Home > Ask the Networking Experts > Network security Questions & Answers > Hardware nor software firewalls stopped a breach in my network. What more should I be doing?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

Hardware nor software firewalls stopped a breach in my network. What more should I be doing?

Puneet Mehta EXPERT RESPONSE FROM: Puneet Mehta

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 11 February 2004
I had a security breach when hackers hacked into my network. I had a similar problem before but was able to manage it by putting a hardware firewall and removing the software firewall. Unfortunately, the problem persists. What can I do?

>
From the information provided by you, it's hard to find the exact cause of the problem. Also, you have not mentioned the techniques you tried. It takes more than a firewall to secure a network infrastructure.

The very first step in preventing network security incidents is to identify the threats and put controls in place to prevent them from happening. Some of the important factors you should consider are:

  • At a very basic level, scan your network for potential entry points. Remove or disable any unneeded devices.
  • Check for any newly added network devices and verify configuration.
  • Check your router/firewall configurations, most importantly the routing information. Check to see if any modifications have been made since your last good configuration.
  • Make sure your firewall/router is blocking ICMP pings originating externally. It's a known fact that most of the attacks tunnel through in the protocol's echo reply. Also, block outgoing ICMP pings, lest your network be an accessory in a distributed denial-of-service attack.
  • Logs are your best friends. Turn on logging on potential network points. They provide a good amount of information in detecting problems.
  • Use tools like port scanners and network monitors to monitor network traffic and ports. Make sure only required ports are open and listening to trusted addresses.
  • Search for activities that are hallmarks of attacks. For example: a malicious script can scan the network logs on machine and then block any randomly chosen network addresses.
  • Intrusion detection system: Make sure it conforms to expected parameters and aren't hiding distributed denial-of-service attacks.
  • Watch for evidence of port scanning in your logs.
  • Web servers are one of the areas of concern. Studies have shown that many a times it's the web server that acts as door for hacker's entry inside the network. I would advise you to visit the W3C site for updated information on securing a web server.
    http://www.w3.org/Security/Faq/
  • The rising numbers of virtual private networks, extra-nets and intranets have created more access points for hackers. The concept of a single point of entry into your network is long gone. An exposed vulnerability in any of these can wreck havoc.
  • Make sure that the application code is reviewed before its put on the website. Eliminate any vulnerability that hacker can exploit.
  • I would also advise you to get network penetration and auditing done by some professional security group.

Hope the above helps you in finding some answers to your problem. If you can send me some more information on your current network setup, I might be able to help you better.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Network Security Monitoring and Analysis
Application-specific network intrusion detection systems emerge
Anomaly-based intrusion protection configuration and installation
How can I calculate perimeter firewall throughput?
How do I find the application on my network that's dropping packets?
Integrating NAC with network security tools
Where can I find a sample security audit report? How can I run my own?
The firewall remains the network traffic cop, but its role is changing
Troubleshooting VLANs: How to monitor 802.1q tagged traffic
Poor data-loss prevention practices almost cost Intel a billion
How can I block my competitor's IP address range from my website?

Network security
Where can I find Puneet Mehta's most recent network security advice?
How do VPN concentrators and network access servers (NAS) differ?
What keeps unauthorized users from accessing my IP address/Internet?
Controlling network access by MAC address restriction on wired networks
Retrieve network resources and email after installing ISA Server 2004
What does a QM FSM error signify on a VPN Concentrator?
How to block porn with ISA-server firewalls
Who is responsible for updating network firewalls?
How to locate the lost IP address of an access point (AP)
What HIPPA-compliant software would you recommend for online medicine?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
deep packet inspection (DPI)  (SearchNetworking.com)
FCAPS  (SearchNetworking.com)
Nessus  (SearchNetworking.com)
netstat  (SearchNetworking.com)
port mirroring  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts