Tuesday, 19 July 2011


Hi Bill,

Thanks for the post. Yes, if you map the window/door analog onto home or SMB networks, the initial intrusion does indeed breach the firewall. In the article, we talk about containment. The interior doors of a home are poor analogs for layered security. You correctly point out that additional security measures are needed to contain the intruder to the room he's breached. (We might also have talked about preventing the theft of items in the breached room - "exfiltration" of data from SMB networks - but I'll save this for another article.)

This issue of zero-day vulnerabilities certainly accentuates the need for multiple layers of protection. The average home pc or small business user who believes they are trying to safeguard themselves is increasingly vulnerable to these types of attack because they tend to rely so heavily on one 'gold-plated', super-duper internet security package rather than taking a layered approach. Your analogy of the open window and preventing access to the rest of the house is a succinct one, but the firewall is essentially breached. If the intruder then has to break through a series of firedoors you at least have a chance to contain the bugger!

