Home > Ask the Networking Experts > Network security with Puneet Mehta Questions & Answers > Without an application-layer firewall, do I run network security risks?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

Without an application-layer firewall, do I run network security risks?

Puneet Mehta EXPERT RESPONSE FROM: Puneet Mehta

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 11 November 2007

What risks will I run by not implementing an application-layer firewall? Am I leaving myself wide open by not using an application-layer firewall?


>
EXPERT RESPONSE

Application-layer filtering firewalls are required to protect networks from modern attackers because attackers now focus their efforts on developing exploits against weaknesses in the services they attack. Since the application layer is the least protected layer, attackers use a variety of application-specific exploits and target the known and unknown weaknesses in server services in order to take control. For example: Stateful inspection firewalls just don't detect worms that are injected as a malicious code within the protocols, since they only look at network-layer packet headers. Worms require a deep inspection for identifying the signatures and the stream to that particular session to analyze the content. An application-layer filtering firewall is able to examine the application-layer commands and data to determine whether the content or commands being sent to a server on the corporate network fall outside the bounds of valid connection attempts.

Another good example of the application layer-risk is buffer overflow attacks against server services. This is one of the most common methods attackers use to disable a network service and potentially take control of the server running the network service. For instance, to initiate an attack, the attacker can craft a packet containing oversized SMTP commands and then send them to an SMTP mail server. If the mail server implementation has a known or unknown buffer overflow weakness, the attack could disable or take over the server. An application-layer firewall is capable of filtering the SMTP traffic and blocks the buffer overflow attempt at the firewall itself, preventing the attack to get past the firewall.


Sound Off! -   Be the first to post a message to Sound Off!


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network security with Puneet Mehta
To simulate voice over IPSec VPNs which simulators work?
How to set passwords on folders in Windows 2003 servers
What commands allow network traffic to pass through PIX firewalls?
For an SMB firewall, what features should I look at?
Can users on my LAN view my computer from other machines?
Does a firewall need two static IPs for port forwarding?
What is layered defense approach to network security?
What is FEC in MPLS?
How can I secure VoIP conversations using free softphone?
What are TCP Wrappers? How do they work?

Network Security Best Practices
Securing the new network architecture: Security for distributed, dynamic networks
How to set passwords on folders in Windows 2003 servers
What are the best methods for handling rogue access points?
How to configure Windows Server 2008 advanced firewall MMC snap-in
Governance, compliance, security: How are these network problems?
Holidays are over; now beware the gadgets
Prevent unauthorized USB devices with software restriction policies, third-party apps
Introduction to firewalls: Types of firewall
Network firewall know-how: Avoid network latency while protecting your network
Firewalls for network security and auditing

Network Security Products
Securing the new network architecture: Security for distributed, dynamic networks
What is data loss prevention? -- An introduction to DLP
To simulate voice over IPSec VPNs which simulators work?
Is my firewall setting preventing wireless network guest access?
How to configure Windows Server 2008 advanced firewall MMC snap-in
How to retrieve passwords from locked laptops
How to interpret test scan results to assess network vulnerability
What commands allow network traffic to pass through PIX firewalls?
For an SMB firewall, what features should I look at?
Creating Remote Access and Site-to-Site VPNs with ISA Firewalls: from 'The Best Damn Firewall Book Period, Second Edition'

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
anti-replay protocol  (SearchNetworking.com)
dynamic packet filter  (SearchNetworking.com)
HELLO packet  (SearchNetworking.com)
packet filtering  (SearchNetworking.com)
rule base  (SearchNetworking.com)
stateful inspection  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsWebcastsWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts