nren & isp security working group 2014 reviewwilfried wöber serge droz...

21
connect • communicate • collaborate Wayne Routly, DANTE 44 th TF-CSIRT Meeting 19 September 2014 Rome NREN & ISP Security Working Group 2014 Review

Upload: others

Post on 15-Mar-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

connect • communicate • collaborate

Wayne Routly, DANTE 44th TF-CSIRT Meeting

19 September 2014

Rome

NREN & ISP Security Working Group

2014 Review

Page 2: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

2

connect • communicate • collaborate

GÉANT : Who What How

• State of the Art Pan-European Network

– …..Transit Network….ISP

– 31 Collection Devices (Juniper MX)

– 50 Million End Users (65 Countries)

• Tb/s Network

– 100s PB of Data

– 15+Millions IPs

– 1000 Devices

– Unusual Traffic – Quasi R&E DoS

• Truly Global

– Interconnects (I2, TEIN, Ubuntunet)

– NRENs - 43

– Commercial & Commodity Traffic

Page 3: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

3

connect • communicate • collaborate

Agenda

• Objectives:

– Background to Working Group

• Achievements: Today (2014)

– NSHaRP security toolset upgrade

– Response to 2013 Audit

• Challenges: Tomorrow (GEANT4)

– Outcomes from 2014 Audit

– New Systems, New Challenges

Demonstrate Leadership

Page 4: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

4

connect • communicate • collaborate

Security Working Group Objectives

List

Recommended

Physical

Security

Approaches

Share

Knowledge of

Current

Threats

High Level

Management

Review

Page 6: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

connect • communicate • collaborate

Achievements: Today (2014)

Page 7: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

7

connect • communicate • collaborate

• NSHaRP Infrastructure

• Nessus

• Web Camera’s in PoPs

• Firewall on Demand

• Dedicated Security Officer

Achievements: Today (2014)

Page 8: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

8

connect • communicate • collaborate

• Sampling Rate 1/100

• v5 – v9

NSHaRP Changes

• Redundant Fan-out Servers • Increased Net Flow Demand

<<< New Trouble Ticketing System; New Anomaly Detection Tools; New Anomaly Type Pallet >>>

Page 9: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

9

connect • communicate • collaborate

Vulnerability Assessment – Finding that Weakest Link

Page 10: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

10

connect • communicate • collaborate

Understanding Your Network…. Nessus

• Understand where Vulnerabilities Lie

• Target Key Areas – Juniper

• Is the situation improving?

• How many vulnerabilities are there?

• Which systems must we prioritise

Page 11: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

11

connect • communicate • collaborate

Controlling Your Network…. Nessus

• When last did we see this host?

• Has it had a vulnerability scan?

• Which zones are vulnerable?

• External Zones must be prioritised

Page 12: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

12

connect • communicate • collaborate

There are other factors that should be

evaluated as well..

Web Camera’s In PoPs

Page 13: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

13

connect • communicate • collaborate

Web Camera’s In PoPs – Prioritise Locations

Page 14: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

14

connect • communicate • collaborate

Firewall on Demand – Who, What, Why?

AKAMAI

FoD

NREN B

LEVEL 3

CUSTOMER

UNIVERSITY

DORM

…… better tools to mitigate transitory attacks

and anomalies

• “Better” in terms of

– Granularity: Per-flow level

– SRC/DST IP/Ports, protocol type, DSCP,

TCP flag……

– Action:

– Drop, rate-limit, redirect

– Speed: More responsive

– (Seconds / Minutes vs. Hours / Days)

– Efficiency:

– Closer to the source, Multi Domain

– Automation:

– Integration with other systems (NSHaRP)

NREN A

Page 15: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

15

connect • communicate • collaborate

Firewall on Demand – Intuitive Interface

• Integrated into

NSHaRP

• Dynamic Auto

Creation &

Expiration

• Federated Logon

Page 16: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

16

connect • communicate • collaborate

Security Officer

Page 17: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

connect • communicate • collaborate

Challenges: Tomorrow (GEANT4)

Page 18: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

18

connect • communicate • collaborate

Stress Testing - Targeted Ingress and Egress Scans

Security WG Report Process & Technology Findings

Walled Gardens: Vulnerable Systems Management

Net Flow Data Anonymisation

Ownership of Virtual Machines (Life Cycle)

Page 19: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

19

connect • communicate • collaborate

Security WG Report Process & Technology Findings

Implement IDS: Verify all certificates in the organisation

DANTE & TERENA – “Sanity Checks”

Appetite for # Vulnerabilities: CVSS Length of exploitability

Page 20: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

20

connect • communicate • collaborate

Change Your View, Change Your Approach

We must inspire a

commitment to security

rather than merely

describing it

– Mich Kabay

Page 21: NREN & ISP Security Working Group 2014 ReviewWilfried Wöber Serge Droz wilfried.woeber@univie.ac.at serge.droz@switch.ch Doug Pearson Wayne Routly dodpears@ren-isac.net wayne.routly@dante.net

connect • communicate • collaborate

Thank you

Any questions…even the funny ones?