QKS Logo
QKS Library Icon

QKS Library

NewsroomSPARK Plus™Sign In
QKS Logo

22.05.2024

QKS Insight

We need Firewalls, (and some more)

Author:

Venkatesh Kopparthi

backgroundImage
FolderIcon

A recent webinar by Stephen Goudreault, Cloud Security Evangelist at Gigamon, titled "Why Firewalls Are No Longer Enough” explored the evolving threat landscape and how firewalls, while crucial, need to be complemented by a layered security approach. Here is a gist of a very insightful discussion:

Stateful firewalls were developed at a time when organizations had a single internet connection and external access required knowing internal IP addresses. These firewalls allowed legitimate outbound traffic and blocked uninvited inbound traffic. These firewalls were also built for perimeter defense and focused solely on external threats.

However, network complexity has increased, and more and more networking services, like routing protocols and VPNs, are being integrated with firewalls. The webinar listed the challenges arising due to the firewalls:

  • Limited Application Visibility: Firewalls only see traffic at the network level and provide no visibility into application activity.
  • Zero-Day Vulnerability Reliance: Firewalls with IPS (Intrusion Prevention System) integrations rely on known threat signatures, leaving them vulnerable to zero-day attacks.
  • BYOD Challenges: Bring-Your-Own-Device (BYOD) policies complicate firewall security measures.
  • Attacker Sophistication: Advanced attackers can cover their tracks before hitting the firewall's inspection point and exploit blind spots within the network.
  • EDR Limitations: Endpoint Detection and Response (EDR) can detect lateral movement post-attack, but this reactive approach offers little real-time protection.
  • Firewall Vulnerabilities: Firewalls themselves can be security weaknesses with some cases of firewalls being the source point of breach.
  • Cloud Firewall Limitations: Cloud firewalls, with broader resource access than traditional firewalls, often require additional security measures due to increased attack opportunities.

However, firewalls remain essential for perimeter defense. Thus, a layered security approach is necessary. The webinar highlighted several strategies towards the same:

  • Microsegmentation: Limiting the attack radius by segmenting the network into smaller zones.
  • Cloud Security Posture Management (CSPM): Continuously monitoring and managing cloud security configurations.
  • East-West Visibility: Gaining deep insights into internal network traffic (East-West traffic) to identify suspicious activity.
  • Application Visibility: Understanding application behavior to detect anomalies and potential threats.
  • Security Tool Integration: Combining firewalls with other security tools like firewall at the perimeter level, EDR for endpoint security, NDR for network security, and SIEM for monitoring offers better security.
  • Proactive Security: Shifting from reactive threat detection to proactive vulnerability management.

Conclusion

Firewalls are a fundamental security component, but they're no longer the sole line of defense. Organizations can build a more robust security posture and effectively combat today's sophisticated threats by adopting a layered security approach that combines firewalls with East-West visibility, application awareness, and integrated security tools.

Author: Venkatesh Kopparthi, Analyst at Quadrant Knowledge Solutions