Skip to main content
Proceedings of the AMIA Symposium logoLink to Proceedings of the AMIA Symposium
. 2000:699–703.

The futility of common firewall policies: an experimental demonstration.

J E Ries 1, P V Asaro 1, A Guillen 1, J Ivanova 1
PMCID: PMC2244072  PMID: 11079974

Abstract

Many healthcare organizations utilize network "firewalls" to protect their networks from being accessed by unauthorized external entities. These same firewalls are also often configured to deny access to certain external services from within the internal network. The latter policy can be subverted through a "protocol tunneling" strategy, which has been implemented as a set of programs called "Firehole." Organizations should be aware of this potential weakness in their network security designs. Policies that deny external services to users should be carefully evaluated in light of clearly defined organizational goals.

Full text

PDF
701

Articles from Proceedings of the AMIA Symposium are provided here courtesy of American Medical Informatics Association

RESOURCES