[Agenda]
[Examples]
[Network Partitioning]
[Concepts]
[Policy]
[Process]
[Organization]
[HW-SW]
[Cases studies]
[Conclusion]
[Resources]
Application layer controls
Network Partitioning applies security at the
network layer
with
IP filtering
IP filtering can go up to
application layer
controls
Within the same session with cut-thru proxies
Many existing filtering devices use application proxies when necessary
Application layer controls you may find
Commands within a protocol
GET vs PUT in FTP
Databases SELECT in SQLNet
Fields size in SMTP
Data type
Word document, Java mobile code, ActiveX mobile code
Content-filtering
Hidden mobile code: Javascript in HTML, macros in Word, Excel, etc
XML Signature
Virus detection
® ©
Hervé Schauer Consultants
December 1999 - 142, rue de Rivoli - F-75001 Paris - France
Phone: +33 141 409 700 - Fax: +33 141 409 709 - Email: <secretariat@hsc.fr>
- Page 29 -