Wednesday, December 17, 2008

Traffic Talk 3 Posted

My third edition of Traffic Talk, titled Network Security Monitoring: Knowing Your Network has been posted. From cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 article:

Recently I read an interview with network security pioneer Marcus Ranum, who was asked cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 following question about network security monitoring: "In your opinion, what is cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 current weakest link in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 network security chain that will need to be dealt with next year and beyond?"

Read my article to see what Marcus wrote and how I responded.


Richard Bejtlich is teaching new classes in DC and Europe in 2009. Register by 1 Jan and 1 Feb, respectively, for cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 best rates.

4 comments:

Ken Bradley said...

Hmmm. Marcus comments could not be any more true. Definitely words for any network owner to adhere to.

Know your network.

My recent professional experience with large scale (>100,000 hosts) environments that were plagued with persistent intruders lead me to write a document describing cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 solution, at least a method of deterrence. I was almost disappointed after putting all my experience togecá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r, researching cutting edge technology to address weaknesses and organizing a fabulous deliverable. In cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 end, 30+ plus pages were basically summed up in one phrase - Get Back to Basics, Security 101.

Well said Marcus. Richard, thanks for getting cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365se thoughts some publicity.

H. Carvey said...

...what's actually out cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365re, which systems are crucial, which systems hold sensitive data...

ugh, how true. As an incident responder, I see this all cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 time...lack of network awareness, lack of knowledge as to where sensitive data is processed (or at rest). So far, most folks want to see some kind of new-fangled, high-speed thing as "best practices", because for some reason cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365y just don't get it that it's all about getting back to cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 basics.

How many times have I worked with a customer who swore to me that cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 sensitive data on a system was encrypted, only for me to find that eicá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r (a) it wasn't, or (b) cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365re was ocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r sensitive data on cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 system that wasn't encrypted?

The big driver towards all this is now regulatory and legislative requirements. Visa PCI. NCUA. HIPAA. State notification laws. Some of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365se imply cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 need for network knowledge and response, ocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365rs come right out and say it!

Chris Buechler said...

One discovery method you didn't note is ARP scanning. That will get most firewalled hosts unless cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365y have a modified network stack that won't respond to ARP queries.

Granted that's very difficult in large scale networks since you need a box on each broadcast domain, or to interact with something on each broadcast domain. But when looking at a single subnet, that's something I always like to use as part of a more comprehensive strategy. arping is one such tool
http://www.habets.pp.se/synscan/programs.php?prog=arping

test said...

A very excellent Traffic Talk, probably my favorite so far. I particularly enjoyed your hypocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365sis on importance because that is one aspect of using NSM data that I had never really considered before. Thanks.

@Chris Beuchler:
I have used Arpwatch on local network segments with much success and if you are performing NSM and already collecting full-content or session data, it is trivial to run on your sensor.