home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



Security
B U Y E R ' S   G U I D E  
Desktop Firewalls

  September 30, 2002
  By Mike DeMaria


TOC Issue TOC
Printer Print full article
Printer Print this page
Printer Download as PDF
E-Mail E-Mail this URL
flame author Flame the author
 
  In this article
arrow
Introduction
arrow
Suite Security
arrow
Interactive Buyer's Guide
arrow
Desktop Firewalls
arrow
Chart
arrow
Customize Chart
arrow
Product Directory
arrow
Search

If a user receives an e-mail message saying "Meg Ryan sunbathing, double click to see" with an executable attached, he may be tempted to open the file. And with that, he'll have installed a remote exploitable Trojan on his computer. Desktop firewall software can help prevent users from running unauthorized Internet applications, limit available services and defend against the Microsoft Outlook executable du jour.

Desktop firewalls serve two purposes. One, they limit the possibility of a Trojan infiltrating your network by letting you set up access controls for incoming and outgoing traffic. For example, many desktop firewalls let you specify which programs can connect to the Internet. However, these firewalls can't prevent users from installing and running a program, legitimate or malicious. If a Trojan attempts to delete c:/winnt, a desktop firewall won't deter it.

Two, desktop firewalls protect internal users from each other. A disgruntled employee might decide to hack his way into the payroll system and send a message companywide listing management salaries. Installing conventional firewalls in front of every subnet or node could solve the problem, but this solution is complex and difficult to manage.


Decisions, Decisions

Before you choose a desktop firewall, determine whether you need a consumer- or enterprise-class model. Both provide similar security capabilities, but enterprise-class firewalls add centralized management and policy distribution. InfoExpress, Sybergen Networks and Securitae Corp. all sell centrally managed firewalls. Other vendors, including Internet Security Solutions (ISS) and ZoneLabs, offer both enterprise and consumer versions of their products.

If you have only a few users or need a firewall for your own machine, a consumer-class firewall might do the trick.

But tattoo this to your eyelids: End users should not have rights to modify firewall settings. Most centrally managed products offer ways to lock down policies. ISS's BlackICE PC Protection, for example, lets you install the product without a GUI.

Some firewalls let you override a policy. Sygate Technologies' Sygate Secure Enterprise Solution, for example, lets you create exceptions for individual users. Other products, such as those from InfoExpress, supply override passwords you can give a user if he or she needs to open a port or turn off the firewall. These special circumstances must be administrator-approved.

Once the firewall is in place, you need to decide how much information the end user should receive. Should he or she receive alerts on all possible attacks--and be inundated with information--or should he or she be left in the dark?

Some firewalls send out alerts simply to show they're functioning. For example, a ZoneLabs ZoneAlarm firewall I once used told me my router was trying to ping my machine. Well, hot damn, glad that security breach was averted! On college campuses, copious alerts can lead to equally copious phone calls from students making accusations like "Your SNMP-based network-management software just hacked my AOL account!" A good rule of thumb is to limit user notifications to serious threats.

Two other considerations: Most enterprise-class firewalls require a database for log files. Do you have licenses and experts in MS SQL or Oracle? Will you need a separate database server, or can you run the database on the policy server?

Also, pricing varies widely. Most vendors charge on a sliding scale and offer discounts for bulk buys. You may have to pay extra for a management server, too. And you'll need to budget resources for maintenance, user training and support.

Application Control

Some Desktop firewalls provide only port/IP blocking, but the best offer additional application controls to help you catch Trojans. Trojans are sneaky--they can send data to a remote server with HTTP to Port 80 or use any of the other common Internet protocols, which means port blocking is not sufficient. With application controls, you can specify which programs are granted network access. Products with this feature usually provide some form of application-integrity testing as well.

Let's say, for example, an MD5 checksum from a clean executable is fed to the desktop firewall. If the user tries to run a modified version of the program--such as a hack Trojan or a virus embedded into iexplore.exe--the checksums won't match and the firewall will deny the program access. Note, though, that this feature can cause an administrative headache: You'll need to maintain a list of approved programs and checksums.

Some desktop firewalls offer more application-control and file-integrity features. InfoExpress' CyborArmor, for instance, lets you control program spawning--you can set a batch script to execute when run from Eudora but not from Outlook.

Even with application control, though, Trojans can be injected into DLLs or running processes. DLL-integrity checking is the next big step, and vendors are working on this capability.

Michael J. DeMaria is an associate technology editor based at Network Computing's Syracuse University Real-World Labs®. Write to him at mdemaria@nwc.com.


start top Introduction Suite Security 





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Aneesh Chopra is looking to other CIOs to advise him on fleshing out a more detailed agenda to best serve the president's IT agenda.

IT spending is expected to decline by 3.8 percent in 2009 according to Gartner.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service