Application Layer Filtering
Application proxy firewalls are the most intelligent firewall architecture. By intelligent, we mean that an application proxy firewall can perform the most detailed inspection on data before making a filtering decision. An application proxy firewall can decode and process at the application layer the data contained in packets. Consequently, application proxy firewalls can filter based on the actual application data content. For example, with a packet-filtering firewall, the firewall can merely permit or deny traffic based on data such as the IP protocol in use. So a packet-filtering firewall merely knows whether it should permit or deny HTTP
traffic, for example, and processes the traffic accordingly. With an application proxy firewall, however, it not only knows whether it should permit or deny HTTP traffic, it can also be configured to filter based on the type of HTTP traffic. Such a configuration allows an application proxy firewall to interrogate the data and identify malicious web traffic, such as being able to distinguish between normal HTTP traffic and Code Red HTTP traffic, and filter accordingly. This capability gives firewall administrators a tremendous amount of flexibility and control over exactly what traffic will and will not be permitted.
Continue reading here: How Application Filtering Works
Was this article helpful?
Readers' Questions
-
BROOKLYN7 months ago
- Reply