Inside a Network Operations Center

Harvard's NOC uses tools from TopLayer and Q1 Labs to keep an eye out for security problems.

By Simson Garfinkel

PAGE 2

The Harvard Network Operations Center has a database with between 1,500 and 2,000 registered system and network managers. When the IDS detects a "hit," the system tries to correlate the hit with other hits. If enough tests pass, the system auto alerts and sends a missive to the responsible manager. Last year roughly 10,000 such messages went out. "We want people to treat the auto alerts as gospel," says Network Security Manager David LaPorte, who works for Tumas.

Real-time alerts are an important part of network surveillance, but without the ability to look back in time, alerts are of limited use. It's important to find systems that have been compromised. But once you've found these systems, it's equally important to evaluate the damage that's been done. For example, says Tumas, Harvard's IDS system recently discovered a Microsoft Active Directory domain controller that had been hacked. Not surprising, none of the system's logs had been turned on.

To find out what had happened to the system, Tumas and his team turned to QRadar, a security monitoring system sold by Q1 Labs. QRadar monitors multiple sources of information, including packet traces, network flows and security events; builds a model of the network; uses the real-time information to update the model; and archives information as necessary to permit event reconstruction at some future time.

Just as every packet in and out of Harvard gets evaluated by the IDS systems, every packet also gets processed by QRadar. The system analyzes the packets, reconstructs the UDP and TCP streams, decodes the protocols, determines whether protocols are running on the correct port and updates a database of what it's learned in real-time. The system can also be programmed to record part or all of every packet that it sees, although doing so obviously requires a significant amount of storage for a network the size of Harvard's.

"We data-mined every single connection that this system created across the border, then went through and picked out the things that were not typical command-and-control bot traffic—anything that we couldn't identify," Tumas says.

It turned out that the compromised system had participated in a 350-megabyte file transfer with a computer system at another university. This was a matter of great concern. So Harvard contacted the other university and had it look at the other compromised system. The administrators at the other school found the files—350 megabytes of French music. "They weren't in [the system] long enough to discover the value of what they had," Tumas surmises.


Loading...
Network MarketSpace
Thinking About Deploying Mobile Broadband?
Explore lessons and best practices experienced by companies that have deployed mobile broadband to their workforce. Learn more »
Increase Application Performance and User Experience
This research shifts the attention from basic load-balancing features to application delivery features. Learn more »
Gartner Magic Quadrant, Application Delivery Controllers 2009
The market for products to improve the delivery of application software over networks remains dynamic. Learn more »
McAfee's Network Security Platform IPS
McAfee's Network Security Platform IPS; the costs, benefits, flexibility, and risk elements. Learn more »
The Cost of SQL Sprawl
Learn how a new approach to SQL server consolidation can reduce server counts by 50%, lower maintenance costs by 70% and reduce administration time by 75%. Learn more »
A Bottleneck-free Infrastructure
Storage bottlenecks have a significant impact on performance and productivity. Learn more »
Application Delivery Despite Emerging Challenges
IT organizations need to choose appropriate application delivery solutions that can scale to support the emerging challenges. Learn more »
 
SPONSORED LINKS
 

ROI of Application Delivery Controllers

Upgrading to VMware vSphere with vWire

Maximizing website Return on Information with high-quality search

See how AT&T can help protect your network.

Webcast: Unleashing the Power of Customer Data

White Paper: Improve Agility with Operational Responsiveness

White Paper: Legacy Tools: Not Built for the Helpdesk

Taking a Seat at the Executive Table: The Reality of Virtualization

White Paper: Next Generation Remote Infrastructure Management

Keeping Your Members Safe from Online Scams and Predators

The Total Economic Impact of Network Security Intrusion Prevention

Generation Remote Infrastructure Management - Changing the Paradigm

Cloud-Based Email Management: Opinion Shifts In Favor

eBook: How Can You Make Your People Productive Anywhere?

Achieving Business Agility with Application Grid

Ready to virtualize tier one applications? Check your virtualization maturity.

Seven Ways ITIL Can Help You in an Economic Downturn

Tips for successful virtualization management.

AT&T Synaptic Storage as a Service. Expand on demand

Trend Micro ranked #1 against real-world malware. Read more.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Streamline IT Costs. Boost Performance with WAN Optimization.

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

eZine: A Roadmap to Reducing IT Complexity

Gartner Magic Quadrant, Application Delivery Controllers 2009

Return on Information: Google Enterprise Search pays you back

Cut Costs & Green Your IT Operations with PC Power Management

White Paper: 4 Customer Service Myths

White Paper: Managed Security for a Not-So-Secure World

White Paper: 5 Best Practices for Smartphone Support

Global Research: CIOs Weigh In On Virtualization

5 Key Virtualization Management Challenges

Secure Email and Web-Based Communication from Evolving Attacks

WagerWorks Takes Fraudsters Out of the Game using iovation

Seven Design Requirements for Web 2.0 Threat Protection

Increase UPS efficiency without sacrificing protection.

Learn how advanced forecasting tools can deliver significant business results for global corporations.

Lower IT Costs with Oracle Database 11g Release 2

White Paper: Visibility and the New Normal of Mobile Work

Taking the Service Desk to the Next Level

Learn about The Information Technology Infrastructure Library.

Return on Information: Google Enterprise Search pays you back. Get the facts.

VMware. The source for Business Infrastructure Virtualization.

ShoreTel tells businesses to untangle from competitors' complexity and turn to its brilliantly simple UC solution

Top Five CIO Challenges

Read the RSA report: Security for Business Innovation

64-page prescriptive guide to security, compliance, and IT operations.

A Clear View Toward Virtualization

Virtualization Technology as a Business Solution

 
 
RESOURCE CENTER