<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>eIQviews &#187; network flow</title>
	<atom:link href="http://blog.eiqnetworks.com/tag/network-flow/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.eiqnetworks.com</link>
	<description>Perspectives on Security and Compliance Management from eIQnetworks</description>
	<lastBuildDate>Mon, 14 Dec 2009 13:04:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.eiqnetworks.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/9a3baa02baa3289d9a8c9a6a0eb652a5?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>eIQviews &#187; network flow</title>
		<link>http://blog.eiqnetworks.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.eiqnetworks.com/osd.xml" title="eIQviews" />
	<atom:link rel='hub' href='http://blog.eiqnetworks.com/?pushpress=hub'/>
		<item>
		<title>Ten Reasons Log Data is Not Enough #6: You can&#8217;t monitor what you can&#8217;t see&#8230;</title>
		<link>http://blog.eiqnetworks.com/2009/10/05/ten-reasons-log-data-is-not-enough-6-you-cant-monitor-what-you-cant-see/</link>
		<comments>http://blog.eiqnetworks.com/2009/10/05/ten-reasons-log-data-is-not-enough-6-you-cant-monitor-what-you-cant-see/#comments</comments>
		<pubDate>Mon, 05 Oct 2009 22:10:28 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[Log Management Series]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[extrusion monitoring]]></category>
		<category><![CDATA[network flow]]></category>
		<category><![CDATA[rogue devices]]></category>
		<category><![CDATA[security monitoring]]></category>
		<category><![CDATA[vulnerability scanning]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=285</guid>
		<description><![CDATA[Let&#8217;s have a candid discussion about rogue devices, shall we? You know, the unauthorized access point plugged into a port in a conference or under someone&#8217;s desk. Or maybe the network behind the off-shore contractors you have maintaining legacy applications. Perhaps someone is running a side business during work hours on a device they bring [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=285&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Let&#8217;s have a candid discussion about rogue devices, shall we? You know, the unauthorized access point plugged into a port in a conference or under someone&#8217;s desk. Or maybe the network behind the off-shore contractors you have maintaining legacy applications. Perhaps someone is running a side business during work hours on a device they bring from home ON YOUR NETWORK.</p>
<p><a href="http://www.flickr.com/photos/foxtongue/2657434642/" target="_blank"><img class="alignleft" style="margin:10px;" title="Blindfolded Typing Competition originally uploaded by foxtongue" src="http://farm4.static.flickr.com/3285/2657434642_543c30685f_m_d.jpg" alt="" width="240" height="173" /></a>Each of these scenarios (regardless of how contrived) happen each day. And every new device presents a significant risk to your environment. Which means you need to be constantly watching for these devices and make sure they are not wreaking havoc. In fact, this is one of the key use cases for network access control (NAC). Of course, that technology is struggling, but it&#8217;s not because of the lack of a problem to solve.</p>
<p>So if you are looking at a <a href="http://www.eiqnetworks.com/solutions/log_management.shtml" target="_blank">log management</a> or <a href="http://www.eiqnetworks.com/solutions/security_information_and_event_management.shtml" target="_blank">security information and event management</a> (<a href="http://www.eiqnetworks.com/solutions/siem.shtml" target="_blank">SIEM</a>) product, won&#8217;t that tell you about new devices? Won&#8217;t it see something funky and flag it? Well, actually no it doesn&#8217;t. Log Management requires logs and your typical rouge device isn&#8217;t too interested in forwarding its logs to much of anything. That&#8217;s right, each managed device needs to be configured to push log files to the log management product. If that doesn&#8217;t happen, the SIEM is blissfully unaware anything is going on &#8211; until a number of managed devices are compromised &#8211; which is too late.</p>
<p>Yes, network devices (at least the right ones) can detect rogue devices and potentially quarantine those until the proper authorization is presented. But what if you don&#8217;t have NAC or can&#8217;t afford to upgrade your entire switching infrastructure? That&#8217;s right, you need to go beyond log data.</p>
<p>As mentioned in <a href="http://blog.eiqnetworks.com/2009/09/17/ten-reasons-log-data-is-not-enough-4-network-blind-mice/" target="_blank">reason #4 about network flows</a>, the network never lies. So we&#8217;ve got to look for new network devices and then kick off a scan to figure out what it is and whether it&#8217;s authorized. eIQ SecureVue makes that pretty simple. You can set a policy to check for any new IP addresses within a specific time period. Then from right within SecureVue, you can kick off a vulnerability scan to figure out what is the story with that device. Once you figure out what it is, then you can understand whether it should be there.</p>
<p>Additionally, you can set network flow policies to check for traffic leaving the network from unmanaged devices. This kind of extrusion monitoring will tell you if a device is moving data off the network. Maybe they should be, maybe not. But the point is to gain situational awareness of what&#8217;s happening in your environment. And just looking at the log data is not going to get you there.</p>
<br />Posted in Log Management Series, Security Tagged: extrusion monitoring, network flow, rogue devices, security monitoring, vulnerability scanning <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/285/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/285/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/285/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/285/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/285/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=285&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/10/05/ten-reasons-log-data-is-not-enough-6-you-cant-monitor-what-you-cant-see/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>

		<media:content url="http://farm4.static.flickr.com/3285/2657434642_543c30685f_m_d.jpg" medium="image">
			<media:title type="html">Blindfolded Typing Competition originally uploaded by foxtongue</media:title>
		</media:content>
	</item>
		<item>
		<title>Ten Reasons Log Data is Not Enough: #4. Network Blind Mice</title>
		<link>http://blog.eiqnetworks.com/2009/09/17/ten-reasons-log-data-is-not-enough-4-network-blind-mice/</link>
		<comments>http://blog.eiqnetworks.com/2009/09/17/ten-reasons-log-data-is-not-enough-4-network-blind-mice/#comments</comments>
		<pubDate>Thu, 17 Sep 2009 13:04:47 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[Log Management Series]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Log Data is Not Enough]]></category>
		<category><![CDATA[log management]]></category>
		<category><![CDATA[network behavioral analysis]]></category>
		<category><![CDATA[network flow]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=275</guid>
		<description><![CDATA[As we discussed in the last post in the Ten Reasons Log Data is Not Enough series, configuration data provides an important additional set of information to help pinpoint potential attacks and make sure that in the absence of log data (if logging is turned off, for example) attacks can still be detected. Network flow [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=275&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.flickr.com/photos/mphoenix/3092082796/" target="_blank"><img class="alignright" style="margin:10px;" title="Three Blind Mice (corgies with doggles) originally uploaded by mphoenix" src="http://farm4.static.flickr.com/3100/3092082796_43ba3ce3f7_m_d.jpg" alt="" width="240" height="180" /></a>As we discussed in the <a href="http://blog.eiqnetworks.com/2009/09/10/ten-reasons-log-data-is-not-enough-3-whats-the-configuration-kenneth/" target="_blank">last post in the Ten Reasons Log Data is Not Enough</a> series, configuration data provides an important additional set of information to help pinpoint potential attacks and make sure that in the absence of log data (if logging is turned off, for example) attacks can still be detected.</p>
<p>Network flow data is another data type that can yield important and interesting corroborating data to go Beyond <a href="http://www.eiqnetworks.com/solutions/security_information_and_event_management.shtml" target="_blank">Security Information and Event Management</a> (<a href="http://www.eiqnetworks.com/solutions/siem.shtml" target="_blank">SIEM</a>) and <a href="http://www.eiqnetworks.com/solutions/log_management.shtml" target="_blank">Log Management</a>. First what is network flow data? Basically, every network device tracks some simple information about who is talking to whom and what protocols they are using. Cisco&#8217;s data is called NetFlow. Juniper has a format called (surprisingly) JFlow and there is a more standard format called cflowd.</p>
<p>Regardless, this network flow data comes in fast and furious, with millions of flow records being generated every second. So scaleability is a key requirement if you are planning to analyze and correlate network flows, along with everything else.</p>
<p>Why is being blind to network flows a huge problem for security professionals? Basically, the network sees everything, at one point or another. In the event of an attack, the attacker needs to move data either within the environment or outside of the environment. Typically you wouldn&#8217;t see huge amounts of data moving to a server in Eastern Europe. Or an open FTP server in Brazil. Or in a government processing center in China. So these are good indications that something may be a bit funky.</p>
<p>Now to be clear, network flow data is not going to be a definitive answer to the presence of an attack, which is probably why the network behavior analysis (NBA) market never really took off, especially for the security use case. But the data can tell you what isn&#8217;t normal and give you some more information to analyze and correlate. It&#8217;s really about having another data source to provide additional corroborating evidence to the potential presence of an attack.</p>
<p>As a bit of a unplanned benefit, your network operations folks could be very interested in building their own alerts based on network flows because not only can flow data detect attacks, it also pinpoint network performance issues pretty effectively. So here is yet another reason that <a href="http://www.logdataisnotenough.com" target="_blank">log data is not enough</a>, and security professionals need to go Beyond Log Management to keep pace with today&#8217;s attacks.</p>
<br />Posted in Log Management Series, Security Tagged: Log Data is Not Enough, log management, network behavioral analysis, network flow <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/275/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/275/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/275/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/275/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/275/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/275/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/275/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/275/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/275/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/275/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=275&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/09/17/ten-reasons-log-data-is-not-enough-4-network-blind-mice/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>

		<media:content url="http://farm4.static.flickr.com/3100/3092082796_43ba3ce3f7_m_d.jpg" medium="image">
			<media:title type="html">Three Blind Mice (corgies with doggles) originally uploaded by mphoenix</media:title>
		</media:content>
	</item>
	</channel>
</rss>