Search FCW


Subscribe Now!
Table of Contents
Sprint
Business
BPM
CXOs
Columns
Columnists
Defense
E-Government
Elections 2008
Enterprise Architecture
Funding
Homeland Security
Health IT
IPv6
LOB
Management
Procurement
Privacy
Policy
Program Management
State and Local
Security
Technology
Telework
Training and Certification
Workforce

More Topics
resourcecenter
Home
Letters to the Editor
Current Issue/Download
Print/Online Archives
Editorial Calendar
researchstore
resourcecenter
Communications for Continuity Operations

Oracle Resource Center
NEW - Data Center Virtualization
NEW - Air Force ELSG Contract Guide
NEW - Security Management
NEW - DOD and Security Guide
Networx Contract Guide
SEWP IV Contract Guide
Priority Report: Virtualization
NEW - CHESS formerly ASCP
New - SATCOM II

More >>


FCW.com BLOG

Latest News
ADVERTISEMENT





 
Letters to the Editor:

Letter: Fewer Internet links mean more risks

Published on December 19, 2007 - 10:13 AM

Comment

Click here to comment on this blog


Newsletters

You might also be interested in these FCW newsletters:

Daily
Security

To learn more, click here.


Regarding “OMB to limit number of Internet connections for agencies,” I am having a hard time understanding the Office of Management and Budget’s decision to decrease the number of gateway connections, especially when it is trying to frame it around security. The vast majority of attacks target the application layer and endpoints. Unless you intend to deny services, one gateway is all that is needed. Limiting connections will not only make it easier for an adversary to disrupt connectivity to a much larger segment of a network, but the spear phishing, malware, Trojan horses, viruses, worms, etc., will have a larger pool of systems to choose from through fewer connections.

I truly believe we do a fairly good job of maintaining a hard network shell in our current state, but the gooey insides make for quite the enticing treat. How easy will it be to recover from a zero-day worm sent in via a carefully crafted spear phishing exploit, which infests a network segment that used to be just a satellite office of 200 computers but is now a Class B segment consisting of 65,000 systems? Will any of this truly make a difference when a laptop computer/removable drive/thumb drive/DVD/desktop computer/personal digital assistant is stolen or a hard drive is improperly disposed of? When are we going to realize that it doesn't matter any more how good the boundary is? 

We need to start focusing on the endpoints for what they have truly become -- compromisable. Just like the old days, put the endpoints in a “demilitarized zone." Treat the systems that connect to your core services as hostile. Force all endpoints to connect to your core only via virtual private network connections that are protected by NAC devices that can enforce well-constructed policy before ever letting them have access to the core, then interlink the cores via closed networks. With interlinked cores inside a closed network, data sharing will be easier to accomplish and data can be replicated and stored at multiple locations to increase survivability. Treating the endpoints as external devices will also increase survivability because they can be relocated and re-attached from anywhere. Almost sounds like going back to the mainframe days, doesn't it?

Anonymous
Air Force

What do you think? Paste a comment in the box below (registration required), or send your comment to letters@fcw.com (subject line: Blog comment) and we'll post it.

View Comments

Cool blog Thanks, webmaster.

Posted by Ipod Nana Online on August 25, 2008 - 07:46 PM

Cool blog Thanks, webmaster.

Posted by best savings accounts us on August 26, 2008 - 12:58 PM


Post a Comment

To post a comment, you must be a registered user of FCW.com and be logged in. Use one of the forms below to login or register for FREE to FCW.com. To protect your privacy, you can use an alias as your username.

Login to FCW.com

E-mail Address:
Password:
Forgot your password?
Register and Post Comment

* First Name:
* Last Name:
* E-mail Address:
* Password:
* Retype Password:
* Blog Username:
* Comments:


E-mail me when new comments are posted in this thread?


upcoming event

Enterprise Architecture 2008 - Washington, DC
September 9 - September 10, 2008

Occupational Health & Safety Executive Summit - Arlington, VA
October 6 - October 7, 2008


 

head
fcw
issue
First Name State
Last Name Zip
Title Email