Error » Security Error » Security News » What Firewall Do And What Firewalls Don’t Do

Security News The Latest Computer Security News

Post New Thread Reply
  What Firewall Do And What Firewalls Don’t Do
LinkBack Thread Tools Display Modes
Old 26-Mar-2008, 06:48 AM   #1 (permalink)
Fixed Error!
 
newsprovider's Avatar

Posts: 136
Join Date: Mar 2008
Rep Power: 1 newsprovider is on a distinguished road

IM:
Default What Firewall Do And What Firewalls Don’t Do

Over the last few years, security threats to companies have grown and altered dramatically and so have the defences. Traditional firewalls, installed over three years ago, are often not best suited for current threats and don’t protect against a number of newer threats.
What firewalls do
A firewall is a system designed to prevent unauthorised access to or from a private computer network. Firewalls are frequently used to prevent unauthorised Internet users from accessing private networks connected to the Internet (often described as intranets). All messages entering or leaving the intranet pass through the firewall, which examines each message and blocks those that do not meet the specified security criteria.
You need a firewall to protect your confidential information from those not authorised to access it and to protect against malicious users and accidents that originate outside your network. One of the most important elements of a firewall is its access control features, which distinguish between good and bad traffic.
There are various types of firewall. In ascending order, they are
* Packet layer
This analyses network traffic at the transport protocol layer.
* Circuit level
This validates that packets are either connection or data packets.
* Application layer
This ensures valid data at the application level before connecting.
* Proxy server
This intercepts all messages entering or leaving the network.
In the real world, threats have evolved over the years and firewalls have evolved to deal with them. While it is still possible to buy packet only firewalls, they are not adequate for business use. Protection against combination threats is best provided by firewalls which combine all of the above elements.
Specific functions performed by firewalls include:
* Gateway defence
* Carrying out defined security policies
* Segregating activity between your trusted network, the Internet and your DMZ (a protected zone midway between your network and the Internet, where you would perhaps have your web or email server).
* Hiding and protecting your internal network addresses (NAT)
* Reporting on threats and activity.
What firewalls don’t do
Even with a firewall, there are still many areas of risk for your network. The most obvious is malware. Malware is a combination of the words ‘malicious’ and ‘software’ and includes viruses, trojan horses, worms, spyware/adware, phishing and pharming. Malware is most commonly acquired through clicking on email attachments and email links.
Viruses, trojans and worms can cause a range of symptoms from the annoying and/or embarrassing to the much more serious which can affect the functioning of your business. Spyware/adware gathers information about you. It can record keystrokes and, as such, can potentially be very dangerous, revealing everything you do on your computer,
Another well-known threat, not covered by your firewall, is SPAM. Dealing with SPAM can seriously affect your productivity and, as SPAM often contains viruses and phishing emails, it is also a direct security threat.
Phishing is about fake emails trying to extract sensitive information, such as your bank passwords or credit card details and a variation of this is pharming, where the criminal sets up a fake web site which looks like one you normally use, typically a banking site. Once you enter your details, the criminal is able to plunder your account.
Many people are also unaware that you can actually acquire malware by simply browsing web sites. This is a rapidly growing threat and some of the malware is used to create Botnets (see below). Some security applications (e.g. those from Finjan) have a facility which protects you against web sites containing malware, by checking the sites before you click on them.
Another danger to your network is from a DDoS (distributed denial of service) attack. This is a malicious attempt to prevent an organisation being able to use its Internet based systems by flooding them with emails until the servers are overwhelmed. These attacks are often carried out by BotNet networks of compromised PCs, which are also used in SPAM campaigns. Specific DDoS software can guard against this threat.
Other dangers to your network include unauthorised access, and the way to deal with this is to have proper authentication procedures in place, for both local and remote access. In many cases, passwords are not enough and the use of strong authentication with tokens provides much better security.
Further potential problems are from data theft or leakage, for example when a laptop is stolen. The answer here is to encrypt all sensitive data. Low cost solutions are available from companies such as Utimaco. Finally all wireless use is risky and requires a specific wireless firewall, and wireless VPN for remote access.
A firewall is no longer enough to protect a company network. Other security solutions to combat the threats outlined above are also necessary, as well as proper staff training.
One of the best ways to protect against the main threats not covered by a firewall is to use a UTM (unified threat management) device. UTM devices are multi-purpose security solutions which have a minimum of a firewall, VPN, anti-virus and intrusion detection/prevention. Some UTMs (sometimes known as super UTMs) also incorporate capabilities such as web filtering (blocking problematic web sites), SPAM blocking and spyware protection.
UTMs are usually lower cost than buying and installing several security components separately. They are also typically greener, as one solution uses much less power than multiple solutions. When buying a UTM or a super UTM, it is important to ensure that your reseller sizes it correctly i.e. ensures that it has the performance capability to deal with current throughput and future business expansion. UTMs are available from IT security companies such as WatchGuard and Check Point.
newsprovider is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
   


   
Post New Thread Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -8. The time now is 06:54 PM.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

DMCA Policy

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227