Thursday, June 17, 2010

Free and Commercial Firewall Analysis Tools

Q:Hello,

Do we have a tool for analyzing Cisco ASA/PIX and router config files? The client has a 2500 line config, and I would like to be able run some reports on the configuration.

Thanks,

A:,
There are several audit tools with different features. The most common features in these tools are:
  • Rule Analysis to detect security holes in the configuration (e.g. allow any)
  • Configuration Analysis to find duplicate/overlapping unnecessary setting/rules/object
  • Logfile analysis to find most used rules objects
  • Rulebase analysis to find unused/unconsolidated objects rules
  • Simulation of changes.
  • Risk Analysis
  • Access Analysis using multiple firewall rules (Can Point A reach at Point B using service C)
  • Workflow automation
  • Backup management
  • Normalization of different firewall rules (e.g. Cisco Juniper Check Point on the same format)
  • Change Management
  • Regular Log Analysis

Of course, it is not possible to find all features on all solutions. Firewall vendors do also provide several tools to make audits easy.

That being said, I have seen 2 freeware config audit tools for Cisco (RAT and Nipper)
http://www.titania.co.uk/ Nipper
http://ncat.sourceforge.net/ RAT

Commercial Area is more active and they usually cover the known suspects (Check Point, Juniper, Cisco, Fortinet):

http://www.tufin.com SecureTrack, SecureChange Workflow
http://www.algosec.com Firewall Analyzer, FireFlow
http://www.securepassage.com Firemon
http://www.manageengine.com Firewall Log Analyzer
http://www.skyboxsecurity.com/ CertiFire, Firewall Analysis
http://www.redseal.net/ Redseal Vulnerability Advisor
http://www.athenasecurity.net FirePac, Verify

Let me know if you have a specific question.
cheers,
- yinal

HIPS and VPN Concentrator Network Deployment

Q: How decide the placement of Host Based Intrusion prevention System & VPN Concentrator
What is criteria to decide the placement of HIPS and VPN Concentrator.

A: Hi XXXXX,
Your question generated more questions than answers : )
Here is how I think on where host based IPS should be:
  • HIPS should be installed on hosts which need IPS (based on risk assessment).
  •  HIPS should not be installed on hosts where installing a 3rd party agent may decrease the reliability of the services on the host system
  • HIPS should not be installed on hosts where installing a 3rd party agent may slow down the speed of the host system due to extra resource utilization, added latency etc.
  • HIPS should be installed when it is possible to manage HIPS. In large scale deployments remote installation, central management etc are usually more important than security.
Here are the important points of VPN Concentrator placement:
  • It is recommended that your VPN concentrator has trusted and untrusted segments (It is also possible to deploy one-arm single interface deployments – but for management and audit I do recommend 2 segments – where untrusted segment is Internet facing
  • Untrusted segment should be protected by a firewall  (usually in a dedicated DMZ) even if all VPN vendors claim to be very secure. Make sure that the firewall protecting your VPN supports IPSEC pass through (if you are using IPSEC).
  •  Instead of hooking the trusted (Internal) segment into your (internal) networks, connect your trusted segment back to the firewall so that decrypted traffic is firewalled. If you have an IPS make sure that IDS/IPS is inspecting decrypted traffic.
  • Make sure that you have a dedicated management network to manage the VPN concentrator. If you do not have an extra management interface, use trusted interface for management. Do not allow management over untrusted interface.
  •  Do not deploy NAT before the VPN traffic hits your concentrator,  try to use real public IP address (es)  on the untrusted /public  side of your concentrator   since using private addresses may create configuration nightmares
  • Check destination networks for VPN clients / or remote VPN sites on your network. Analyze the protocols. Sometimes based on the nature of the traffic (e.g. complex VOIP)  you may need to hook your concentrator directly into your network.  Always check reverse routing for VPN networks.
  • Verify IP addressing assignments for VPN clients, choose a subnet that will not create internal routing problems (e.g. overlapping IP address space. Dynamic routing etc). If you are dealing with site to site VPNs make sure that you address overlapping IP address spaces.
  • Check the location of authentication servers. The placement of the concentrator must be is close/redundant proximity to authentication servers (AD, RADIUS, TACACS, LDAP etc). Make sure that the communication with auth servers is not a n issue
  • Verify multiple entry points, if you are deploying concentrators in HA, make sure that failover works properly, and NAT issues, IP address assignments for different concentrators  are configured properly. Also make sure that your access logs can be unified.

Let me know if you have a specific question,
Cheers,
- yinal

Saturday, June 5, 2010

Why did Symantec buy Verisign's security business ?

Q: Why did Symantec buy Verisign's security business ?
A 3.5 revenue multiple for a revenue stream comprising largely of a commoditized business (SSL) begs for a strong rationale that goes beyond pure top line growth for this acquistion. Would love to hear of use cases that this will enable that will result in new products/offers from this combined entity.

A: Here are quick comments:
1- Symantec will have direct access to almost all major enterprise accounts using Verisign's SSL certificate relationship. there are a lot of cross-sell opportunities for Symantec such as securing server 2 server communication. On the retail side Symantec can cross sell Norton line at Verisign's high-volume SSL online store

2- Last year Verisign asold MSS (to Secureworks) and security consulting (to AT&T) units, these were the overlapping units for Symantec. The security products that Symantec acquired from Verisign do not have an overlap with Symantec's existing portfolio.

3- Related with the note above, Symantec could not provide full identity management solutions. With Verisign acqusition (SSL certificates, Trust Seal, PKI, VIP ) they will fill-in a big gap. This creates a nice go-to-market plan. e.g. Hosted PKI, Norton Identity Safe etc..

4- All cloud based / remote management solutions (e.g. HEP from Symantec) rely on certificates, Verisign acquisition will play a strong role for Symantec's cloud strategy. Identity security is a key block in delivering cloud based solutions for data security and compliance.

5- Check-out PGP and GuardianEdge acquisitions. They will all integrate well with Vontu line when Verisign's solutions are added to the mix..Verisign complements encryption really well. Re-evaluate data at rest, data in transit and data in use terms : )

6- Verisign has a good brand name, Symantec can definitely leverage the Verisign name

7- The value of the deal can be multiplied if Symantec manages to integrate security solutions (inlcuding this Verisign Portfolio) with its Veritas, Altiris, MSS, and Hosted Security (MessageLabs) lines.

Let me know if you have a specific question,

regards,
- yinal ozkan
 (on personal behalf)

DLP as a Service: What's the business case for this?

Question:
DLP as a Service: What's the business case for this?

Answer:
Xxxxxx,
DLP can leverage all the advantages of service-alization on legacy information systems.
If we define service a standard offering delivered by a service provider, business case (of DLP as a service versus technology solution) can be summarized as:
1- Leveraging economies of scale with utilizing shared resources at service provider
2- Leveraging deep-dive technical specialization at service provider since service provider can effort dedicated specialists (not because they are more intelligent). Levering know-how gained from managing multiple customers.
3- Measurements and metrics program guaranteed by service level agreements
4- Ability to scale up/down easily, more reliability and redundancy on the provider side.
5- The old capex vs opex discussion
6- No operational worries (e.g. who will patch my appliance) / focus on core business goals, competitiveness
7- Pay as you go elastic service.

But if you look at DLP specific cases, the answers could be categorized in many different buckets. (this might be different for different organizations). We believe that a DLP program must include
• DLP program management (GRC, Policies , Procedures)
• Endpoint enforcement components,
• Secure remote access components,
• Data classification & governance components,
• Encryption components
• Rights management components.
• Training and user awareness component
• Incident management component
• Central monitoring , Access Control, RBCA the usual InfoSec components

This can all be offered as a hybrid service of people, process, technology and managed services. Usually an important component of DLP program is the network based DLP gateway solutions. A managed offering for network level DLP gateway may offer
1- Ability to get a clean pipe from service provider (e..g prevention in the cloud)
2- Ability to leverage a wide set of solutions for the recognition of different data types / file formats since service provider is developing the service for other customers
3- Ability get experts for custom scripting (yes you will need this)
4- Transparent deployment
5- Correlation of events with other network activities (e.g. IPS, Anomaly Detection, Content security solutions, Firewalls, AV etc)


Type rest of the post here

Open Source IDS/IPS

Question : Are there an open source IDS or Firewall which alert the command center or system administrator by pager, e-mail or cell phone when an event listed on the company’s security event list is triggered?

Answer:
Xxxxxxxxxx,
The answer will be based on the company’s security event list. The first prerequisite is that you need to find an opensource IDS or Firewall that can detect security events in the list. Detection success rate will be based on the complexity of the security events in your list.

Firewalls are usually not very good in malicious activity detection so IDS/IPS is a better idea. Snort is a good start (http://www.snort.org/) . It is opensource and it allows you to configure your custom detection signature and rules.

Alerting is simple, you can configure Snort to alert via e-mail E-mail messages can be converted to SMS and pager messages easily. (you may need to pay for SMS messages depending on the destination and or geographic location)

For IDS/IPS deployment you have to be careful. You might be receiving millions of alerts so forwarding them as a message might not be the best good idea. You need to tune your IDS to report real incidents only (e.g. you may have detected 1 million identical events but all you need is to know what the incident is when it started and what is the frequency). Also remember that Snort will only inspect cleartext traffic in day1 unless you are decrypting the encrypted traffic.

Another approach is to use a Security Information Event Management Solution in addition to the IDS. Forward all Snort alerts and other alerts (e.g. Windows logs, Syslog) to your SIEM tool and make sure that the SIEM consolidates normalizes and correlates the alerts for you, so that you receive the ultimate information from SIEM instead of IDS tools. There are opensource SIEM tools like OSSIM (http://sourceforge.net/projects/os-sim/) and Cyberoam iView (http://sourceforge.net/projects/cyberoam-iview/files/)

Let me know if you have a specific question,

Cheers,
- yinal

Tuesday, March 23, 2010

Securing Offshore Remote Access

Question:
How to secure data and protect intellectual property while allowing remote access to remote consultants / outsourcing partners / offshore captive operations?

Answer:
This is a long procedural and legal discussion. Restriction of access for remote administrators / consultants / offshore centers is not an actual “productivity” solution, so there is a clear need for sharing data in an intelligent and secure way.
Recently I have seen several discussions on policy based governance and operational controls but I was disappointed with the available technical options. Most of the articles I have seen so far were limited with phrases like “We do use firewalls”, ”We have SAS 70” , “We have strong authentication” or “We do have encryption” type of over the counter canned answers. The most joyful one was (this was on an overseas web site describing how secure the outsourcing operations were) : “We do use SecureFTP”
Well, basic technical controls are nice, like using scrubbed test data, segmenting servers,  using strong auth, physical data center security, or using full VPNs..But, what if the requirement is to have real controls?

The technical controls can be deployed at 2 layers:
1-    Controls at the Offshore Center: Regardless of the desktop security controls, endusers at remote data centers can access and steal critical data, at the end of the day, who will stop them if they can take a 5 megapixel shot of their screens with their cell phones. So it is a good idea to have a CCTV / camera based monitoring where access stations are (All remote access should be limited to secured facilities where it is possible – try to avoid roaming laptop based remote workers). I use the term access station because it makes no sense to have regular desktops at offshore operational centers.  Using terminal server type of solutions are great but citrix/terminal server type of emulations do not work great for developers. I like virtual desktop infrastructure (VDI) for developers since it gives them full independence in a controlled environment.  Base station should be thin clients or must be managed (e.g. group policies with limited user rights) even if they are using the base station only for terminal session.
If you do not have a captive center, and you do not have the full control on remote desktops or you cannot enforce thin client stations or managed workstations, securing the other endpoint (where terminal connection/citrix/VDI term is run) is very difficult. On these cases, make sure that you require VPN connection from individual endpoints so that you can control split tunneling, and you can apply /enforce pre-auth/during-auth posture checks very much like a NAC. The idea is to enforce endusers to install a security applet before they login to your network and run cleaning prior to auth. Create onetime secure virtual workspace that expire at the end of the session. You may also create remediation and quarantine options for non-managed remote access.
When you are securing the remote offshore centers never skip the “air” piece. Roque AP detection is a key feature. Your remote switch must detect any attached device to network esp if it is working as a switch. Also your policies must limit usage of cell phones and other wireless gadgets.
Of course endpoint security is still a key, like using full group policies, firewall/IPS, antimalware, antivirus, encryption, rights management etc, but it is much better to have it on a VDI system. It is also easier to control peripherals on a VDI.
Non-repudiation is another important point. Like the physical camera, a secure remote tamper proof logging facility is highly recommended.
2-    Controls at the server level: Consultants / remote system administrators/ offshore developers do need to access servers in development, test and sometimes production environment. It is a mandate to enforce individual user identities, with full access audit. Actually you can steal the PCI requirements.  There are systems that record every single move (literally on a video file  - ObserveIT) of a remote administrator. Or you can basically deploy privilege escalation management systems integrated with jump servers (e.g. SSH proxies, Power Broker) Need to know access is essential, but even after policy decisions, make sure that every activity is logged at different layers (network layer, OS layer, DB layer and Application layer) Remote admins should never access to log settings or the log repository (tamper proof logging is the key). This is the time to put SIEM solutions in use. Write correlation rules to alert you when suspicious activity is detected.
Segmentation is another key, but today’s high speed computing makes network level firewalling very difficult. (If you have 100 servers with only 1 Gbps NICs, you will a 100Gbps full duplex firewall ,  and as of today there is no IPS). I do expect switch vendors to offer port based filrewalling / IPS in the very near future but not today unless you have 7 figures to spend. Either way segment your servers at network level as much as possible, Even if you are using VMware, categorize servers physically according to their risk levels. There are also creative solutions like Apani Networks, Rohati Networks (now Cisco), or the NAC vendors for network based segmentation using user identities. Basically segmenting users with their user IDs instead of their source and destination addresses is better. You can even utilize secure de


Again, none of the technical controls eliminate the need for governance, policy based controls and the risk management frameworks.
Full data life-cycle management, data privacy, data security, audit program, security management program (like ISO 27001)  are all essential. But technical controls do really help you to reach your security objectives.

Let me know if you have a detailed question

Regards,
-    Yinal Ozkan

Monday, February 8, 2010

Security awareness - what worked for you

Question:
I am interested to know from you guys what methods you have used to prick the consciousness of your end users - from the standard policy delivery & enforcement tools (e.g. neupart, policy matter, netconsent, et al), through posters & startup screens, right through to "guerilla tactics" rather like Chris Nickerson & hisd guys who did the job on the car dealer.

I had thought of gearing ideas around end user pain points - e.g. post-it notes with a PIN on a dummy credit card, etc. Interested in what low-cost ways others have used.

Thanks in advance guys

Answer:

........,
I have gone through several iterations of awareness initiatives. Web based, class based, print media based, campaign based you name it…
Information Security Practitioners usually skip a very important part of awareness programs, these programs are not security projects where you deliver a technical solution; awareness programs depend on the training component…
Here is the most important thing I learned: Adult psychology is different, you cannot train adults as you train kids.. When you put kids a in a class they simply listen and they learn. Adults never do, they keep questioning: “ Why I am here? Is this good for me? What will I lose if I do not listen? What is in it for me? etc”  The questions above must be answered within security awareness initiative since they will keep occupying the short focus of the of the adult minds during training..
So the important structural shift of awareness program initiative is that this is not a project, this not about a portal with multiple choice questions with diagrams, this is not about an application that pops-up,  this is about training, and the adult training rules apply.
Years ago, I was in charge of security awareness training  of a large trading house.. Participation of all employees was mandatory. Everybody in the class (pre WebEx days) thought this was yet another training, and the eyes were focused on the clock.. I started the conversation with, “I am reading all your e-mail” Well, I got the attention. The whole class got mad . But we had established the training rationale, everybody wanted to how and why I was able to read their e-mail , they were questioning on who else can read their e-mail. Until that moment most of them thought the problems were someone else’s.
In order to share create the  personal interest, the best way is to demonstrate vulnerability in day to day applications with live demonstrations (not the checklists, and the pop-quizzes) that employees can associate themselves individually.  The demo should not be about the millions that a distant company lost (yes we all heard about TJ Max) or powerpointing defaced web sites to death to bore sales team away. There must be personal interest in security awareness program. Unfortunately not too many people care about the greater good of their employers or the security teams…A salesperson will be more interested so see his CRM database being stolen using his own small blackberry.  Or displaying chain of evidence for intellectual property for design engineers, more examples can be given but I think everybody who has managed to read until this paragraph gets the idea; unless there is personal interest there won’t be success.
That being said classical program components like continuous improvement, cyclic approach, audit, measurement/metrics etc will help. ISO programs or the programs like neupart can be used as a good base program management.
-Regards,
-          Yinal Ozkan

Sunday, December 6, 2009

Using Certificates for Authentication ? Where to store them ?

Question: 
Has anyone deployed a VPN solution that leverages user certificates for authentication?
We are considering the possibility of leveraging digital certificates as an authentication factor for VPN. Has anyone implemented this or looked at solutions that do this? We are not comfortable with solely relying on a certificate and the security/integrity of the PC as an authentication mechanism. If you are currently using certificates, I would be interested in hearing how you are deploying this.

Answer:
.....,
The short answer is yes.  We did deploy several off-the-shelf certificate based authentication solutions for remote access VPN systems such as Cisco, Check Point, Juniper, Citrix, Nortel.. It is again very possible to deploy similar solutions over SSL VPN solutions (This time easier since browser is the client).   I worked with Entrust as the PKI integration provider.  When using certs, most of the questions/problems are generic PKI related questions (CRLs,  OCSP, identity management etc)


9 out of 10, enterprise shops store the certs on PC or mobile devices since they want to avoid using tokens/smart cards. Using a 3rd party storage is ideal but to be honest smart cards share the fate of PKI for complexity so many solution sets avoid tokens/smart cards, unless the policies mandate certificates.
When smart cards are more expensive/complex (readers, personalization etc) enterprises use USB tokens to store certificates. (Several companies  provide tokens with certificate support, ActivIdentity, Aladdin, Authenex, Entrust, SafeNet (merged with Aladdin) , RSA (RSA has a hybrid token for OTP + certs)).


If you would like to use smart cards as the certificate container, or use the same certs for physical security simultaneously, you can simple take one of the ready to use HSPD-12 Personal Identity Verification (PIV) Card solutions (http://fips201ep.cio.gov/apl.php) so that you can avoid designing all components architecture yourself.


Of course do it yourself path is more fun, technically it is straightforward to integrate certs with any 802.1x based authentication server but as you know it usually gets more complex. We have deployed a complete system for enrollment, biometrics, cards, CMS etc, (took 3+ years)


cheers,
-     - yinal ozkan