Educause Security Discussion mailing list archives

Re: Thoughts on Jericho Forum


From: Bruce Curtis <bruce.curtis () NDSU EDU>
Date: Mon, 18 Jun 2007 13:20:55 -0500

On Jun 17, 2007, at 7:28 PM, Jordan Wiens wrote:

I'm in total agreement that the "perimeter" that we have now is not
the same defensible position that once existed.  That said, there's
still a lot of value in a /detection/ model that takes into account
natural bottlenecks for traffic.

  We currently make use of network data.  For example if we detect
that a machine is sending SPAM from our campus network we block it's
MAC address.

  If I were forced to put something at the perimeter edge I'd
install an IPS before a firewall.  An IPS might have a false positive
and block traffic, a firewall is designed to block traffic (and a
firewall causes problems with video and is a flow based device so it
becomes a liability when a bunch of machines behind the firewall are
compromised and scanning, the scanning can overload the firewall and
cause packet loss for legitimate traffic).

While I know that all manner of malicious code enters campus by
legs, bikes, cars, and buses, once it's here and on the network,
most of it--nearly all of it--will be trying to talk to the
internet at large.  There are many problems with trying to keep
malware from ever getting on campus, however no matter how it
arrives, I can at least detect it based on those few places where
traffic's aggregated enough to support consistent and thorough
analysis.

  While I don't disagree that there can be some useful info obtained
from network traffic our goal is to have all traffic on our network
encrypted.  The closer we get to that goal the less useful network
traffic info from the perimeter is.

  An example about encryption in general is that when bot herders
use encrypted traffic between the bots (infected hosts) and bot
controllers it will be a lot more difficult to detect that the
session seen at the perimeter is a bot control session.

  The trend I see for the future is for the info from the perimeter
to be less and less useful as more and more traffic is encrypted.

---
Bruce Curtis                         bruce.curtis () ndsu edu
Certified NetAnalyst II                701-231-8527
North Dakota State University

Current thread: