Great Circle Associates Firewalls
(November 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: ActiveX and Risks
From: Rick Murphy <rick @ tis . com>
Date: Fri, 22 Nov 1996 16:09:17 -0500
To: ""A. Ömer Köker"" <omer @ superonline . net>
Cc: "'Ken Hardy'" <ken @ bridge . com>, "'Russ . Cooper @ rc . on . ca'" <Russ . Cooper @ rc . on . ca>, "'firewalls @ greatcircle . com'" <firewalls @ greatcircle . com>

At 10:37 PM 11/22/96 +0200, A. Ömer Köker wrote:
>Now if your going to scan the <B>html tag</B> for every single document
>checking for java, activex, and various scripts this will be a great
>strain on the system.  Wont this at a certain point result in "over
>logging" with a ping-o-death kind of result?
Given a reasonable design - that is context sensitive about what's permitted
at a given point - you don't need to add very much overhead to perform
the scanning. One side effect of the redesign of our HTTP proxy to allow
this context sensitivity was that the performance improved dramatically.
(The older code was not context aware and was thus forced to read and write
HTML a byte at a time. The new stuff can read and write in much larger chunks
without breaking the protocol.)

> Also what about live
>mail, that is html included mail coming in over SMTP and not HTTP ?

We do this *only* for HTML fed through the http proxy. We don't have any form
of mail filtering for Java/ActiveX/etc.
	-Rick


Indexed By Date Previous: RE: ActiveX and Risks
From: "A. Ömer Köker" <omer @ superonline . net>
Next: RE: ActiveX and Risks
From: Ken Hardy <ken @ bridge . com>
Indexed By Thread Previous: RE: ActiveX and Risks
From: "A. Ömer Köker" <omer @ superonline . net>
Next: RE: ActiveX and Risks
From: Ken Hardy <ken @ bridge . com>

Google
 
Search Internet Search www.greatcircle.com