Firewalls are an important element in ensuring computer security in times when we simply cannot imagine living without the Internet. These applications and devices control network traffic between the internal local and external public networks. Software and hardware firewall solutions are available or, as the case may be, independent devices. The bachelor's thesis focuses primarily on the hardware firewall solutions. The first firewall solutions occurred at the end of the 1980's and were sufficient for the needs of Internet technologies of the time. However, the incredible development of information technologies and services, but especially the occurrence of malicious software and hacking attacks, made those forms of firewalls inefficient as regards providing high levels of security. Gradually, new forms of firewalls began to spring up, as well as new ways of monitoring network traffic to meet the requirements of the time. In addition to firewalls, a number of additional tools occurred on the market which, together with firewalls, enabled efficient monitoring of network traffic. The tools were of good quality, but the additional cost of purchasing new devices and licences was a problem for many. Moreover, additional training was required for their use, additional space for installing the devices and so on. The needs for high quality network protection and adjustment to new forms of network services have brought on the development of next-generation firewalls. These are high capacity devices which, in combination with advanced tools, ensure security of local networks, monitoring of applications, as well as monitoring of network users. The essence of the next-generation firewalls is that not only do they combine the good characteristics of previous versions and contain advanced tools, but also that they use novel approaches to discovering malicious software codes and hacking attacks. In addition to ensuring security and monitoring, the next-generation firewalls also provide transparent use in order to simplify the management of these devices for network administrators as much as possible. In the last few years, a capable device came to the market which would, as an addition to next-generation firewalls, ensure a high level of security. These are the so-called Sandbox devices, which employ advanced levels of searching to discover malicious contents and attacks. The first part of the bachelor's thesis explains the general operation of firewalls by using theory, whilst the second part uses laboratory work to demonstrate the practical tests on devices.
|