SEARCH Archives
Loading
Sponsored by:

Even firewalls have holes

Firewalls are the main barriers between an organization’s internal and external networks. Over the past 25 years, they have become the foundation of perimeter security and there are those that consider them commodity products.

By Gregory Hale; Source: ISS Source

04/26/2011


Firewalls are the main barriers between an organization’s internal and external networks. Over the past 25 years, they have become the foundation of perimeter security and there are those that consider them commodity products.

Now as another generation of firewall technology is taking hold, NSS Labs started testing traditional network firewalls and next generation firewalls. NSS Labs engineers have discovered serious flaws in these products, despite the maturity of the market and their certification by two other major certification bodies.

Researchers found:

  • Three out of six firewall products failed to remain operational when subjected to stability tests. This lack of resiliency is alarming, especially considering the tested firewalls were ICSA Labs and Common Criteria certified.
  • Five out of six vendors failed to correctly handle the TCP Split Handshake spoof (aka Sneak ACK attack), thus allowing an attacker to bypass the firewall.
  • Measuring performance based upon RFC-2544 (UDP) does not provide an accurate representation of how the firewall will perform in live real-world environments.

“IT organizations worldwide have relied on third-party testing and been misled,” said Vik Phatak, CTO, NSS Labs. “These test results point toward the need for a much higher level of continuous testing of network firewalls to ensure they are delivering appropriate security and reliability.”

All leading network firewall vendors were able to participate in the test at no cost. All testing occurred in an independent environment and no vendor paid for testing. Products tested include:

  • Check Point Power-1 11065
  • Cisco ASA 5585
  • Fortinet Fortigate 3950
  • Juniper SRX 5800
  • Palo Alto Networks PA-4020
  • Sonicwall E8500

Click here for the Network Firewall Comparative Group Test Report.



No comments
Consulting-Specifying Engineer's Product of the Year (POY) contest is the premier award for new products in the HVAC, fire, electrical, and...
Consulting-Specifying Engineer magazine is dedicated to encouraging and recognizing the most talented young individuals...
The MEP Giants program lists the top mechanical, electrical, plumbing, and fire protection engineering firms in the United States.
Integrating lighting, HVAC systems, Energy codes and lighting, BIM and fire protection engineering
Engineering hospital electrical systems, Boilers and boiler systems, Building envelope best practices
Hospital indoor air quality, ASHRAE 90.1 update, Specifying piping materials, Integrated project delivery
Case Study Database

Case Study Database

Get more exposure for your case study by uploading it to the Consulting-Specifying Engineer case study database, where end-users can identify relevant solutions and explore what the experts are doing to effectively implement a variety of technology and productivity related projects.

These case studies provide examples of how knowledgeable solution providers have used technology, processes and people to create effective and successful implementations in real-world situations. Case studies can be completed by filling out a simple online form where you can outline the project title, abstract, and full story in 1500 words or less; upload photos, videos and a logo.

Click here to visit the Case Study Database and upload your case study.

Estimating data center PUE, Design tips for cost savings, Networked controls, NFPA 70E
Preventing arc flash, Backup power fuel choices, power for high-tech facilities
Using BIM in electrical power design; Closed-transition transfer; Medium-voltage distribution; Diesel emission regulations; Increasing emergency power capacity

Poll of the Week

When engineering systems in military buildings, what’s the most difficult issue you face?
Automation and controls
Codes and standards
Electrical and power
Energy efficiency, sustainability
Fire and life safety
HVAC


Click Here for Poll Archives
Sponsored by:

About Us | Contact Us | Advertise | Subscribe to Magazine | Site Map | Privacy Policy
Home | Channels | New Products | Media Library | Connect | Industry News | Events and Awards | Newsletters | Blogs | Magazine
Control Engineering | Plant Engineering | Consulting-Specifying Engineer
All content copyright © 2010-2013 CFE Media. All rights reserved.