Home > Networking Tips > Network Security > Security Spotlight: Network Behavior Analysis goes long and wide
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY

Security Spotlight: Network Behavior Analysis goes long and wide


Lisa Phifer
10.23.2006
Rating: -4.33- (out of 5)


Network security news, advice and technical information
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Despite massive investment in firewalls, intrusion prevention and antivirus, enterprise networks continue to be plagued by internal misuse and attack. For seven years straight, insider abuse and virus outbreaks have topped the CSI/FBI Computer Crime and Security Survey. Network operations center staff, already overwhelmed by security perimeter alerts, just can't afford to battle internal threats the same old way. Perhaps it is time to consider a new approach: Network Behavior Analysis (NBA).

Why deploy Network Behavior Analysis?

NBA, also known as Network Behavior Anomaly Detection, describes a relatively new field of products that employ passive observation and profiling to spot traffic spikes, atypical usage and policy violations. Conventional intrusion prevention system solutions like Snort and Intrusion.com defend your network's perimeter through in-line traffic inspection, signature detection and real-time blocking. However, NBA solutions watch what's happening inside your network, aggregating flow data from many points to support offline behavioral analysis, relationship profiling, anomaly identification and human-assisted "soft touch" remediation.

By operating passively, NBA avoids latency or becoming a performance bottleneck. By monitoring traffic flows inside your network, NBA can detect employee use of forbidden protocols and behind-the-firewall connections of infected laptops and removable storage. By comparing current behavior with past behavior, NBA can spot zero-day attacks and worm outbreaks for which signatures and patches have not yet been deployed. By taking a long-term view, NBA not only supports defense-in-depth -- but it also enables capacity planning and compliance reporting.

Adding NBA to your network

Emerging NBA solutions may vary in terminology and interfaces, but all distribute sensor appliances (aka monitors or collectors) throughout your internal network, at high-traffic intersections. NBA sensors are us


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Network Security
Rogue access points: Preventing, detecting and handling best practices
The TPM chip: An unexploited resource for network security
Shifting defenses and dynamic perimeters challenge network security
Compliance in a virtualized world: Server virtualization and NAC security
Securing the new network architecture: Security for distributed, dynamic networks
How to configure Windows Server 2008 advanced firewall MMC snap-in
USB storage devices: Two ways to stop the threat to network security
Network security: Using unified threat management (UTM)
Network security: Empower users without endangering IT
Network analysis -- Enhancing security assessments

Network Security Monitoring and Analysis
Where can I find a sample security audit report? How can I run my own?
The firewall remains the network traffic cop, but its role is changing
Troubleshooting VLANs: How to monitor 802.1q tagged traffic
Poor data-loss prevention practices almost cost Intel a billion
How can I block my competitor's IP address range from my website?
Hospital gains network visibility by convincing vendors to collaborate
What software monitors and locks users from accessing my router?
Data leak prevention starts with trusting your users
NagVis -- 'Nagios: System and Network Monitoring, Second Edition,' Chapter 18
What is a genetic algorithm and where can I learn more about them online?

Network Monitoring
Understand Windows tracert output to troubleshoot network connectivity
Network management and monitoring market remains crowded, fragmented
When do applications suffer from poor network performance?
Xangati help desk 'DVR' feature speeds up trouble ticketing resolution
Network change and configuration management vendors see big changes
YouTube, Facebook make bandwidth monitoring best practices challenging
How a new casino manages a giant network with 500 switches, IP voice
How network performance management can save money, boost applications
Return-all-values script: Managing Windows networks using scripts, Part 13
HTTP error code troubleshooting, Part 2: How to use IIS tool WFetch
Network Monitoring Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
deep packet inspection (DPI)  (SearchNetworking.com)
FCAPS  (SearchNetworking.com)
Nessus  (SearchNetworking.com)
netstat  (SearchNetworking.com)
port mirroring  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


ually connected to LAN taps or switch mirror (SPAN) ports. Some collect raw packets; others collect flow records from network switches and routers. For example, most NBA products can consume NetFlow and/or sFlow records that document the IP address, port, protocol and interface of each traffic stream passing through a router or switch.

Sensors relay observations to a central analyzer appliance (aka manager or controller). The analyzer creates a baseline of your network, observing client/server exchanges, the protocols they use, data rates, time of day and other metrics. Once this baseline has been established, the analyzer watches for variances -- for example, a rate spike that could indicate a worm outbreak, or an unusual peer-to-peer protocol being sent over port 80 to bypass firewall rules. Most analyzers can be configured with zone-based policies that spot violations -- for example, otherwise permissible traffic being exchanged between systems in different workgroups, defying data compartmentalization rules.

When anomalous behavior is detected, analyzers generate alerts. Role-based consoles let operators view alerts, visualize real-time service and user activity, and generate detailed reports for incident investigation or compliance reporting. As they do not operate in-line, NBA products are not designed to persistently auto-block intrusions. But some NBA products can take stop-loss actions, like adding a temporary access control list (ACL) to your router, switch, or firewall to quarantine the apparent source of a high-impact worm.

Choosing the right NBA appliance

What should you look for in an NBA solution?

Finding an NBA appliance

Some IPS vendors (e.g., Sourcefire Inc. in Columbia, Md.) are now adding NBA features to their product lines, complementing in-line defenses. Behavior analysis techniques are also creeping into SIM products (e.g., Enterasys Networks Inc. in Andover, Mass.). But many analysts consider NBA to be a distinct category, differentiated by location, role and focus. NBA appliances available today include the following:

About the author
Lisa Phifer is vice president of Core Competence Inc., a consulting firm specializing in network security and management technology. Phifer has been involved in the design, implementation and evaluation of data communications, internetworking, security and network management products for nearly 20 years. She teaches about wireless LANs and virtual private networking at industry conferences and has written extensively about network infrastructure and security technologies for numerous publications. She is also a site expert to SearchMobileComputing.com and SearchNetworking.com.

Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business

Alcatel-Lucent Network Business Communications Solutions

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts