Beware Of The Red Dragon
I have dedicated several posts to NG-IPS, the next step of the evolution in network security (or better to say context security). I have pointed out that one of the main features of this kind of devices is the capability to enforce Location Based security services. Now it is time to make some practical examples indicating how Geo Protection features may be helpful and why they are needed in this troubled days.
Few days ago I had the opportunity to analyze the data collected from a network security equipment, placed at the perimeter of an important Italian customer, with IPS engine turned on and Geo Protection feature enabled. I show here a brief summary of the collected data, that span approximatively a thirty days period ranging from 1 to 27 November 2011.
As you may easily notice, collected data show Geo Protection events undoubtedly at number one with 713,117 occurences. The enforced Geo Protection Policy blocked traffic from and to several “bad countries”. Just try to Guess which country was detected by the Geo Protection Policy with the highest rate of attacks? The top attack source report contains the answer to this question, but if yoy want I can suggest you a quick hint: one of the countries which appeared in the unwelcomed list of Geo Protection Policy was just China.
The top 5 attack sources generated together nearly 150,000 events. I was not that surprised when I looked up the IP Addresses (which I did not explicitly report on the graph) and realized that all of them came from China. These addresses were blocked a priori by Geo Protection.
The tabular report is also more explicit: 9 out of 10 sources at the top for the number of attacks, came from China whilst 1 was shown to be an internal address (revealed to be a misconfigured device generating bogus events). Together the 9 top sources generated nearly 260,000 on a total of 800,000 events collected from nearly 90,000 addresses.
As far as the impacted services are concerned, traditional protocols ranked at the first positions of the chart with some strange occurrences (TCP/0 or UDP/0 that might mean malformed packets or also the attempt to exploit old attacks targeting security devices). It is worthwhile to notice the presence of the well-known TCP port 1433 (MS-SQL).
Of course the attempts to exploit Microsoft Ports and (maybe) to harvest the network were detected by the geo protection engine as shown in the following table.
While I was analysing these data I could not help but think to the recent post by Brian Kerbs suggesting that the same attack perpetrated against RSA targeted more than 760 other organizations (almost 20 percent of the current Fortune 100 companies were on the alleged list). The same post indicated that the location of 299 (on more than 300) command and control networks used in these attacks were located in China.
Besides some concern regarding the Chinese Cyber Strategy, the parallelism suggested me that Geo Protection might provide a valuable support for thwarting APTs or, more in general, for thwarting attacks phoning home to C&C Server located in “bad” countries, provided that Geo Protection Service Database is constantly updated. Unfortunately I am afraid that attackers will not take so long to learn and enforce some workarounds using (un)secure compromised C&C servers in “good” (i.e. not classified by the Geo Protection) countries. In any case Geo Protection cannot be considered the only cure, but at the end this is the reason why NG-IPS are capable to enforce different algorithms to provide a context base security model.
Related articles
- The China Cyber Attacks Syndrome (paulsparrows.wordpress.com)
Leave a Reply Cancel reply
Stats
- 488,871 hits since November 2010
Interesting Links
News
08/13/2011 - My Post on Android Malware Mentioned on Engadget.
04/14/2011 - The Article Smart Grid: L'ultima Frontiera del Cybercrime published on ICT Security Magazine May 2011.
03/14/2011 - Security Summit 2011: Paolo Passeri guest at Round Table "Mobile Security: Rischi, Tecnologie, Mercato"
02/14/2011 - The Article Gears of Cyberwar published on ICT Security Magazine January 2011.
About This Blog
|
In this blog I express my personal opinion, which does not necessarily reflects the opinion of my organization, about events and news or interest, concerning information security, winking to mobile world and, why not, to some curious personal event. Every information is reported with its source. Anyone intending to use information contained in my post is free to do so, provided that mention my blog in your article. |
Calendar
Archive
Tag
Recent Posts
Top Posts & Pages
- List Of Hacked Celebrities Who Had (Nude) Photos Leaked
- 2013 Cyber Attacks Timeline Master Index
- 2012 Cyber Attacks Statistics
- 2012 Cyber Attacks Timeline Master Index
- 15-31 May 2013 Cyber Attacks Timeline
- May 2013 Cyber Attacks Statistics
- March 2013 Cyber Attacks Statistics
- 1-15 May 2013 Cyber Attacks Timeline
- A (Graphical) World of Botnets and Cyber Attacks
- About Me
- @taosecurity @Mandiant Sure, could I have more details? - 1 week ago
- 2013 Cyber Attacks Master Index wp.me/p14J6X-2q5 - 1 week ago
- Edward Snowden: the whistleblower behind revelations of NSA surveillance gu.com/p/3gec7/tw via @guardian - 1 week ago
- May 2013 Cyber Attacks Statistics lnkd.in/FFm8cN - 1 week ago
- May 2013 Cyber Attacks Statistics hackmageddon.com/2013/06/09/may… #Infosec #Cybercrime - 1 week ago
- Domino’s Pizza testing pizza-delivering drones fxn.ws/10NTX38 via @hushedfeet - 2 weeks ago
- Hard Work during the WE to post in time the May 2013 Cyber Attacks TImeline lnkd.in/BABPvC I'm abusing of my wife's patience :) - 2 weeks ago
- 15-31 May 2013 Cyber Attacks Timeline wp.me/p14J6X-2pl - 2 weeks ago
- @OPSWAT This test is incoherent. Wepawet only handles Flash, JavaScript, and PDF files, you also tested office and exe files - 2 weeks ago
- RT @teamcymru: 30million 'wi-fi' credit cards can be plundered by cyber identity thieves exploiting contactless payment technology http://t… - 2 weeks ago





