Home > Security Tips > Compliance Counselor > Seven problem areas to monitor for AS/400-TCP/IP host intrusion
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE COUNSELOR

Seven problem areas to monitor for AS/400-TCP/IP host intrusion


Peter Martin
12.20.2000
Rating: -4.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


This article by Peter Martin is an excerpt from the Dec. 11, 2000, Insider Weekly for AS/400 Managers. It is provided courtesy of The 400 Group.

TCP/IP is the preferred Internet communication protocol for AS/400 shops (an Insider Weekly survey found that over 90% of shops use it), but it can open up your network to a host of holes and exposures. IBM says to be on the watch for these potential security breaches.

Problem 1: System probing

What to look for: Connection attempts to inactive servers, packets with source routing (don't let them in the firewall), packets denied due to packet filtering rules (enable journaling for native packet filtering), TCP/IP connections left in an unusual state, and excessive pings and other ICMP (Internet Control Message Protocol), which is used to notify the sender that its destination node isn't available).

Problem 2: Abnormal system utilization

What to look for: Excessive CPU, I/O, bandwidth, or disk usage. Also, look for service uses during non-working hours, like TELNET at 4 a.m.

Problem 3: Blatant access attempts

What to look for: SSL, IP Security, and digital signature verification failures, as well as authentication failures that are chronicled in the AS/400 audit journal.

Problem 4: Abnormal deletions

What to look for: Audit logs should never be changed, so look there first for suspicious items. Also, look to deleting QSYSOPR, QSYSMSG, or QHST messages, deleting problem log entries, or stopping monitor programs.

Problem 5: Installing backdoors

What to look for: Any new objects installed on your system, as well as changes in system values, user profiles, validation lists, object authority, work management, job scheduler, service programs, or communication configurations. Use auditing tools to monitor these items.

Problem 6: Activation of services

What to look for: Jobs or subsystems started, communication lines varied on or off, servers such as TCP/IP or Client Access being started, and the starting and stopping of communication lines, servers and jobs.

Problem 7: Server exploitation

What to look for: Trend deviations and invalid request methods. Watch for trends with various servers, such as HTTP (invalid URLs or cgi-bin program failures), FTP (invalid path), SMTP (spamming or excess mail for a particular user), DNS (zone transfers or reverse queries for site mapping).

Secure your TCP/IP connection follow these seven tips

  • Start only TCP/IP servers that are needed

  • Consider using non-global IP addresses

  • Stop applications from using popular ports

  • Turn IP Source Routing off

  • Allow IP Datagram forwarding when needed

  • Don't leave PPP or SLIP lines waiting in answer state

  • Turn off DNS and HTTP server


Related book

AS/400 TCP/IP Handbook
Author : Chris Peters
Publisher : Midrange Computing
ISBN/CODE : 1583470050
Cover Type : Soft Cover
Pages : 400
Published : Oct. 1999
Summary:
This book is intended to give AS/400 professionals an understanding of the protocol at the heart of Internet and intranet communications. The information presented here will position you to take full advantage of your AS/400s potential for optimizing your business.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Compliance Counselor,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Compliance Counselor
Benefits of ISO 27001 and ISO 27002 certification for your enterprise
Identity lifecycle management for security and compliance
Interpreting 'risk' in the Massachusetts data protection law
FTC Red Flags Rules: How to create an identity theft prevention plan
Creating a HIPAA employee training program
Data protection tips for corporate compliance leaders
PCI DSS compliance requirements: Ensuring data integrity
Understanding PCI DSS compliance requirements for log management
Are 'strong authentication' methods strong enough for compliance?
Strategies for using technology to enable automated compliance

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts