Jul 24, 2008
Got an opinion about IPS?
As an exercise to accompany our 10Gbps Network IPS group test, we decided to ask end-users what they like and dislike about their current IPS products, how they use them, and what they'd wish for in their next go around.
Simply take the short survey, and you could also win a $50 Amazon gift certificate.
Jun 17, 2008
To infinity and beyond!
Jun 9, 2008
10 Gbps Intrusion Prevention - Finally?
The races are now officially on. After a couple of quiet and not so quiet announcements of 10Gbps network IPS products this last year, it appears the market has achieved a quorum. And NSS Labs is continuing its tradition by leading the industry's first group test of these speed-demons. We will be evaluating the security effectiveness of these products at various performance levels, as well as their stability, usability/management features. See the methodology (link below) if you're interested in the details.
Several vendors are offering appliances boasting true 10Gbps throughput, while yet others are offering solutions which combine a load balancer and multiple smaller NIPS appliances. There are operational and financial reasons for both approaches. Some of the trade-offs will be discussed in the final group report to be published in Q4. If you're a vendor, we'd like to hear from you. If you're a user, buyer, or otherwise interested, you may wish to sign up to be alerted when the results are out (newsletter sign-up).
More Info:
- Details of the test announcement
- The preliminary test methodology
May 29, 2008
PCI Research Survey
NSS Labs is collaborating with the Aberdeen Group on a benchmark study regarding best practices for achieving and sustaining PCI DSS compliance. In exchange for your participation in this 15-minute survey, you’ll receive a full copy of the final report when it publishes on 6/30/08 (a $399 value). Individual responses will be kept strictly confidential, and data will only be used in aggregate. Take the survey.
More research from NSS Labs.
May 21, 2008
Interview with TechTarget's Neil Roiter on PCI Suitability Reports
May 17, 2008
PCI Compliant Products
Kurt Roemer, CTO at Citrix recently discussed PCI Compliant Products on his blog, and I agree with his points thoroughly. So, since he mentioned us so kindly, I thought I'd offer some support and clarification.
I've written before in the NSS Labs blog , there's no such thing as a PCI compliant product . No product will make you compliant, but having the wrong product, or even the right product incorrectly configured could impede validation of compliance. From a terminology perspective, we prefer to say that products address or support compliance (to varying degrees).
That's right, there's no wholesale certification. Different aspects of a product support different requirements either completely, partially, or not at all. And in some cases, the requirements are not even directly applicable to a product. To get this "factual information" that Kurt is calling for, someone has to get their hands dirty with the details. This is what we are about at NSS Labs. Our reports only contain statements of a product's ability to support the specific individual requirements of the PCI DSS that we have empirically validated in the lab. Given that there is no official PCI certification for network/security products (other than PEDs), this is a pretty good start. Note: NSS Labs has been certifying network/security productsagainst our openly published standards since the 1990's. Our new reports focus on the suitability of a product for use in merchant networks, using the PCI DSS as a reference.
In this manner, I believe we're helping security and compliance professionals get beyond broad marketing claims and make more informed buying and implementation decisions. (So far, we've released 2 public PCI Suitability reports and have a number of others in the queue.)
PS. Eventually I will have 'the talk' with my kids about Santa Claus, Unicorns and PCI compliance. But thankfully, no time soon. ;-)
Thanks Kurt!
May 9, 2008
Keep It In The Family
Let me explain.
NSS is ONLY prepared to certify any product after a thorough evaluation of that product. Our view is that performance and security effectiveness BOTH need to be evaluated completely for every product. If you have a range of seven products ranging from 100Mbps to 2Gbps, the vendor might claim that they are all using the same code base, but for them to receive an NSS Approved award we have to verify that fact. After all, if someone tried to convince you that Bart and Lisa were both identical because they are both Simpsons you would be more than a little skeptical, would you not?
We need to put every device in our test rig and subject each one to the same extensive battery of tests that we would for a single product certification. That is the ONLY way to ensure that you, the reader and eventual purchaser of these products, are getting the real information on how these devices will perform in your network. The only thing that stays constant across an entire product family (usually!) is the management interface and usability.
It pains me to see so called "product family certifications" from other sources, because we know how they are produced - after all, those same vendors are our clients also. We read the "reports" and note the lack of any valid performance figures for each of the products. We note the lack of any individual security effectiveness analyses for the individual products. We note also an abundance of "as reported by vendor" statements in some of these, indicating a willingness to take vendor claims on faith without verifying them. They read like a marketing or branding exercise rather than a technical evaluation - a waste of money for the vendor and a waste of time for the reader.
As a testing house, it may be painful but you DO need to test absolutely everything for every single product in the family. A "representative sample" just does not cut it.
You, dear reader, need to know individual performance details, for example. How can you rely on manufacturers performance figures? Isn't that why you read NSS reports in the first place? You need to know if the 1Gbps device is going to give you a true 1Gbps across the wire when you load it up or if you will need to budget for the 2Gbps device instead. If you were buying a TV, wouldn't you want to know why you should consider paying 20% more for the next model in the range? You also need to know that the 100Mbps device doesn't disable fragmentation reassembly or curtail the signature set, opening up huge security holes in the process of trying to get higher performance out of low-end hardware.
That is the value NSS provides with its detailed individual product reports.
Right now, two enlightened vendors are putting their entire UTM product range through our labs, and the results will appear later this year. The advantage for the vendor is that they receive a true NSS Approved award for every device in the product line. The end result for you, dear reader, will not be a single product family report, but one complete report for every device tested, allowing you to make your purchasing or short-listing decisions with absolute confidence.
Rest assured that when you read an NSS report, you will be getting a detailed evaluation of the device under test in terms of usability, security effectiveness and performance. For every single product in the range!
-Bob Walder, CTO/Founder