The Experts below are selected from a list of 1992 Experts worldwide ranked by ideXlab platform
Thomas W. Shinder - One of the best experts on this subject based on the ideXlab platform.
-
ISA 2006 Stateful Inspection and Application Layer Filtering
The Best Damn Firewall Book Period, 2007Co-Authors: Thomas W. ShinderAbstract:The ISA firewall is able to perform stateful Application Layer inspection, which enables it to fully inspect the communication streams passed by it from one network to another. In contrast to stateful Filtering where only the network and transport Layer information is filtered, true stateful inspection requires that the firewall be able to analyze and make decisions on all Layers of the communication, including the most important Layer, the Application Layer. The Web filters perform stateful Application Layer inspection on communications handled by the ISA firewall's Web Proxy components. The Web Proxy handles connections for HTTP, HTTPS (SSL), and HTTP tunneled FTP connections. This chapter discusses the ISA firewall's Application Layer Filtering feature set. It discusses the two main types of Application filters employed by the ISA firewall—access filters and security filters. Both the access filters and the security filters impose requirements that the connections meet specifications of legitimate communications using those protocols. Finally, the chapterdiscusses the ISA firewall's intrusion detection and prevention mechanisms. Common network Layer attacks that can be launched against the ISA firewall and how the ISA firewall protects you against them are covered in this chapter.
-
chapter 7 isa 2006 stateful inspection and Application Layer Filtering
Dr. Tom Shinder's ISA Server 2006 Migration Guide, 2007Co-Authors: Thomas W. ShinderAbstract:Publisher Summary This chapter describes ISA 2006 stateful inspection and Application Layer Filtering. The ISA firewall's Simple Mail Transfer Protocol (SMTP) filter configuration interface can be accessed by opening the Microsoft Internet Security and Acceleration Server 2006 management console, expanding the server name and then, expanding the Configuration node. The Post Office Protocol (POP) Intrusion Detection filter protects POP3 servers published by the ISA firewall using Server Publishing Rules from POP services buffer overflow attacks. There is no configuration interface for the POP Intrusion Detection filter. The Firewall client is a generic Winsock Proxy client Application. All Applications designed to the Windows Sockets specification will automatically use the Firewall client. The Maximum headers length option allows you to configure the maximum length of all headers included in a request Hypertext Transfer Protocol (HTTP) communication. This setting applies to all rules that use the HTTP Security filter. The Allow only specified methods option allows you to specify the exact methods you want to allow through the ISA firewall. It is found that an HTTP policy can be exported from or imported into an Access Rule that uses the HTTP protocol, or a Web Publishing Rule.
-
ISA 2004 Stateful Inspection and Application Layer Filtering
How to Cheat at Configuring ISA Server 2004, 2006Co-Authors: Thomas W. ShinderAbstract:The chapter discusses the ISA firewall's Application Layer Filtering feature set. It focuses on the two main types of Application filters employed by the ISA firewall: access filters and security filters. Both access filters and security filters impose requirements that the connections meet specifications of legitimate communications using those protocols. The ISA firewall is able to perform both stateful Filtering and stateful Application Layer inspection. The ISA firewall's stateful Filtering feature set makes the ISA firewall a network Layer stateful firewall in the same class as any hardware firewall that performs stateful Filtering at the network and transport Layers. Stateful Filtering is often referred to as stateful packet inspection. The chapter also discusses the ISA firewall's intrusion detection and prevention mechanisms.
Adriano Valenzano - One of the best experts on this subject based on the ideXlab platform.
-
performance evaluation and modeling of an industrial Application Layer firewall
IEEE Transactions on Industrial Informatics, 2018Co-Authors: Manuel Cheminod, Luca Durante, Lucia Seno, Adriano ValenzanoAbstract:The availability of performance studies and simple models for firewalls able to deal with industrial Application-Layer communication protocols, such as Modbus/TCP, is crucial when the impact of these devices has to be estimated, even roughly, before their actual deployment in industrial networks. Unfortunately, most manufacturers do not provide this kind of information for commercial off-the-shelf available products. Thus, a viable solution is the development and experimental validation of simple models that can be used by designers to predict those firewall characteristics not explicitly related to their security capabilities. As an example, latency introduced on message forwarding is an aspect of significant interest in many industrial control systems, where delays and jitters in data delivery can severely impact on the effectiveness of the control actions. This paper reports on our experience in developing a performance model for a commercial device able to perform advanced Application-Layer Filtering, in particular of Modbus/TCP traffic. A set of ad hoc designed experiments, performed by means of a purposely developed laboratory testbed, enabled both model development and validation, confirming a good correspondence of the estimated performance with the device actual behavior.
Manuel Cheminod - One of the best experts on this subject based on the ideXlab platform.
-
performance evaluation and modeling of an industrial Application Layer firewall
IEEE Transactions on Industrial Informatics, 2018Co-Authors: Manuel Cheminod, Luca Durante, Lucia Seno, Adriano ValenzanoAbstract:The availability of performance studies and simple models for firewalls able to deal with industrial Application-Layer communication protocols, such as Modbus/TCP, is crucial when the impact of these devices has to be estimated, even roughly, before their actual deployment in industrial networks. Unfortunately, most manufacturers do not provide this kind of information for commercial off-the-shelf available products. Thus, a viable solution is the development and experimental validation of simple models that can be used by designers to predict those firewall characteristics not explicitly related to their security capabilities. As an example, latency introduced on message forwarding is an aspect of significant interest in many industrial control systems, where delays and jitters in data delivery can severely impact on the effectiveness of the control actions. This paper reports on our experience in developing a performance model for a commercial device able to perform advanced Application-Layer Filtering, in particular of Modbus/TCP traffic. A set of ad hoc designed experiments, performed by means of a purposely developed laboratory testbed, enabled both model development and validation, confirming a good correspondence of the estimated performance with the device actual behavior.
Luca Durante - One of the best experts on this subject based on the ideXlab platform.
-
performance evaluation and modeling of an industrial Application Layer firewall
IEEE Transactions on Industrial Informatics, 2018Co-Authors: Manuel Cheminod, Luca Durante, Lucia Seno, Adriano ValenzanoAbstract:The availability of performance studies and simple models for firewalls able to deal with industrial Application-Layer communication protocols, such as Modbus/TCP, is crucial when the impact of these devices has to be estimated, even roughly, before their actual deployment in industrial networks. Unfortunately, most manufacturers do not provide this kind of information for commercial off-the-shelf available products. Thus, a viable solution is the development and experimental validation of simple models that can be used by designers to predict those firewall characteristics not explicitly related to their security capabilities. As an example, latency introduced on message forwarding is an aspect of significant interest in many industrial control systems, where delays and jitters in data delivery can severely impact on the effectiveness of the control actions. This paper reports on our experience in developing a performance model for a commercial device able to perform advanced Application-Layer Filtering, in particular of Modbus/TCP traffic. A set of ad hoc designed experiments, performed by means of a purposely developed laboratory testbed, enabled both model development and validation, confirming a good correspondence of the estimated performance with the device actual behavior.
Lucia Seno - One of the best experts on this subject based on the ideXlab platform.
-
performance evaluation and modeling of an industrial Application Layer firewall
IEEE Transactions on Industrial Informatics, 2018Co-Authors: Manuel Cheminod, Luca Durante, Lucia Seno, Adriano ValenzanoAbstract:The availability of performance studies and simple models for firewalls able to deal with industrial Application-Layer communication protocols, such as Modbus/TCP, is crucial when the impact of these devices has to be estimated, even roughly, before their actual deployment in industrial networks. Unfortunately, most manufacturers do not provide this kind of information for commercial off-the-shelf available products. Thus, a viable solution is the development and experimental validation of simple models that can be used by designers to predict those firewall characteristics not explicitly related to their security capabilities. As an example, latency introduced on message forwarding is an aspect of significant interest in many industrial control systems, where delays and jitters in data delivery can severely impact on the effectiveness of the control actions. This paper reports on our experience in developing a performance model for a commercial device able to perform advanced Application-Layer Filtering, in particular of Modbus/TCP traffic. A set of ad hoc designed experiments, performed by means of a purposely developed laboratory testbed, enabled both model development and validation, confirming a good correspondence of the estimated performance with the device actual behavior.