Firewall Wizards mailing list archives
Re: Proxy 2.0 secure?
From: tqbf () pobox com
Date: Fri, 26 Jun 1998 01:15:35 -0500 (CDT)
Ok, I'll bite. What would YOU describe as "real firewall testing", given that you had to test a number of independent, but NT-based firewall products, and provide advice on their performance?
First off, I would not claim that I was capable of presenting a real comparitive review of the security of multiple firewall packages in a tiny magazine article. Following that, I would not makes claims about the security of firewall packages based on the assumption that I had done any real testing of them. In other words, I'd be honest with my readers about what my capabilities were, and what conclusions the model reader could draw from my article. Now, if you want to ask me how I think firewalls can be tested, you're asking a big loaded question that has an even larger and more controversial answer. Some people don't believe in firewall testing --- they think the results are misleading, since it is both practically infeasable to completely test many firewalls in the short amount of time available (ie, before everything changes revisions again), and because the information obtained from a real design review doesn't compare neatly with the information from other reviews (unless your reviewing strategy is either revolutionary or completely flawed). I agree with this viewpoint somewhat. Obviously, I have some experience reviewing commercial security software (my work has focussed on IDS). My opinion, drawn from my experience reviewing software, is that attempts to present "quick" reviews of security software are usually going to fail. It doesn't take a lot of research to see that almost every review of security software to date HAS failed. In any case, real firewall testing is complicated and outside the scope of this message. For-profit companies (like the ICSA) are making money by selling the idea that they have competancy in this area. If there was an obvious way to review firewalls, we wouldn't have this problem. However, there are certainly techniques that are more valuable than running ISS (or CCS) against a firewall and making sure the report doesn't list any vulnerabilities. Techniques such as marked-packet analysis and active probing are good examples of ways that automated analysis can draw useful conclusions about firewall characteristics, while treating them as a black box. However, these are just useful tools. The real issue boils down to this: You should not trust software that has neither open source nor published peer review results. ----------------------------------------------------------------------------- Thomas H. Ptacek SNI Labs, Network Associates, Inc. ----------------------------------------------------------------------------- http://www.pobox.com/~tqbf "If you're so special, why aren't you dead?"
Current thread:
- Re: Proxy 2.0 secure?, (continued)
- Re: Proxy 2.0 secure? Ted Doty (Jun 25)
- Re: Proxy 2.0 secure? Mark Horn [ Net Ops ] (Jun 25)
- RE: Proxy 2.0 secure? Vanja Hrustic (Jun 25)
- RE: Proxy 2.0 secure? ark (Jun 25)
- RE: Proxy 2.0 secure? Stout, Bill (Jun 25)
- Re: Proxy 2.0 secure? Brian Steele (Jun 25)
- Re: Proxy 2.0 secure? Brian Steele (Jun 25)
- Re: Proxy 2.0 secure? tqbf (Jun 26)
- Re: Proxy 2.0 secure? Vanja Hrustic (Jun 26)
- Re: Proxy 2.0 secure? Brian Steele (Jun 25)
- Re: Proxy 2.0 secure? tqbf (Jun 26)
- Re: Proxy 2.0 secure? Kjell Wooding (Jun 26)
- Re: Proxy 2.0 secure? ark (Jun 26)
- RE: Proxy 2.0 secure? Choi, Byoung (Jun 26)
- Re: Proxy 2.0 secure? Gillian Steele (Jun 26)
- Re: Proxy 2.0 secure? Ted Doty (Jun 29)
- Re: Proxy 2.0 secure? Brian Steele (Jun 26)
- Re: Proxy 2.0 secure? Brian Steele (Jun 28)
- Re: Proxy 2.0 secure? Rodney van den Oever (Jun 29)
- Re: Proxy 2.0 secure? Brian Steele (Jun 29)
- Re: Proxy 2.0 secure? ark (Jun 29)
(Thread continues...)
