Companies launch anti-virus education programme
Computer Fraud & Security · 1999
In this article, Simon Heron of Network Box considers the requirement to change security policy to treat outbound connections in the same way as inbound. It assesses the threat to company security from inside the network, including malware, tunnelling applications, and man-in-the-middle attacks.The use of signatures, walled garden and raw IP format blocking are considered, along with the option of blocking outbound ports except those to secure proxies such as DNS, SMTP email and so on, forcing all web access through a web proxy for control and policy enforcement.A long time ago, I installed my first firewall and took the unusual approach at the time of blocking all incoming ports below 1024 and only opening up those incoming connections that the company needed. Back then, it was far more common to allow all incoming connections and to block only certain specified ports (such as telnet, rsh etc.). It seems incredible now that that was a realistic approach to perimeter security.