Network Security - The Road Ahead

Network Security - The road aheadOutbound traffic reportsIntranet reportsInternet
IntroductionWhat is Network Security?"NetworkreportsTrend reports
Security" -Monitoring"Network Security" -Forensics
"Network Security"
-ComplianceHIPAASOXGLBAConclusionReports to expect from compliance and internal
monitoring:
( see compliance sub-heading for reports on
Introductioncompliance)
Network Security is the next wave which is bound toUser Audit reports (successfull/unsuccessful login
sweep the softwareattempts)Audit policy changes (ex: change in privileges
market. Increase in offshore projects and transfer ofetc)Password changesAccount LockoutUser account
informationchangesIIS reportsDHCP reportsMSI reports( lists the
across the wire has added fuel to the burning urge toproducts installed/uninstalled)Group policy changesRPC
secure thereportsDNS reportsActive directory reports
network. As the famous adage goes, the most
safest computer isThe gating factor for choosing a monitoring product is
one which has been unplugged from theto cross verify
network(making it almostwhether the devices you have in your network are
useless). Network securitysupported by the
is becoming more of a necessity. Interestingly the typevendor you choose. There are quite a number of
of securityproducts which
required across different enterprises depends on theaddress this market, you might want to search for
nature of its"firewall analyzer"
business. Offlate some laws & acts have beenand "eventlog analyzer" in google.
defined to
identify security breaches, which is a very good move
to prevent"Network Security" -Compliance
fradulent use/access of information. There are two
types of softwaresMost of the industries such as health care and
for Network security, one which prevents it and onefinancial
which does theinstitutions are mandated to be compliant with HIPAA
forensic analysis. The main focus of this article wouldand SOX acts.
beThese acts enforce stringent rules in all aspects of
the forensics of network security.the enterprise
including the physical access of information. (This
What is Network Security?section
network security: theconcetrates on the software requirement of the acts)
protection of a computer network and its servicesThere are quite a
from unauthorizednumber of agencies that offer the compliance as a
modification, destruction, orservice for an
disclosureenterprise. But it all depends on whether you want to
handle compliance
Network security is a self-contradicting philosophyyourself or employ a third party vendor to ensure
where you need tocompliance to the
give absolute access and at the same time provideacts.
absolute security.HIPAA Compliance:
Any enterprise needs to secure itself from twoHIPAA defines the Security Standards for monitoring
different access ofand auditing system
information/transaction for that matter(ex:ftp,http etc.),activity. HIPAA regulations mandate analysis of all
internallogs,
access and external access. Securing the access ofincluding OS
information orand application logs including both perimeter devices,
resources from the external world(WWW) is quite asuch as IDSs, as
task to master, thatwell as insider activity. Here are some of the
is where the firewalls pitch in. The firewalls act asimportant reports that
gatekeepers whoneed to be in place:
seggregate the intrusive and non-intrusive requestsUser Logon report: HIPAA requirements (164.308
and allow access.(a)(5) -
Configuring & maintaining a firewall is by itself a tasklog-in/log-out monitoring) clearly state that user
whichaccesses to the
needs experience and knowledge. There are no hardsystem be recorded and monitored for possible
and fast rulesabuse. Remember, this
to instruct the firewalls, it depends on where theintent is not just to catch hackers but also to
firewall isdocument the accesses
installed and how the enterprise intends to provideto medical details by legitimate users. In most cases,
access tothe very fact
information/resources. So, the effectivity of anythat the access is recorded is deterrent enough for
firewall depends onmalicious activity,
how well or how bad you configure it. Please bemuch like the presence of a surveillance camera in a
informed many firewallsparking lot.User Logoff report: HIPAA requirements
come with pre-configured rules, which intend to makeclearly state that user
the job ofaccesses to the system be recorded and monitored
securing the information access from externalfor possible abuse.
sources. In shortRemember, this intent is not just to catch hackers but
firewall gives you information about attacksalso to document
happenning from thethe accesses to medical details by legitimate users. In
external world.most cases, the
very fact that the access is recorded is deterrent
The toughest job is to secure information from theenough for malicious
internal sources.activity, much like the presence of a surveillance
More than securing it, managers need to track thecamera in a parking
information flow, tolot.Logon Failure report: The security logon feature
identify possible casuatives. The tracking ofincludes logging
information flow willall unsuccessful login attempts. The user name, date
come in handy in case of legal situations. Becauseand time are
what seemingly to beincluded in this report.Audit Logs access report: HIPAA
a sharing of information could be held against you inrequirements (164.308 (a)(3) -
the court ofreview and audit access logs) calls for procedures to
law. To enforce this, acts such as HIPAA, GLBA,regularly review
SOX have beenrecords of information system activity such as audit
putforth, to ensure that the scam(s) like that oflogs.Security Log Archiving Utility:Periodically, the
"Enron" doessystem
not happen. In short the tracking of information andadministrator will be able to back up encrypted copies
audit gives youof the log data
information abouot security breaches and possibleand restart the logs.
internal attacks.
There are a variety of network security attacks/SOX Compliance:
breaches:Sarbanes-Oxlet defines the collection,retention and
Denial of ServiceVirus attacksUnauthorizedreview of audit
AccessConfidentiality breachesDestruction oftrail log data from all sources under section 404's IT
informationData manipulationprocess
controls. These logs form the basis of the internal
controls that
Interestingly , all these information are available acrossprovide corporations with the assurance that financial
theand business
enterprise in the form of log files. But to read itinformation is factual and accurate. Here are some of
throughthe important
and making sense out of it, will take a life time. That isreports to look for:
where theUser Logon report:SOX requirements (Sec 302
"Network Security" monitoring also known as "Log(a)(4)(C) and (D) -
Monitoring" softwareslog-in/log-out monitoring) clearly state that user
pitch in. They do a beautifulaccesses to the
job of making sense out of the information spreadsystem be recorded and monitored for possible
across variousabuse. Remember, this
locations and offer the system administrators a holisticintent is not just to catch hackers but also to
view of whatdocument the accesses
is happening in their network, in terms of Networkto medical details by legitimate users. In most cases,
Security. In short theythe very fact
collect,collate,analyze & produce reports which helpthat the access is recorded is deterrent enough for
themalicious activity,
system administrator to keep tabs on Networkmuch like the presence of a surveillance camera in a
Security.parking lot.User Logoff report:SOX requirements (Sec
302 (a)(4)(C) and (D)
clearly state that user accesses to the system be
"Network Security" -Monitoringrecorded and
monitored for possible abuse. Remember, this intent is
No matter how fine your defense systems are, younot just to
need to have someonecatch hackers but also to document the accesses to
to make sense out of the huge amount of datamedical details by
churned out of a edgelegitimate users. In most cases, the very fact that the
device like firewall and the system logs. The typicalaccess is
enterprise logsrecorded is deterrent enough for malicious activity,
about 2-3GB/day depending upon the enterprise themuch like the
size might vary. Thepresence of a surveillance camera in a parking
main goal of the forensic software is to mine throughlot.Logon Failure reportThe security logon feature
the vast amountincludes logging
of information and pull out events that need attention.all unsuccessful login attempts. The user name, date
Theand time are
"Network security" softwares play a major role inincluded in this report.Audit Logs access report:SOX
identifying therequirements (Sec 302 (a)(4)(C) and
causatives and security breaches that are happenning(D) - review and audit access logs) calls for
in theprocedures to regularly
enterprise.review records of information system activity such as
audit logs.Security Log Archiving Utility:Periodically, the
Some of the major areas that needed to besystem
addressed by any networkadministrator will be able to back up encrypted copies
security product is to provide a collective virus attacksof the log data
acrossand restart the logs.Track Account management
different edge devices in the network. What thischanges:Significant changes in the
offers for aninternal controls sec 302 (a)(6). Changes in the
enterprise is a holistic view, of the attacks happeningsecurity configuration
across thesettings such as adding or removing a user account
enterprise. It offers a detailed overview of theto a admistrative
bandwidthgroup. These changes can be tracked by analyzing
usage, it should also provide user based accessevent logs.Track Audit policy changes:Internal controls
reports. Thesec 302 (a)(5) by
product has to highlight sescurity breaches andtracking the event logs
misuse of internetfor any changes in the security audit policy.Track
access, this will enable the administrator to take theindividual user actions:Internal controls sec 302 (a)(5) by
necessaryauditing user activity.Track application access:Internal
steps. The edge devices monitoring product has tocontrols sec 302 (a)(5) by
provide othertracking application
stuffs like Traffic trends,insight into capacity planningprocess.Track directory / file access:Internal controls
and Livesec 302 (a)(5)
traffic monitoring, which will help the administrator tofor any access violation.
find causes
for network congestion.GLBA Compliance:
The Financial Services Modernization Act (FMA99)
The internal monitoring product has to offer the auditwas signed into law in
information ofJanuary 1999 (PL 106-102). Commonly referred to as
users, system security breaches and activity auditthe
trails (ex: remoteGramm-Leach-Bliley Act or GLBA, Title V of the Act
access) As most of the administrators are ignorant ofgoverns the steps
the requirementsthat financial institutions and financial service
for thecompanies must
compliance acts, it is better to cross reference whichundertake to ensure the security and confidentiality of
acts apply tocustomer
their enterprise and ensure that the product supportsinformation. The Act asserts that financial services
reporting for thecompanies
compliance acts(please refer hereroutinely collect Non-Public Personal Information (NPI)
for details on compliance)from
individuals, and must notify those individuals when
In altoghether they will have to support archiving,sharing information
scheduling ofoutside of the company (or affiliate structure) and, in
reports and a comprehensive list of reports. pleasesome cases,
follow the nextwhen using such information in situations not related to
section for more details.the
furtherance of a specific financial transaction.
User Logon report:GLBA Compliance requirements
"Network Security" -Forensicsclearly state that
user accesses to the system be recorded and
The most important features you need tomonitored for possible
lookout,when you short list a network security forensicabuse. Remember, this intent is not just to catch
product is thehackers but also to
abilitydocument the accesses to medical details by
to archive the raw records. This is a major factorlegitimate users. In most
when it comes tocases, the very fact that the access is recorded is
acts and laws. So in the court of law, the originaldeterrent enough
record has to befor malicious activity, much like the presence of a
produced as proof and not the custom format of thesurveillance camera
vendor. Thein a parking lot.User Logoff report:GLBA requirements
next one to lookout for is the ability to create alerts, i.eclearly state that user
theaccesses to the system be recorded and monitored
ability to notify whenever some criteria happens ex:for possible abuse.
when 3Remember, this intent is not just to catch hackers but
unsuccessfull login attempts mail me kind of stuff, oralso to document
better still ifthe accesses to medical details by legitimate users. In
there is a virus attack for from the same host moremost cases, the
than once, notifyvery fact that the access is recorded is deterrent
me etc. This will reduce the lot of manual interventionenough for malicious
needed inactivity, much like the presence of a surveillance
keeping the network secure. Moreover the ability tocamera in a parking
schedulelot.Logon Failure report:The security logon feature
reports is a big plus. You don't have to check theincludes logging
reports daily. Onceall unsuccessful login attempts. The user name, date
you have done your ground work as to configureand time are
some basic alerts andincluded in this report.Audit Logs access report:GLAB
some scheduled reports. It should be a cakewalkrequirements (review and audit
from then on. Allaccess logs) calls for procedures to regularly review
you need to do is check out the information(alertsrecords of
reports) you get ininformation system activity such as audit logs.Security
your inbox. It is recommended that you configureLog Archiving Utility:Periodically, the system
reports on a weeklyadministrator will be able to back up encrypted copies
basis. So that it is never too late to react to aof the log data
potential threat.and restart the logs.
And finally a comprehensive list of reports is a vital
feature to
lookout for. Here is a list of reports that might come inConclusion
handy"Network Security" has to be done both internally as
for any enterprise:well as
externally, the job of nailing the problem is a huge task
Reports to expect from edge devices such as awhich needs expertise and mostly help from
firewall:softwares such as EventLog Analyzers(compliance
Live monitoring Security reportsVirus reportsAttackand internal monitoring of internal machines) and
reportsTraffic reportsProtocol usage reportsWebFirewall Analyzer(virus,attacks
usage reportsMail usage reportsFTP usageand traffic monitoring of edge devices).
reportsTelnet usage reportsVPN reportsInbound