Educause Security Discussion mailing list archives
Re: Thoughts on Jericho Forum
From: Bruce Curtis <bruce.curtis () NDSU EDU>
Date: Mon, 18 Jun 2007 13:20:55 -0500
On Jun 17, 2007, at 7:28 PM, Jordan Wiens wrote:
I'm in total agreement that the "perimeter" that we have now is not the same defensible position that once existed. That said, there's still a lot of value in a /detection/ model that takes into account natural bottlenecks for traffic.
We currently make use of network data. For example if we detect that a machine is sending SPAM from our campus network we block it's MAC address. If I were forced to put something at the perimeter edge I'd install an IPS before a firewall. An IPS might have a false positive and block traffic, a firewall is designed to block traffic (and a firewall causes problems with video and is a flow based device so it becomes a liability when a bunch of machines behind the firewall are compromised and scanning, the scanning can overload the firewall and cause packet loss for legitimate traffic).
While I know that all manner of malicious code enters campus by legs, bikes, cars, and buses, once it's here and on the network, most of it--nearly all of it--will be trying to talk to the internet at large. There are many problems with trying to keep malware from ever getting on campus, however no matter how it arrives, I can at least detect it based on those few places where traffic's aggregated enough to support consistent and thorough analysis.
While I don't disagree that there can be some useful info obtained from network traffic our goal is to have all traffic on our network encrypted. The closer we get to that goal the less useful network traffic info from the perimeter is. An example about encryption in general is that when bot herders use encrypted traffic between the bots (infected hosts) and bot controllers it will be a lot more difficult to detect that the session seen at the perimeter is a bot control session. The trend I see for the future is for the info from the perimeter to be less and less useful as more and more traffic is encrypted. --- Bruce Curtis bruce.curtis () ndsu edu Certified NetAnalyst II 701-231-8527 North Dakota State University
Current thread:
- Re: Thoughts on Jericho Forum, (continued)
- Re: Thoughts on Jericho Forum Lovaas,Steven (Jun 14)
- Re: Thoughts on Jericho Forum Mclaughlin, Kevin (mclaugkl) (Jun 14)
- Re: Thoughts on Jericho Forum Deke Kassabian (Jun 14)
- Re: Thoughts on Jericho Forum Lovaas,Steven (Jun 14)
- Re: Thoughts on Jericho Forum Karen Duncanson (Jun 14)
- Re: Thoughts on Jericho Forum Bruce Curtis (Jun 14)
- Re: Thoughts on Jericho Forum Bruce Curtis (Jun 14)
- Re: Thoughts on Jericho Forum Bruce Curtis (Jun 14)
- Re: Thoughts on Jericho Forum Cal Frye (Jun 14)
- Re: Thoughts on Jericho Forum Jordan Wiens (Jun 17)
- Re: Thoughts on Jericho Forum Bruce Curtis (Jun 18)
- Re: Thoughts on Jericho Forum Gary Flynn (Jun 19)
- Re: Thoughts on Jericho Forum Bruce Curtis (Jun 19)
