Home > Networking Tips > Network Security > Security Spotlight: Network Behavior Analysis goes long and wide
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY

Security Spotlight: Network Behavior Analysis goes long and wide


Lisa Phifer
10.23.2006
Rating: -4.33- (out of 5)


Network security news, advice and technical information
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


SECURITY SPOTLIGHT
Despite massive investment in firewalls, intrusion prevention and antivirus, enterprise networks continue to be plagued by internal misuse and attack. For seven years straight, insider abuse and virus outbreaks have topped the CSI/FBI Computer Crime and Security Survey. Network operations center staff, already overwhelmed by security perimeter alerts, just can't afford to battle internal threats the same old way. Perhaps it is time to consider a new approach: Network Behavior Analysis (NBA).

Why deploy Network Behavior Analysis?

NBA, also known as Network Behavior Anomaly Detection, describes a relatively new field of products that employ passive observation and profiling to spot traffic spikes, atypical usage and policy violations. Conventional intrusion prevention system solutions like Snort and Intrusion.com defend your network's perimeter through in-line traffic inspection, signature detection and real-time blocking. However, NBA solutions watch what's happening inside your network, aggregating flow data from many points to support offline behavioral analysis, relationship profiling, anomaly identification and human-assisted "soft touch" remediation.

By operating passively, NBA avoids latency or becoming a performance bottleneck. By monitoring traffic flows inside your network, NBA can detect employee use of forbidden protocols and behind-the-firewall connections of infected laptops and removable storage. By comparing current behavior with past behavior, NBA can spot zero-day attacks and worm outbreaks for which signatures and patches have not yet been deployed. By taking a long-term view, NBA not only supports defense-in-depth -- but it also enables capacity planning and compliance reporting.

Adding NBA to your network

Emerging NBA solutions may vary in terminology and interfaces, but all distribute sensor appliances (aka monitors or collectors) throughout your internal network, at high-traffic intersections. NBA sensors are usually connected to LAN taps or switch mirror (SPAN) ports. Some collect raw packets; others collect flow records from network switches and routers. For example, most NBA products can consume NetFlow and/or sFlow records that document the IP address, port, protocol and interface of each traffic stream passing through a router or switch.

Sensors relay observations to a central analyzer appliance (aka manager or controller). The analyzer creates a baseline of your network, observing client/server exchanges, the protocols they use, data rates, time of day and other metrics. Once this baseline has been established, the analyzer watches for variances -- for example, a rate spike that could indicate a worm outbreak, or an unusual peer-to-peer protocol being sent over port 80 to bypass firewall rules. Most analyzers can be configured with zone-based policies that spot violations -- for example, otherwise permissible traffic being exchanged between systems in different workgroups, defying data compartmentalization rules.

When anomalous behavior is detected, analyzers generate alerts. Role-based consoles let operators view alerts, visualize real-time service and user activity, and generate detailed reports for incident investigation or compliance reporting. As they do not operate in-line, NBA products are not designed to persistently auto-block intrusions. But some NBA products can take stop-loss actions, like adding a temporary access control list (ACL) to your router, switch, or firewall to quarantine the apparent source of a high-impact worm.

Choosing the right NBA appliance

What should you look for in an NBA solution?

  1. Consider where to deploy NBA sensor appliances throughout your network. Sensors that gather raw packets can be expensive in very large networks -- you may want to start by creating "security zones" around high-value assets. Gathering flow records from routers and switches leverages your existing network infrastructure to provide broader NBA coverage with fewer sensors.
  2. Check sensor compatibility with your existing network at the physical, data link and network layers, including NetFlow and sFlow versions, support for proprietary flow protocols, number/type of LAN ports, and verified-interoperable network devices. For some products, different observation methods require different sensor models.
  3. Match NBA sensors and your central analyzer to your network size. For example, Mazu Network Inc.'s Profiler is sold in three configurations, based on number of monitored hosts (from 2,500 to 400,000) and observed flows (from 100K to 1M flows per minute.) For large offices, consider regional analysis or regional flow data aggregation.
  4. The analyzer is the heart and soul of any NBA. Take a hard look at how threats are detected, how the baseline adjusts over time, how zones and policies are configured, and how alerts are reported. For example, an NBA should automatically learn who normally talks to whom, along with how often and when they talk. If your business tends to have very busy periods, will the NBA generate false positives? How quickly will it adjust when the busy period ends? How accurately does it model relationships between your systems, and how accurately can it pinpoint the root cause of an outbreak?
  5. NBA products are evolving at the human/system interface: expanding integration with NMS and SIM systems, providing customizable views optimized for each person's job and catering to compliance reporting. For example, can your NBA add ACLs to your router, switch or firewall -- or coordinate that action through your NMS? Can it tie alerts to individual users by consulting your authentication systems? How long is data retained for ad hoc queries and historical reporting?

  6. As with any security system, look for encrypted/authenticated management interfaces, platform hardening and high-availability. Extend this care to all flow data sources leveraged by your NBA. Use your NBA not only to spot surges and flows that should not be there, but also to detect dropouts and absence of traffic that should be there.

Finding an NBA appliance

Some IPS vendors (e.g., Sourcefire Inc. in Columbia, Md.) are now adding NBA features to their product lines, complementing in-line defenses. Behavior analysis techniques are also creeping into SIM products (e.g., Enterasys Networks Inc. in Andover, Mass.). But many analysts consider NBA to be a distinct category, differentiated by location, role and focus. NBA appliances available today include the following:

About the author
Lisa Phifer is vice president of Core Competence Inc., a consulting firm specializing in network security and management technology. Phifer has been involved in the design, implementation and evaluation of data communications, internetworking, security and network management products for nearly 20 years. She teaches about wireless LANs and virtual private networking at industry conferences and has written extensively about network infrastructure and security technologies for numerous publications. She is also a site expert to SearchMobileComputing.com and SearchNetworking.com.

Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Network Security
Shifting defenses and dynamic perimeters challenge network security
Compliance in a virtualized world: Server virtualization and NAC security
Securing the new network architecture: Security for distributed, dynamic networks
How to configure Windows Server 2008 advanced firewall MMC snap-in
Security across network boundaries with Secure Mobile Architecture
USB storage devices: Two ways to stop the threat to network security
Network security: Using unified threat management (UTM)
Network security: Empower users without endangering IT
Network analysis -- Enhancing security assessments
VPN security: Hiding in plain sight, using network encryption

Network Security Monitoring
Networking data visualization not just for pointy-headed bosses
Visual Security Analysis -- 'Applied Security Visualization,' Chapter 5
SIEM platform secures university's open network
Network forensics appliance gets storage boost and 10 GbE support
Tracking NetFlow over MPLS helps airline with compliance
Securing the new network architecture: Security for distributed, dynamic networks
When it comes to data loss prevention, networking should be part of the conversation
What is data loss prevention? -- An introduction to DLP
What are the best methods for handling rogue access points?
Internet monitoring vendor adds throttling, filtering, to its appliance

Network Monitoring
Networking data visualization not just for pointy-headed bosses
What network security threat does a QM FSM error pose in IPsec VPNs?
Juniper updates Network and Security Manager to manage full portfolio
Network management software vendors readying IPv6
DNS management becoming critical to businesses but poorly understood
SolarWinds adds enterprise scalability to its network monitoring tool
Network forensics appliance gets storage boost and 10 GbE support
Tracking NetFlow over MPLS helps airline with compliance
When it comes to data loss prevention, networking should be part of the conversation
Network management takes interface tips from gaming industry, Google
Network Monitoring Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
deep packet inspection (DPI)  (SearchNetworking.com)
FCAPS  (SearchNetworking.com)
Nessus  (SearchNetworking.com)
netstat  (SearchNetworking.com)
port mirroring  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business
IT Management Solutions and Services Directory.
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts