Firewall Wizards mailing list archives

Re: Sliding/Shifting/Morphing firewalls


From: Joseph S D Yao <jsdy () cospo osis gov>
Date: Fri, 12 Feb 1999 12:36:33 -0500 (EST)

groups of uberlusers who possess diagnostic skills roughly on a par
with a troop of mildly concussed tarsiers.  ...

May I express my admiration, and ask for permission to use this neat
turn of phrase?  ;-)  ;-)  ;-)

In terms of bandwidth, the best method would probably be to use a
PRNG with a reasonably long period.  Set the seed during the
initial setup of the constituent firewalls in the RAIFsets, and
then exchange a new seed at some pre-defined interval (some wee bit
less than your PRNG's period).

And have somebody sabotage one of the upstream time servers, or perhaps
your tarsier-equivalents are maintaining it, and the two lose sync
during that time period and can no longer communicate.  (Happened
here - tarsiers.)

Just to be reasonably paranoid - a virtue in this field, eh?

;-)

--
Joe Yao                         jsdy () cospo osis gov - Joseph S. D. Yao
COSPO/OSIS Computer Support                                     EMT-A/B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.



Current thread: