CyberGuard and Microsoft Firewall Market Positioning
Robert L. Carberry, Ph.D. Chairman, President and CEO CyberGuard Corporation
Note: The intent of this document is to position Microsoft's new Proxy Server 2.0 product in the context of the general firewall market and specifically address the two different markets CyberGuard and Microsoft serve.
CyberGuard Corporation (NASDAQ:CYBG) is a leading security solutions provider to Fortune 1000 companies and governments worldwide. CyberGuard's award-winning, industrial-strength firewall and security products protect the integrity of data and applications from unauthorized access in Internet, Intranet and Extranet environments. CyberGuard's subsidiary, TradeWave, provides encryption, Entrust-aware authentication, and certificate authority products and services to safeguard electronic-commerce applications particularly focused on the finance, healthcare, communications and utility vertical market segments.
CyberGuard Poised to Capitalize on Market Growth
Although estimates of market size and growth rates vary, the network security market and related segments are expanding rapidly. According to a January 1997 study by UBS Securities LLC, the annual compound growth rate in revenue associated with the firewall segment is estimated to be 44 percent, with industry revenues rising from $160 million in 1995 to $980 million in the year 2000. International Data Corp. predicts the worldwide firewall market will expand from $220 million last year to over $700 million by 2001.
Additionally, UBS projects a 71 percent compound annual growth rate for the combined firewall, authentication, encryption and services markets between 1995 and 2000. Dataquest estimates the worldwide information security market will grow from $5.2 billion to $13.1 billion during this same period.
Additionally, Forrester Research Inc. predicts the electronic commerce market, in which CyberGuard now participates, will become a $6.6 billion market by the year 2000. The Internet research firm specialist Strategic Focus Inc., estimates the electronic commerce market in 1996 was $243 million, up from $77 million in 1995. That's an increase of more than 300 percent in a single year.
CyberGuard - One-Stop Solutions Provider
CyberGuard is well-positioned to take advantage of the exponential growth rate in the network security market. The Company's strategy is unique compared to competitors who develop only firewalls and ally with other product providers who fill in the missing product elements. The key difference is that CyberGuard provides its customers with a broad range of security products and services which are provided as a turnkey system offering, are fully integrated, and can be installed and administered in a consistent, integrated manner. For those customers who wish to have the day-to-day operation of the combined firewall, encryption, and authentication system "outsourced," CyberGuard's TradeWave subsidiary provides customers a complete certificate authority service which is operated by TradeWave as a service offering. TradeWave presently operates an electronic commerce network which is expected to support more than $25B in transaction revenues during 1997. The ability to offer its customers a complete, integrated network security systems solution, provided as either individual products, a turnkey system, or an out-sourced service offering, makes CyberGuard unique in its industry.
CyberGuard Product Positioning:
CyberGuard's UNIXr-based firewall product line serves the high-end segment of the firewall market. Prudential characterizes this market segment as "upper-tier." This upper-tier segment of the firewall market requires the highest level of security possible to protect valuable assets. Here, security is the primary factor in the purchase decision, with performance, functionality and ease of use playing secondary roles. CyberGuard and TradeWave's upper-tier security offerings are particularly well-suited for large organizations in the financial, health care, communications and manufacturing vertical market segments. The soon-to-be-announced CyberGuard NT Firewall product line will distinguish itself by offering a "security shield" which will make the CyberGuard NT offering more secure than other offerings in the marketplace that only use NT in its native, unprotected form.
Other firewall vendors such as Raptor and Check Point cater to the "mid-tier" firewall product market with their UNIX and NT product offerings. Here, security does not play the major role in the purchase decision.
Microsoft to Enter Firewall Market
According to a June 30 report by Dean Takahashi, Staff Reporter for the Wall Street Journal, Microsoft is expected to enter the Internet firewall market with the beta release of their Proxy Server 2.0 product in the coming weeks. Availability is expected in September.
Paul L. Merenbloom, research analyst for Prudential Securities, commented on this news, "In our opinion, Microsoft's news does not pose any near-term material threat to the commercial firewall marketplace. While we understand the confusion and concern that Microsoft's intended action could bring to the marketplace, we believe that the Microsoft products, if and when they actually are released for general availability, will offer capabilities and functionality that is far lesser than those found in commercial products available from . . . CyberGuard and others."
"It is our expectation that the market for products in the mid-and upper-tier firewall segment as represented by UNIX-based firewall products from Check Point, Raptor, TIS, Secure Computing and CyberGuard will remain healthy and strong for the next three to five years," Merenbloom added.
NT Operating System Versus UNIX
It is important to note that the new Microsoft Proxy Server 2.0 product will address only the NT market.
A report by Forrester Research featured in the March 26 issue of Washington Technology Magazine projected growth rates for the NT and UNIX operating systems market. This report indicated that the install base for NT operating systems will not catch up to the install base for UNIX operating systems until the end of the decade. This means the opportunity for protecting UNIX-based installations will be equal to or greater than NT-based installations through 1999. Forrester Research also indicated, per the figure below, that revenues for the UNIX market are expected to generally remain above those of the NT market.
<Picture>
CyberGuard's Security Solution
Buyers intentions surveys indicate that the primary reason for a customer to purchase a firewall is security.
CyberGuard is currently shipping products that have been certified by the National Security Agency's US National Computer Security Center, the National Computer Security Association and the European Information Technology Security Evaluation Criteria. CyberGuard's software security solutions also comply with B1 and E3 certifications from the NCSA and ITSEC. The CyberGuard Firewall Release 2 was the first firewall to be certified to the E3 level of trust in Europe and has recently become the first E3-certified firewall in Australia.
Unlike conventional firewall solutions on the market, CyberGuard's strong solution is comprised of a three-tier security structure. CyberGuard's secure software application (ITSEC E3 evaluated) resides on top of an operating system and networking software that have been 'hardened' with extra security measures and evaluated by the NCSC at the B1 level of trust. Other firewall offerings secure only the application layer and do not secure the underlying networking software and operating system layer which remains a vulnerable point of attack.
Official certification is a rigorous process that takes several years to complete. This government certification stems from standards established in 1985 by the U.S. Department of Defense. The criteria defines six levels of operating system security. Each level specifies security functionality that is suitable for a defined environment.
Below note the levels of security explained. The security increases from top to bottom in the table. (The letters decrease and the numbers increase as security improves.)
<Picture>
ÿ
Microsoft's Security Solution
Microsoft's Windows NT Release 3.5 is certified as a C2 operating system, and has been certified to the E3 level of trust in Europe. It is critically important to note, however, that both of these certifications were for the operating system as a standalone product. No certification of the communication portion of the system was ever completed. This underlying networking software or communication stack remains a vulnerable point of attack.
Microsoft is currently shipping only Windows NT Release 4.0 which has been noted for its security weaknesses.
Commenting on Microsoft's Proxy Server 2.0, Michael Parekh of Goldman, Sachs & Co. Investment Research, noted, "The product is designed to fill the need for firewall protection at the low-end of the marketplace, competing with similar proxy and application gateway firewalls from Netscape (NSCP), Novell (NOVL) and dozens of small firewall vendors.
CyberGuard's NT Security Solution
Companies such as Axent Technologies (a CyberGuard strategic partner) recently noted their products check for more than 90 security related issues associated with the NT operating system. CyberGuard's NT security solution will eliminate many of the security exposures occurring when NT is used as a firewall host by placing a field-installable security shield around the NT operating system prior to installation of the CyberGuard Firewall.
CyberGuard's demonstrated ability to successfully bring world class network security products to market, combined with the Company's many credentials related to obtaining security agency product certifications, uniquely position CyberGuard to bring a differentiated, secure Windows NT environment to market. Slated for availability in the first fiscal quarter of 1998, CyberGuard's NT product offering will serve the middle to upper-tier segment of the firewall market. CyberGuard will address security issues with its unique NT security solution by limiting access to certain networking areas of Windows NT and providing a more secure network environment.
Customers Demand Security, Functionality, Performance, and Ease of Use
CyberGuard's security, functionality, performance, and ease of use have been recognized by more than seven major awards this year including:
Byte Magazine's BYTE BEST Award
Network Computing Magazine's Editor's Choice Award
Federal Computer Week's Government Best Buys Award
Data Communications Magazine's Tester's Choice Award
Communication Week's MAX Award
Secure Computing Magazine's Editor's Choice Award
The National Software Testing Laboratory gave the CyberGuard Firewall a 5-star rating in its March 1997 Software Digest Report
Customers today are requiring high-level functionality and the ability to centrally manage large numbers of firewalls across the enterprise. While the CyberGuard Firewall meets and exceeds these requirements, Microsoft positions their future offering as a platform on which to build the robust firewalls required by enterprise customers. Richard Tong, Microsoft's vice president of marketing for personal business systems, noted, "The new software will not replace competitor's products. . . other companies can offer additions with more features on top of what we provide."
The fact remains, however, that the present Microsoft NT design is marginally secure unless additional protection such as the CyberGuard's NT security solution is added. Additionally, the entire NT operating system would have to be redesigned to begin to approach the security levels provided by the government-mandated Multi-Level Security (MLS) design offered by the CyberGuard Release 2 and Release 3 family of products. Buyers Intentions Surveys also indicate that customers want a turn-key, total security solution which consists of firewall, encryption, |