I was surprised how many people I talked to were not aware of this specific topic so I figured I would shed some light for all.
To keep things simple, I will address the business and technical angles separately.
For those who want to skip this section, here is the high level summary:
Many of the firewalls that have been deployed in the past (and sadly even some that are deployed today) only rely on what is referred to as Stateful Packet Inspection (SPI). When CPU was expensive and bandwidth was growing, this was way better than just a router. It did all the things you expected:
What they did not do: Inspect that actual content of the packets
And in today’s world that is unacceptable.
The Internet is a place of wonders, but it is also a fairly unsafe place. Gone are the days where hackers were hobbyist that wanted to learn new systems and help their owners improve them. The so called “black hat” hackers are now using their talent for profit and it is becoming a huge industry. Although many organizations are not necessarily targets (this is becoming less and less true), many attacks today just aim for everyone. It is just a game of numbers, even you have a %0.001 percent success rate, targeting 100 million people still gives you 1,000 successes. A good example of this is ransomware (read my previous post here for more details).
So a firewall today needs to do a lot of things:
And that is the just the minimum, some of the things you should also be looking for:
And here is my favorite of all: configure it properly! (I am still shocked how many environments we walk in that bought the right equipment, but all the goodies are turned off).
Side note: a comment I hear often: “I don’t need anti-virus on my firewall, I have it on my PCs”, you should have both!!! If there is a bad wolf trying to get in your house while your sleeping, do you prefer that it gets stops at the front door and that worst case scenario if it gets in it will be stopped by your bedroom door, or do you just leave the front door open and hope that all the bedroom doors are closed?
If you want to learn more, here is a website that does a great job at going into more details of SPI vs DPI.
http://www.sans.edu/research/security-laboratory/article/pirc-john-firewalls
In this case, justifying the investment can be harder: you are investing against an intangible risk. But, if you look at it the other way around you are ensuring to keep your company in business and are ensuring predictable costs (no unexpected spend to clean up the environment or restore your reputation). Think of it as insurance against the wild wild west that the Internet is becoming. The good news is that you can verify how leaky (or not!) your firewall is through a security assessment. Here are a couple of statistics to help you make a business case:
I also wanted to provide a couple of scenarios we see commonly and provide some options.
The important point is to view the problem from the right angle, it is not about “can you afford the security you know you need” it is “can you afford not to have the security you know you need”.
As always, please post comments below and reach out to me if you have any questions or want to schedule an assessment.
Loïc