Inside a Network Operations Center

Harvard's NOC uses tools from TopLayer and Q1 Labs to keep an eye out for security problems.

By Simson Garfinkel

Thu, June 21, 2007CSO I recently had a chance to visit Harvard University's network surveillance center. One doesn't normally see the words university and network surveillance in the same sentence, because surveillance of any kind is usually seen as being at odds with the tradition of academic freedom present at most universities. Unfortunately, higher education has long been associated with Internet-related computer crime—both as victims and as the home institution of many perpetrators. As a result, many universities have had to make significant investment in various kinds of network monitoring.

What makes Harvard's network surveillance notable is not the fact that Crimson engages in network surveillance but the scale and technical sophistication of those monitoring operations. Harvard has 6-gigabit connections to both Tier 1 Internet providers and Internet2. Between 10 and 20 terabytes of data moves across Harvard's border every day. What's more, traffic frequently undergoes asymmetric routing, which means that packets travel across different border routers depending on whether they are leaving Harvard or returning—one of the unfortunate consequences of something known as "hot potato routing."

Yet despite this complexity, Harvard manages to categorize and record information about practically every packet crossing its borders.

To find out how Harvard works this magic, I met with Jay Tumas, Harvard’s network operations manager. It wasn’t a long walk: Jay's office at University Information Systems is just a block down the street from my office at the School of Engineering and Applied Science.

No Packet Left Behind
Harvard's connections to the Internet and Internet2 take place in three physical locations: two in Boston and one in Cambridge. But rather than deploy intrusion and anomaly-detection systems at the border, Tumas has built a dedicated monitoring system that takes all critical traffic, makes a copy of every packet and sends those copies to the network surveillance center on 10-gigabit optical fibers. There the flows are reassembled using Cisco switches and sorted according to protocol family using a cluster of Top Layer 4508 IDS Balancers.

This architecture both lets Harvard split the load among multiple systems—it’s too much data for one IDS—and lets each IDS be configured with only the signatures that it actually needs, which makes each IDS run faster than it would if it were responsible for the full protocol suite.

"Last year we had over 10 million IDS hits," says Tumas. But instead of sending out an alert for each hit or just tabulating them in some log file that nobody ever really reads, Harvard has built a reactive system that rates the severity of each IDS hit, judges the chance of a false positive and then automatically alerts the responsible security manager.

Loading...
Network MarketSpace
White Papers
The Challenge of a Demanding Network Infrastructure
Today's data centers are expanding as demand for data and storage continues to grow exponentially. Learn more »
Reduce Infrastructure and Administrative Costs
The Brocade® FastIron® CX Series of switches provides new levels of performance. Learn more »
A New Generation of Application Delivery Controllers (ADCs)
Learn more about Brocade® ServerIron® intelligent application delivery and traffic management solutions. Learn more »
Want to Offer a Superior User Experience?
Control a "boundary-less" enterprise with scalable solutions. Learn more »
Realize Potential Without Increasing Your Risk
Combining Brocade's high-performance infrastructure and McAfee's Web gateway solution ensures trusted environments. Learn more »
Brocade and Imperva: Providing Best-of-Breed Products
Web applications have become the backbone of business in nearly every segment of the economy. Learn more »
 
SPONSORED LINKS
 

Maximizing the Business Value of the PC Infrastructure

Enterprise PBX Comparison Guide

Getting Value from Outdated Networking Equipment

Seven Ways ITIL Can Help You in an Economic Downturn

Data Loss Prevention: A Better Way to Approach Security

Learn how to managing client systems in the enterprise.

Cloud Computing: Read about VMware's compelling vision & set of products

Losing Ground: 2009 TMT Global Security Survey

Accenture IT Consulting: Logical meets technological. More . . .

Stop Application Fraud at the Source with Device Reputation

Learn about the VMware vSphere (TM) & Intel (R) Xeon (R) Processor 5500 Series

Learn how a virtualized enterprise can help your company reduce costs

Why Isn't Server Virtualization Saving Us More?

8 Key Ingredients to Building an Internal Cloud

Data Center Optimization: Three Key Strategies

A CIO Executive Guide: Cloud Computing Looms Big on the Horizon

Oracle WebLogic Server Technical Demo

Data Grids and Service-Oriented Architecture

Achieving the Impossible: Unlimited Application Scalability

A Middleware Foundation for Application Grid

Tips for successful virtualization management.

Smart Decisions: The Role of Key Performance Indicators

Gartner Shares Predictions for 2009

Accenture IT Consulting: Enabling high performance. More...

Top Five CIO Challenges

Enterprise PBX Buyer's Guide

Secondary Market Primer: Your Network at Half Price

Taking the Service Desk to the Next Level

Why Data Loss is Increasing--and What You Can Do About It

Communications and Collaboration Needs at Business Organizations

Using Open Source to Deploy Web Applications

Mid-Sized Company CIO Community: infoBOOM!

Top-line Performance that's Bottom-line Efficient

Accenture: Outsourcing for uncertain times. Click to learn more.

White Paper: 8 Key Ingredients to Building an Internal Cloud

Read about virtualization and consolidation effort best practices

Building the Virtualized Enterprise with VMware Infrastructure

Top 10 Business and IT Drivers for the Wealth Management Sector

Bottom-Line Benefits of Virtualization

White Paper: The Building Blocks for Cloud Computing

Oracle's Application Grid Technical Demo

Next-Generation Application Servers and Infrastructure

Application Infrastructure at Enterprise Organizations

Achieving Business Agility with Application Grid

Learn about The Information Technology Infrastructure Library.

Achieving Pervasive Performance Management

Automating the Generation and Secure Distribution of Excel Reports

Introducing the new HP ProLiant G6 server family

Accenture: Outsourcing for Competitive Advantage. More...

Better spam protection with Postini for just $1/user/mo

 
 
RESOURCE CENTER