Re: Why Firewalls Are Uninteresting?

"Darden, Patrick" <[email protected]> Wed, 2 Jul 2014 08:58:04 -0500
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <74825E6950ECDE449817715200CEAD2703BA6EDA97@BRTEXMB76.phillips66.net>
Part One of the Red book (Trusted Network Interpretation):
http://csrc.nist.gov/publications/secpubs/rainbow/tg005.txt

--Patrick Darden

-----Original Message-----
From: [email protected] [mailto:firewall-wiz=
[email protected]] On Behalf Of =C1rp=E1d Magos=E1nyi
Sent: Tuesday, July 01, 2014 1:03 AM
To: [email protected]
Subject: [EXTERNAL][fw-wiz] Why Firewalls Are Uninteresting?

Okay, here is my 5 cents for popcorn :)

One of the core tasks of network perimeter defence is to keep the structure=
 of the network - hence the application architecture - in shape, and provid=
e information flow control on the macroarchitecture level. This is what the=
 Red Book is about, and the Red Book is the most thoroughly forgotten piece=
 of knowledge in IT security if not in IT as a whole.

If you take a look at the Red Book - I mean the concepts. Do not get distra=
cted by the language or little details - you will find a whole book with th=
e title containing network, but talking about application macroarchitecture=
 and infrastructures. Big mistake? No and yes. No, because macroarchitectur=
e is what should (have been) define(d) network structure. Yes, because ther=
e are no more than 3 people left (4 with you now), who knows where to look =
at knowledge about how to build secure enterprise architecture.

So now we have network security, which should be treated at the very first =
step of development - sketching macroarchitecture and enterprise architectu=
ral guidelines -, usually treated at the last step "hey, we have this host =
with some apps on it, lease put it to the network somehow", using equipment=
 utterly unsuitable for the task (yes, stateful packet filter vendors, I am=
 pointing at you).

So some people went to other areas with more probability of success, the mo=
st have died in boredom, and here we are who have left because we like to d=
o impossible missions with unsuitable tools.

Oh, wait, I am not even here. I do enterprise architecture, not network sec=
urity. Did I mention the Red Book yet?

_______________________________________________
firewall-wizards mailing list
[email protected]
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards