NetScreen Technologies later this year will improve its security products to help customers combat attacks disguised as innocuous traffic that might sneak by traditional firewalls.
By incorporating technology it gained when it bought OneSecure last year, NetScreen will add the ability to inspect packets at the application level to detect and thwart threats that make their way through firewall ports left open for Web traffic, for example. This will complement NetScreen’s current firewall, which protects against network layer attacks by methods such as selectively blocking TCP ports.
Adding application protection pits the company against vendors specializing in this technology such as Teros and Sanctum, and security vendors such as Symantec. NetScreen’s new firewall also follows a trend of VPN vendors toward supporting application security (see graphic, below).
“Network-layer security only takes you so far. Worms get through open ports in firewalls and masquerade as harmless traffic – instant messaging, e-mails,” says Jeff Wilson, research director for Infonetics. He says customers will have to wait for this technology to be incorporated in NetScreen gear before it can be evaluated because OneSecure didn’t have much of a track record to judge by before NetScreen bought it.
By inspecting packets more deeply than a network-layer firewall, application security identifies application sessions and looks for illicit behavior. Based on user controlled policies, suspect traffic can be dropped.
NetScreen’s firewall and VPN equipment ranges from hardware and software with 12G bit/sec firewall throughput designed for data centers to 20M bit/sec firewall/VPN appliances meant for telecommuter offices. The company last week hinted at a variety of imminent product upgrades during a briefing that was long on direction and short on product details.
The company will announce specifics about the form its application security will take by year-end, says Robert Ma, senior director of product management and marketing for the company.
NetScreen also is looking to upgrade its GlobalPro management platform to make it possible to grant different levels of access to the security gear. For example, a security auditor would have no need to alter security policies, but would need to view what those policies are, Ma says.
“It should let you do what you need to do without letting you access too much,” he says. Support for role-based access will be added with a new version of GlobalPro later this year that also will include a new user interface to make deployment easier, he says.
|
NetScreen still has no firm plans for adding Secure Sockets Layer (SSL) remote-access capabilities to its gear, Ma says. But he acknowledges that customers are asking about it because it is easier to deploy and is adequate for many remote-access needs.
“Customers definitely see a place for both [IP Security] VPNs and SSL VPNs,” Ma says. And he says SSL remote access is less costly than VPN remote access. “We are definitely looking into it,” he says.




