XML Firewalls – Stopping Attacks at the Top of the Stack

Opinion
Aug 27, 20091 min

XML Firewalls - Stopping Attacks at the Top of the Stack

XML firewalls are an important component in implementing a secure parameter in today’s XML-laden world. After more than a decade since its incipience, XML has become a fact of life; however, it is notoriously verbose, relatively costly to process, and it opens up many new attack vectors. Surprisingly, many engineers and IT pros have not deployed or worked with this type of gateway and are unaware of the benefits and capabilities they provide. These defensive devices are akin to the low-level firewalls that we are all familiar with except that they scan entire messages at the top of the stack, in the application layer rather than packets at the IP layer. This is an important difference because, as many, including Scott Charney, VP of Trustworthy Computing at Microsoft, said at RSA earlier this year, attacks are happening in increasing numbers at this level not further down where they’ve traditionally taken place. Read the complete post on Tek-tips