Skip Links

Network World

  • Social Web 
  • Email 
  • Close
Networking's 50 greatest arguments. A look at the all-time greatest controversies in the history of the network industry
Data Center Management LANs & WANs Security Software Wireless Top 10 lists

Perimeter security vs. inside security

Role of Internet firewall comes into sharp question
By Ellen Messmer , Network World , 10/26/2007
  • Share/Email
  • Comment
  • Print

When businesses began hooking up to the Internet in earnest in the late 1980s, it was with a sense of trepidation and awe, knowing an unprecedented public interaction was commencing. In the hope of holding dangers at bay, the bastion firewall emerged as the fortress guard, thanks to technology innovators such as Marcus Ranum and Bill Cheswick. Early commercial firewalls, including Digital Equipment Corp.’s SEAL, meant enterprises would no longer have to roll their own.

The perimeter firewall has become a fixture, the point of demarcation where specialists lavish attention on complex security rules to define permitted inbound and outbound traffic. But 20 years later, the role of the Internet firewall and similar perimeter defense has come under sharp question by a growing number of security managers who base their arguments on one simple point: the perimeter has disappeared.

The demands of e-commerce to access internal systems, collaboration with outsourcing partners, the mobile laptops and computer-based handhelds carried by business people to the ends of the earth — these all contribute to the “disruptive change,” argues Paul Simmonds, chief information security officer at U.K.-based chemicals and paint manufacturer ICI.

“Your security perimeter is disappearing,” notes Simmonds, energetic supporter of the Jericho Forum, the group founded by corporate information security managers in early 2004 to encourage the development of more innovative data-centric approaches to enterprise security that reflect today’s malleable business situation. “What we’re architecting at the Jericho Forum is not an individual solution, a single fix. We call it a collaboration-oriented architecture.”

Jericho Forum now has about 45 members, mostly large European firms but with more U.S.-based ones joining these days.

One of Jericho Forum’s favored terms is “de-perimeterization” (the British spell it with an ‘s’ not a ‘z’) and while the group doesn’t specifically advocate doing away with perimeter firewalls, its critique of them as a barrier to e-commerce has at times elicited strong opposing opinions that the group’s views are wrong-headed, misguided or naïve.

“At best, Jericho will help raise awareness of the usefulness of a defense-in-depth network security strategy,” stated Joel Snyder, senior partner at Opus One and a member of Network World's Lab Alliance, writing about the group two years ago. “More likely the Forum will end up on the scrap heap of unrealized ideas and wasted effort.” Snyder says his opinion that some of the Forum’s thinking is “moronic” is no different today.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (1)
Login
Forgot your account info?

RE: Perimeter security vs. inside securityBy tkopczynski on October 30, 2007, 2:14 pmThe context of what a perimeter is changing as organizational boundaries become dispersed across the internet. In other words, as more and more businesses adopt...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed