martin_roesch
VP and chief architect, Cisco's Security Business Group

Advanced Firewalls, part 2

Opinion
Oct 31, 20132 mins

The integration of IPS functionality and threat intelligence

The firewall has served as a primary barrier between a company’s IT assets and the outside world for many years. In our last video, we examined some of the major advancements that have been incorporated into advanced firewalls over the last few years, including more granular application and user-level controls. These controls allow firewalls to more effectively restrict unnecessary or risky application usage, ultimately reducing the attack surface.

To further broaden the functionality of advanced firewalls to confront application-layer exploits along with the attacks that have long targeted networks, advanced firewalls have also adopted some threat-centric functionalities.

The first of these functionalities is intrusion prevention system technology, commonly known as IPS. This critical element enables advanced firewalls, or next-generation firewalls (NGFW), to detect and block networks attacks. Some NGFWs, when incorporating IPS functionality also provision real-time network visibility of hosts, applications, operating systems, users, content, and attacks.

The other functionality to protect against newly discovered threats is the use of threat intelligence research. This research, carried out by NGFW vendors, must understand emerging threats and be quickly translated into effective vulnerability-based protections in an NGFW that detect and block the myriad vulnerabilities and exploits that emerge daily.

In our next video Chalk Talk, we’ll discuss the evolution of malware.

Did you miss our first episode? Watch Part 1 here.

martin_roesch
VP and chief architect, Cisco's Security Business Group

Martin Roesch founded Sourcefire in 2001 where he was Chief Technology Officer (CTO) and a member of its Board of Directors. He is now vice president and chief architect for Cisco's Security Business Group. For more than a decade, Roesch has dedicated himself to developing intelligent network security tools and technologies to address evolving threats, applying his knowledge of network security to network threat analytics and network forensics for numerous government and multinational customers. A respected authority on intrusion prevention and detection technology and forensics, he is the author and lead developer of the Snort Intrusion Prevention and Detection System (www.snort.org) that forms the foundation for the Sourcefire Next-Generation IPS. For more than a decade, Roesch has dedicated himself to developing intelligent network security tools and technologies to address evolving threats, applying his knowledge of network security to network threat analytics and network forensics for numerous government and multinational customers. Roesch holds a B.S. in Electrical and Computer Engineering from Clarkson University.

More from this author