• No results found

Network Security Management with Firewalls

N/A
N/A
Protected

Academic year: 2021

Share "Network Security Management with Firewalls"

Copied!
32
0
0

Loading.... (view fulltext now)

Full text

(1)

Network Security Management

with Firewalls

Stephen P. Cooper

Advanced Security Projects

Computer Security Technology Center Lawrence Livermore National Laboratory

Email: [email protected]

Computer Security Practitioners Conference February 7, 1996

UCRL-MI-123352

Work performed under the auspices of the U.S. Department of Energy by Lawrence Livermore National Laboratory under Contract W-7405-ENG-48.

Reference to any specific commercial product, process, or service by trade name, trademark, manufacturer, or otherwise, does not necessarily constitute or imply its endorsement, recommendation or favoring by the U.S. Department of Energy or the University of California.

(2)

This is your network...

Proprietary Data Personnel Data

(3)

This is your network on the Internet

Proprietary Data Personnel Data Sensitive Data VIRUS Trojan Horse

(4)

Unless you have a

Fire

wall

Proprietary Data Personnel Data

(5)

Why a firewall?

You have information and resources that

need protection.

You have a need to connect to a network that

has a different view of the world.

Strong host-based security is too costly or

(6)
(7)

A Firewall is...

A gateway between a trusted network and a

less trusted one.

An enforcer of security policy.

A system designed to:

Control external access to company data and resources.

Control internal access to Internet systems and services.

(8)

... or in a nutshell

A firewall is a tool for managing and

controlling traffic that crosses a network “boundary.”

(9)

Reality Check!

The purpose of a business is to provide some

product or service.

The purpose of security is to reduce some of

the risks associated with operating and maintaining a business.

The purpose of a firewall is to support some

(10)

Reality Check, Part 2!

A firewall, as a chokepoint, may also be a

single point-of-failure.

Reliability, performance become issues.

Therefore, the firewall’s status may quickly

(11)

How do you set up a firewall?

Policies

Requirements

Resources Magic

Our goal is to try and reduce the magic.

(12)

Develop a policy and requirements

Need to understand the assets to be

protected and the threats to those assets.

Need to understand the user requirements.

The target is probably somewhere between

the two.

Security

(13)

Assess the threats vs. assets

High Threat

Low

(14)

What about protocols?

The good...

Telnet

...the bad...

Any UDP, finger

...and the ugly.

FTP, X11

(15)

Understand your resources

Financial.

Time.

Technical expertise.

(16)

To build your own...

It takes a certain level of expertise in

computer network security, UNIX system administration, and programming.

“The FWTK is meant for individuals who:

know C

know TCP/IP

know UNIX as a system manager

have built C software packages on UNIX systems.” — Frederick Avolio, Trusted Information Systems

(17)

Products and Services

There are over 40 commercial firewalls

offering a wide range of configurations and capabilities.

(18)

Configurations range from

simple to complex

Dual-homed Gateway Screened Host Gateway

Screened Subnet Gateway

Application Gateway Application Gateway Router Router Router Application Gateway(s)

(19)

Here is a physical sample...

External Network Internal Network Screening Router Bastion Host

(20)

...and here is the logical view

Remote User

Remote

Services Internal User

Internal Services Secure Authentication Proxy Services Screening Router ? Bastion Host

(21)

White House Firewall*

DEC SEAL, Gauntlet based.

9 months and $275K.

2 full-time Secret Service agents for

administration.

25-30K mail messages per day, filtered for

content.

* From a presentation by Bill Hancock to the DECUS Bay LUG, 7/10/95.

(22)

Build your own?

There is ample software available:

TIS Firewall Toolkit (FWTK)

Freestone from SOS Corp.

Socks

Screend

KarlBridge (demo and commercial), DrawBridge

S/Key

(23)

Other Sources:

Commercial ServicesInternet ProvidersConsultantsCommercial ProductsScreening RoutersSoftwareOperating SystemsHardware

(24)

How to select

Start with the go/no-go decisions:

Will a particular product or service support your security policy?

Do you have the necessary resources?

Are there other show stoppers?

Performance (T1, Ethernet, FDDI, etc.)Protocols supported (Appletalk, DECnet)Encryption

(25)

How to select (cont.)

For the rest, balance your priorities against

the offerings of the target products.

Priorities Support Reliability Cost Flexibility User Interface Offerings GUI

Reboot for changes 24h phone support $20,000 + 1200/year

(26)

Some Selection Criteria

Protocols

Hardware and Operating Systems

Management Interfaces

User Authentication

Encryption

Firewall Validation

(27)

A Sampling of Products

Sidewinder

Gauntlet

Digital’s Firewall Service (formerly SEAL)

Firewall-1

Internet Site Patrol

Firewall-Plus

(28)

Future directions

Better integration of security components.

Management, host-based security, intrusion detection.

CSTC and partners have several research projects on the table.

Standards

Firewall management, cooperative firewalls.

(29)

References:

Cheswick, William R. and Steven M. Bellovin.

Firewalls and Internet Security: Repelling the Wily Hacker, Addison-Wesley, 1994.

Chapman, Brent and Elizabeth Zwicky.

Building Internet Firewalls, O’Reilly & Associates, 1995.

Hare, R. Christopher and Karanjit Siyan.

Internet Firewalls and Network Security, New Riders Publishing, 1995.

(30)

On the WWW:

The Firewall Report, by Outlink Market

Research (http://www.outlink.com), contains over 600 pages reviewing over 40 firewall

products.

Catherine Fulmer maintains a list of firewall

products at:

http://www.waterw.com/~manowar/vendor.html.

The Firewalls Mailing List:

Send E-Mail to [email protected] with “subscribe firewalls” as the message body.

(31)

Crossing the finish line

There are many good products out there, with

more emerging.

Avoid “analysis paralysis.”

Don’t fall into a false sense of security.

We (the CSTC) are here to help you reach your security goals through our various services and projects, but...

(32)

...We need your help!

Feedback on commercial products and

services.

Information on what products and services

you are using so that we may serve as an information broker. CONTACTS [email protected] [email protected] Visit: http://ciac.llnl.gov/ cstc/CSTCHome.html CSTC

References

Related documents

Additional security measures from MegaPath can protect your data if you include Internet access in your private network design.. A gateway security service will check the

• Use network zones: create DMZ for data exchange, deny-all default policy for firewalls • Use security functions in protocols where available. • Security shall not compromise

Diagnostic accuracy of computed tomography scout film and chest X-ray for detection of rib fractures in patients with chest trauma: A cross-sectional study.... This is an open

RTL Synthesis Instruction-set Simulator Mapping, Placement, Routing application (C) Software Tool suite Generation Coding Leakage Explorer Base Processor (HDL) Interface (XML)

Therefore, this study analyses the school multicultural leadership practices and examines other factors that are influential such as the teachers' attitudes and

What do you do to start reviewing Manajemen Risiko 2 (Indonesian Edition) By Ikatan Bankir Indonesia Searching guide that you love to check out first or locate

OL/UL / Subcell Load Distribution / Tight BCCH Frequency Reuse Cell OL/UL Multi Operator in BSS Multiband. Neighbouring Cell

Network security: Best security practices for multi-function printers also protect sensitive data by placing them on internal networks which are protected by firewalls or