Host Based Firewalls

Table 4-10 shows the summary information for host-based firewalls.

Table 4-10. Host-Based Firewalls

Readers' Questions

  • Maria
    Which of the following are elements of host hardening?
    8 months ago
    1. Install and configure antivirus software
    2. Disable unnecessary services
    3. Implement file system access control lists
    4. Harden network protocols and encryption
    5. Regularly patch operating system and software
    6. Restrict physical access to host systems

    Name

    Host-based firewalls

    Common example

    IPFilter

    Attack elements detected

    Probe/scan

    Attack elements prevented

    Direct access Remote control software

    Difficulty in attacker bypass

    2

    Ease of network implementation

    2

    User impact

    2

    Application transparency

    1

    Maturity of technology

    2

    Ease of management

    1

    Performance

    4

    Scalability

    2

    Financial affordability

    3

    Overall value of technology

    51

    Host-based firewalls are also commonly called personal firewalls when run on a client PC. They are exactly what their name describes: a firewall running on a host configured to protect only the host. Many host-based firewalls offer IDS in the form of rudimentary application checks for the system they are configured to protect.

    Trying to maintain these firewalls on all client PCs or even just on critical systems is operationally burdensome. Organizations have enough trouble managing firewalls when they exist only at security perimeters. Like network firewalls, host firewalls are only as good as their configuration. Some firewalls have wizards to aid in configuration; others ask the user to select a default posture such as default, cautious, or paranoid.

    As the configuration of a host firewall increases in security, the impact on the host increases as well. This is particularly true with user PCs, which often have lots of applications running. One popular firewall prompts the user when an unknown application attempts to access the network. Often, though, the application is referenced using an obscure system file rather than the name of the application. This can confuse the user, who might make an incorrect choice, causing failures on your system and an increase in calls to your support center.

    Host firewalls are getting better over time and will become more viable as their manageability increases. Many modern OSs ship with firewall software built-in; often it is basic in its function, but that also reduces the chances of user error. With today's technology, it is best to stick with basic firewall configuration for user PCs (for instance, allowing any outbound traffic but not allowing any inbound traffic). Deploy host firewalls on server systems only when it is significantly adding to the security of that host.

    For example, if you already have a network firewall in front of some servers, adding a host firewall might improve security slightly, but it will increase the management requirements significantly. If, on the other hand, a system must be out in the open, a host firewall could be a good option. In the design sections of this book, you will see certain cases in which a host firewall makes sense to deploy. Timely patching and host hardening do more to secure a host than a firewall does, so never consider a firewall as an alternative to good system administration practices. Host firewalls should augment basic host security practices, not replace them.

    Continue reading here: Hids

    Was this article helpful?

    0 0