Content Filtering Summary
Table 4-20 shows the summary scores for the content-filtering options.
|
Attack Element |
Proxy Server |
Web Filtering |
E-Mail Filtering |
|
Detection |
0 |
0 |
0 |
|
Attack Element |
Proxy Server |
Web Filtering |
E-Mail Filtering |
|
Prevention |
39 |
81 |
79 |
|
Bypass |
3 |
3 |
4 |
|
Ease of networking implementation |
4 |
4 |
5 |
|
User impact |
2 |
1 |
5 |
|
Application transparency |
1 |
4 |
4 |
|
Maturity |
4 |
3 |
4 |
|
Ease of management |
3 |
4 |
4 |
|
Performance |
2 |
1 |
4 |
|
Scalability |
3 |
1 |
4 |
|
Affordability |
4 |
3 |
3 |
|
Overall |
43 |
53 |
69 |
Because the ratings in this chapter are skewed toward threat prevention, the overall ratings for the content filtering technologies are lower than other sections. E-mail filtering has a clear security benefit, as do portions of web filtering (mobile code). Proxy servers perform more as a user control function than they do in a security role, so the rating results are expected.
In your own environment, the deployment of these technologies is primarily about policy enforcement. If your security policy dictates that user access to the World Wide Web should be authenticated and controlled and likewise that all e-mail messages should be scanned for viruses, you probably must deploy all three technologies, regardless of their ratings. If, however, user authentication and control is not required, you might deploy only e-mail filtering and leave the caching to network-based cache systems, which don't require user configuration to access.
Continue reading here: Disable Unneeded Services
Was this article helpful?