Palo Alto Offers 'Read Only' Facebook Access

Next-generation firewalls are increasingly blending not just packet inspection, but also IPS, policy enforcement, and better security intelligence.

Network security vendor Palo Alto Networks announced Tuesday that its firewalls can now control which groups of users have access to specific Facebook functionality -- reading, posting, chatting, sending messages, using apps, or other plug-ins -- as well as when.

Furthermore, any Facebook activity can also be scanned to ensure that data doesn't contain confidential information and to ensure it's not part of an unfolding security incident, such as a clickjacking worm.


More Hardware Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

The words "Facebook" and "firewall" might not seem like a natural fit, but according to Gartner Group, this is the direction in which next-generation firewalls are evolving.

Today, firewalls typically provide stateful packet inspection -- keeping track of network connections -- while a different appliance serves as a network-based intrusion prevention system (IPS). But according to Gartner, that approach has become outdated as applications move to the cloud, and users begin using the Internet not just occasionally, but constantly, both at home and at work.

"Before, it was one port, one application. Things were really straightforward, but now there's a whole bunch of gray, and digging into that grayness is a challenge that the stateful firewall and packet filtering hasn't been able to deal with," said Greg Young, the Gartner analyst responsible for network security, in a security webinar.

Next-generation firewalls, however, can help, he said, by blending the usual firewall stateful inspection -- at enterprise scale -- together with an IPS that's closely integrated with the firewall.

These next-generation firewalls -- as defined by Gartner -- also provide "full stack visibility" to see not just which applications are running, but who's using them, as well as "extra firewall intelligence" that puts all of the disparate pieces of information together to provide better security and policy enforcement, he said.

Increasingly, these devices will also be able to enforce policies based on user and application types. For example, companies could block Facebook outside of work hours for anyone who doesn't need access to the site for work, such as corporate communications. Or universities could shape traffic for peer-to-peer applications to minimize the bandwidth they consume during the day, but relax restrictions at night.

Attend an InformationWeek virtual event on creating and leveraging the private cloud and how could affect your business' most critical systems and information. It happens June 23. Click here to find out more and register.

Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS

Resource Links