Great Circle Associates Firewalls
(April 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall Failure Modes
From: matt @ zilker . net (Matt Lawrence)
Date: Wed, 26 Apr 1995 10:43:35 -0500
To: fc @ all . net (Dr. Frederick B. Cohen), firewalls @ GreatCircle . COM

At 08:00 AM 4/25/95 -0400, Dr. Frederick B. Cohen wrote:
[...snip...]
>Most of the firewall vendors and other people on this list write
>programs, never test them at the boundary conditions, and assume that
>they works properly because the code looks right to them and seems to
>work when they try it on their application.  When someone asks about
>boundary conditions, they say they have never tested it, but that they
>looked at the source code and figure it will work the same way under
>high stress conditions as under normal load conditions.  The lack of
>experimental confirmation presents no problem for the producers or
>consumers and presents no impediment to the purchase of a firewall from
>such a vendor. 

I've really go to agree with Dr. Cohen here.  Software testing in almost all
of the Unix community is woefully lax.  Even basic functionally testing is
often ignored, look at what a gibberish generator will do to most commands.
I'd really be surprised if much in the way of stress testing was happening,
in fact, I doubt if thorough functional testing is happening.

Yes, I am obsessive about this.  I once worked (briefly) on a project that I
believe would have killed people if it had ever been installed.  This was
because of the testing philosophy that too many folks had -- if we can make
it work once, it passes.  I was overjoyed when I heard the FAA had killed
the project.

-- Matt



Follow-Ups:
Indexed By Date Previous: Livingston IRX Firewall Router
From: fwall @ eng . ricohcorp . com (Firewall Subscriber)
Next: PORTUS distributor in UK
From: ted @ gw . lsli . com
Indexed By Thread Previous: Re: Firewall Failure Modes
From: James Smilanich <jsmilan @ subzero . winternet . com>
Next: Re: Firewall Failure Modes
From: Scott Barman <scott @ Disclosure . COM>

Google
 
Search Internet Search www.greatcircle.com