[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference noted::seal

Title:SEAL
Moderator:GALVIA::SMITH
Created:Mon Mar 21 1994
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:1989
Total number of notes:8209

1784.0. "what info application-level: contextual data provide?" by TENNIS::KAM (AltaVista Software 714/261-4133 DTN 535.4133) Sat Feb 08 1997 12:14

    According to the Internet Firewalls: A White Paper -
    
    "Proxies operate at the application-level, rather than at the network
    level.  This allows the proxies to examine all of the contextual data
    in a packet.  In effect, the proxy examines the content of the packet. 
    By examing all the data packets for each connection, the proxies give
    the firewall much more information about the connection. ..."
    
    I know it can tell Source Port, Destination Port.  I assume that the
    only additional beneficial thing it can do is to ensure that the
    checksum is correct.  I know it can't tell what this piece of data 
    will do since it's only a piece of a puzzle.  It would need to gather
    and store all the pieces to determine if it's a virus or something
    destructive.
    
    Anyone know what else it can do by examining the contextual data?
    
    	Regards,
    
T.RTitleUserPersonal
Name
DateLines
1784.1EEMELI::EINAMOMon Feb 10 1997 02:0721
>   This allows the proxies to examine all of the contextual data
>   in a packet.  In effect, the proxy examines the content of the packet. 
>   By examing all the data packets for each connection, the proxies give
>   the firewall much more information about the connection. ..."

Every time I say this to customer I feel like I am laying ... because 

when I say "proxy examines the content of ..." the next question from customer
is ... yes like virus scaning java / active-x alerts and mail-snoopping by
context and virus cheks for mail-extentions .... cool

When I try to examine that for virus scanning you need to collect all packets 
to do real virus check the customer say that --- lets do it on packet level and
drop the conection as soon as virus is detected ... sure you can do that.

We are loosing markets for gauntlet,firewall 1 here

MARKO