home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



Security
F E A T U R E  
Tactical Security 101

  January 23, 2003
  By Greg Shipley


>> continued from previous page

Control Issues
TOC Issue TOC
Printer Print full article
Printer Print this page
Printer Download as PDF
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author
 
  In this article
arrow
Introduction
arrow
Vulnerability Management
arrow
Firewalls Get Hotter
arrow
Control Issues
arrow
Event Correlation
arrow
HIP Hosts
arrow
Technology Areas
arrow
How We Got Here

As the number of deployed firewalls increases, so do operational headaches and administrative overhead. Check Point Software Technologies has dominated on this front because its platform offers one of the few truly scalable management frameworks. However, as NetScreen Technologies and other competitors get their management acts together, Check Point will have to fight for continued dominance. Regardless, organizations considering enterprise-level firewall implementations should scrutinize the management framework. Pilot error is still a big problem in firewall administration, and a clear interface can help reduce mistakes.

Rapid quarantining and containment is crucial for large-scale, multinational corporations that need to combat worm outbreaks. For example, in 2001 a number of the Fortune 500 took serious hits when Nimbda rapidly infected key Web and mail servers and wreaked havoc within organizations that had "mushy" centers.

In fact, in 2002 we even saw worms take down PBXs, evidence that some of the industry's leading voicemail systems have vulnerable Sun Solaris and Microsoft Windows operating systems running under the hood. Smart organizations were able to contain outbreaks, however, with detection and quarantine processes. Although many of these manual quarantine efforts used simple router ACLs (access-control lists), strategically placed firewalls with unified management frameworks could have made the process even more efficient. And for those that didn't have choke points in place, these deployments could have made the difference between safety and six- to seven-figure losses.


Rapid-response capabilities are a combination of technology and process: Organizations with response procedures, timely access to router and firewall reprogramming capabilities, and the ability to tune their Web caching engines saved hundreds of thousands of dollars in downtime and repair costs.

The enterprise firewall market is dominated by Cisco and Check Point, according to Gartner, with NetScreen slowly gaining ground. Check Point packs in more options than a Japanese cell phone, but

it will be interesting to see if Cisco and NetScreen start leveraging their integration plans to gain ground. NetScreen is looking to integrate its recently acquired OneSecure inline NIPS and normalization technology into its firewall line, and Cisco has begun putting firewall, VPN (virtual private networking) and IDS functionality into its core switching platforms.

Finally, organizations that are looking for more than just a strong front door may want to keep an eye on Intruvert Networks, TippingPoint Technologies, NetScreen and others that offer Layer 7 inspection and scrubbing features. While few will argue the security benefits of traditional Layer 7 application-proxy-based firewalls, the lack of clear development progress on many traditional proxy-based solutions, such as Secure Computing's SideWinder and Gauntlet (recently acquired from Network Associates) and Symantec's Raptor, has left many practitioners scratching their heads. Some of the "normalization" features found in OpenBSD have sparked interest, and products such as OneSecure's (now NetScreen's) IDP offer a curious blend of intrusion prevention and normalization features.We may see such "proxy killers" gain momentum in the coming months (for more on normalization, see www.aciri.org/vern/papers/norm-usenix-sec-01.pdf).


start top  Firewalls Get Hotter Event Correlation 





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights