Today’s next-generation firewalls are “application aware” but they aren’t aware of the connectivity needs among applications. It’s common for a change in a firewall rule for one application to break the business process of another application because no one understood that the rule impacted more than one application. Tufin Software Technologies has a new tool that automates that process to maintain business continuity.
There was a time not so long ago that firewalls were used exclusively for perimeter security. Now they are commonly used to create internal network segments, or to create a perimeter around certain critical devices within a network. This shift helped to accelerate the commercialization of next-generation firewalls (NGFWs), which are “application aware.” This means a next-gen firewall has the ability to identify and control traffic at the application layer. [See “Next-gen firewalls: Off to a good start“)
As a result of a wider set of uses for firewalls, and the fact that next-gen firewalls are now common, the tasks that firewall administrators perform have changed. A recent survey conducted by Tufin Software Technologies shows that 90% of today’s firewall rules are used for connecting internal applications to each other. Firewall teams spend 80% of their time supporting these application needs.
TECH PRIORITIES: Moving to a next-generation firewall
Compounding this problem is the sheer number and frequency of changes to firewalls. Tufin’s survey revealed that 35% of firewall teams make more than 50 changes per week — and up to 50% of the changes made need to be redone. Errors in firewall configuration can lead to a security breach or a break in business continuity.
Tufin looked at this challenge from different angles and realized that the problem stems from the fact that NGFWs may be application aware, but they are not “application connectivity aware.” That is, a firewall and the people who administer it are not typically aware when a change in a firewall rule to accommodate one application may actually break another application. Allow me to use an example to show what I mean.
Let’s say a large insurance company offers different types of consumer policies: auto, homeowner, life, etc. The application that rates a consumer and generates his automobile policy is completely separate from the application that generates his homeowner policy. What’s more, the two applications are owned by different business units within the company. The insurance company wants to be able to offer the consumer a multi-policy discount. This means the two applications need to talk to each other to share information about the specific customer and to calculate the discount. This requires a rule in the firewall that enables the necessary application connectivity.
Now let’s say the department that owns the Automobile Policy application re-IPs the server it runs on. This group updates its firewall rule and everything is fine … until the Homeowner Policy application needs to connect to that server. The firewall change broke that connection and no one anticipated this until the business process was interrupted. According to Michael Hamelin, chief security architect at Tufin, this type of scenario plays out all too often these days.
The newest module in the Tufin Security Suite, SecureApp, introduces application connectivity management. Tufin focuses on firewall security policy management — tracking changes, looking for conflicts, automating trouble tickets, and now, understanding and monitoring the connections among applications.
SecureApp takes a top-down approach to mapping how applications relate to each other and the network connections they need. It’s done from a application viewpoint to help ensure business continuity. A dashboard allows an admin to view the underlying technical connections and visually see when a firewall configuration change has impacted the required linkage between applications.
SecureApp acts as a central repository for application connectivity related firewall data and also automates the process of generating service tickets for all the interconnected pieces when firewall changes are necessary. So, going back to the insurance application example, if the department that owns the Automobile Policy application needs to make a firewall change for the re-IP’d server, SecureApp would enable administrators to understand what the change should be and then trigger a ticket to create the change needed by the Homeowner Policy application. All changes would get done together so that no business processes are left broken.
This tool is also useful for commissioning and decommissioning applications and their firewall rules. According to Hamelin, nobody decommissions rules because they are afraid something might still be needed. This leaves holes in the firewall that could be exploited for attacks.
SecureApp is the third leg of the Tufin Security Suite for firewall administrators and it runs on top of Tufin’s change management product, SecureChange. SecureChange automates the change request process in a way that proactively reduces risk and enforces continuous compliance with corporate and regulatory policies. Both products rely on information provided by Tufin’s flagship product, SecureTrack, which delivers in-depth visibility and control over all of the firewalls, routers and switches on a network. It alerts about risks and compliance violations, and provides intelligence to diagnose and remediate issues before they impact the business. By adding an application connectivity-oriented front end to its suite, Tufin aims to improve communication with application owners and extend the benefits of its automation to firewall management processes that are ripe for it.
Linda Musthaler is a principal analyst with Essential Solutions Corporation. You can write to her at LMusthaler@essential-iws.com.
______________________________________________________________
About Essential Solutions Corp:
Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive. Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.




