Home > Ask the Security Experts > Network Security Questions & Answers > How will the centralized logging of network flow data benefit an enterprise?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How will the centralized logging of network flow data benefit an enterprise?

Mike Chapple EXPERT RESPONSE FROM: Mike Chapple

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 11 January 2008
My organization is implementing centralized network flow logging. To what extent will better knowledge of network utilization help our security posture, and what are some common pitfalls to look out for?

>
EXPERT RESPONSE
Centralized logging of network flow data is an extremely valuable mechanism for both security and network professionals. Logging provides a single, authoritative record of all connections between a network's systems, including the amount of data that passes over each connection.

These records can help security professionals when responding to an incident. During an attack, for example, network flow information often effectively reveals the quantity (but not content) of a network's extracted data. The logged info can also help identify systems infected with malicious code. Networking professionals can use the data to troubleshoot network anomalies and analyze bandwidth utilization. I strongly recommend network flow logging as part of a well-rounded security program.

Two common pitfalls come to mind, though: user privacy and storage capacity. Many organizations logging flow data don't think about privacy concerns because they're only retaining connection-level data and not logging packet payloads. The destination IP addresses in outbound connections, however, may also contain sensitive personal information about, say, the Web sites visited by a user. Depending upon your organization's privacy policy, this may be a significant concern.

Additionally, in a large enterprise, flow data may quickly consume large quantities of storage space. You'll need to estimate your storage needs and develop a retention policy that balances business needs with the technical capabilities of the system.

More information:

  • Fellow expert Joel Dubin explains some challenges that occur when designing a logging mechanism for peer-to-peer networks.
  • Myriad devices produce waves of logs. See how to get all that network data under control.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Network Security
    Will Cisco's plan to open access to the IOS improve network security?
    Will VoIP attacks result in more than just spam?
    Should enterprises implement a mandatory iPhone VPN?
    Will organizations that lag behind on IPv6 adoption have greater security risks?
    Should iPhone email be sent without SSL encryption?
    How to secure an FTP connection
    DMVPN configuration: Is an additional firewall needed between the router and the Internet?
    Is centralized logging worth all the effort?
    What are the pros and cons of shaping P2P packets?
    Should an ISP keep corrupted machines off of a network?

    Network Behavior Anomaly Detection (NBAD)
    Is centralized logging worth all the effort?
    Can reputation services be applied to network security?
    How well can network behavior anomaly detection (NBAD) products detect rootkits and malware?
    Sourcefire, Nmap deal to open vulnerability scanning
    Sourcefire expands strategy in effort to leverage its network real estate
    Combining NetFlow analysis with security information management systems
    Security information management finally arrives, thanks to enhanced features
    Are honeypots safe to implement in a router?
    How to protect against port scans
    Extensive coverage in a single box

    Monitoring Network Traffic and Network Forensics
    Windows registry forensics guide: Investigating hacker activities
    More built-in Windows commands for system analysis
    Is security improved when the number of Internet gateways is reduced?
    Screencast: Using Nessus to scan for vulnerabilities
    What are the pros and cons of shaping P2P packets?
    Built-in Windows commands to determine if a system has been hacked
    The forensics mindset: Making life easier for investigators
    Data Loss Prevention Tools Offer Insight into Where Data Lives
    vPro: Making the case for network security on a chip
    PING: Fyodor

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    network behavior analysis  (SearchSecurity.com)
    network behavior anomaly detection  (SearchSecurity.com)
    nonce  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts