IT DRILLDOWN
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Social Responsibility's Strategic Benefits

December 15, 11:30 AM - 12:30 PM US/Eastern (GMT-5)

Join Ed Granger-Happ, CIO of Save the Children, for a discussion of how creating an organization that is socially responsible improves staffing, retention, leadership development and overall corporate health.

Working With and Communicating to Your Board of Directors

January 13, 2009, 4:00 PM - 5:00 PM US/Eastern (GMT-5)

CIO panelists who will share tips and experiences working with their boards: Twila Day of SYSCO; Jeff O'Hare, West Corp.; Marc West, formerly with H&R Block.

IT's Role in Growing Mid-Market Companies

January 14, 4:00 PM - 5:00 PM ET (GMT-5)

Mid-market Council members will share their companies' stories and challenges in driving or coping with growth. Panelists represent Veterinary Pet Insurance, Medicis Pharmaceutical, and Intrax Cultural Exchange.

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 

Inside a Network Operations Center

Harvard's NOC uses tools from TopLayer and Q1 Labs to keep an eye out for security problems.

 

June 21, 2007CSO — I recently had a chance to visit Harvard University's network surveillance center. One doesn't normally see the words university and network surveillance in the same sentence, because surveillance of any kind is usually seen as being at odds with the tradition of academic freedom present at most universities. Unfortunately, higher education has long been associated with Internet-related computer crime—both as victims and as the home institution of many perpetrators. As a result, many universities have had to make significant investment in various kinds of network monitoring.

What makes Harvard's network surveillance notable is not the fact that Crimson engages in network surveillance but the scale and technical sophistication of those monitoring operations. Harvard has 6-gigabit connections to both Tier 1 Internet providers and Internet2. Between 10 and 20 terabytes of data moves across Harvard's border every day. What's more, traffic frequently undergoes asymmetric routing, which means that packets travel across different border routers depending on whether they are leaving Harvard or returning—one of the unfortunate consequences of something known as "hot potato routing."

Yet despite this complexity, Harvard manages to categorize and record information about practically every packet crossing its borders.

To find out how Harvard works this magic, I met with Jay Tumas, Harvard’s network operations manager. It wasn’t a long walk: Jay's office at University Information Systems is just a block down the street from my office at the School of Engineering and Applied Science.

No Packet Left Behind
Harvard's connections to the Internet and Internet2 take place in three physical locations: two in Boston and one in Cambridge. But rather than deploy intrusion and anomaly-detection systems at the border, Tumas has built a dedicated monitoring system that takes all critical traffic, makes a copy of every packet and sends those copies to the network surveillance center on 10-gigabit optical fibers. There the flows are reassembled using Cisco switches and sorted according to protocol family using a cluster of Top Layer 4508 IDS Balancers.

This architecture both lets Harvard split the load among multiple systems—it’s too much data for one IDS—and lets each IDS be configured with only the signatures that it actually needs, which makes each IDS run faster than it would if it were responsible for the full protocol suite.

"Last year we had over 10 million IDS hits," says Tumas. But instead of sending out an alert for each hit or just tabulating them in some log file that nobody ever really reads, Harvard has built a reactive system that rates the severity of each IDS hit, judges the chance of a false positive and then automatically alerts the responsible security manager.

Loading...
 
 
CENTER OF EXCELLENCE
 
Infrastructure
» Outbound Email and Data Loss Prevention
This report shows the findings of a recent Proofpoint and Forrester Consulting study on e-mail security, data loss prevention, and includes statistics on electronic risks.
» A Modern Approach to On-Demand Email and Data Security
Learn how Proofpoint delivers a dedicated, hosted e-mail security solution that combines state-of-the-art anti-spam and virus control.
» A Proactive Approach to e-Discovery
Learn about the key e-discovery challenges facing legal and IT departments today and how businesses can develop an e-mail archiving strategy to deal with e-discovery requests.
» The Advantages of Identity Based Encryption
Download this paper to learn why e-mail encyrption is critical to an organization's overall security architecture and the advantages of identity-based encryption.
» Global Best Practices in Email Security, Privacy and Compliance
This whitepaper discusses the latest global regulations that impact the e-mail security policies and strategies of today's enterprises, universities and government organizations.
Center sponsored by

 
 
ABCs
 

Just the basics, please. Sometimes we all need a refresher or we need to make sure our team and our colleagues are all on the same page.

Over 25 tutorials on everything from business intelligence to virtualization.

 
 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Unified Communications & Collaboration: Game-Changing Business Results

Conquering Information Management Challenges

Integrating ActiveRoles With IBM Tivoli Identity Manager 5.0

Quest Authentication Services: Simplify Identity Management

Data Protection: Challenges for the Traveling User

Learn how wide-area data services can help deliver the benefits of virtualization

Learn how companies are changing how they reach out to their most profitable customers.

Learn how to leverage virtualization for a 74% savings in TCO.

Find out how you can affordably consolidate applications with VMware.

ESG Research on Server and Storage Virtualization

Data Center ROI with RFID Asset Tracking

Get help navigating the management challenges of virtualization.

Narrow the gap between virtualization's benefits and the management risks.

Cash in on the promise of virtualization

Determine the ROI of Web Application Acceleration Managed Services

Achieve a 50:1 Data Deduplication Ratio

Remote Infrastructure Management - What Your Peers are Thinking

Complementary BI: The New Approach to Business Intelligence

Expand High-Performance Computing (HPC) Capabilities

Power the Platform of Choice for Virtualization in the Enterprise

Boost your top- and bottom- lines.

Learn what it takes to build a holistic digital collaboration platform

The ECM Paradox: Extending Local Flexibility to Strengthen Central Control

Customer Insight Yields Sales, Marketing Gains

7 Requirements of Data Loss Prevention

Unify and Conquer: The Benefits of Unified Communications.

Operational Excellence Is Key to Maximizing IT Investments

Quest Authentication and IBM Tivoli Identity Management

Get IDC's take on one company's foray into storage virtualization.

White Paper: Centralized Data Backup and Your WAN

White Paper: Accelerating the Next Phase of Virtualization

The Right and Wrong Master Data Management Strategies to Start Small and Grow Big

Find out why IDC thinks virtualization is changing operating environments.

Explore the impact virtualization can have on your bottom-line.

Save with 0% Lease Offer on HP Servers and Storage

How RFID Improves Data Center Efficiency

Find out how to manage virtualization's risks and reap the rewards.

Conquer the realities of managing virtualization

Improve Web-Enabled SAP Performance

Gartner on Data Deduplication Cost Savings

Data Protection Options Explained

Webcast - "Into the Wild: Managing Laptops Outside the Office"

5 Steps to Successful IT Consolidation

High-performance computing is no longer just for Big Business

Leading university calls on Nokia for mobile unified communications.

Mobility is Growing: Survey Shows Why CIOs are Concerned

Best Intel Info for IT Pros/Intel Premier IT Professional Program: Stay up to date with roadmaps, technologies & best practices

Make Hidden Trends, Inter-Relationships and Influences Visible.

Improve delivery of product information to customers.

Prudential Financial Protects its Brand with Symantec