Firewall certification

被引:0
作者
Harris, B [1 ]
Hunt, R
机构
[1] Deloitte Touche Tohmatsu, Enterprise Risk Serv, Canterbury, New Zealand
[2] Univ Canterbury, Dept Comp Sci, Canterbury, New Zealand
关键词
firewall; evaluation; certification; common criteria; ITSEC; ICSA; AISEP; TCSEC;
D O I
10.1016/S0167-4048(99)80052-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The degree of trust which can be placed in a firewall can be measured through independent evaluation using a suitable criteria. Such criteria provide a measure by which end-users can make informed decisions on the purchase of firewall products in conjunction with their security policy. This paper examines two groups of evaluation criteria and their suitability for firewall certification. The first group consists of criteria used by government certification programmes to meet the particular needs of government and related agencies. Members of this group include the: Information Technology Security Evaluation Criteria and the Common Criteria for Information Technology Security Evaluation. The second group consists of criteria created specifically for commercial certification programmes, and focuses on penetration testing to meet the needs of the private sector. Members of this group include the International Computer Security Association's Firewall Product Developers' Consortium Product Certification Criteria, and West Coast Labs Firewall Checkmark Criteria. The paper also shows the certification status of a number of firewall products currently on the market. Finally the paper reviews the success and applicability of these criteria in practice.
引用
收藏
页码:165 / 177
页数:13
相关论文
共 13 条
[1]  
*AISEP, 1997, 1 AISEP
[2]  
[Anonymous], 1991, INF TECHN SEC EV CRI
[3]  
*AUSTR INF SEC EV, 1997, 7 AUSTR INF SEC EV P, P11
[4]  
CAFARCHIO P, 1998, COMMUNICATION 0303
[5]  
COHEN A, 1998, COMMUNICATION 0328
[6]  
*COMM EV METH ED B, 1997, CEM97017 ED BOARD
[7]  
*DEP DEF TRUST COM, 1985, 520028STD DOD NAT CO
[8]  
*FDIS, 1998, COMM CRIT INF TECHN
[9]  
Schultz E., 1996, COMPUTER SECURITY J, V12, P47
[10]  
*UK SCH, 1997, UK SCHEM PUBL, V6