« Multimedia Minivan | Main | Solving World Peace »

June 09, 2005

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8341f053853ef00d834240ff653ef

Listed below are links to weblogs that reference Getting Published:

» Barnett and Berman Network Security (CompSci And PoliSci Makes NetSci) from tdaxp
"Life After DoDth or: How the Evernet Changes Everything," by Thomas P.M. Barnett, Proceedings of US Naval Institute, May 2000, http://www.thomaspmbarnett.com/published/ladod.htm. "The Death of a Firewall," by Stuart Berman, Network Magazine, 1 June... [Read More]

» Re: Death of a Firewall from ModInfoSec
Congratulations to fellow SANS GSEC Advisory board member Stuart Berman on his recently published article Death of a Firewall (see Getting Published for Stuart's brief writeup of the article and experience). Stuart is a very sharp fellow, and the ideas [Read More]

» Stuart Berman on Slashdot! from tdaxp
"Tear Down the Firewall," by timothy, Slashdot, 9 July 2005, http://it.slashdot.org/article.pl?sid=05/07/09/1758205&tid=172&tid=230&tid=218. Congratulation to Stuart Berman of My Kids' Dad for having his article on firewalls mentioned on ... [Read More]

Comments

Dan

Interesting article!!

Saar Drimer

Stu, good job!
Saar.

Darrin Wassom

Nice work, Stu!

Phil Hollows

Great article.

At the risk of being too self-serving, I have just recorded a webcast with SearchSecurity.com on the same concept but at a larger scale: the fallacy of defence in depth. The basic premise is that each layer is not at all perfect, and that the weaknesses of the interactions beteween the elements of each layer and between the layers cripples security. This piece makes the same point, I think, about firewalls alone, but the challenge I believe goes to most of the security systems we deploy. We tune out the IDS thanks to fals positives for example. We can't patch in time but we kid oursleves that we're invulnerable. Each of these technologies is just a year or two behind where the firewall is now, and none of them - not one - address the ultimate weak link - himan beings and social engineering.

A slightly broader discussion and a link to the webcast (registration required, can't change that, but you've been warned) is at http://www.openservice.com/blogs/2005/06/webcast-want-better-security-how-to.jsp

FWIW

Phil

Stuart Berman

You guys are trying to make me blush ;)

And thanks Phil - I took the opportunity to listen to your webcast (love the stuff at SearchSecurity and they put on a great conference) and couldn't agree with you more. I like your take at the failing of Defense In Depth. I have felt strongly that the inability to enforce security should be balanced by the ability to monitor (similar to the parking lot cameras in England). I'll try to post a comment on your blog soon.

Dan

Great article again, Stuart.

And great point, Phil. Related to the concept of defense-in-depth is offense-in-depth. The widespread use of either weakens the importance of firewalls, as Stuart's article aptly demonstrates.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

My Photo

Navigate

January 2009

Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31

Views


Blog powered by TypePad
Member since 09/2004

Search site


TTLB


Affiliations

Blogshares


  • Listed on BlogShares

Technocrati

Blog Barrel