Microsoft: Firewalls are failing to keep out hackers

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Speaking in London on Monday at a technical briefing on the need for next generation firewalls, Microsoft security technology architect Fred Baumhardt outlined some of the gaps that traditional firewalls are leaving open.

"We are all bloody lucky that something hasn't obliterated IT on earth," said Baumhardt. "Firewalls are like retarded routers. They just look at the ports, sources and destinations they like. If a train comes from Gare du Nord [Paris] to Waterloo [London] via Eurostar you allow it to enter the country because you trust it. That's what firewalls currently do. They don't check to see if al-Quaeda is riding inside."

Ports allow certain types of Internet traffic to travel if they correspond with the correct port number. For example, HTTP runs on port 80 and is often regarded as a trusted port, and left open. In the past firewalls have often worked on this basis, without checking the content of traffic. But Baumhardt called for IT professionals to ensure they had better equipment.

"I don't care which vendor you get it from," he said. "I just want to see [next generation firewall] technology in front of your network."

Baumhardt was demonstrating Microsoft's Internet Security and Acceleration (ISA) Server 2004. He said that traditional firewalls were failing to scan Internet traffic deeply enough to detect malicious traffic.

"We trust traffic on ports that we think it should be on," said Baumhardt. "But when you do that you relay control to the security vendor. You need to understand the traffic you are trying to block."

Baumhardt gave the example of how many hackers use port 80 to enter a network because it is treated as trusted traffic. He added that it was also important to protect the network internally, not just at the perimeter.

"We don't place devices to protect from within the internal network. But if you don't put firewalls on chokepoints [critical areas in the network] you won't defend your internal network."

The latest version of ISA Server has the ability to run 1.9-gigabit throughput, said Baumhardt, and to scan port traffic at the application layer, which could lead to better transparency. He said it also offers VPN and port scanning technology.

But Baumhardt added that it was unwise to use firewalls without the support of other security technology: "Believe it or not, Microsoft is not the be-all and end-all of everything. We could be a platform for other things to run on. You buy ISA so that you can complement it with SurfControl or McAfee."

Talkback

Obliteration of IT? Al-qaeda? Nothing like a bit of scaremongering hyperbole is there?

So firewalls aren't the be-all and end-all of security. Well done, MS, welcome to the world the rest of us have been in for years.

Perhaps if Microsoft locked their products down to start with we'd all be better off.

via Facebook 5 October, 2004 13:55
Reply

If Microsoft did produce a "smart firewall" like this, it would just be another excuse for the security of the end applications, like Microsoft IIS server, to suck even more than they do now. Maybe if they wrote decent apps in the first place they wouldn't have to worry so much about malicious traffic.

via Facebook 5 October, 2004 19:37
Reply

Use encryption (openssh, https) and his next step is gone. The idea of a firewall is not to provide absolute, but just to make it harder, rather like how even glass windows, and hollow-core dores keep nearly 100% of all theives away.

via Facebook 6 October, 2004 14:55
Reply

I saw this presentation - and the quotes are out of context. Microsoft is talking about having intelligence at the network level - not replacing it anywhere else, Fred made a good point when he said that its not about companies anymore - as soon as HTTP filters come online people will switch to encryption - someone will also need a way to inspect outbound encryption to help eliminate these vectors - if you think Microsoft are insecure, wait until Linux takes off (and it will) as soon as hackers see its now worthwile to attack them (cuz now there arent enough to bother with) - we will go through the same process again. Networks make a good place to filter - the body filters viruses in the bloodstream - why cant we as an industry ?

via Facebook 6 October, 2004 16:24
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

1 hour ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

3 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

8 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

11 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

11 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

12 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

13 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

14 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

14 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

14 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

15 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

15 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

15 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

15 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

16 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

19 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

20 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

20 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

21 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

22 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule