Showing posts with label NAC. Show all posts
Showing posts with label NAC. Show all posts

Friday, May 22, 2009

NAC and DLP - lets break them and put them together again

[NAC and DLP can be so effective together, they just need to be trimmed down]

So, Art Coviello's company (RSA) arranges the biggest and certainly the most important Information Security conference. And so he gets to give the Keynote. But, to his credit he is either brilliant or has brilliant people around him because his keynote is always interesting, ground breaking even. I believe that RSA certainly has the best vision in terms of Security.

But enough of that... lets get back to the topic of this blog. (Btw, if anyone from RSA is reading this - contact me for my details to send whatever SWAG you have to give me for the above... cash is best ;)...

Coviello's main points (in my opinion) are that Security tools are point solutions and don't play nicely together. This needs to change and they need to be more open. Following that, they can then start to specialize.

I guess this is sortof what Check Point were trying to achieve with OPSEC. You have "smart machines" that understand policy.

Think - Firewall Policy server, Anti virus server, IPS. Traffic is sent to these machines and they work out what needs to happen to the traffic - allow, block, log, etc. This is communicated to a dumb device like a firewall node which just follows orders.

Coviello names the functions as follows:

  • PolicyManagement
  • PolicyDecision points
  • PolicyEnforcement
  • PolicyAudit
So, assuming I am reading a file on how my company makes its secret widgets. I download the file from the server and the following information is available to the different systems around me:

My username,
The time,
My location by network
My location by GPS (not usually but why not?)
My PC's latest patches and antivirus level (From NAC)
MY PC's installed software
My PC's hardware (including USB devices)
Any IPS triggers

This information is in many separate databases that don't really interact but imagine if they did.

It would allow the system to make a decision to allow/block based on any of the above conditions or all of the above together. So, if I try to access a file from my desk but it is 1AM then maybe I am denied the file. If my antivirus is old then tough, no files are available.

Every piece of network equipment (including workstations and servers) can be PolicyEnforcement machines. Which means that if I try to access a file that I'm not supposed to then the Server will block the connection, the switch will block it too and my laptop will block it too. This may be over-protection, but it may not be.

So, you may have a DLP server and a NAC server and a centrally controlled personal firewall policy but really the enforcement for all of these is "Allow" or "Block" and network switches can do that already. So, all your systems need to talk and when they all agree on "Allow" then the traffic flows.

Exciting times ahead.

Friday, September 21, 2007

Seven Habits of Highly Effective Security Plans [Part 3]

In this post we deal with habit 1: Be Proactive

Please first read The Seven Habits of Highly Effective Security Plans [Part 1]
Please first read the Seven Habits of Highly Effective Security Plans [Part 2]

This is based on Stephen Covey's book The Seven Habits of Highly Effective People and in this post we look at how being proactive can help raise the general security of an organisation. This is applicable from a micro 1 person business to a multi-national company.

Being proactive really translates into taking ownership. There is a general feeling that Information Security is someone else's problem - usually IT. The thing is that even IT shelve the responsibility onto technology such as Firewalls, Antivirus and IDS boxes.

It has taken legislation in the United States and Europe (not so much in South Africa yet) to put Information Security risk back where it should be - the Business and by "Business" I mean non-IT people. Is this fair? Sure, it is their data and they must protect it from getting lost. Security is there to help and IT is there to make sure that the technology is there but at the end of the day if a spreadsheet with financial information goes missing - it is the department that owns the spreadsheet that is going to suffer.

Of course, all the three camps can be proactive. InfoSec can, should, must promote awareness of Security. They need Business and IT to understand what the dangers are and what is expected from a regulatory point of view. Posters, education, emails, etc etc can all be done.

IT can help by telling InfoSec of incidents that they may find, by making systems secure from the start, from being enthusiastic about patching and hardening servers and helping out with standards that are secure.

Business can be aware that it is information they use everyday that IT and InfoSec are protecting and the protection is for them so they can do their work more effectively which is what business is all about. They should strive to understand the tools that they use and how to use them securely. Strong passwords, clean desk policy, locking workstations, locking offices, thinking twice before opening strange files are all things that can be done for free and together are far more effective than anti virus, firewalls and NAC.

It is difficult to get the inertia going and people are reluctant to change but it is important to at least start working on a culture where information is seen as an important asset is protected as such.

I think this is lot more productive than playing each part of the business off against each other.

Wednesday, March 7, 2007

My 2 cents - NAC and FLOSS (Part 2 - NAC)

This has taken me a bit of time. I tried to put aside all of the hype and advertising running about in my head and come up with a good reason for NAC.

And without all the hype and such it wasn't easy. A short time back I asked a bunch of CISSPs "Are Firewalls Really Necessary?" and I see a similar question has popped up about anti-virus. I think its good to go back and question the holy assumptions made in the past. And those holy grails of the future. I got some interesting answers to my question and the antivirus debate is heating up nicely.

When I am in doubt I turn to my collection of wisdom, quote I have collected over the years made by guys a lot more interesting than I and a lot more wise. I hope. One of these sages is Kevin Kelly. My university lecturer was a fan of KK and we actually had to learn his rules of god for our exams. Anyhow, Kevin Kelly said "More is more than more, its different".

What does he mean by this? How does this relate to NAC?

Take a PC and put someone in charge of it. No problem. Add another PC. No problem. At some stage the guy will have too much work, so add another guy. No problem. Add a few more PCs and a few more guys. At some stage you are no longer dealing with a few guys and some PCs. You are dealing with a Corporate Network and an IT Department.

It is at this stage that the whole takes on a life of its own. Now, Kevin Kelly encourages you to embrace this sort of chaos because something amazing may come out of it. Look at the wikipedia. Noone planned something so huge and amazing would happen; likewise the Internet. Maybe I am talking about Web1.0 and Web2.0 and when Web3.0 happens it will come out of the chaos that is the Internet and totally take center stage.


If you are trying to innovate by all means embrace the chaos. But if you are in charge of a computer network the chaos could produce a new way of working that will boost your company to be a leader in its field but could more likely boost your customer list to your competitors or innovate your 5 years of financial documents into meaningless junk.

NAC is about control. Hence the name, I guess. And really, its not a product, its a mindset. If you like you can limit connections by MAC address on switches - you always have been able to. You could have a big guy that walks around unplugging PCs that have no business being on your network.

Without even going into the whole "is the antivirus up-to-date, is the box patched" functionality I think it is important for a security officer to be able to say "All users on the network are authenticated."

Then he could go on to say "All the PCs on the network are up-to-date with the controls I need them to have to make sure they behave themselves".

There will be issues in doing this and I don't see the point in having security-through-obscurity which is what DHCP NAC seems to be, there needs to be a chokepoint and it needs to be the switch which is the closest trusted piece of equipment to the user. Their PC is closer but it is not trusted.