The Experts below are selected from a list of 39 Experts worldwide ranked by ideXlab platform
Avishai Wool - One of the best experts on this subject based on the ideXlab platform.
-
The use and usability of direction-based filtering in Firewalls
Computers & Security, 2004Co-Authors: Avishai WoolAbstract:The common match fields in Firewall rules refer to a packet's source and destination IP addresses, protocol, and source and destination port numbers. However, most Firewalls are also capable of filtering based on a packet's direction: which network interface card the packet is crossing, and whether the packet is crossing the interface from the network into the Firewall (''inbound'') or vice versa (''outbound''). Taking a packet's direction into account in the Firewall's rules is extremely useful: it lets the Firewall Administrator protect against source address spoofing, write effective egress-filtering rules, and avoid unpleasant side-effects when referring to subnets that span the Firewall. Unfortunately, the Firewall's definition of a packet's direction is different from what users normally assume. If interface eth0 connects the Firewall to the internal network, then, from a user's perspective, ''inbound on eth0'' is actually ''Outbound'' traffic. This discrepancy makes it very confusing for Firewall Administrators to use the packet direction correctly, and creates a significant usability problem. In this paper we review the usefulness of direction-based filtering, identify the usability problem, and critically review the approaches taken by several major Firewall vendors. Most vendors expose the raw and confusing functionality to the Firewall Administrators, while one vendor (Check Point) hides the functionality entirely. Both approaches leave much to be desired. However, recent advances in Firewall research show that better alternatives exist: the Firmato prototype demonstrates that the Firewall management software can compute the directions algorithmically for a perimeter Firewall.
-
The use and usability of direction-based filtering in Firewalls
Computers and Security, 2004Co-Authors: Avishai WoolAbstract:The common match fields in Firewall rules refer to a packet's source and destination IP addresses, protocol, and source and destination port numbers. However, most Firewalls are also capable of filtering based on a packet's direction: which network interface card the packet is crossing, and whether the packet is crossing the interface from the network into the Firewall ("inbound") or vice versa ("outbound"). Taking a packet's direction into account in the Firewall's rules is extremely useful: it lets the Firewall Administrator protect against source address spoofing, write effective egress-filtering rules, and avoid unpleasant side-effects when referring to subnets that span the Firewall. Unfortunately, the Firewall's definition of a packet's direction is different from what users normally assume. If interface eth0 connects the Firewall to the internal network, then, from a user's perspective, "inbound on eth0" is actually "Outbound" traffic. This discrepancy makes it very confusing for Firewall Administrators to use the packet direction correctly, and creates a significant usability problem. In this paper we review the usefulness of direction-based filtering, identify the usability problem, and critically review the approaches taken by several major Firewall vendors. Most vendors expose the raw and confusing functionality to the Firewall Administrators, while one vendor (Check Point) hides the functionality entirely. Both approaches leave much to be desired. However, recent advances in Firewall research show that better alternatives exist: the Firmato prototype demonstrates that the Firewall management software can compute the directions algorithmically for a perimeter Firewall. © 2004 Elsevier Ltd. All rights reserved.
Phil Dibowitz - One of the best experts on this subject based on the ideXlab platform.
-
LISA - Over-Zealous Security Administrators Are Breaking the Internet
2002Co-Authors: Richard Van Den Berg, Phil DibowitzAbstract:As the security threats on the Internet are becoming more prevalent, Firewalls and other forms of protection are becoming more commonplace. Unfortunately, improperly configured Firewalls can cause a variety of problems. One particularly nasty problem is when a Firewall Administrator chooses to use - or continue using - Path MTU Discovery (a good choice in most situations), but blocks packets required for the protocol to work: ICMP type 3 code 4 packets. This problem, the Path MTU Discovery Black Hole, has been discussed many times before. However with under- 1500 MTU protocols such as PPPoE becoming common for both home and business high-speed connections, this problem is affecting more people than ever before.
Richard Van Den Berg - One of the best experts on this subject based on the ideXlab platform.
-
LISA - Over-Zealous Security Administrators Are Breaking the Internet
2002Co-Authors: Richard Van Den Berg, Phil DibowitzAbstract:As the security threats on the Internet are becoming more prevalent, Firewalls and other forms of protection are becoming more commonplace. Unfortunately, improperly configured Firewalls can cause a variety of problems. One particularly nasty problem is when a Firewall Administrator chooses to use - or continue using - Path MTU Discovery (a good choice in most situations), but blocks packets required for the protocol to work: ICMP type 3 code 4 packets. This problem, the Path MTU Discovery Black Hole, has been discussed many times before. However with under- 1500 MTU protocols such as PPPoE becoming common for both home and business high-speed connections, this problem is affecting more people than ever before.
Fabrizio Fabbrini - One of the best experts on this subject based on the ideXlab platform.
-
IICIS - Firewall policies definition tools: an implementation idea
Integrity and Internal Control in Information Systems, 2000Co-Authors: Patrizia Dí, Fabrizio FabbriniAbstract:We present some ideas for a declarative approach to the implementation of a tool to define Firewall policies. Our aim is to show how a deductive system, such as a deductive database management system, can be used to build a tool that a Firewall Administrator can use to define its policy. We present a Firewall example only to highlight the advantages of such type of approach as a policy definition tool. The deductive database system we have used, besides the obvious deductive capabilities, has the ability of structuring the necessary knowledge into parts, the capability of composing the parts together by means of importing mechanisms and the ability to define and prove properties of the policy.
Saroj Singh - One of the best experts on this subject based on the ideXlab platform.
-
IP Security
International Research Journal of Management IT & Social Sciences, 2016Co-Authors: Saroj SinghAbstract:IP is stands for Internet Protocol. IP security is a set service which secures the documents by the unauthorized entity. IP Sec covers the three areas of functionality that is authentication, confidentiality, and key management. IP Sec encrypts and authenticates all the data traffic at the IP level security. The IP level security or Firewall Administrator, we got basically the same concerns (as plumber) the size of the pipe the contents of the pipe, making sure the correct traffic is in the correct pipes and keeping the pipes from splitting and leaking all over the places of course like plumbers. When the pipes do leak: we are the ones responsible for cleaning up the mess and we are the ones who come up smelling awful. Firewall is a device that is used to provide protection to a system from network based security threats. Firewall uses service, behavior, user and direction control techniques.
-
Security: Hash Function-Authentications
International Research Journal of Engineering IT and Scientific Research, 2016Co-Authors: Saroj SinghAbstract:As security or Firewall Administrator, we got basically the same concerns (as plumber) the size of the pipe the contents of the pipe, making sure the correct traffic is in the correct pipes and keeping the pipes from splitting and leaking all over the places of course like plumbers. When the pipes do leak: we are the ones responsible for cleaning up the mess and we are the ones who come up smelling awful. Firewall is a device that is used to provide protection to a system from network based security threats. Firewall uses service, behaviour, user and direction control techniques.