Home > Ask the Security Experts > Network Security Questions & Answers > How helpful is the centralized logging of network flow data?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How helpful is the centralized logging of network flow data?

Mike Chapple, featured expert EXPERT RESPONSE FROM: Mike Chapple, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 11 January 2008
My organization is implementing centralized network flow logging. To what extent will better knowledge of network utilization help our security posture, and what are some common pitfalls to look out for?

>
Centralized logging of network flow data is an extremely valuable mechanism for both security and network professionals. Logging provides a single, authoritative record of all connections between a network's systems, including the amount of data that passes over each connection.

These records can help security professionals when responding to an incident. During an attack, for example, network flow information often effectively reveals the quantity (but not content) of a network's extracted data. The logged info can also help identify systems infected with malicious code. Networking professionals can use the data to troubleshoot network anomalies and analyze bandwidth utilization. I strongly recommend network flow logging as part of a well-rounded security program.

Two common pitfalls come to mind, though: user privacy and storage capacity. Many organizations logging flow data don't think about privacy concerns because they're only retaining connection-level data and not logging packet payloads. The destination IP addresses in outbound connections, however, may also contain sensitive personal information about, say, the Web sites visited by a user. Depending upon your organization's privacy policy, this may be a significant concern.

Additionally, in a large enterprise, flow data may quickly consume large quantities of storage space. You'll need to estimate your storage needs and develop a retention policy that balances business needs with the technical capabilities of the system.

More information:

  • Fellow expert Joel Dubin explains some challenges that occur when designing a logging mechanism for peer-to-peer networks.
  • Myriad devices produce waves of logs. See how to get all that network data under control.


  • BROWSE BY TAG
    Network Security,   Network Intrusion Detection and Analysis,   Network Behavior Anomaly Detection (NBAD),   Enterprise Network Security,   Monitoring Network Traffic and Network Forensics,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Network Security
    How to set up a split-tunnel VPN in Windows Vista
    What is the difference between static and dynamic network validation?
    Port scan attack prevention best practices
    Securing the intranet with remote access VPN security
    How to prevent network sniffing and eavesdropping
    How to implement virtual firewalls in a complex network infrastructure
    How to manage network bandwidth with distributed ISP bandwidth
    How to edit group policy objects to give a user local admin rights
    How to prevent operating system cloning with AES 256-bit encryption
    How to securely connect a LAN POS to a remote point-of-sale device

    Network Behavior Anomaly Detection (NBAD)
    Trend Micro to acquire Third Brigade for virtualization, cloud security
    Use BotHunter for botnet detection
    Is centralized logging worth all the effort?
    Can reputation services be applied to network security?
    SIM and NBA product combination is powerful
    Can network behavior anomaly detection (NBAD) products stop rootkits?
    Sourcefire, Nmap deal to open vulnerability scanning
    Sourcefire expands strategy in effort to leverage its network real estate
    Combining NetFlow analysis with security information management systems
    Security information management finally arrives, thanks to enhanced features

    Monitoring Network Traffic and Network Forensics
    Preventing SQL injection attacks: A network admin's perspective
    Breach prevention: How to keep track of data and applications
    Researchers find thousands of flawed embedded devices
    Network traffic collection, analysis helps prevent data breaches
    Lifecycle of a network security vulnerability
    Port scan attack prevention best practices
    How to prevent network sniffing and eavesdropping
    DoD urges less network anonymity, more PKI use
    Chained Exploits: How to prevent phishing attacks from corporate spies
    PCI compliance requirement 10: Auditing

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    network behavior analysis  (SearchSecurity.com)
    network behavior anomaly detection  (SearchSecurity.com)
    nonce  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts