Great Circle Associates Firewalls
(March 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Cooking a firewall benchmark...
From: mdr @ vodka . sse . att . com
Date: Thu, 21 Mar 1996 16:51:30 -0500 (EST)
To: peter @ nmti . com (Peter da Silva)
Cc: firewalls @ greatcircle . com
In-reply-to: <9603201515 . AA29790 @ sonic . nmti . com . nmti . com> from "Peter da Silva" at Mar 20, 96 09:15:57 am

In regards to filtering for viruses and data based security problems:

This is all interesting stuff.  I remember reading recently that 
virus checkers on the PC are faced with a similar detection problem
with respect to stealth viruses.  One vendor claims that their virus
detector simulates execution of the program that is being scanned to
discover viruses as they unencrypt themselves.  I'm not sure how they
handle viruses that unencrypt on the third invokation or only on
thursdays etc.   The problem is really difficult.   Whenever you "fix"
security problems in one layer of the hierarchy they reappear at a
higher level.  Viruses in Word macros are an example of that.

Lately I've been seeing more holes in the security dike than I can plug.
Frankly I'm running out of fingers and toes.

A things are getting nastier faster lately or is it just my
perception?

W.r.t Java's virtual machine.  The idea has merit.  Theoretically, one
could monitor the applet as it is interpreted, basically adding
another layer of security.  The problem lies in defining unacceptable
behaviour (or its complement) and correctly implementing the VM.  So
far all of the Java security problems that I have heard of were
problems with the implementation, not with the design.  Does anyone
see a fundamental problem with Java's security model?

Mark Riggins
Secure Systems Engineering
AT&T Bell Labs




Follow-Ups:
References:
Indexed By Date Previous: Re: Dos based Firewalls
From: mdr @ vodka . sse . att . com
Next: Re[2]: Firewall organizational opinions?
From: Don_Tompkins @ esd . tracor . com
Indexed By Thread Previous: Re: Cooking a firewall benchmark...
From: peter @ nmti . com (Peter da Silva)
Next: Re: Cooking a firewall benchmark...
From: Scott Barman <scott @ di2 . disclosure . com>

Google
 
Search Internet Search www.greatcircle.com