Wednesday, July 8, 2015

3 Small to Medium Sized Network Security Solution part 3



Web Application Firewalls
WAF operates at the application layer where it monitors web traffic using SSL decryption. It blocks identified threats after reassembling web sessions. WAF works within sessions.
Intrusion Prevention Systems
IPS applies a predefined policy or signature set across all traffic. It inspects packets for policy or signature violations to find and shut down any identified threats.
There are fundamental differences between these IPS and WAF. IPS discards packets for better performance. WAF must retain packets for context. They both use baselining in different ways. IPS for statistical deviations in throughput and traffic flows. WAF uses baselining at the application layer. IPS is packet smart while WAF is application smart. WAF will protect against application level vulnerabilities where IPS cannot. IPS provides protection at a lower level before patches for known vulnerabilities are provided. WAF should not be used as a replacement for a traditional network firewall. These solutions complement each other along with a traditional firewall.
When considering IPS do we choose Stateful Packet Inspection (SPI) or Deep Packet Inspection (DPI)? It’s about security vs speed. SPI examines the basic information in a packet, the header, the footer, whether or not it belongs to a valid session.
DPI as the name suggests takes a much deeper look but also takes a much greater performance hit. DPI makes use of greater security capabilities including stealth payload detection and signature matching.
Once again we find that a combination of both can bring about the best of both worlds. In this scenario SPI stops malformed packets at the edge and DPI handles the rest.
Other considerations include using secure passwords changed at frequent intervals, Encryption is effective but could be risky a user fails to remember the decryption key.
These are all important layers of any network security solution. Another layer would include managed scanning of any web applications being used, for security flaws, poor coding practices, and weak configuration management. Penetration testing is another way to verify the security of your network.
With all these layers you can see that you could quickly be overwhelmed by administration of the various solutions being applied. Thus emerged the Unified Threat Management appliance. Next we discuss the advantages and disadvantages of the UTM.

2 Small to Medium Sized Network Security Solution part 2



Review of other work
In the SMB space many will seek out a vendor for assistance, as I have sometimes done in the past. In most cases, these will send out a sales rep; who will tell you he knows little about the technical aspects of his product, although he will use a couple of buzzwords that will only prove to you he really doesn’t, then will sell you the largest package deal they can get you to buy, whether you need it or not, promise you the world, place it, configure it, take the money and run. You may be able to say you provided a solution, but can you say you did your due diligence? Can you really say for sure that the shiny new product you have just invested your company’s money in is doing the job intended? Not if you have no clue as to how it was configured and not if the persons installing it made no effort to explain in clear English what exactly their product is doing and how.
This is why I rarely read white pages. Some are fairly impressive, and some are even informative, but the majority in my opinion are a sales pitch leading to the solution the company paying the writer want you to buy. These never really get to the true nitty-gritty of the problem. They rarely discuss the nuts and bolts of what is really going on and what is needed to address it properly. They razzle dazzle those who have just enough knowledge to be dangerous and are ready to throw the first warm and fuzzy solution at the identified problem. The plethora of these just make the decision maker all that more confused and desperate. This is no way to handle something as critical as the security of your business network. Would you leave the front door unlocked to your physical place of business? I dare say you would not. Why then would you leave the front door or even the back one, for that manner, to your business or home network unlocked and or even open?
There are many ways that people are addressing these vulnerabilities to protect themselves against the threats that abound. Still, you are only as strong as your weakest link. How can you be sure that all of the vulnerabilities are properly addressed and that your network is safe? You must have multiple layers of security in place… like an onion. Let’s consider the available options.
We will discuss the various available solutions and the pros and cons of each to develop an overall view of what solutions are being implemented to mitigate security risk.

1 Small to Medium Sized Network Security Solution



Introduction
IT Professionals are continually occupied with the planning and integration of a variety of solutions necessary to the security and safety of the networks and the systems and information that traverse the networks they are obligated to protect. Proponents of a free and open World Wide Web and the possibilities that it allows for, understand that like the real world, freedom has its price. There are malevolent factions who are willing to use that freedom for personal gain without regard for what is ethically and or morally proper.
Your business, your privacy, your finances and even your family are at risk due to these various factions. The world we live in and pretty much everything that we do is tied to the very dynamic and somewhat ambiguous world of technology. Always growing and changing but not always clearly defined… most of us have little to no real understanding of what goes on behind the scenes of the devices that we interact with on a daily basis. Like the real world we do what we can to feel safe and protected.
In our time, the Cyber World is the real world. You are only as safe as the precautions you take, the choices you make, and the defense mechanisms you use to protect yourself.
Simply put, the inherent risks are 2 way:
1. The dangers within
2. The dangers without
You must secure your network from those who want to get in but have no right to be on your personal network. You must also monitor and protect your users from the harmful places that are accessible online.
This report assesses and details these risks, tests the effectiveness of the solution built, and does indeed provide a cost-effective and reliable solution for the typical small to medium size network.
It educates the typical family unit and SOHO/SMB of the risks they face online, and provides a solution that will secure these networks in a cost-effective manner, bringing together the chosen available components to secure these networks from intrusion, and to detect and track any rogue activity, and to track the internet use of those that have legitimate access to the network.
It testifies to what those risks are and how they can be managed.            It explains these various risks including the mechanisms used to exploit the vulnerabilities that are often left open to attack. It details the risk, threat, and vulnerability as it applies to these smaller network scenarios, since it is these who cannot often justify the expense of an “enterprise class” solution.
It consolidates, in as clear a manner as possible the reality of the dangers that exist in the modern world of connected devices and cuts through the misinformation that is so readily disseminated by many who “think” they know what they are doing when it comes to network security. It’s beneficial to both home users and SOHO/SMB’s.
The resources and talent of those with the expertise to address these issues with a legitimate solution and ongoing support is only now starting to make its way to those managing a smaller network. This report serves to warn against taking your network security into your own hands and not taking it seriously enough until it is too late.
We start with a discussion of what is currently being done to address the security threats we are concerned with.