Tutorial

Go Back   Tutorial > Technology > Home security tips

Forum overview

Latest topics
Show:

Portalsearch

Advanced Search

Statistic
Topics: 37428
We welcome our newest user: Fubembemflumn
New users:
12-05-2008
- Fubembemflumn
12-05-2008
- TabSleernezen
12-04-2008
- bedDeldMype
12-04-2008
- bedGeseejaina
12-04-2008
- VitLover


Why UTM Will Win


Home security tips

Sponsored Links:

Reply
 
Thread Tools Search this Thread Display Modes

  #1  
Old 04-28-2007, 03:47 PM
LapTop's Avatar
LapTop LapTop is offline
Administrator
 
Join Date: Apr 2007
Posts: 21,895
Why UTM Will Win

Sponsored Links:

We know how many words a picture is worth. The figure above, from Boxed In by Information Security magazine, shows why Unified Threat Management appliances are going to replace all the middleboxes in the modern enterprise. At some point the UTM will be the firewall, so the gold UTM box above will also disappear. In some places even the firewall will disappear and all network security functions will collapse into switches and/or routers.

I'd like to show one other diagram from the story.



Figures like these, showing which products and their "features," are another reason UTM will replace point product middleboxes. "Hey, I read in this magazine that product X checks 7 boxes, but product Y only checks 3. Let's look at product X." These are the sorts of figures that people who are not security experts and are not interested in or capable of assessing security products like.

Just because I think this is going to happen (or is happening -- look at what your Cisco router can do) doesn't mean I like it. The more functions a box performs, the greater the likelihood that all of those functions will be performed at a mediocre level. Mediocrity is an improvement over zero security protection for some sites, but elsewhere it will not be sufficient.

I should say that the top diagram has its merits, with simplicity being the primary advantage. With so many networks having multiple "moving parts," it can be tough to stay operational and understand what's working or not working. Moving all those moving parts onto a single platform may not yield all the simplicity one might expect, however!

One way to address the weaknesses of these UTMs is to deploy stand-alone devices performing network forensics, so they record exactly what happens on the network. Using that data, one can investigate security incidents as well as measure the effectiveness of the UTM. I do not foresee network forensics collapsing into security switches/routers due to the data retention requirements and reconstruction workload required for investigations.

To survive I think network security inspection/interdiction vendors either need to be in the "meta-security" space (SIM/SEM) or in the do-it-all space (UTM). If your favorite vendor is in neither space, expect them to be acquired or go out of business.

Richard Bejtlich is training in a city near you! Seats in classes at the Sys Admin Magazine Conference, Techno Security 2007, SANSFIRE 2007, USENIX Annual, and Black Hat Las Vegas are filling fast -- register today.

Copyright 2007 Richard BejtlichCopyright 2003-2007 Richard Bejtlich
Sponsored Links:
Reply With Quote
Reply

Sponsored Links:

Compare price

Compare products

Download software


Free Download Softwware


Tags: ,



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Forum Jump



All times are GMT. The time now is 12:09 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.

RSS 2.0 HOME