Firewall Wizards mailing list archives
RE: Worms, Air Gaps and Responsibility
From: "Paul D. Robertson" <paul () compuwar net>
Date: Tue, 18 May 2004 17:28:10 -0400 (EDT)
On Tue, 18 May 2004, Dana Nowell wrote:
about short term vs. long term environments. The short term (usually less technical) guys (home users, small business, etc.) are unlikely to take the time or have the knowledge to analyse the proper 'air gaps', especially when it includes things like cell phones and PDAs which are not thought of as 'part of the network'. Additionally they are less likely to approve
They're also unlikely to read Firewall-Wizards, and therefore unlikely to get any of the points made...
expenditures for security devices that they can't justify simply because some security paper says so. So this discussion is wonderful for
However, one of my original points still stands- if we the security community make common practice to question connectivity _at_all_ then it's more likely that such ideas will filter down to those who are interested. [I know a fair number of folks who administer small networks who care about and spend time on security- if "nobody does it" or "nobody gives me a reason to do it" then it doesn't get done, but with peer activity and good rationale, it has a chance of being adopted.] I'm going to use a real world example. Two years or so ago, I met a network administrator for a swimming pool company at a conference. They said "I'd like to do more security stuff, but it really doesn't apply, we sell and maintain swimming pools- like $large_name's house, $important_CEO's name's house...." I said "Let me get this straight- you have people driving large trucks full of chlorine with access to $list_of_people's residences, and you don't think you have a good case for security?" Now, does that mean they get to go out, purchase 3 firewalls, 2 AR-15's and a set of frequency hopping bone conductive radios? Nope, but does it mean they can present some useful cases to management that allow them to do *what they really want to do*, which is secure their infrastructure in a sane way? Absolutely.
network, it is less than useful. I'm willing to bet that the bulk of the network connections (specifically the more insecure parts of the Internet) falls into the short term bucket, especially with home use.
I'm going to offer a follow-up to "It doesn't have to be our fault to be our responsibility." It doesn't have to be our responsibility for us to try to make it better.
Premise: these networks/hosts will be compromised, as air gaps are unlikely to be implemented and new technology connected devices will flourish, that creates a lot of places for bugs to breed.
Premise: Every network operator we get to do the right thing[tm] means one less network to produce traffic which attacks us.
Premise: devices are moving toward interconnectivity via Infrared, Bluetooth, WiFi, 802.11, and other technologies. Direct peer-to-peer connectivity between these devices is coming and one day 'soon' walking down the street with one in your pocket will cause tens or hundreds of connections to be attempted/created/broken, with all the inherent risks.
Premise: When this becomes a real risk, we'll get real solutions.
Premise: security typically lags functionality as new technology rolls out (palms get synced to desktops before security knows a palm is in the building in most companies).
Premise: New technologies aren't attacked at the same rate as current technologies, and therefore need less protection.
Conclusion: Air gaps will not solve the problem as large breeding grounds, device connectivity, and security lag will allow networks to be compromised. At best air gaps are another stop gap measure, which is certainly better than nothing. but not much.
Fact: If the network can be attacked via a foreign device, it doesn't have an air gap. That doesn't make air gaps less effective. That's like saying "If I ran Windows in an X86 emulator on my Sparc, it'd be as vulnerable as Windows!" Air gaps are effective protection devices. I've worked in places where you couldn't take a pager, camera, laptop, or whatever else into the facility. The air gap there was particularly effective.
Whine: The security professionals in the Internet community need to take a longer view. Until we 'solve' the problem for the average guy playing a short term game (or at least greatly reduce his risk) we can't really solve the issue in our own networks, we can only play technology catch-up. We
Counter-Whine: You can't dismiss strategic thinking then say we need to take a longer view!
need to be involved either via this list or another mechanism in helping set device/protocol 'best practices' and beating vendors about the head until they do it, so security is designed in rather than cobbled on. We
Nobody's willing to pay for security to be designed in, can't in that battle.
need to concentrate on how we solve the political/corporate/vendor issue and not the technical issue because the technical issue isn't soluble (not that the political issue is, but we might get more bang for the effort buck). Basically I'm damned tired of fighting the same war and upgrading from a rock to a knife to a dagger to a sword to a flintlock to a ... So air gaps are nice, but in the long run, it's just another musket, one that will be circumvented by targeting devices difficult to air gap (PDAs
The original message wasn't about airgapping desktops, it was about airgapping non-user production networks, such as power distribution systems, medical equipment (think the a CAT scanner should be on the same network as the person in the mail room at the hospital?)
syncing to desktop?). Before you ask, no I don't have a plan. Like most in a small company I spend 95% of my day digging a deeper foxhole and looking over the latest in flintlock design. We have a lot of bright people here and we ought to be using those IQ points for the long term instead of designing today's Mark XII network rock.
Just like they're not appropriate for user networks where you can't enforce device additions, they're appropriate for sets of networks in lots of organizations. In my mind, air gaps are more effective than buying and deploying IPS (you want a new flintlock?) for a large number of networks. Sure, protocol and vendor issues abound, but so do the basic network design issues that are able to negate large swaths of protocol and vendor issues. We've touched on some of them in this thread, like inter-machine communication, separation, segmentation, per-class networking, etc. One answer isn't going to get us where we want to go any more than one vehicle is going to make everyone happy on the road. What we can do is ensure that mopeds don't go on freeways, skateboards aren't used inside the office and that people pull over for emergency vehicles. We won't get 100% compliance, but we'll get navigable roads and we can ticket the offenders. We can also deal with people who're not doing what the rest of us are doing by making them liable for their actions, or ensuring they need to be insured beyond what the rest of us are- either way is effective. Paul ----------------------------------------------------------------------------- Paul D. Robertson "My statements in this message are personal opinions paul () compuwar net which may have no basis whatsoever in fact." probertson () trusecure com Director of Risk Assessment TruSecure Corporation _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- RE: Worms, Air Gaps and Responsibility, (continued)
- RE: Worms, Air Gaps and Responsibility Dana Nowell (May 17)
- RE: Worms, Air Gaps and Responsibility Paul D. Robertson (May 17)
- RE: Worms, Air Gaps and Responsibility Dana Nowell (May 17)
- RE: Worms, Air Gaps and Responsibility Frank Knobbe (May 18)
- RE: Worms, Air Gaps and Responsibility Dana Nowell (May 18)
- Re: Worms, Air Gaps and Responsibility Adam Shostack (May 18)
- Re: Worms, Air Gaps and Responsibility Dana Nowell (May 18)
- Re: Worms, Air Gaps and Responsibility Frank Knobbe (May 18)
- RE: Worms, Air Gaps and Responsibility Gwendolynn ferch Elydyr (May 18)
- RE: Worms, Air Gaps and Responsibility Dana Nowell (May 18)
- RE: Worms, Air Gaps and Responsibility Paul D. Robertson (May 18)
- RE: Worms, Air Gaps and Responsibility Dana Nowell (May 18)
- RE: Worms, Air Gaps and Responsibility Gwendolynn ferch Elydyr (May 18)
- RE: Worms, Air Gaps and Responsibility Dana Nowell (May 19)
- RE: Worms, Air Gaps and Responsibility Gwendolynn ferch Elydyr (May 19)
- Best Practices Paul D. Robertson (May 19)
- Re: Best Practices Dana Nowell (May 21)
- Re: Best Practices Gwendolynn ferch Elydyr (May 21)
- Re: Best Practices Dana Nowell (May 21)
- Re: Re: Best Practices R. DuFresne (May 21)
- Message not available
- Re: Re: Best Practices Dana Nowell (May 21)
