Re: [fw-wiz] How automate firewall tests



Jean-Denis,

On 8/18/06, Jean-Denis Gorin <jdgorin@xxxxxxxxxxxx> wrote:
Strabla Ruggero wrote:
What I need is someone that could tell me which type of tests you do on
your firewalls and that you like too see automated

What I would like, is a tool able to answer 2 questions:
1/ what is the security level of my firewal platform (OS security, patches up
to date, is the firewall protect itself well, ...)?
2/ is the configuration of that firewall compliant with my security policy?


If you don't mind commercial tools, then
I suggest that you take a look at the AlgoSec Firewall Analyzer
http://www.algosec.com
It will do all of item 2 and part of item 1
(check that the firewall policy protects the firewall itself)

The first point could be achieved with tools like vulnerability scanner,
malformed packet scanner, patch manager, and so on. You have to add a tool able
to audit the security configuration of the firewall to check what is the level
of auto protection

yep


The second point requires a tool able to *understand* a security policy. And
that requires a tool able to *model* a security policy.
Then, you have to code a security policy checker. And analyzing the firewall
configuration files is *not* the right way: you have to find an external way to
check that to be sure that the firewall implementation of the security policy is
right. That means accepting the authorized data flows, *and* reject all others
kind. The difficult part is to check 'all others kind of data flows', including
tunneling, covert channel, ...


I agree with almost all the above except the statement
"analyzing the firewall configuration files is *not* the right way"
It's not very easy to do, certainly not easy to do *well*, but it is
very possible!
if you are interested, you can find some academic
papers about how it works at: http://www.eng.tau.ac.il/~yash/fw/index.html

The AlgoSec firewall analyzer implements all the things you mentioned,
and then some: it parses the config files, builds a model,
does a comprehensive offline analysis of what the firewall is
configured to allow,
and then compares the results with a knowledge base about what is risky.

Avishai.

.disclosure: I created the firewall analyzer starting at Bell Labs
circa 1998, then at
Lumeta, and now at AlgoSec. So I am naturally biased.


JDG
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Security for 64 bit Vista Laptop
    ... Windows Defender is enabled, as is Windows firewall. ... I'd like to address strong security. ... Understanding and Configuring User Account Control in Windows Vista. ... Internet Explorer Enhanced Security Configuration changes the browsing ...
    (microsoft.public.windows.vista.security)
  • [REVS] Bypassing Client Application Protection Techniques
    ... Get your security news from a reliable source. ... protection programs. ... * Kerio Personal Firewall 4.0 ... And we got actually nothing in the field of client application ...
    (Securiteam)
  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Why hasnt Symantec addressed nastier Messenger spoofs
    ... Norton / Symantec has been silent on whether Norton Internet Security ... DSL firewall will stop these kinds of pop-ups. ... major ISPs and broadband systems. ...
    (comp.security.misc)
  • Re:RE : suggestions on a good firewall
    ... Subject: RE: suggestions on a good firewall ... CheckPoint does! ... with a url-filtering server. ... IT Technical Security Officer ...
    (Security-Basics)