Amnesty International Australia — global defenders of human rights

Médecins Sans Frontières — help us save lives around the world

Wed, 17 Nov 2004

Firewall configuration errors

Just read an article from the June issue of Computer entitled A Quantitative Study of Firewall Configuration Errors by security researcher Avishai Wool. He has an online PDF copy available for those who aren’t members of the IEEE Computer Society.

The quantitative data are probably what make this interesting—in that they confirm what seems obvious with some useful numbers. The main conclusions are that “there are no good high-complexity rule sets” and that simplicity alone does not guarantee good results. This won’t surprise anybody, but the numbers were interesting.