Great Circle Associates Firewalls
(July 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: proving secure -Reply
From: jgt10 @ amdahl . com (John G. Thompson)
Date: Wed, 26 Jul 1995 12:31:57 -0700 (PDT)
To: firewalls @ greatcircle . com
In-reply-to: <s015f0bc . 005 @ langate . tnet . state . tn . us> from "Samuel T. Baker" at Jul 26, 95 07:32:43 am

> >>> Marcus J Ranum <mjr @
 iwi .
 com> 12:15 25 July 1995 >>>
> [snip]
> > This is such a common misapprehension I should probably add this 
> > spiel to the FAQ:
> >"Designed to meet C2" is not the same as "evaluated at C2" ....
> I concur.  

Ditto!  

> Could you also summarize the Orange Book evalation terminology in the FAQ.

Don't bother.  The Orange book is useless for firewalls.  If anything,
look at the new federal criteria or the European Common Criteria.
Neither of these really address the issues or criteria for operating
an internet firewall.

[mjr's insightufl comments deleted]
>
> The Orange Book criteria were intended to be applied in essentially a 
> stand-alone
> environment.  Any focus on the "rainbow" documents should instead look at the Trusted
> Network criteria focusing on the Multiple Level Security (MLS) efforts which come closer
> to the problems being addressed in firewalls where the system has to service an
> unsecured, potentially hostile environment.

Even the TNI isn't real helpful.  The DOD standards where designed for a
secured physical environment (Marines and M16s) and a benign environemnt
otherwise.  

The internet is as far from that environement as you can get.
The evaluation of a product to a criteria is useful for the 
product (provided you have the time and money for it), but it
isn't going to do alot for making that product firewall ready.
It is just as easy to take a B1 evaluated OS and make it a 
bad firewall as it is a C2, C1 or D evaluated system.

JGT
firewall sysadmin and former VSA (been there, done both!)
-- 
John G. Thompson    jgt10 @
 amdahl .
 com      1-408-992-2088
Amdahl Corporation, P.O. Box 3470 MS 383, Sunnyvale, CA 94088-3470

[The opinions expressed are MINE. They do not necessarily reflect the 
policies, procedures, press releases or opionions of the Amdahl Corporation.]


Follow-Ups:
References:
Indexed By Date Previous: Re: Info about PIX
From: tbcc!bwc @ uunet . uu . net
Next: Re: established keyword vs. firewall-1 again
From: Dave Mischler <mischler @ Cubic . COM>
Indexed By Thread Previous: proving secure -Reply
From: "Samuel T. Baker" <sbaker @ mail . state . tn . us>
Next: Re: proving secure -Reply
From: Christopher Smith <chris @ deltacom . mindspring . com>

Google
 
Search Internet Search www.greatcircle.com