Firewall Wizards mailing list archives

RE: Worms, Air Gaps and Responsibility


From: "Paul D. Robertson" <paul () compuwar net>
Date: Tue, 18 May 2004 17:28:10 -0400 (EDT)

On Tue, 18 May 2004, Dana Nowell wrote:

about short term vs. long term environments.  The short term (usually less
technical) guys (home users, small business, etc.) are unlikely to take the
time or have the knowledge to analyse the proper 'air gaps', especially
when it includes things like cell phones and PDAs which are not thought of
as 'part of the network'.  Additionally they are less likely to approve

They're also unlikely to read Firewall-Wizards, and therefore unlikely to
get any of the points made...

expenditures for security devices that they can't justify simply because
some security paper says so.  So this discussion is wonderful for

However, one of my original points still stands- if we the security
community make common practice to question connectivity _at_all_ then it's
more likely that such ideas will filter down to those who are interested.

[I know a fair number of folks who administer small networks who care
about and spend time on security- if "nobody does it" or "nobody gives me
a reason to do it" then it doesn't get done, but with peer activity and
good rationale, it has a chance of being adopted.]

I'm going to use a real world example.  Two years or so ago, I met a
network administrator for a swimming pool company at a conference.  They
said "I'd like to do more security stuff, but it really doesn't apply, we
sell and maintain swimming pools- like $large_name's house,
$important_CEO's name's house...."

I said "Let me get this straight- you have people driving large trucks
full of chlorine with access to $list_of_people's residences, and you
don't think you have a good case for security?"

Now, does that mean they get to go out, purchase 3 firewalls, 2 AR-15's
and a set of frequency hopping bone conductive radios?  Nope, but does it
mean they can present some useful cases to management that allow them to
do *what they really want to do*, which is secure their infrastructure in
a sane way?  Absolutely.

network, it is less than useful.  I'm willing to bet that the bulk of the
network connections (specifically the more insecure parts of the Internet)
falls into the short term bucket, especially with home use.

I'm going to offer a follow-up to "It doesn't have to be our fault to be
our responsibility."  It doesn't have to be our responsibility for us to
try to make it better.

Premise: these networks/hosts will be compromised, as air gaps are unlikely
to be implemented and new technology connected devices will flourish, that
creates a lot of places for bugs to breed.

Premise:  Every network operator we get to do the right thing[tm] means
one less network to produce traffic which attacks us.

Premise: devices are moving toward interconnectivity via Infrared,
Bluetooth, WiFi, 802.11, and other technologies.  Direct peer-to-peer
connectivity between these devices is coming and one day 'soon' walking
down the street with one in your pocket will cause tens or hundreds of
connections to be attempted/created/broken, with all the inherent risks.

Premise: When this becomes a real risk, we'll get real solutions.

Premise: security typically lags functionality as new technology rolls out
(palms get synced to desktops before security knows a palm is in the
building in most companies).

Premise: New technologies aren't attacked at the same rate as current
technologies, and therefore need less protection.

Conclusion: Air gaps will not solve the problem as large breeding grounds,
device connectivity, and security lag will allow networks to be
compromised.  At best air gaps are another stop gap measure, which is
certainly better than nothing. but not much.

Fact: If the network can be attacked via a foreign device, it doesn't have
an air gap.  That doesn't make air gaps less effective.  That's like
saying "If I ran Windows in an X86 emulator on my Sparc, it'd be as
vulnerable as Windows!"  Air gaps are effective protection devices.

I've worked in places where you couldn't take a pager, camera, laptop, or
whatever else into the facility.  The air gap there was particularly
effective.

Whine: The security professionals in the Internet community need to take a
longer view.  Until we 'solve' the problem for the average guy playing a
short term game (or at least greatly reduce his risk) we can't really solve
the issue in our own networks, we can only play technology catch-up.  We

Counter-Whine:  You can't dismiss strategic thinking then say we need to
take a longer view!

need to be involved either via this list or another mechanism in helping
set device/protocol 'best practices' and beating vendors about the head
until they do it, so security is designed in rather than cobbled on.  We

Nobody's willing to pay for security to be designed in, can't in that
battle.

need to concentrate on how we solve the political/corporate/vendor issue
and not the technical issue because the technical issue isn't soluble (not
that the political issue is, but we might get more bang for the effort
buck).  Basically I'm damned tired of fighting the same war and upgrading
from a rock to a knife to a dagger to a sword to a flintlock to a ...  So
air gaps are nice, but in the long run, it's just another musket, one that
will be circumvented by targeting devices difficult to air gap (PDAs

The original message wasn't about airgapping desktops, it was about
airgapping non-user production networks, such as power distribution
systems, medical equipment (think the a CAT scanner should be on
the same network as the person in the mail room at the hospital?)

syncing to desktop?).  Before you ask, no I don't have a plan.  Like most
in a small company I spend 95% of my day digging a deeper foxhole and
looking over the latest in flintlock design.  We have a lot of bright
people here and we ought to be using those IQ points for the long term
instead of designing today's Mark XII network rock.

Just like they're not appropriate for user networks where you can't
enforce device additions, they're appropriate for sets of networks in lots
of organizations.  In my mind, air gaps are more effective than buying and
deploying IPS (you want a new flintlock?) for a large number of networks.

Sure, protocol and vendor issues abound, but so do the basic network
design issues that are able to negate large swaths of protocol and vendor
issues.  We've touched on some of them in this thread, like inter-machine
communication, separation, segmentation, per-class networking, etc.  One
answer isn't going to get us where we want to go any more than one vehicle
is going to make everyone happy on the road.  What we can do is ensure
that mopeds don't go on freeways, skateboards aren't used inside the
office and that people pull over for emergency vehicles.  We won't get
100% compliance, but we'll get navigable roads and we can ticket the
offenders.  We can also deal with people who're not doing what the rest of
us are doing by making them liable for their actions, or ensuring they
need to be insured beyond what the rest of us are- either way is
effective.

Paul
-----------------------------------------------------------------------------
Paul D. Robertson      "My statements in this message are personal opinions
paul () compuwar net       which may have no basis whatsoever in fact."
probertson () trusecure com Director of Risk Assessment TruSecure Corporation
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: