Re: Why Firewalls Are Uninteresting?
"Darden, Patrick" <[email protected]> Wed, 2 Jul 2014 08:58:04 -0500
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <74825E6950ECDE449817715200CEAD2703BA6EDA97@BRTEXMB76.phillips66.net> |
Part One of the Red book (Trusted Network Interpretation): http://csrc.nist.gov/publications/secpubs/rainbow/tg005.txt --Patrick Darden -----Original Message----- From: [email protected] [mailto:firewall-wiz= [email protected]] On Behalf Of =C1rp=E1d Magos=E1nyi Sent: Tuesday, July 01, 2014 1:03 AM To: [email protected] Subject: [EXTERNAL][fw-wiz] Why Firewalls Are Uninteresting? Okay, here is my 5 cents for popcorn :) One of the core tasks of network perimeter defence is to keep the structure= of the network - hence the application architecture - in shape, and provid= e information flow control on the macroarchitecture level. This is what the= Red Book is about, and the Red Book is the most thoroughly forgotten piece= of knowledge in IT security if not in IT as a whole. If you take a look at the Red Book - I mean the concepts. Do not get distra= cted by the language or little details - you will find a whole book with th= e title containing network, but talking about application macroarchitecture= and infrastructures. Big mistake? No and yes. No, because macroarchitectur= e is what should (have been) define(d) network structure. Yes, because ther= e are no more than 3 people left (4 with you now), who knows where to look = at knowledge about how to build secure enterprise architecture. So now we have network security, which should be treated at the very first = step of development - sketching macroarchitecture and enterprise architectu= ral guidelines -, usually treated at the last step "hey, we have this host = with some apps on it, lease put it to the network somehow", using equipment= utterly unsuitable for the task (yes, stateful packet filter vendors, I am= pointing at you). So some people went to other areas with more probability of success, the mo= st have died in boredom, and here we are who have left because we like to d= o impossible missions with unsuitable tools. Oh, wait, I am not even here. I do enterprise architecture, not network sec= urity. Did I mention the Red Book yet? _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards