Upcoming Events

Executive conference

Cloud Connect March 16-18

Comprehensive thought leadership for executives, IT professionals and developers. Topics include: the ROI, cost and economics of on-demand computing; Migration strategies to move from on-premise to cloud-based IT; Vertical cloud specialization, tailoring features and architectures to specific applications, industries, and customer ecosystems

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up
8th Annual Well Connected Awards
F E A T U R E  
SECURITY

New Security Threats - Stronger Defenses

  May 13, 2002
  By Mike Fratto


TOC Issue TOC
Printer Print this page
Printer Print full article
Printer Download as PDF
E-Mail E-Mail this URL
 
  In This Article
arrow
Product of the Year
arrow
Winners & Finalists By Category
arrow
Heads Up
arrow
Web Links
A seemingly endless stream of new vulnerabilities made news this past year. Bill Gates touted turning Microsoft on a dime with a new security focus while Larry Ellison hawked Oracle software as "unbreakable." Microsoft, @Stake and friends joined forces to prevent full disclosure on software vulnerabilities. Oh, and let's not forget CodeRed, Nimda, CodeRed II and a host of other embarrassments.

Speaking of embarrassments, the unbreakable Oracle was, well, broken. Several times (see "Covert Labs Warns of Oracle8i Vulnerabilities"). The fact is, nothing is unbreakable. Superman could be felled by Kryptonite. Captain Kirk's weakness was women. The Six Million Dollar Man couldn't function without batteries. And the worms rampaging across the Internet during the summer of 2001 showed just how fragile our networks are. As for Gates' making security a priority, only time will tell if Microsoft will succeed (see "Should We Trust Microsoft's Security Push?"). And as for trying to squelch full disclosure, if vendors can keep you in the dark, the more likely they are to separate you from your money (see "Microsoft Pushes Cone of Silence").




By now you should know there is no silver security bullet. The defense-in-depth strategy dictates that, starting at the network edge and moving in toward your most important assets, your defenses should become more restrictive and tightly tailored to specific security problems. For example, a stateful packet-filter firewall, such as Check Point Software Technologies' VPN-1 Pro or Cisco Systems' PIX, is fine on the edge, but as you move closer to Web and e-mail servers and other critical resources, application proxy servers, such as Secure Computing's Sidewinder and Symantec's Enterprise Firewall, provide tighter control--though often at a performance expense.

But defense in depth, while important, is still mainly product-focused--what widgets get deployed where. Before you even get that far, focus on the three pillars of network security: authentication, access control and auditing.

Authentication: Who Is It?

Authentication plays a big part in most of the security products we test (see "Authentication Gets Tough"). It's a myth that passwords are not adequate protection for many applications. With the exception of biometric devices, nearly all authentication comes down to a password (a PIN is, after all, just a numeric password). For example, digital certificates, often thought to provide strong authentication, are protected by weak passwords. Although they're well-suited for targeted, high-value applications, both biometric readers and security tokens, including USB tokens, are still too expensive and cumbersome for wide deployment. Passwords, on the other hand, are relatively inexpensive and have nearly universal support.

But passwords fail because users pick easy-to-guess passwords--even when they are forced to use symbols and numbers. And precious few security applications--including firewalls, VPN systems, PKI tools, disk- and file-encryption schemes and IDSs--let you enforce password complexity. Luckily, with the ubiquity of LDAP-enabled services, we may see a move back toward single sign on, with the directory consolidating user authentication.

Access: Who Can Do What?

Access control can be dealt with on many levels, each particular to who is attempting to do what. Typically, access-control products restrict user access to OS objects and program functions. However, many technologies-- firewalls, VPNs and even antivirus products with active scanning--are, in reality, access-control products.

Firewalls, with the exception of a vendor's firewall client, generally don't provide user-based access control. However, the closer you can place firewalls to destinations or sources, the tighter you can control access. For example, perimeter firewalls control access for all the nodes they protect, and that leads to the "hard candy shell/soft, chewy middle" syndrome. In contrast, multiple firewalls throughout your network mean multiple defenses to break through. Desktop firewalls are making great strides in pushing security to the edge. Products from InfoExpress, Symantec and Zone Labs provide not only port blocking but application network-access control and privacy protection (cookie management and ad blocking, for example). The protection is not perfect; in fact, a well-written e-mail virus could defeat most of these products. But the theory is good--place access control, for both users and applications, close to the edge, where many of the problems lie, and target user and process access control (see "Defense Mechanisms").

User access control can be managed via education and finely tuned systems. But the crux of the matter is that you need to tighten access control at the OS level through sandboxing. Application sandboxing defines a set of resources, such as memory, disk space, network ports or calling other applications, that an application can access. The application cannot go beyond its boundaries. Typically stated in a positive manner, such as "Only Microsoft Word is allowed to write to .DOC files," sandboxing protects your critical systems from modification and exploitation. Although the products in this market are still young, expect the time spent properly configuring and deploying application sandboxing to pay off the next time a worm tries to crawl across your network.

Auditing: What Did What?

Authentication and access-control processes lose effectiveness when you lose track of who is doing what. The more you audit, the more you have to review: Firewalls, IDSs, routers and authentication servers spew tons of audit logs daily in a slew of formats containing all kinds of data.

But there are two distinct but related challenges with audit data. The first is aggregating data from multiple sources into a central repository. This is simply a matter of processing power, storage and integration with typical and proprietary reporting formats. The second is processing and correlating disparate events, and presenting the data for human consumption. The latter part is by far the harder task because the traffic patterns have to be defined, the events have to be identified across platforms, and intelligent connections have to be made to decipher the events. Security information management, or SIM, is still in its infancy, but the promise is clear--the data that can be mined from your network devices can go a long way toward getting a grip on security (see "Connect the Dots").

Your Mission...

Athletes, musicians and other professionals will tell you that practicing the basics--throwing fastballs or playing scales--keeps their skills finely honed. If the basics suffer, so do the advanced skills. Same is true for network security. To reduce your vulnerability to attack, keep going back to basics. Do vulnerability analyses to see what resources are ripe for attack. Lock your servers down tight with as few permissions as possible. Don't accept the defaults of any installation without understanding what the defaults mean. Restrict network and server access--inbound and outbound. Deploy virus scanning on mail and file servers and on the desktop, and keep your virus data files up to date. Treat remote-access users as hostile, and limit what they can do. Log everything.

But security can't be laid entirely at the network manager's feet. Vendors must focus on the basics as well. Their programmers and system designers should follow good coding practices. Buffer overflows are all the rage in the press, but other conditions, such as improper use of temp files, race conditions and program logic flow problems, can open a door. If vendors are using externally developed libraries, they should do their own QAs on the libraries to make sure their software isn't compromised, as happened with the zlib double free vulnerability.

Vendors should take the possibility of attacks seriously. They should design security into every product from inception, not as an afterthought. And if they don't do so, hit them where it hurts and take your business elsewhere.

Mike Fratto is a senior technology editor based in Network Computing's Syracuse University Real-World Labs®; he covers all security-related topics. Prior to joining this magazine, Mike worked as an independent consultant in central New York. Send your comments on this article to him at mfratto@nwc.com.



Heads Up: Security

Companies

Riptech: Management services are a dime a dozen, but in-depth security-information data mining and trend analysis set Riptech apart.

TippingPoint Technologies: The company's UnityOne combines intrustion detection, vulnerability scanning and firewall/VPN capabilities in one device. All three features work together for active security.

Products

Flatrock Instant Extranet: Simple-to-use, IPsec-based VPN could be extended with more features, making a compelling case for distributed extranet installations.

ForeScout Technologies ActiveScout: Automatically detects and deflects active network attacks.

Okena StormWatch: Offers application sandboxing for the OS and the applications running on it. You provide the permissions for application access, StormWatch enforces them.

Postini Active EMS: Tracks and monitors SMTP in real time; uses McAfee AVERT for in-line virus scanning, spam filtering and detection of attacks against Port 25.

Technologies

IETF IPsec Working Group: Actively trying to improve the current set of IPsec protocol drafts.

Security Assertion Markup: Provides an XML framework for products to exchange authentication and authorization Language (SAML) data.




Web Links

"Security Information Management: Connect the Dots" (Network Computing, April 1, 2002)

"Check Point Offers Provider-1 NG FP-1 for Managing Multiple Firewalls" (Network Computing, March 18, 2002)

"With Flatrock Instant Extranet, Building a VPN Is as Easy as Skipping Stones" (Network Computing, April 2, 2002)

"PGPvpn Keeps IPsec Simple" (Network Computing, Feb. 4, 2002)

"NetScreen's Global Pro Express 3.0 Simplifies Multifirewall Management" (Network Computing, Jan. 7, 2002)



start top introduction Winners & Finalists By Category

Best of the Web

Data deduplication: Declawing the clones

Data deduplication is emerging as a critically important new arrow in the storage administrator's quiver to answer hard questions about the increasing problem in storage growth costs.

Quick Read

Compression, Encryption, Deduplication, and Replication: Strange Bedfellows

One of the great ironies of storage technology is the inverse relationship between efficiency and security: Adding performance or reducing storage requirements almost always results in reducing the confidentiality, integrity, or availability of a system.

Quick Read

WAN Optimization Whitelists and Blacklists

Optimization is a fantastic way of saving money and creating really happy customers at the same time, but it doesn't work flawlessly for all applications.

Quick Read

WAN Optimization as a Managed Service: It's Not About the Cost

This insight examines how organizations outsourcing their WAN optimization initiatives to a third-party go about achieving their goals for application performance, reducing operational costs, and streamlining enterprise infrastructure.

Quick Read

  Sponsored Links

Premium Content

Data Centers Gone Wild
February 22, 2010

NWC


Salary

Video