Firewalls not enough

Mention the words network security and most people will immediately respond, “I have a firewall.”

But according to some industry experts that’s just not enough.

Seifert Systems Invests in Energy Efficiency to Strengthen Operations

For manufacturers, energy is more than just another operating expense. It plays a critical role…

Learn More

A firewall system can be a router, a personal computer or a host, set up specifically to shield a site or subnet from protocols and services that can be abused from hosts outside the subnet. It’s usually located at a higher-level gateway, such as a site’s connection to the Internet.

But according to some in the industry, a firewall is only as good as the company that manages it.

- Advertisement -

“A firewall can sometimes give companies a false sense of security,” said Carl Stolfi, of Genuity, a Massachusetts-based company that specializes in Internet security. “You really have to pay attention to how a firewall is applied. A simple administrative error can leave a company’s network open for serious attack.”

According to the fifth annual “Computer Crime and Security Survey,” conducted by the Computer Security Institute, 90 percent of the companies surveyed detected a computer security breach within the last year. In addition, 70 percent of those companies reported a variety of serious computer security breaches such as theft of proprietary information, financial fraud, system penetration from outside the company, denial of service attacks and sabotage of data or networks.

Forty-two percent of respondents were able to quantify their financial losses at close to $265 million.

“The trends the CSI/FBI survey has highlighted over the years are disturbing,” said Patrice Rapalus, CSI director. “Clearly must more be done in terms of adherence to sound practices, deployment of sophisticated technologies, and most importantly adequate staffing and training of information security practitioners in both the private sector and the government.”

Stolfi believes human nature is the greatest contributing factor to the invasion of a network.

“We live in an open culture that depends too much on trust,” he said. “In many of today’s offices employees have access to a lot of things that they shouldn’t have because the more people that have access, the higher the human error factor.”

According to Stolfi good security is “a marriage between people, the process, and technology.”

“You definitely need balance,” he said. “Often companies depend too much on their firewall and don’t think about other security breaches.”

Breaches in security from outside locations are also growing. According to the Sans Institute, a cooperative research and education organization founded in 1989, the majority of successful attacks on computers systems via the Internet are the result or certain areas of vulnerability, from weak modems to holes in the server.

“A few software vulnerabilities account for the majority of successful attacks because attackers are opportunistic, taking the easiest and the most convenient route,” according to a SANS report on the top 10 Internet security threats. “They exploit the most convenient route. They exploit the best-known flaws with the most effective and widely available attack tools. They count on organizations not fixing the problems and they often attack indiscriminately, by scanning the Internet for vulnerable systems.”

According to SANS one of the most common ways to gain access to a network through the Internet is by a Denial of Service Attack (DoS). There are three basic Denial of Service Attacks: consumption of resources, destruction or alteration of configuration information; and physical destruction or alteration of components.

“DoS attacks are the most frequently used against network connectivity,” it said in a SANS report on Internet Security released earlier this year. “The goal is to prevent hosts or networks from communicating.”

For example, with an SYN Flood attack, the attacker begins establishing a connection to the victim machine, but in such a way as to prevent completion of the connection. In the meantime, the victim machine has reserved one of a limited number of data structures to complete the connection. The result is that legitimate connections are denied while the victim machine is waiting to complete bogus “half open” connections.

In another instance, an intruder can use the system’s own resources against itself with the result being that the two services consume all available network bandwidth between them.

“A denial of service is basically a way of taking advantage of apparent weaknesses,” Stolfi said.

What it basically comes down to, Stolfi said is making “security part of an overall strategic plan.” This includes monitoring, checking, and balancing the processes. While it may be cost effective for larger firms to do all of this themselves, Stolfi said, if companies don’t have the confidence or the manpower to do it, outsourcing is an alternative.

“If you think you can step up to the task, then do it,” he said. “But it all comes back to people. If you can’t manage or maintain technology, then you must let others help you.”

No posts to display