Sunday | 23 November, 2008
Networking's greatest debates in Security
Classic debates include Immediate flaw alerts vs. Disclosing with patches, IDS vs. IPS and Perimeter security vs. inside security
Staff Writers (Network World) 29/10/2007 08:05:00

Perimeter security vs. inside security

When businesses began hooking up to the Internet in earnest in the late 1980s, it was with a sense of trepidation and awe, knowing an unprecedented public interaction was commencing. In the hope of holding dangers at bay, the bastion firewall emerged as the fortress guard, thanks to technology innovators such as Marcus Ranum and Bill Cheswick. Early commercial firewalls, including Digital Equipment Corp.'s SEAL, meant enterprises would no longer have to roll their own.

The perimeter firewall has become a fixture, the point of demarcation where specialists lavish attention on complex security rules to define permitted inbound and outbound traffic. But 20 years later, the role of the Internet firewall and similar perimeter defense has come under sharp question by a growing number of security managers who base their arguments on one simple point: the perimeter has disappeared.

The demands of e-commerce to access internal systems, collaboration with outsourcing partners, the mobile laptops and computer-based handhelds carried by business people to the ends of the earth - these all contribute to the "disruptive change," argues Paul Simmonds, chief information security officer at U.K.-based chemicals and paint manufacturer ICI.

"Your security perimeter is disappearing," notes Simmonds, energetic supporter of the Jericho Forum, the group founded by corporate information security managers in early 2004 to encourage the development of more innovative data-centric approaches to enterprise security that reflect today's malleable business situation. "What we're architecting at the Jericho Forum is not an individual solution, a single fix. We call it a collaboration-oriented architecture."

Jericho Forum now has about 45 members, mostly large European firms but with more U.S.-based ones joining these days.

One of Jericho Forum's favored terms is "de-perimeterization" (the British spell it with an 's' not a 'z') and while the group doesn't specifically advocate doing away with perimeter firewalls, its critique of them as a barrier to e-commerce has at times elicited strong opposing opinions that the group's views are wrong-headed, misguided or naive.

"At best, Jericho will help raise awareness of the usefulness of a defense-in-depth network security strategy," stated Joel Snyder, senior partner at Opus One and a member of Network World's Lab Alliance, writing about the group two years ago. "More likely the Forum will end up on the scrap heap of unrealized ideas and wasted effort." Snyder says his opinion that some of the Forum's thinking is "moronic" is no different today.

Firewall innovator of legend, Cheswick, lead member of technical staff at AT&T Research, acknowledges it's appealing to consider a world where corporate security doesn't rely on perimeter defense. But in his keynote presentation at the Jericho Forum meeting in New York last September, Cheswick said the limitation in foregoing perimeter defense is that "you won't stop a [distributed denial-of-service] attack, so we may still need a walled garden."

Nonetheless, the Jericho Forum soldiers on with its work to convince enterprises and vendors alike to think outside the perimeter box. "De-perimeterization for most corporations is a fact of life," Simmonds points out. "For most corporations, it's happening whether you like it or not." -Ellen Messmer

Read Networking's greatest debates in Software
Read Newtorking's greatest debates in the Data Center
Read Networking's greatest debates in Management
Read Networking's greatest debates in LANs and WANs

Computerworld Buyer's Guide - Vendors Matched to this Article
Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15

    Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
    Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
  • +

    Toxic Mix or Bit of a Mixed Blessing? 31/12/2007 10:36:30

    “Eye of newt, and toe of frog, Wool of bat, and tongue of dog . . . ” The inter-generational office brew of Boomer, Gen X and Gen Y may not be quite as odious as that of the three witches in Shakespeare’s Macbeth, but even so it makes “for a charm of powerful trouble”
    "Eye of newt, and toe of frog, Wool of bat, and tongue of dog . . . " The inter-generational office brew of Boomer, Gen X and Gen Y may not be quite as odious as that of the three witches in Shakespeare's Macbeth, but even so it makes "for a charm of powerful trouble"
  • +

    Strategies for Dealing With IT Complexity 24/12/2007 10:30:47

    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Sign up for our Computerworld newsletters!
RSS Feeds
Market Place

 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Solve Exchange Mailbox Storage Issues Once and for All

Join industry expert Bob Spurzem and Chuck Arconi of Fox Hollow to discover how to reduce Exchange total storage and keep it at a manageable level. Learn how Exchange storage growth can be contained without sacrificing security and accessibility.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links