Skip to content

Commit 4ae196d

Browse files
committed
chapter reorg and new firewall chapter
1 parent 6ee711e commit 4ae196d

File tree

3 files changed

+15
-471
lines changed

3 files changed

+15
-471
lines changed

firewall.rst

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ The historical meaning of a firewall is a barrier to prevent the
1818
spread of fire from one part of a building to another. Firewalls are also
1919
present in many automotive vehicles to separate passengers from the
2020
noisy (and possibly fire-prone) engine compartment. Saltzer and
21-
Schroeder in 1975 applied the term, possibly for the first time, in
21+
Schroeder in 1975 applied the term, possibly for the first time in
2222
the context of computer security, when discussing least privilege.
2323

2424
A network firewall is a system that typically sits between two regions
@@ -324,7 +324,10 @@ of lateral movement attacks are extremely common and have been well
324324
documented, often lasting for months before they are detected.
325325

326326
The obvious solution to problems of lateral movement would seem to be
327-
internal firewalls.
327+
internal firewalls. However, such a solution raises a new set of
328+
challenges. Consider the example in :numref:`Figure %s
329+
<fig-dc-firewall>`, in which a single firewall has been deployed to
330+
filter traffic flows among a set of virtual machines in a datacenter.
328331

329332

330333

0 commit comments

Comments
 (0)