Hackers have exhausted the protocol level attacks that firewalls traditionally were designed to protect against, and have moved their focus to the application layer. With up to 70 new vulnerabilities being reported weekly in applications and operating systems, combined with the lack of protection afforded by current installed solutions, the application layer attack is clearly the entry point of choice for external hackers to break into your internet-connected network.
The debate over firewall architectures is over The internet community has been the host for a long-running debate between stateful firewall supporters and application proxy firewall supporters.
Stateful firewall supporters claimed that the additional inspection afforded by application firewalls was too complex to configure and caused too high a performance penalty.
Application proxy vendors maintained that you had to inspect the application layer model to afford 'real' security and anything less was simply unacceptable.
The change in the threat vector by the hacking community has allowed the application proxy firewall vendors to quietly win this debate. In fact, today many stateful packet filter firewall vendors are adopting some form of application layer filtering, and attempting to reinvent themselves as a next-generation product in an effort to try to meet today's threats.
Read more... Source : InformaticsOnline