网络安全

NetSecOPEN Fair Testing Has Arrived!

作者:

Blog - NetSecOPEN Fair Testing Has Arrived!

In a previous blog, I highlighted the merits of open standards-based assessments for today’s modern content-aware network security and inspection solutions

In a previous blog, I highlighted the merits of open standards-based assessments for today’s modern content-aware network security and inspection solutions. Understanding how well solutions work under a multitude of performance vectors can guide users with consistent empirical data on how well these solutions will work when under real-world conditions. NetSecOPEN has brought this to a reality via the IETF Benchmarking Methodology for Network Security Device Performance draft-02, allowing vendors and users alike to size up a solution’s capability via reliable, repeatable and transparent test constructs. The industry analyst firm HardenStance made a recent observation “The number of lawsuits between vendors and independent test firms in recent years points to how trust in third party security product testing is breaking down.” 1

No longer does the industry have to rely on inconsistent, “paid to play” private lab results that many times do not represent a solution’s real capability when used in mission critical environments... i.e. your network!

Well, all that work to create a new standards body has paid off. In mid-February of 2020, four major security solution vendors achieved NetSecOPEN certification. Cisco, Fortinet, Palo Alto Networks and SonicWall have all gained NetSecOPEN certification and have published full reports on specific firewalls via the NetSecOPEN standards methodologies. What does this mean?

At one level, this showcases these vendors desire to highlight how their solutions will work based on common and established configuration options that are in use by most organizations today. The NetSecOPEN requires specific device configuration specifications and right at the top of the certification reports, you can see how the security solution was configured for the obtained results:

NetSecOPEN Fair Testing Has Arrived

With this information, you know specifically how many options for security inspection are active. Typically, the more inspection a device is expected to perform has a direct impact on overall performance and capacity.

At another level are the results themselves. They cover a wide range of common metrics that organizations can rely on to understand how a solution may fit for their needs, including HTTP and HTTPS/TLS throughput, transaction latencies and concurrent connection capacities.

And finally, there is the process. The assessment methodologies are fully transparent and open and the formal certification results are done by an independent lab, then the results are ratified by the NetSecOPEN standards body which includes exactly how the tests were run. This oversight ensures the results are accurate and there are no conflicts of interests in deriving the numbers. This provides real and reliable information to compare one solution to another.

Spirent is a founding member of NetSecOPEN and has been deeply involved in working with the consortium on defining and developing this standards-based approach to assessing modern security solutions. This consortium includes vendors, enterprises, test labs, and test tool providers - all working together to provide the market with new and accurate performance and security capabilities assessments that are purposefully impartial.

For more information on NetSecOPEN and to see these actual certification reports, go to https://www.netsecopen.org/certifications

Spirent solutions were heavily used in this initial set of NetSecOPEN certifications and all the test plans are available in the Spirent CyberFlood assessment platform, allowing users to model NetSecOPEN tests in their own labs.

1 HardenStance - A New Era in Trusted Network Security Testing White Paper Feb 2020

喜欢我们的内容吗?

在这里订阅我们的博客

博客订阅

Mike Jack
Mike Jack

安全解决方案产品营销高级经理

Michael Jack现任思博伦通信公司应用和安全解决方案组合产品营销高级经理。他拥有数据通信行业20年的工作经历,和网络测试和测量机构超过15年的工作经验。在思博伦通信公司,他与产品管理团队协作定义、生产和交付适用于网络设备制造商、企业和服务商的尖端的多种应用安全测试解决方案。Michael还参加过多次行业展会,并且在众多联网企业中担任产品营销和管理职务,其中包括Thomas-Conrad、UB Networks、Newbridge Networks、Compaq和Antara。