Perimeter
3/28/2016
01:23 PM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

Like It Or Not, Firewalls Still Front And Center

Firewalls are still central to most network defense strategies, new State of the Firewall report says.

In spite of lots of advanced technology and moves to add many more layers of security to most enterprise defenses, firewalls aren't going anywhere soon as the heart of the cybersecurity toolset, according to a new report out today. Based on a survey of over 600 IT security practitioners, the State of the Firewall Report shows that the firewall is as entrenched as ever in modern network defense strategies.

"We're seeing small shifts in IT professionals' perceptions of the firewall as new technologies enter the market," says Jody Brazil, co-founder and chief product strategy officer at FireMon. "Adoption of SDN and network virtualization in general won't decrease the need for firewalls, but it may open the door to advancements or a new category of network protection. It will be more of a continuous evolution rather than a complete upheaval as so many are quick to claim."

According to survey respondents, 91% of security practitioners say that firewalls are as critical as always or more critical than ever to their security architecture, and the same ratio believe this will continue to be the case for the next half decade. These conclusions jibe with other industry reports that show how central firewalls still remain to network defense and management. For example, the InformationWeek 2015 Strategic Security Survey saw 61% of security practitioners reporting firewalls among their top three products on their security tool belt, the number one tool by some 25 percentage points.

Firewall technology and firewall strategies seem to be adjusting to the cloud and hybrid architectures today, as the number of organizations who find value in traditional and next generation firewalls (NGFW) for cloud services they manage increased by 10% in the past year, with over 67.7% of respondents finding them somewhat to highly valuable in cloud management.

That's not to say that changes in networking architecture won't impact firewall strategies; in fact, 90% of those surveyed report that software-defined networking (SDN) has impacted or will impact networking to a certain degree. And more than three times the number of respondents this year say they believe that native controls found in SDN solutions and new technologies will eventually pose a threat to the firewall's hegemony.

But with SDN adoption still in its infancy, that's a ways off. What's more, advancements in NGFW may offer a forward-looking roadmap that jibes with most organizations' security strategies, with or without SDN. Approximately, 66.5% of those surveyed say that NGFW plays a role in their SDN/virtualized environments.

As things stand, 50% of current firewall infrastructure in close to half of organizations is comprised of NGFWs, as compared to 34% in 2014. And only 6.7% of organizations today have no NGFW. The top benefits organizatons hope to gain from NGFW are IPS functionality, threat data integration and applicaton awareness.

"The threat to the firewall as the center of the security infrastructure is not immediate. It continues to play a critical role in the majority of today’s enterprises," the report stated. "However, the role of the firewall will have to evolve more as NGFWs become the norm and as emerging infrastructure paradigms such as SDN, cloud and micro-segmentation take hold."

Related Content:

 

Interop 2016 Las VegasFind out more about security threats at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Click here for pricing information and to register.

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.