home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Powered by InformationWeek Business Technology Network
InformationWeek 500 Conference -- September 14-16, 2008 Registed Today!

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


8th Annual Well Connected Awards
F E A T U R E  
SECURITY

New Security Threats - Stronger Defenses

  May 13, 2002
  By Mike Fratto


TOC Issue TOC
Printer Print this page
Printer Print full article
Printer Download as PDF
E-Mail E-Mail this URL
 
  In This Article
arrow
Product of the Year
arrow
Winners & Finalists By Category
arrow
Heads Up
arrow
Web Links
A seemingly endless stream of new vulnerabilities made news this past year. Bill Gates touted turning Microsoft on a dime with a new security focus while Larry Ellison hawked Oracle software as "unbreakable." Microsoft, @Stake and friends joined forces to prevent full disclosure on software vulnerabilities. Oh, and let's not forget CodeRed, Nimda, CodeRed II and a host of other embarrassments.

Speaking of embarrassments, the unbreakable Oracle was, well, broken. Several times (see "Covert Labs Warns of Oracle8i Vulnerabilities"). The fact is, nothing is unbreakable. Superman could be felled by Kryptonite. Captain Kirk's weakness was women. The Six Million Dollar Man couldn't function without batteries. And the worms rampaging across the Internet during the summer of 2001 showed just how fragile our networks are. As for Gates' making security a priority, only time will tell if Microsoft will succeed (see "Should We Trust Microsoft's Security Push?"). And as for trying to squelch full disclosure, if vendors can keep you in the dark, the more likely they are to separate you from your money (see "Microsoft Pushes Cone of Silence").




By now you should know there is no silver security bullet. The defense-in-depth strategy dictates that, starting at the network edge and moving in toward your most important assets, your defenses should become more restrictive and tightly tailored to specific security problems. For example, a stateful packet-filter firewall, such as Check Point Software Technologies' VPN-1 Pro or Cisco Systems' PIX, is fine on the edge, but as you move closer to Web and e-mail servers and other critical resources, application proxy servers, such as Secure Computing's Sidewinder and Symantec's Enterprise Firewall, provide tighter control--though often at a performance expense.

But defense in depth, while important, is still mainly product-focused--what widgets get deployed where. Before you even get that far, focus on the three pillars of network security: authentication, access control and auditing.

Authentication: Who Is It?

Authentication plays a big part in most of the security products we test (see "Authentication Gets Tough"). It's a myth that passwords are not adequate protection for many applications. With the exception of biometric devices, nearly all authentication comes down to a password (a PIN is, after all, just a numeric password). For example, digital certificates, often thought to provide strong authentication, are protected by weak passwords. Although they're well-suited for targeted, high-value applications, both biometric readers and security tokens, including USB tokens, are still too expensive and cumbersome for wide deployment. Passwords, on the other hand, are relatively inexpensive and have nearly universal support.

But passwords fail because users pick easy-to-guess passwords--even when they are forced to use symbols and numbers. And precious few security applications--including firewalls, VPN systems, PKI tools, disk- and file-encryption schemes and IDSs--let you enforce password complexity. Luckily, with the ubiquity of LDAP-enabled services, we may see a move back toward single sign on, with the directory consolidating user authentication.

Access: Who Can Do What?

Access control can be dealt with on many levels, each particular to who is attempting to do what. Typically, access-control products restrict user access to OS objects and program functions. However, many technologies-- firewalls, VPNs and even antivirus products with active scanning--are, in reality, access-control products.

Firewalls, with the exception of a vendor's firewall client, generally don't provide user-based access control. However, the closer you can place firewalls to destinations or sources, the tighter you can control access. For example, perimeter firewalls control access for all the nodes they protect, and that leads to the "hard candy shell/soft, chewy middle" syndrome. In contrast, multiple firewalls throughout your network mean multiple defenses to break through. Desktop firewalls are making great strides in pushing security to the edge. Products from InfoExpress, Symantec and Zone Labs provide not only port blocking but application network-access control and privacy protection (cookie management and ad blocking, for example). The protection is not perfect; in fact, a well-written e-mail virus could defeat most of these products. But the theory is good--place access control, for both users and applications, close to the edge, where many of the problems lie, and target user and process access control (see "Defense Mechanisms").

User access control can be managed via education and finely tuned systems. But the crux of the matter is that you need to tighten access control at the OS level through sandboxing. Application sandboxing defines a set of resources, such as memory, disk space, network ports or calling other applications, that an application can access. The application cannot go beyond its boundaries. Typically stated in a positive manner, such as "Only Microsoft Word is allowed to write to .DOC files," sandboxing protects your critical systems from modification and exploitation. Although the products in this market are still young, expect the time spent properly configuring and deploying application sandboxing to pay off the next time a worm tries to crawl across your network.

Auditing: What Did What?

Authentication and access-control processes lose effectiveness when you lose track of who is doing what. The more you audit, the more you have to review: Firewalls, IDSs, routers and authentication servers spew tons of audit logs daily in a slew of formats containing all kinds of data.

But there are two distinct but related challenges with audit data. The first is aggregating data from multiple sources into a central repository. This is simply a matter of processing power, storage and integration with typical and proprietary reporting formats. The second is processing and correlating disparate events, and presenting the data for human consumption. The latter part is by far the harder task because the traffic patterns have to be defined, the events have to be identified across platforms, and intelligent connections have to be made to decipher the events. Security information management, or SIM, is still in its infancy, but the promise is clear--the data that can be mined from your network devices can go a long way toward getting a grip on security (see "Connect the Dots").

Your Mission...

Athletes, musicians and other professionals will tell you that practicing the basics--throwing fastballs or playing scales--keeps their skills finely honed. If the basics suffer, so do the advanced skills. Same is true for network security. To reduce your vulnerability to attack, keep going back to basics. Do vulnerability analyses to see what resources are ripe for attack. Lock your servers down tight with as few permissions as possible. Don't accept the defaults of any installation without understanding what the defaults mean. Restrict network and server access--inbound and outbound. Deploy virus scanning on mail and file servers and on the desktop, and keep your virus data files up to date. Treat remote-access users as hostile, and limit what they can do. Log everything.

But security can't be laid entirely at the network manager's feet. Vendors must focus on the basics as well. Their programmers and system designers should follow good coding practices. Buffer overflows are all the rage in the press, but other conditions, such as improper use of temp files, race conditions and program logic flow problems, can open a door. If vendors are using externally developed libraries, they should do their own QAs on the libraries to make sure their software isn't compromised, as happened with the zlib double free vulnerability.

Vendors should take the possibility of attacks seriously. They should design security into every product from inception, not as an afterthought. And if they don't do so, hit them where it hurts and take your business elsewhere.

Mike Fratto is a senior technology editor based in Network Computing's Syracuse University Real-World Labs®; he covers all security-related topics. Prior to joining this magazine, Mike worked as an independent consultant in central New York. Send your comments on this article to him at mfratto@nwc.com.



Heads Up: Security

Companies

Riptech: Management services are a dime a dozen, but in-depth security-information data mining and trend analysis set Riptech apart.

TippingPoint Technologies: The company's UnityOne combines intrustion detection, vulnerability scanning and firewall/VPN capabilities in one device. All three features work together for active security.

Products

Flatrock Instant Extranet: Simple-to-use, IPsec-based VPN could be extended with more features, making a compelling case for distributed extranet installations.

ForeScout Technologies ActiveScout: Automatically detects and deflects active network attacks.

Okena StormWatch: Offers application sandboxing for the OS and the applications running on it. You provide the permissions for application access, StormWatch enforces them.

Postini Active EMS: Tracks and monitors SMTP in real time; uses McAfee AVERT for in-line virus scanning, spam filtering and detection of attacks against Port 25.

Technologies

IETF IPsec Working Group: Actively trying to improve the current set of IPsec protocol drafts.

Security Assertion Markup: Provides an XML framework for products to exchange authentication and authorization Language (SAML) data.




Web Links

"Security Information Management: Connect the Dots" (Network Computing, April 1, 2002)

"Check Point Offers Provider-1 NG FP-1 for Managing Multiple Firewalls" (Network Computing, March 18, 2002)

"With Flatrock Instant Extranet, Building a VPN Is as Easy as Skipping Stones" (Network Computing, April 2, 2002)

"PGPvpn Keeps IPsec Simple" (Network Computing, Feb. 4, 2002)

"NetScreen's Global Pro Express 3.0 Simplifies Multifirewall Management" (Network Computing, Jan. 7, 2002)



start top introduction Winners & Finalists By Category





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo Jitter
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet Evolution
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights