Wednesday, July 8, 2015

6 Small to Medium Sized Network Security Solution part 6



Research shows that the typical small to medium sized network is not secure and is susceptible to intrusion by factions with bad intent. Lack of awareness of the true nature of the risk is the greatest obstacle to overcome. New vulnerabilities are discovered every day. How will we address this?
Every IT project should begin with two questions:
1. What business problem are we trying to solve?
2. Does everyone agree it’s worth the effort to solve it?
Here we have helped to solve the problem of security vulnerabilities in a small to medium sized network. The same ignorance of these vulnerabilities exists from a typical home network, to a SOHO, to an SMB size network. In each case important personal information and reputation are at risk including monetary assets.
This report represents an effort to educate the public and provide a reasonable path towards an affordable security solution. It should be noted that the enterprise class security solutions are starting to reach out to the SMB sector. They are trying to fill the gap between what is effective and affordable to a typical SMB size network. Still this sector must also be educated, even convinced that if they do not take some action they will remain at risk. The solution I have proposed will merit the consideration of these same SMB’s although it will target more closely a home to a SOHO size network.
Here, I would like to succinctly address the nature of the beast we are facing. Addressing network security involves three factors: vulnerability, threat, and attack.
The primary vulnerabilities are technological, configuration, and security policy weaknesses. Technological vulnerabilities include protocols, operating systems, and network equipment. Configuration vulnerabilities involve laxity on the part of the administration. Due diligence requires that the administrator do everything possible to correctly configure and protect the network in his charge. Security policy weaknesses include not having a clear cut written policy and not following it if you do… or not enforcing it, as they need may be. Network policy informs users, staff, and managers of their obligatory requirements for protecting technology and information assets, specifies the mechanisms through which these requirements are met, and provides a baseline from which to acquire, configure, and audit computers and networks for compliance.

On to the four types of attacks, reconnaissance, access, denial of service (DOS, and worms, viruses, Trojan horses. Reconnaissance involves Internet information lookup, Ping sweeps, Port scans, and Packet sniffers. Access attacks include password cracking, trust exploitation, port redirection, man – in – the – middle. DOS overwhelms system resources via ping of death, SYN flood, email bombs, malicious applets. Last would be various types of malware which compromise a system of systems in various ways… many serious.

Lastly, we have threats. These include structured, unstructured, internal, and external. Here we have a taste of what is out there and a way to categorize them for more effective defense management. We can see that this is an ugly animal with many heads.
Does everyone agree it is worth the effort to solve it? Is it worth the effort to lock your door when you go to bed at night? There will always be an ongoing need for risk mitigation regardless of the size network we are on just as the need to mitigate the risk of crime in the physical world remains. The question is are you ready? We shall see in our next section.
 

5 Small to Medium Sized Network Security Solution part 5



Rationale
So with all the various options to choose from, I proposed to not only educate those who setup and use a small to medium size network but to provide an affordable model of protection for these same networks that addresses the risks within and without.
This education work is critical since we are ever evolving towards a continually connected state of everything. You’ve heard of the internet of things. What is it? It’s a concept leading to a state of connectivity to everything. A state that also requires protection against those who would use that connectivity for ulterior advantage.
Notice a most recent of security exploits found:
SEC Consult Vulnerability Lab discovered a flaw found to affect the products of up to 26 vendors. The details of the flaw are well explained in the article but the nature of the vulnerability speaks to the bigger problem.
This article states:
"Here we have another case that shows the sad state of embedded systems security," the SEC Consult blog reads, "Because the same vendors are building the IoT devices of tomorrow, we will see a lot of this in the future." – Tamarov, Maxim(2015). Retrieved from http://searchsecurity.techtarget.com/news/4500246976/NetUSB-router-vulnerability-puts-devices-in-jeopardy?track=NL-1820&ad=900884&src=900884
This is a statement worth remembering if you care about the security of your network no matter how small, both now and tomorrow.
What other concerns are there? The next incident report, one of many available will help to make this rivetingly clear:
‘Lying on his family room floor with assault weapons trained on him, shouts of "pedophile!" and "pornographer!" stinging like his fresh cuts and bruises, the Buffalo homeowner didn't need long to figure out the reason for the early morning wake-up call from a swarm of federal agents.
That new wireless router. He'd gotten fed up trying to set a password. Someone must have used his Internet connection, he thought.
"We know who you are! You downloaded thousands of images at 11:30 last night," the man's lawyer, Barry Covert, recounted the agents saying. They referred to a screen name, "Doldrum."
"No, I didn't," he insisted. "Somebody else could have but I didn't do anything like that."
"You're a creep ... just admit it," they said.
Law enforcement officials say the case is a cautionary tale. Their advice: Password-protect your wireless router.’ – Associated Press (2011). Retrieved from http://www.cbsnews.com/news/unprotected-wi-fi-getting-owners-in-trouble/

4 Small to Medium Sized Network Security Solution part 4



 The Advantages of UTM
The advantages have to do with simplification and cost advantages. Less total hardware, simplified management, and licensing. Lower Total Cost of Ownership (TCO) including administrative expenses.
The disadvantages include lower performance, vendor lock-in, single point of failure, limited feature set, and difficult to scale in larger environments.
Included in the UTM solution space is Next Generation Firewall Products (NGFW).
Research firm Gartner defines UTM as a product that offers:
• Standard network firewall functions;
• Remote Access and site-to-site Virtual Private Network (VPN) support;
• Web Access Gateway (WAG) functionality with anti-malware, URL and content filtering;
• Network Intrusion Protection System (NIPS) focused on blocking attacks against PCs and servers.
The standard and Next-Generation Network Firewall (NGFS) functions include:
• The ability to track and maintain state information for communications to determine the source and purpose of network communications.
• The ability to allow or block traffic based on configured policy (which can be integrated with the state information).
• The ability to perform Network Address Translation (NAT) and Port Address Translation (PAT).
• The ability to perform application aware network traffic scanning, tracking and control.
• The ability to optimize a network connection (i.e. using TCP optimization).
Remote Access and Site-to-Site VPN functions include:
• The ability to connect multiple sites securely using a VPN (i.e. IPsec, SSL).
• The ability to have clients connect from remote locations securely using VPN (i.e. Clientless SSL, IPsec and SSL client).
• The ability to connect to the device from a remote location for the purposes of management (i.e. HTTPS, SSH).
Web Access Gateway functions include:
• The ability to perform URL filtering.
• The ability to perform web application monitoring and control.
• The ability to perform web Application Firewall (WAF) functions.
• The ability to perform antivirus and anti-malware scanning.
• The ability to perform HTTPS scanning (decode).
Network Intrusion Protection System (NIPS) is tasked with detecting network attack traffic and offers the ability to alter the action taken on the traffic based on policy. A NIPS component offers a number of different options for detecting attacks, including:
• The ability to detect based on signature.
• The ability to detect based on anomalous activity.
• The ability to detect based on behavioral analysis.