Home > Information Security Tips > Network security tips > Enterprise UTM security: The best threat management solution?
Security UK Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TIPS

Enterprise UTM security: The best threat management solution?


Mike Chapple, Contributor
05.20.2009
Rating: --- (out of 5)


Security UK Tips and Expert Advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


If you believe everything you read, enterprise unified threat management (UTM) products and appliances are the silver bullet for information security. These all-in-one boxes claim to offer a panacea for any enterprise's security ailments, with functions including network perimeter protection, content filtering, malware protection and more. However, I've never met a security professional who believes everything he or she reads! In reality, UTM provides decent network security for small and midsized businesses, but probably has no place in the enterprise.

What is unified threat management (UTM)?
UTM products are, quite simply, several security products combined in a single device. From a performance standpoint, this is a perfectly reasonable thing to do. As we all know, many specialized servers, such as those often used to host security applications, sit idle for a substantial portion of the time. Hosting multiple services on the same server is resource efficient, reducing unused capacity.

The basic building block for a UTM product is a network firewall. (For more on firewalls, read my Firewall Architecture Tutorial.) The other components of the UTM will depend upon the vendor and model that you select. Common features include:

  • Spam protection
  • Content filtering
  • Antivirus/antispyware protection
  • Intrusion prevention

UTM vendors will be happy to show you fancy charts and graphs "proving" that you'll save tons of time and money by deploying UTM products in lieu of separate components. However, based upon my experience, other than saving a few minutes performing basic NIC configurations and the like, deploying a UTM product doesn't really make a significant dent in the time you'll spend configuring and working with the product. On the other hand, the cost savings do exist, as getting multiple security services from a single device -- and a single purchase -- can provide good value for your IT dollar.

UTM deployment risks
From my perspective, there are two major risks involved when deploying a UTM product: lack of fault tolerance and lack of vendor diversity. Fault tolerance is a major concern because a hardware or software failure that causes a disruption to the UTM box will take down all of your security services simultaneously. Depending upon your network configuration, this will either take your entire enterprise offline (just wait for that phone call at 3:00 a.m.!) or cause an outage of your entire security infrastructure: also not an ideal scenario. With UTM, the comforting feeling of knowing that each of the security services is running on a separate hardware platform, isolated from the ripple effects of the outage of another security service, doesn't exist.

Vendor commitment is, in my opinion, the greatest downside to UTM products. Take a moment and think about the first UTM offering that comes to mind and the company that produces it. How would you classify that company? If you said "firewall vendor," that's what you'll be buying: a firewall developed by that vendor with some other security features bolted on so they could apply the UTM moniker. Similarly, a UTM product from a content filtering vendor will have excellent content filtering capabilities, most likely supplemented by a mediocre firewall. Is that really what you want?

I'm a big fan of the "best-of-breed" approach to security infrastructure: Find the best firewall, the best IPS, the best content filter (and so on … ) and tie them together with a great security information and event management (SIEM) product. That approach simply isn't possible in the world of UTM.

The role of UTM
So now that I've walked you to the edge of cliff with a UTM box in your hands, let's back up a few steps. I can think of at least two scenarios where UTM can play an important role in securing a network.

First, for a small or medium-sized business, UTM may be the right approach. The cost savings and convenience of having all of these features hosted on a single box may simply outweigh the benefit of having the best individual products available. If that's the case, by all means, consider a UTM.

Second, if budgetary or other constraints prohibit the company from purchasing spam protection, content filtering, malware protection or an IPS, a UTM is a great way to get a feature that you wouldn't otherwise have by adding a small cost on to a previously planned purchase. With this approach, remember to consider the added feature a "freebie" and don't let it play a significant role in the purchase decision. Find the best possible firewall and then see if, for example, the IPS thrown in for free is suitable for use in the environment.

In conclusion, unified threat management products are probably a little overhyped. They do take advantage of unused hardware capacity by hosting multiple security services on the same hardware platform, but security pros are unlikely to see significant time savings as a result and may find themselves chained to a non-ideal vendor. That said, if the budget won't permit an alternative, UTM just might be the way to go.

About the author:
Mike Chapple, CISA, CISSP, is an IT security professional with the University of Notre Dame. He previously served as an information security researcher with the National Security Agency and the U.S. Air Force. Mike is a frequent contributor to SearchSecurity.com, a technical editor for Information Security magazine and the author of several information security titles, including the CISSP Prep Guide and Information Security Illuminated.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.co.UK.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Network security tips
Cloud-based services require stalwart business continuity plans
How to perform an Active Directory health check
Look into SIEM services to cut costs, comply with PCI DSS, HIPAA
Windows management tips: How to backup and restore Active Directory
Cloud computing compliance: Exploring data security in the cloud
Configuring a Windows network infrastructure: Wired, wireless security
How to use Google Webmaster tools to help protect your site
How to set your baseline with host integrity monitoring software
A closer look at Internet Explorer 8 security features
Network discovery and the Simple Network Management Protocol

Threat and Vulnerability Management
Zeus botnet temporarily disrupted, but back in full force
Considering two-factor authentication? Do cost, risk analysis
Clientless SSL VPN vulnerability and Web browser protection
Microsoft's Charney details new botnet protection, IdM technology at RSA
Look into SIEM services to cut costs, comply with PCI DSS, HIPAA
Cloud security issues, targeted attacks to be hot-button topics at RSA
Zeus Trojan continues reign infecting 74,000 PCs in global botnet
How to use Google Webmaster tools to help protect your site
New Community Security Policy aims to reduce computer misuse
The value of booting from a VHD in Windows 7

Endpoint and NAC Protection
Considering two-factor authentication? Do cost, risk analysis
Look into SIEM services to cut costs, comply with PCI DSS, HIPAA
Voice data security risks on the rise, say experts
The value of booting from a VHD in Windows 7
Thin-client technologies surge thanks to easier security, says Deloitte
A closer look at Internet Explorer 8 security features
USB drive security best practices and processes
First step in forensics: Create a bootable Windows environment CD
Protecting enterprise networks from new mobile application downloads
Four things to remember about server virtualization security concerns

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Centre for the Protection of National Infrastructure  (SearchSecurityUK.com)
Serious Organized Crime Agency  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



UK Data Security Solutions: Data Privacy, Identity Theft, Data Loss
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts