home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Network Computing
HOT PICKS

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Centerfold
C E N T E R F O L D  
Major League Soccer Fields a Deep Line of Defense

  April 16, 2001
  By Kelly Jackson Higgins


During Major League Soccer's preseason and championships, the MLS network is under fire like a goalkeeper in a shoot-out. That's when illegal gambling on MLS games is in high season, with desperate hackers trying to score inside information on MLS teams and players from the league's servers.



The U.S. men's professional soccer league has built a new VPN (virtual private network) and security architecture to help block would-be intruders from stealing proprietary information. MLS runs a multitier security architecture at its New York headquarters; in addition to firewalls, this system includes an antivirus appliance and a Web monitoring server to track and control content in and out of the organization. "Our firewall is set to kill almost anything inbound," says Joseph Dalessio, network administrator for MLS, which runs a VPN for most of the 12 pro soccer teams in the league. "And we have security at the gateway, server and desktop."

MLS is one of a growing number of organizations instituting content control, both incoming and outgoing, as a security strategy. Dalessio's IT department has set filters with SurfControl's SuperScout software to prohibit users at headquarters from surfing sites with objectionable content or downloading inappropriate data. SuperScout, which MLS recently configured to run on a Microsoft Windows NT server, is the league's second shot at content control.

Content filtering is not an exact science, and MLS experienced that firsthand with its former firewall-based filtering configuration using the WatchGuard Technologies Firebox II. MLS users initially were blocked from the CNN/Sports Illustrated site because the tool weeded out SI's infamous swimsuit edition as inappropriate content. "Obviously, blocking the cnnsi.com site is not good for our organization," Dalessio says. The SuperScout content-filtering server, however, allows more detailed filtering, so it's less likely to block MLS users from sports sites, for instance.

The antivirus piece is Network Associates' WebShield e50, which scans for viruses and other malicious code entering MLS' SMTP server. The e50 was christened during the Anna Kournikova virus outbreak earlier this year. Once Dalessio spotted the virus disguised as an e-mail message, he put a block on any messages with the subject/title and body of the virus. "The e50 took all the variants of the virus, quarantined them and got rid of them," he says.

Having an antivirus appliance is key for MLS, which at first considered loading antivirus software onto its old WatchGuard firewall. Today MLS' firewall, antivirus and content-filtering functions are separate. "We didn't want a single point of failure," Dalessio says. The catch with the e50, however, is that it handles just SMTP traffic. "I'd like it to cover all content coming in over our Internet connection, including HTTP-borne viruses and other malicious code," he says.

MLS' SurfControl box, meanwhile, checks users' HTTP behavior, plus SMTP traffic patterns -- but not the content of the messages. MLS doesn't monitor outgoing e-mail for league-sensitive information, but that could change. "Generally, we've got a good Internet usage policy in place so nothing goes out that we don't want," Dalessio says. "But we are beginning to think about filtering e-mail based on content as well."

When MLS first installed SuperScout, the software set off multiple false alarms in the league's IDS (intrusion-detection system) sensors. That's because SuperScout requires a "promiscuous mode" network card for scanning the Internet gateway, and that function triggers alarms from the IDS sensors. So Dalessio configured the IDS to let SuperScout "sniff" the network without setting off the alarms.

Meanwhile, nearly all the MLS teams now have Cisco Systems PIX firewalls and will have SuperScout servers at their sites this year. The teams manage their own networks, except for the e-mail system, which is handled at MLS headquarters.







Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Purchase Today: $299
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



techweb
Online Communities TechWebInformationWeekLight ReadingIntelligent EnterprisebMightyNetwork ComputingDark ReadingDigital LibraryWall Street & Technology
Byte & SwitchNo JitterInternet EvolutionLight Reading's Cable Digital NewsContentinopleUnStrungBank Systems & TechnologyAdvanced TradingInsurance & Technology
Face-to-Face Events
InteropWeb 2.0 ExpoWeb 2.0 SummitVoiceConBlack HatCSISoftwareEntrprise 2.0 ConferenceGTEC
Mobile Business Expo
InformationWeek 500 ConferenceBuy Side Trading XchangeBuy Side Trading SummitBank Executive SummitInsurance Executive SummitTelcoTVEthernet ExpoOptical Expo
Magazines  
InformationWeekWall Street & TechnologyInsurance & TechnologyBank Systems & TechnologyAdvanced TradingMSDNTechNetSmart EnterpriseThe Architecture JournalDatabase Magazine
 
Research & Analyst Services  
Heavy ReadingInformationWeek ReportsInformationWeek Analytics
 
   
   
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights