From Check Point NG/AI: Next Generation with Application Intelligence Security Administration

Introduction

The basic principle of any firewall is to allow access to legitimate services while denying all other network access. Although in the past this level of security may have been sufficient, in today s world of increasingly sophisticated network-based applications comes the threat that malicious users may be able to exploit vulnerabilities in these applications. As a result, the simplistic permit or deny firewall model is no longer effective on its own as a successful network security defense mechanism.

SmartDefense, a key component of Check Point s VPN-1/FireWall-1 NG with Application Intelligence, is the solution to the problem permitting legitimate access to a network resource while protecting that resource from malicious attacks.

SmartDefense s underlying methodology is to monitor network traffic flowing through the firewall, comparing characteristics of the traffic to patterns known to be indicative of malicious activity. Suspicious activity is logged, and notifications may be sent so that the network administrator can choose to take action against the threat. SmartDefense supports the detection of five categories of attack: Denial of Service (DoS) attacks, Transmission Control Protocol/Internet Protocol (TCP/IP) attacks, application attacks, port and IP scanning, and worms.

With new attacks constantly being designed, it is not sufficient protection to have a static list of algorithms for SmartDefense to use to compare to network traffic. As a result, Check Point offers a subscription service, whereby SmartDefense can be kept constantly up to date on newly released attack algorithms. Updating SmartDefense is a simple, one-step procedure, with the intention that updates may...

Copyright Syngress Publishing, Inc. 2004 under license agreement with Books24x7

Products & Services
Network Security Services
Network security services determine vulnerability of networks to outside intruders, as well as maintain anti-viral and firewall updates and usage.
Network Appliances
Network appliances are inexpensive personal computers (PC) or computer boards that provide Internet access and promote network security. They lack many of the features of fully-equipped PCs, however.
Network Security Software
Network security software includes everything from remote access protection to firewall and security appliance solutions to email security to web filtering, monitoring, bandwidth protection, and all elements of computer network security/computer security.
Network Firewalls
Network firewalls protect computer networks against unauthorized use or attack. They permit or deny access to private network devices and applications, and represent an important part of an organization's overall security policy. Firewalls may be software applications, hardware devices (such as routers), or a combination of both. They include turnkey products that are relatively easy to install as well as complex, multi-layer installations that require the expertise of a certified network administrator. 
Security Software
Security software programs are used to restrict access to data, files and users on a computer or server.

Topics of Interest

This cheat sheet can come in handy when working with network addresses and subnet masks. A standard netmask is written 255.255.255.0 which is equivalent to the aggregate /24. Using aggregates has...

Summary SmartDefense not only protects against a variety of recognized attacks that vary from the dissimilar classes of Microsoft networking worms through to DDoS attacks, but it also integrates...

Introduction SmartDefense is a compilation of technologies built into the Check Point enforcement point to add extra fortifications against attacks. The technologies include: Network...

Network Security In this section, we will discuss the best-practice network security provisions of SmartDefense. The Network Security and Application Intelligence technologies are free with...

Frequently Asked Questions Q: What protocol is most often used to attack the network layer of the OSI stack, and how can Check Point help in stopping these attacks? A: IP is used for attacks...