Home > Security Tips > Network Security Tactics > Bridging the gap between perimeter and host security
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

Bridging the gap between perimeter and host security


Mike Chapple, CISSP
05.16.2005
Rating: -4.67- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



What you will learn from this tip: How intrusion-detection systems, honeypots and darknets bridge the gap between perimeter and host security to secure the network.

Most organizations recognize the importance of information security and devote resources to an information security program with adequate technical controls. In many cases, controls are well-developed in the areas of controlling access to the network (perimeter protection) and fortifying individual systems on the network (host protection). We're now beginning to see an increased emphasis on bridging the gap between these two areas with network-based security mechanisms.

In this tip, we'll explore three technical controls you can put in place to help bridge the gap in your enterprise: intrusion-detection systems, honeypots/honeynets and darknets. Each of these tools allows for a range of implementations from simple to complex.

Intrusion-detection systems

There are two basic approaches to intrusion detection:

  • Signature-based intrusion-detection systems (IDSes) work in a manner similar to modern antivirus technology. They are constantly updated with attack-definition files (signatures) that describe each type of known malicious activity. They then scan network traffic for packets that match the signatures, and then raise alerts to security administrators.
  • Anomaly-based IDSes work on a different principle. They learn the profile of "normal" network activity by monitoring the network over time, and then alert administrators to any deviations from that norm. The major advantage to anomaly-based systems is their ability to identify previously unknown attacks. Unfortunately, they haven't quite entered the mainstream of information security and reached the point of maturity where they're reliable enough for use on production networks.

If you'd like to implement an IDS, you may consider two different avenues, depending upon the time and financial resources you're able to commit to the project. The first option is the open-source route. The Snort intrusion-detection system is available for free at Snort.org and is well-supported by the information security community. If you're not willing to spend the time necessary to get Snort up and running, you may purchase a commercial IDS. There are quite a few products available today from vendors like Cisco and Enterasys. You also might wish to consider the commercial appliance versions of Snort available from Sourcefire.

Honeypots and honeynets

Honeypots and honeynets are another option available to security practitioners to secure the network. These tools are, believe it or not, designed to attract malicious attackers. Honeypots are systems designed to be targets of opportunity, useful for monitoring and observing hacker activity in an attempt to learn new hacking tools and techniques. Knowledge gained from honeypot systems may be used to protect the production network.

Honeynets are networks of honeypot systems, normally running different operating systems and applications with differing configurations. There is quite a bit of research underway in the academic community on so-called self-healing honeynets. These honeynets are designed to attract and monitor malicious activity and then quickly restore themselves to their original state, ready for the next attack attempt and saving a considerable amount of administrative time. For more information on establishing a honeypot or honeynet, consult the Honeynet Project at Honeynet.org.

Darknet

One of the simplest tools you can implement on your network is a darknet. All you need to do is set aside a portion of unused IP address space and designate it as the darknet. Next, configure your IDS or other network-monitoring device to detect any traffic headed to a darknet address. As there are no legitimate systems running on the darknet, you may safely assume that any traffic bearing a darknet destination address is from a malicious or misconfigured system. Darknets are especially useful for detecting systems on your network that may be infected by worms or other malicious code and are attempting to spread to random addresses on your network.


More information:

About the author
Mike Chapple, CISSP is an IT Security Professional with the University of Notre Dame. He previously served as an information security researcher with the National Security Agency and the U.S. Air Force. Mike is a frequent contributor to SearchSecurity, a technical editor for Information Security magazine and the author of several information security titles including the CISSP Prep Guide and Information Security Illuminated.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Network Security Tactics,   Network Intrusion Detection and Analysis,   Enterprise Network Security,   Network Intrusion Detection (IDS),   Monitoring Network Traffic and Network Forensics,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Network Security Tactics
Screencast: Find rogue wireless acess points with Vistumbler
How to prepare for a secure network hardware upgrade
Preventing SQL injection attacks: A network admin's perspective
Screencast: How to launch an OpenVAS scan
Wireless network guidelines for PCI DSS compliance
Aligning network security with business priorities
Scanning with N-Stalker offers basic Web application security assessment
Lifecycle of a network security vulnerability
Screencast: BackTrack 4 offers an arsenal of penetration testing tools
Network access control technology: Over-hyped or underused?

Network Intrusion Detection (IDS)
Preventing SQL injection attacks: A network admin's perspective
Lifecycle of a network security vulnerability
Best Intrusion Prevention and Detection Products
Rogue AP containment methods
SIMs tools and tactics for business intelligence
IPS and IDS deployment strategies
Know when you need IDS, IPS or both
Trend Micro to acquire Third Brigade for virtualization, cloud security
New product aims to control rogue applications that avoid firewalls
How to perform a network forensic analysis and investigation
Network Intrusion Detection (IDS) Research

Monitoring Network Traffic and Network Forensics
Botnet masters turn to Google, social networks to avoid detection
Preventing SQL injection attacks: A network admin's perspective
Breach prevention: How to keep track of data and applications
Researchers find thousands of flawed embedded devices
Network traffic collection, analysis helps prevent data breaches
Lifecycle of a network security vulnerability
Port scan attack prevention best practices
How to prevent network sniffing and eavesdropping
DoD urges less network anonymity, more PKI use
Chained Exploits: How to prevent phishing attacks from corporate spies

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
computer forensics  (SearchSecurity.com)
Diffie-Hellman key exchange  (SearchSecurity.com)
Einstein  (SearchSecurity.com)
HIDS/NIDS  (SearchSecurity.com)
network behavior analysis  (SearchSecurity.com)
ultrasound  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts