home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



Column - Down to Business
S N E A K   P R E V I E W  
Keeping an eEye on IIS Web Server

  May 29, 2003
  By Jeff Forristal


TOC Issue TOC
Printer Print full article
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author

I don't want to sound like yet another IT geek bashing Microsoft for the lack of IIS security, but let's face it: IIS doesn't have a great security track record, and even Microsoft realizes that. A whole host of IIS-centric security products has been developed over the last few years, including URLScan, developed by none other than Microsoft!

Managing the IIS Web server is one thing, and a relatively easy thing at that. Managing the security of IIS server and its security add-ons, however, is quite another. You need to manage security events from your Web server for the same reason you need to manage IDS events: Each attack event has forensic value and should be researched to ensure the attacker didn't successfully exploit other avenues. That's where eEye steps in. EWP (Enterprise Web Protection), eEye's latest offering, integrates eEye's SecureIIS product with its REM Events Server and REM Events Manager components. EWP provides a framework to manage SecureIIS security events in trouble-ticket fashion.


The main EWP solution workhorse and source of events is SecureIIS. A security-enhancing ISAPI plugin for IIS, SecureIIS protects against known and unknown vulnerabilities. Windows administrators familiar with Microsoft's URLScan will find SecureIIS easy to navigate; plus, it offers more features and granularity than URLScan. In many ways, SecureIIS acts as a host-based HTTP protocol firewall, inspecting each request and looking for signs of attack. SecureIIS focuses on global HTTP request aspects, which is more than enough to protect your Web server, but not necessarily enough to protect your Web applications. Unlike a true Web application proxy/firewall, it does not inspect or enforce hidden form fields, cookie tampering and so on.

Monitoring Events

The REM Events Server is the main collection point for SecureIIS events, including policy violations, attack attempt notifications and administrative notices related to SecureIIS configuration. An REM Events Server Client is installed on each individual SecureIIS machine, and it is responsible for taking the SecureIIS events and sending them to the REM Events Server in a secure manner using public/private key encryption. Once the REM Events Server receives the event, it is placed in a preexisting ODBC-compliant database. This version of REM Events Server requires you to provide your own database server software. I would like to have had a database engine included--specifically, Microsoft's free MSDE engine.

After the events are safely tucked into the database, there are two ways to view them. The first way is to have the REM Events Server export all events to the Windows event log, allowing other event management systems like Tivoli or HP OpenView to pick up the log events. This allows integration into existing helpdesk/IT event management infrastructure. The second way to view events collected by the REM Events Server is to use the REM Events Manager, a multiuser Web portal application that installs into an existing IIS server. It allows viewing, searching and reporting of received events.

The REM Events Manager is designed to act as an IT helpdesk or trouble-ticket system. Incoming events can be sifted and automatically delegated to the appropriate personnel for action; delegated events are tracked until completion. The REM Events Manager can produce myriad reports, detailing information such as events, tasks and the top 20 event types grouped by severity, source or destination.

Watch it Run

It wasn't difficult to install the components; preparing the database to use REM Events Server was the biggest hurdle of the entire installation process. Fortunately, the purchase of an EWP solution from eEye includes an engineer installation visit. You don't need to worry about installation nuances beyond the integration of future additional SecureIIS clients. Luckily, I found incorporating a new SecureIIS install into the EWP framework a piece of cake. You simply install SecureIIS like normal, then install the REM Events Server Client and supply the public key produced by your REM Events Server.

Good
• Integrates with all eEye products
• Trouble-ticket system greatly streamlines the security incident follow-up process

Bad
• Lacks integrated SecureIIS configuration management support
• Is only valuable in eEye-product-laden environments

Vendor Info
Enterprise Web Protection eEye Digital Security; Price starts at $20,000 for five servers (949) 349-9062 (866)339-3732 www.eeye.com
Once all the components were installed and configured, I tested EWP by triggering a few choice Unicode attacks against my SecureIIS-protected Web server. The attack alerts showed up on the REM Events Manager alerts Web page, and I could view the particulars of each event as well as assign them for handling and remediation.

My main disappointment with EWP is its inability to manage the actual SecureIIS configuration. Fortunately, SecureIIS allows you to import a central configuration policy file. It would be nice, however, if that central policy was integrated into the REM Events Manager.

I also encountered a few minor annoyances. Rule construction for the automatic assigning of predefined incoming events is a bit inflexible and general in nature. The event search functionality is limited to keyword searches of the generic event titles, rather than event specifics, which makes it nearly impossible to search for events generated by a specific source IP address.

It should be obvious that the EWP solution is only applicable to Windows IIS sites either having or looking to have moderate to large-scale SecureIIS deployments. The cost-effectiveness of using eEye's REM components is largely based on the number of eEye products plugged into it. If you currently use eEye products, or you're a Windows shop looking to deploy a from-start-to-finish security event management solution for your IIS Web sites, it would be worthwhile to look at eEye EWP as an event management candidate.

Jeff Forristal is a senior security consultant for Neohapsis.

Post a comment or question on this story.









Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights