Microsoft Windows Vista Community Forums - Vistaheads
Driver Scanner 2009 - Free Scan Now



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Registry Mechanic - Free Scan Now

Cyber Security Awareness Tip #7: Host-Based Firewalls and Filtering, (Sun, Oct 7th)

Security News



Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Reply
  #1 (permalink)  
Old 10-08-2007
Steve's Avatar
Steve Steve is offline
Moderator
 
Join Date: Sep 2006
Location: Emerald Isle
Posts: 46,133
Steve is a jewel in the roughSteve is a jewel in the roughSteve is a jewel in the rough
Thanks: 7
Thanked 24 Times in 11 Posts
Cyber Security Awareness Tip #7: Host-Based Firewalls and Filtering, (Sun, Oct 7th)
Host-Based Firewalls and Filtering

Increasingly I have seen Host-Based firewalls being brought up on the corporate radar in those arenas that have to deal with such things at VPN's, other remote computing solutions, and thusly trojans, worms, and other auto-spreading malware.

Host-Based firewalls are basically exactly what they sound like (excuse me for taking a step back for everyone's benefit), a firewall that resides on the HOST itself. Your computer. The Machine you using right now. Whether it be Windows, OSX, *nix, or *bsd variant, there is a firewall available for every OS, and every OS has one built in. Some better then others (in the interest of full disclosure, I am typing this on a PowerMac, which has a built in firewall, and one that needs a bit more tweaking). As firewalls should be (IMHO) Deny All, Permit by Exception.

When my parents or a friend asks me what kind of free firewall to install on their Windows machine, I usually go with at least turn on the built in one! (Which is now on by default as of XPSP2), and then if more assistance is needed I usually go with ZoneAlarm. I'm not partial to any one firewall in particular, whichever gets the job done quickly and efficiently. Basically I say all that to make this point: Host-Based firewalls (especially for home users) are a great idea, they come in alot of variants, and should be deployed.

Several years ago I was asked (along with several of my other co-workers at the time) to test various host-based firewall solutions on my work desktop. I was stuck with Symantec's offering at the time (this was about 2001), and was not impressed. I have no touched it since then, and had no desire to. The firewall was not centrally managed, as it was only a test, and the ability to block things like port 445 to 10.0.1.5 was available. I played user and what did I click? Accept! (You know the user I am talking about in your network that says Oh, Gator Wallet! Of course I'll accept. Guess what 10.0.1.5 was? Domain Controller. It let me block my Domain Controller! Guess what happened the next time I wanted to log onto my machine? You guessed it.. Nada. (In all fairness, how was the firewall to know that that IP was our Domain Controller? (yes, I am being sarcastic))
So, obviously with any security solution (like anti-virus), you'd need to have central management to keep users from doing things like what I did in my test. Is it necessary for you to deploy firewalls in your corporate environment? That's something that you need to access by looking at your corporate landscape. Do you have problems with Worms? Viruses? Do you have perimeter security on your network? Can you mitigate the threat? How do you mitigate the threat.

I'm not making a case in either direction, simply saying that both avenues need to be explored and a decision made. Does this help me do my job in a more efficient manner and generally make my life easier?

Filtering solutions (ex: Websense, etc) have a special place in my heart as well. I had a bad experience in my previous job with a filtering solution, so I am biased to NOT being a fan. But the same assessments as before need to be made. Does this make my life easier? Does this make it easier to do my job, as the security person? Are you defending your networks against bad websites? Or are you defending the corporation against your users? Are you keeping people from doing their jobs, or are you keeping them doing their jobs? (By keeping them on task).

Good Luck!

Joel Esler
http://handlers.sans.org/jesler

More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Cyber Security Awareness Tip #6: Developing policies and Distribution, (Sat, Oct 6th) Steve Security News 0 10-06-2007 09:11
Cyber Security Awareness Tip #4: Enabling the Road Warrior, (Thu, Oct 4th) Steve Security News 0 10-04-2007 02:30
Cyber Security Awareness Tip #3: Getting the Boss Involved, (Wed, Oct 3rd) Steve Security News 0 10-03-2007 15:40
Cyber Security Awareness Tip #2: Multimedia Tools, Online Training, and Useful Websites, (Tue, Oct 2nd) Steve Security News 0 10-02-2007 19:53
Cyber Security Awareness Tip #1: Penetrating the This Does Not Apply To Me Attitude, (Mon, Oct 1st) Steve Security News 0 10-01-2007 01:41


All times are GMT +1. The time now is 05:37.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119