Re: [fw-wiz] A fun smackdown...

From: Martin (marty_at_supine.com)
Date: 05/21/05

  • Next message: Marcus J. Ranum: "Re: [fw-wiz] Thoughts on the new Cisco ASA 5500 firewalls"
    To: firewall-wizards@honor.icsalabs.com
    Date: Sat, 21 May 2005 08:05:25 +1000
    
    

    $quoted_author = "Paul D. Robertson" ;
    >
    > On Tue, 17 May 2005, Martin wrote:
    >
    > > "Be liberal in what you accept; be strict in what you send."
    >
    > _All_ effective security controls break that tenet. The more liberal your
    > controls, the more risk you assume.

    My original use of the quote was in the context of "adaptive" IDS/IPS as
    mentioned in the article. If the system gets too "smart" about recognising
    "new"[1] attacks then it can break that tenet and deny legitimate traffic.

    I guess the point I'm trying to make that in a security context the quote
    only applies to protocols / connections that should be allowed according to
    policy but may be denied due to "smart" software[2].

    cheers
    marty

    [1] where "new" = "no signature / fingerprint / definition available for it"
    [2] which doesn't really exist, all software sucks.
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Marcus J. Ranum: "Re: [fw-wiz] Thoughts on the new Cisco ASA 5500 firewalls"

    Relevant Pages

    • Re: Found the actual quote by John Gibson
      ... The quote from Rich's memory: ... Gibson said you'd have to imagine a Democrat GOING TO WAR. ... sentence..but to get that meaning he had to entirely ignore the context ...
      (rec.sport.football.college)
    • Re: "Friendly Premises"
      ... <snip, quote out of sequence> ... >you don't define the term) but by talking about context and quotation. ... So, you know about that Kant piece, eh? ... hands clutching "Critique of Pure Reason." ...
      (sci.logic)
    • Re: Found the actual quote by John Gibson
      ... The quote from Rich's memory: ... "You'd have to imagine a fictional person to imagine ... Gibson said you'd have to imagine a Democrat GOING TO WAR. ... sentence..but to get that meaning he had to entirely ignore the context ...
      (rec.sport.football.college)
    • Re: Found the actual quote by John Gibson
      ... The quote from Rich's memory: ... that is clearly not the context at all of what Gibson was talking ... Gibson said can be equated to the silliness that Rich threw into the mix. ...
      (rec.sport.football.college)
    • Re: Found the actual quote by John Gibson
      ... The quote from Rich's memory: ... Charles. ... that is clearly not the context at all of what Gibson was talking ...
      (rec.sport.football.college)