Great Circle Associates Firewalls
(March 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: WinNT and C2
From: Leonard Miyata <leonard @ geminisecure . com>
Date: Thu, 13 Mar 1997 09:49:31 -0800 (PST)
To: Michael S Hines <mshines @ purdue . edu>
Cc: firewalls @ GreatCircle . COM
In-reply-to: <3327fa8c16ea002 @ scribe . cc . purdue . edu>

Yes, if your talking of a 'Orange Book' rating, the certification 
only involves a single isolated Host.

Microsoft is claiming the ITSEC equivalent of a 'Red Book' C2 rating
which does cover intrusions (DAC, I&A) coming over the Network.

Since the rating is only C2, the question that now needs to be asked is
'What is the limitations of DAC, I&A and Audit of WinNT' since from a 
'paranoid' point of view, C2 is really quite limited.

Personal Opinions provided by
Leonard Miyata
Gemini Computers Inc.

On Thu, 13 Mar 1997, Michael S Hines wrote:

> 
> I believe the Orange Book ratings revolve around access security and 
> activity logging - nothing at all about being proactive with some 
> means of Intrusion Detection -- is this correct?
> 
> After you have an "incident" you can see what happened...   not a lot 
> of emphasis on preventing an "incident".    Corrrect?
> 
> On the other hand, filtering routers and firewalls are designed to 
> prevent an "incident"..     
> 
> Are these views consistent?
> 
> Also, the ratings pertain to a box (configured in a particular way)
> on the network - but not an overall evaluation of any particular
> instance of a network.   Correct?
> 
> 
> -----------------------------------------------------------------
> Internet: mshines @
 purdue .
 edu    * Michael S. Hines, CDP, CFE
> Voice: (765) 494-5845           * Sr. Information Systems Auditor
> FAX:   (765) 496-1814           * Purdue University
>                                 * 1065 Freehafer Hall
>                                 * West Lafayette, IN 47907-1065
> 


References:
  • WinNT and C2
    From: "Michael S Hines" <mshines @ purdue . edu>
Indexed By Date Previous: Re: firewalls and sendmail
From: Tony Prince <tprince @ lurhq . com>
Next: VLAN security
From: Brian Betterton <brian_betterton @ INS . COM>
Indexed By Thread Previous: WinNT and C2
From: "Michael S Hines" <mshines @ purdue . edu>
Next: Re: WinNT and C2
From: "NetSurfer" <netsurf @ pixi . com>

Google
 
Search Internet Search www.greatcircle.com