incoming and outgoing traffic. The products we reviewed go deeper into the protocol and can block things that look like HTTP but aren't. Look at the table with the Information Security magazine article for features such as "HTTP Header Filtering," for example.


I thought that proxy makers didn't just claim more control but more security (even in the absence of more control), because of RFC enforcement and other things that they can never seem to explain. Please comment.

They do continue to make this claim. What has not happened is a consensus on whether the additional security is useful or not. Taking an example from the physical world, if I put a safe inside of another safe, it's more secure, isn't it? But is that second, inner safe needed? Is the cost/benefit ratio there? I think that this debate has continued and will go on forever. For some enterprises, the cost/benefit ratio is there; for others, it's not. In general, the marketplace has voted with its dollars in favor of products based on stateful-packet filtering over proxies. But the proxies still have a significant market. Folks like Secure Computing and WatchGuard and CyberGuard are all still in business.



MORE INFORMATION ON FIREWALLS:


What capabilities exist in the latest firewall products to break and re-establish SSL encryption so application scanning of encrypted HTTP is possible?

None in the products I tested, but I don't know about all firewalls out there. The companies I spoke with were more than circumspect about that -- they think that even if they have the capability to decrypt encrypted SSL that this may not be a good idea. It may be a more dangerous tool than should be given to most companies.

Your question is actually a bit different. You're asking about possibly setting up two SSL sessions. That's very common -- all the SSL VPN vendors are doing that already. But I'm guessing you're more interested in maintaining end-to-end integrity and decrypting the data on the fly.

Do you think that this is an important feature? Are you concerned that your SSL-based Web server is vulnerable to attack? Or are you worried about end users going out on the Internet using encrypted traffic that you can't evaluate for proper policy compliance?


Have any firewalls added intelligence to evaluate or alert on poor firewall rule sets?

Not the ones I looked at. I would be a bit surprised if the firewall itself had done that. But I've been surprised before.


What do you think of the DoD common criteria process?

At the high end, having certification is generally a waste of time and money. It becomes largely a paper chase of getting certification for operating at some level below where you already are. Thus, high-end products go far beyond the basic common criteria. However, at the low end, there are products that cannot meet the basic levels required not just in DoD, but in all sorts of other certification programs. So it is a reasonable barrier.

My impression is that every high-end product vendor gets these certifications because they are required as part of the purchasing process by some large customers, but that most consider it a waste of time. On the other hand, it does keep the riff-raff out. So it's both good and bad, in my opinion.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network Security Tactics
IE 8 beta 2 security features may mark improvements for browser security
Screencast: How to use Nipper to create network security reports
Mining enterprise SIM logs for relevant security event data
How to configure NAP for Windows Server 2008
Exploring Microsoft's Network Access Protection policy options
Screencast: How to use Wikto for Web server assessment
How to avoid DLP implementation pitfalls
Microsoft Baseline Security Analyzer: Do updates offer improved Windows security?
How to patch Kaminsky's DNS vulnerability
Directory services and beyond: The future of LDAP

Network Firewalls
Kaminsky: DNS issue still major threat
Product Review: Sophos Endpoint Security and Control 8.0
PCI DSS 1.2 clarifies wireless, antivirus use
Check Point adds virtual firewall appliance
Researchers develop lightweight Cisco IOS rootkit
Is it possible to allow select access to IP addresses using Windows Server 2003?
Sophos finds patching issues through endpoint NAC tool
Fortinet acquires database vulnerability scanner from IPLocks
Users are complaining that they can no longer reach any login site belonging to Microsoft. Any ideas?
Is an IPsec VPN necessary when connecting remote servers that process financial transactions?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bastion host  (SearchSecurity.com)
firewall  (SearchSecurity.com)
Firewall Builder  (SearchSecurity.com)
personal firewall  (SearchSecurity.com)
screened subnet  (SearchSecurity.com)
virus  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts