Archive
Are You Ready For The Next Generation IPS?
Advanced Persistent Threats are changing the information security paradigm and Next Generation IPS will probably be, together with SIEM, the new weapons in the hands of information security professionals for stopping this new category of threats that are proving to be the real nightmares for CISOs in this troubled 2011.
If you have just learned what a Next Generation Firewall is, you will probably be a little disappointed in knowing that it is not the last frontier of information security (as many security firms claim), instead the growing impact and influence of APTs, which are threats acting on different layers (user, network and applications), different timeframes and different portions of the network, are redesigning the network security paradigm, requiring additional intelligence at the perimeter, and shifting the game to a context-aware model in order to grant the holistic view that is necessary to stop them.
Traditional Firewall and IPS Technologies are rapidly shifting towards the Next Generation Firewall model, which is user aware and application aware. Unfortunately a Next-Gen Firewall is not enough to stop an APT, since, although focused on the application control, a NGF remains essentially user oriented, and consequently lacks the global vision necessary to stop a persistent threats acting on different layers besides user and application. At the same time traditional network security technologies (FW and IPS) are not enough since they are anchored to the old model: a Firewall enforces access control at the protocol level, which is useless for threats carried inside legitimate traffic, instead an IPS enforces a security model based on protocols and vulnerabilities, being completely unaware (and in certain sense blind unless complex integrations are put in place) of the context in terms of user activity, and user interaction with applications, directories, etc.
Now let us suppose to make a brand new information security recipe, taking the main features of a NGF (user awareness and application awareness), the main features of a Firewall (access control) and the main features of an IPS (protocol awareness and vulnerability awareness), blend them in a virtual pot and add a little bit of reputation (for instance obtained from a globally distributed network of sensors) and other features such as geo-location, application heuristics and, last but not least, an application anomaly detection engine (which is completely different from a traditional protocol anomaly engine). You will obtain a new information security dish: the Next Generation IPS, a new class of devices that likely represents the near future of network security.
NG-IPSs are characterized by two main features:
- They shift the enforcement of security policies from a content-based to a context-based model (where the context is defined by the interaction of user with applications);
- They leverage new technologies such as reputation and geo-location to provide the holistic view necessary to stop APTs.
So what do we have to expect at the perimeter? The traditional Firewall and IPS (or UTMs) will likely be replaced by NG-IPS, while specific “vertical” security devices, such as Web Application Firewall will remain in place in strategic portion of the netowork (just in front of Web Farms) to protect specifically Web (read HTTP and HTTPS) applications. As you may see from the following table a NG-IPS encompasses all the features of the “old” technologies plus new features allowed by a growing adoption of Reputation and Cloud-Based services.
Since WAF will follow a parallel and co-existing walk, meanwhile I reccomend you to read my Q&A on Next-Gen and Web Application Firewall.
Related articles
- Next Generation Firewalls and Web Applications Firewall Q&A (paulsparrows.wordpress.com)
Stats
- 463,713 hits since November 2010
Interesting Links
News
08/13/2011 - My Post on Android Malware Mentioned on Engadget.
04/14/2011 - The Article Smart Grid: L'ultima Frontiera del Cybercrime published on ICT Security Magazine May 2011.
03/14/2011 - Security Summit 2011: Paolo Passeri guest at Round Table "Mobile Security: Rischi, Tecnologie, Mercato"
02/14/2011 - The Article Gears of Cyberwar published on ICT Security Magazine January 2011.
About This Blog
|
In this blog I express my personal opinion, which does not necessarily reflects the opinion of my organization, about events and news or interest, concerning information security, winking to mobile world and, why not, to some curious personal event. Every information is reported with its source. Anyone intending to use information contained in my post is free to do so, provided that mention my blog in your article. |
Archive
Tag
Recent Posts
Top Posts & Pages
- List Of Hacked Celebrities Who Had (Nude) Photos Leaked
- 1-15 May 2013 Cyber Attacks Timeline
- 2012 Cyber Attacks Statistics
- 2012 Cyber Attacks Timeline Master Index
- 2013 Cyber Attacks Timeline Master Index
- April 2013 Cyber Attacks Statistics
- About Me
- March 2013 Cyber Attacks Statistics
- Cyber Attacks Timeline Master Indexes
- 16-30 April 2013 Cyber Attacks Timeline
- 1-15 May 2013 Cyber Attacks Timeline hackmageddon.com/2013/05/23/1-1… #Infosec - 19 hours ago
- Apparently someone flags the Cisco Website as malicious... virustotal.com/en/url/fb74e6d… - 1 day ago
- RT @marco_cova: IE8 0-day exploit (CVE-2013-1347) analyzed on Wepawet: bit.ly/13IZs2E - 2 days ago
- RT @jc_vazquez: Vista Equity Partners to Buy Websense #News #InfoSec on.wsj.com/13BfWaw via @WSJ - 3 days ago
- Pentagon OKs Androids, BlackBerrys for soldiers nakedsecurity.sophos.com/2013/05/07/pen… - 4 days ago
- April 2013 Cyber Attacks Statistics wp.me/p14J6X-2oX - 5 days ago
- RT @LastlineLabs: Marco Cova from Lastline talking about hacktivism on Italian TV ow.ly/l8Az6 - 6 days ago
- RT @lastlineinc: Malware can make itself invisible: in the case of RSA security's breach, malware went undetected for 1/2 year http://t.co/… - 6 days ago
- RT @gianlucaSB: SMS-based command and control protocols are here ow.ly/l47Ye - 1 week ago
- Skype with care Microsoft is reading everything you write h-online.com/security/news/… - 1 week ago


