Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Are firewalls obsolete in a world involving enterprise applications SOA? |
|---|---|
| Date: | Tue, 25 Mar 2008 21:06:37 -0000 |
Dear William,
I have provided Information Assurance consultancy services on behalf of the UK
Security Services for some 8 years. In my experience the phrase Defence in
Depth is key! Basic perimeter security devices play an important role however,
as you correctly note, their effectiveness is no longer what it was. The role
of dedicated / specific application security firewalls are required to mitigate
the risks introduced by the new breed of web technologies. It is important to
note that such solutions complement the protection offered by other more
fundemental solutions.
I wish you well in your studies.
Kind Regards
Alan
-----Original Message-----
From: listbounce@securityfocus.com <listbounce@securityfocus.com>
To: firewalls@securityfocus.com <firewalls@securityfocus.com>
Sent: Tue Mar 25 11:56:05 2008
Subject: Are firewalls obsolete in a world involving enterprise applications
SOA?
Dear Firewall Experts,
Provocative Question:
++++++++++++++++++++
Are firewalls obsolete in a world involving enterprise Web Service SOA?
What do I mean by the above question: given that Web Services (J2EE and
so forth) tend to tunnel through http and https (eg. SOAP) what role can
a traditional network firewall play? If its just a matter of opening
ports http and https for your dedicated enterprise services then is
there even a need for a firewall!
I am asking this question not to be flamed but to provoke a discussion
as to why we still need firewalls.
Assumptions:
++++++++++++
I use the term firewall loosely to mean "network access control". That
is, its a mechanism to prevent unwanted packets. Therefore, a firewall
could be iptables (stateful, DPI etc) or even the proxy TCP Wrappers,
cisco and so forth.
In particular, I have focused on Linux iptables and TCP Wrapper. I
realize that one can install an xml based firewall to inspect packet
content in regard to web services.
Scenario Network:
++++++++++++++++++
Internet ---> Firewall ---> Enterprise SOA Server ---> Additional
firewalls and back-end database servers etc.
Is it a case that in this Enterprise SOA environment the NAC firewall is
made redundant (as opposed to an xml firewall):
Internet ---> Enterprise SOA Webservice server
Assuming of course the servers are dedicated Web Service servers that
run no other services such as DHCP, intranet web server, email and so
forth that need to be protected?
Firewall Justification:
+++++++++++++++++++++++
I am trying to find publications, white papers, reports etc that state
the case for the need for firewalls. I need something concrete.
The current information I have found (web service orientated!) tends to
say firewalls are obsolete when talking about enterprise SOA given that
once port 80 and 443 is open on the firewall the SOS services are
exposed and hence protection happens at the application layer of the
particular service.
However, best practice suggests one should take a more holistic approach
to security and apply the "belt-and-braces" approach. That is, install
firewalls, IDS, AV, proper authentication at various OSI stack layers
etc etc. So we get a layered security affect, thus there must be a
justification for using a firewall still.
My Opinion:
+++++++++++
My opinion on what NAC firewalls can offer to web service SOA other than
simply opening port http and https is as follows:
1) control access to those ports via ip address ranges (eg.
customer/business subscribers)
2) deep packet inspection to solicit appropriate content incoming and
outgoing from the SOA enterprise servers.
3) ???? what else would be done? please comment.
While I agree that there are xml based firewalls to monitor xml based
Web Service traffic, I wonder can it perform access controls at the
lower levels like network based firewalls (for example, block certain IP
addresses)? My guess is they don't given the operate at the application
layer.
I also wonder why one would invest in an xml firewall that is dedicated
to one kind of traffic profiling and not use for example a very
expensive cisco firewall that can cover a multitude of traffic
profiling. Presumably these expensive firewalls (or the equivalent
unexpensive iptables firewall) can inspect the packet for malicious
content to and from the enterprise servers (I believe we have
snort-2-iptables to also help here). At any rate, I do not want to start
a huge debate on the pros and cons of an xml firewall versus a network
firewall as I am aware dedicated firewalls specialize in various traffic
profiling. Also its best practice to install a wide range for firewall
capabilities.
The real issue is the justification of NAC's in an enterprise SOA
environment. Of course, if this enterprise environment also included the
company standard services such as email, dns, web server etc I can see
the major impact of the NAC firewall. But what is the case for dedicated
enterprise SOA?
My shortcomings:
++++++++++++++++
My inexperience in an enterprise network environment of how things are
really carried out rather than what is done in theory.
Summary:
++++++++
What role do NAC's have to play in an environment of enterprise
application services?
All pointers to documentation and your comments are welcome.
I look forward to your support,
regards,
Will.
--
William M. Fitzgerald,
PhD Student,
Telecommunications Software & Systems Group,
ArcLabs Research and Innovation Centre,
Waterford Institute of Technology,
WIT West Campus,
Carriganore,
Waterford.
Office Ph: +353 51 302937
Mobile Ph: +353 87 9527083
Web: www.williamfitzgerald.org
www.linkedin.com/in/williamfitzgerald
www.ryze.com/go/wfitzgerald
CONFIDENTIALITY NOTICE: This email and any attachments may be confidential.
They may contain privileged information and are intended for the named
addressee only. They must not be distributed without our consent. If you are
not the intended recipient, please notify us immediately and delete the message
and any attachments from your computer, do not disclose, distribute, or retain
this email or any part of it.
DISCLAIMER: Internet communications are not secure and therefore Ogilvie Group
Ltd does not accept legal responsibility for the contents of this message.
Unless expressly stated, opinions in this email are those of the individual
sender and not of Ogilvie Group Ltd. Ogilvie Group Ltd checks outgoing
e-mails with anti-virus software that is regularly updated however this does
not guarantee that any files attached to this e-mail are virus free. You must
therefore take full responsibility for virus checking. Ogilvie Group Ltd
reserves the right to monitor all email communications through their networks.
Ogilvie Communications ltd
Registered in Scotland No. 116592
Ogilvie House
Pirnhall Business Park
Stirling
FK7 8ES
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Are firewalls obsolete in a world involving enterprise applications SOA?, Geoffrey Gowey |
|---|---|
| Next by Date: | Re: Are firewalls obsolete in a world involving enterprise applications SOA?, Ron Brown |
| Previous by Thread: | Are firewalls obsolete in a world involving enterprise applications SOA?, william fitzgerald |
| Indexes: | [Date] [Thread] [Top] [All Lists] |