Upcoming Events

Cloud Connect
Santa Clara
Feb 13-16, 2012

Cloud Connect brings together the entire cloud eco-system to better understand the transformation we're experiencing and promises to be the defining event of the cloud computing industry. Learn about the latest cloud technologies and platforms from thought leaders in Cloud Connect’s comprehensive conference.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up
Security
F E A T U R E  
Don't Panic. Plan

  May 1, 2003
  By Mike Fratto


>> continued from previous page

Reduce the Danger

TOC Issue TOC
Printer Print full article
Printer Print this page
Printer Download as PDF
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author
 
  In this article
arrow
Introduction
arrow
Give 'Em an Inch ...
arrow
Control the Things You Can
arrow
Resources
arrow
Full Disclosure Works
arrow
Reduce the Danger

Before you start throwing stones at neighbors with vulnerable networks, take a good look at your own network. Traffic flows are two-way streets and screwed-up configurations affect systems near and far. It takes a village to raze a network.

In some cases, you may have to get your service provider to make configuration changes for you. It's worth the hassle--the more relatively minor misconfigurations get fixed, the better off everyone will be. In no particular order, here's a checklist to get you started:

• Filter outbound traffic: If the firewall is blocking only inbound traffic, you're using only half its capabilities. Start identifying necessary outbound traffic and disallowing everything else. Doing so makes getting data through the firewall more difficult.

• Filter your egress: Your organization should know what subnets are hosted on the network. Allowing only traffic originating from those subnets to traverse the border router or firewall prevents traffic with spoofed source addresses from passing. Enable antispoofing at the router.

• Disable directed broadcasts: Directed broadcasts are a side effect of networking. Send an ICMP Echo Request to a network broadcast address, and all available hosts will respond. There is little need to allow directed broadcasts--or any from from foreign networks. Disable directed broadcasts at the router.



E-Poll Results

click to enlarge

• Block protocols at the router: Some traffic--such as NetBIOS, SNMP and some ICMP types, including echo request, time request and subnet request--shouldn't traverse the border. Just drop it all at the router and be done with it. That way, even if a badly configured firewall crops up, the traffic won't leak out.

• Implement tiered defenses: If you have one border router between your network and the world, what happens if it is compromised? Examine your traffic flows and design your network to restrict flows even if components fail.


start top   Full Disclosure Works Reduce the Danger

Research and Reports

Hypervisor Derby
August 2011

Network Computing: August 2011

TechWeb Careers