Two research studies have shown there is a direct correlation between firewall rule set complexity and the likelihood of configuration errors. One study shows most firewalls are badly configured and use “very lax rules that constitute gross mistakes.” Could yours be among them?
Firewalls have to be the unsung heroes of every network. Practically every company connected to the Internet uses firewalls as the first line of defense. Despite the deep faith we place in them to keep bad things out (and good stuff in), these devices are only as strong as the policies (or rule sets) they are asked to enforce. In many instances, those rule sets are so complex that the firewalls are actually less effective than we’d like them to be.
Two classic studies, one in 2004 and the follow-up in 2009, have shown that there is a direct correlation between the level of policy complexity and the likelihood of configuration errors.
VULNERABILITY: Firewall security issue raised in report ignites vendors’ ire
The 2009 study, “Firewall Configuration Errors Revisited,” was conducted by Avishai Wool of the School of Electrical Engineering at Tel Aviv University. Wool is also the chief technology officer of the firewall analyzer company AlgoSec. In his research, Wool studied 84 rule sets from Cisco and Check Point firewalls owned by organizations that wanted an audit of their firewall rule set and that deployed software to do the analysis.
Wool drew two major conclusions from his research. No. 1: For the most part, firewalls are badly configured. No. 2: The complexity of the rule set matters; a small rule set is the best way to go.
He cites a few examples of poor configurations from his test bed:
• In the inbound direction, more than 45% of the firewalls allowed DNS, or FTP, or SMTP to reach more than 256 addresses. Also, 42% of firewalls allowed inbound NetBIOS traffic.
• In the outbound direction, more than 80% of the firewalls allowed broad outbound SMTP access.
• More than 60% allowed outbound peer-to-peer traffic — a service which rarely has a business use.
• More than 60% of firewalls have rules of the form “from somewhere to Any allow Any service.”
In Wool’s words, these are “very lax rules that constitute gross mistakes.”
Complexity is the big issue. According to Wool’s report, very few highly complex rule sets are well configured, and they are difficult to manage effectively. “It’s safer to limit the complexity of a firewall rule set,” he says. “Instead of connecting yet another subnet to the main firewall, and adding more rules and more objects, it seems preferable to install a new, dedicated firewall to protect only that new subnet.” His research results also suggest that “using multiple small (virtual) firewalls is likely to be more secure than a single large firewall.”
So last week I talked to Wool and asked him what best practices he would advise for firewall management. He says it comes down to three steps:
Step 1: Develop awareness. Recognize that the problem of managing your firewalls is costing you time and money and it may cause compliance issues if your business falls under mandates like PCI or SOX. The unnecessary complexity means it takes longer to conduct audits and perform security reviews. Realize that there are products that can help you analyze your firewalls and get your rule sets back under control.
Step 2: Decide what aspect of the problem is most urgent. You might declare that the situation is so bad you have to do a big cleanup. Or maybe you want to deploy a workflow system. Sometimes there are issues when migrating from one vendor’s firewall to another. Whatever the situation, pick an area to tackle and get after it.
Step 3: Use tools to automate the process of addressing your issues. There are many firewall tools that can analyze your rule set and look for conflicts, redundancies and mistakes. Firewall maintenance has to be an ongoing process. Wool says the human mind can really only understand about one page of rules. When the rule set gets longer than that, it time to deploy tools that automate the change process.
Check out Avishai’s report from his 2009 study to see the most common configuration errors. Download the report from the Cornell University Library website.
Firewalls are the workhorses of every network. If your firewalls have been “rode hard and put up wet” (as we say in Texas), then it’s time to give those horses a little tender loving care to get them back under control.
Linda Musthaler is a principal analyst with Essential Solutions Corporation. You can write to her at LMusthaler@essential-iws.com.
Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive. Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.




