Proactive Security Framework
Many network security frameworks are in the marketplace and most of them have the common goal of providing a methodical and efficient approach to network security. No framework is perfect, you should choose an approach that can help reduce the time, cost, and resources needed to plan and deploy your security strategy. This chapter highlights best practices and benefits of different security frameworks.
A framework can help you establish a view of your entire security landscape, identify potential capability gaps, and prioritize initiatives for improvement.
The Security Assessment, Validation, and Execution (SAVE) framework, formerly known as the Cisco Operational Process Model (COPM), is a security framework that enables visibility and control for end-to-end security. Cisco initially designed SAVE for the Internet service provider (ISP) part of the Next-Generation Network (NGN) initiative. However, you can also apply its practices to enterprises.
Today, malicious traffic within ISPs is spreading faster than before because attack tools are becoming more sophisticated and easier to find. ISPs have witnessed a transformation in the community that engages in cybercrime activities for financial reward, otherwise known as the miscreant economy. The principles introduced by SAVE allow ISPs and other organizations to defend against these threats while maintaining control and visibility of their networks.
SAVE defines network security in six major categories or "pillars." Figure 7-1 illustrates the different categories within the SAVE framework.
The six pillars in SAVE are as follows:
• Identity and trust
• Visibility
• Correlation
• Instrumentation and management
• Isolation and virtualization
• Policy enforcement
Figure 7-1 SAVE Categories Illustrated
Identity and Trust
Identity State of Trust
Visibility
Observe IP Packets
Layer 2 through Layer 7
Stateful and Stateless
Correlation
Relational Analysis of System-Wide Events
Instrumentation and Management
Device Hardening and Operational Views
Isolation and Virtualization
Policy Enforcement
|
Resiliency |
|
|
Total Visibility Classify, Categorize and Associate Events to a Given Control Policy |
Complete Control Service Policies that allow for Containment, Mitigation and Service Constraint Enforcement |
SAVE Versus ITU-T X.805
There is a security methodology created by the Lucent consulting practice called ITU-T X.805, "Security Architecture for Systems Providing End-to-End Communications." ITU-T X.805 defines a threat model that includes five categories:
• Destruction
• Corruption
• Disclosure
• Interruption
ITU-T X.805 defines three security layers:
• Applications layer
Figure 7-2 ITU-T X.805 Security Layers
Figure 7-2 ITU-T X.805 Security Layers
Infrastructure Layer ' Routers ' Switches ' Firewalls ■ Servers and Workstations
Services Layer
• Location Services
• Other IP Services
Applications Layer
• Web Browsing
Infrastructure Layer ' Routers ' Switches ' Firewalls ■ Servers and Workstations
Services Layer
• Location Services
• Other IP Services
Applications Layer
• Web Browsing
The ITU-T X.805 infrastructure layer includes all infrastructure devices, including:
• Switches
• Firewalls
• End-user workstations
The services layer includes services such as the following:
• Location services
• Other IP services
The applications layer includes all Layer 7 applications that run on the network infrastructure. Each layer has unique threats, vulnerabilities, and ways to mitigate them. X.805 also has three security planes:
• Control/Signaling plane
These security planes are illustrated in Figure 7-3.
Figure 7-3 ITU-T X.805 Planes
Figure 7-3 ITU-T X.805 Planes
|
Infrastructure Layer |
Services Layer |
Applications Layer |
||
|
• Routers |
• Voice over IP (VoIP) |
• Web Browsing |
||
|
• Switches |
• Quality of Service (QoS) |
|
||
|
• Firewalls |
• Location Services |
• E-Commerce |
||
|
• Servers and Workstations |
• Other IP Services |
• Mobile Web |
||
End-User Security Control/Signaling Security
End-User Security Control/Signaling Security
Management Security
X.805 also includes eight security dimensions that apply to each security layer and plane. The following are these dimensions:
• Access control: Firewall policies and access control lists (ACL).
• Authentication: Public key infrastructure (PKI), shared secrets, and one-time-passwords.
• Nonrepudiation: Syslogs and digital signatures.
• Data confidentiality: This confidentiality occurs through the use of encryption.
• Communication security: Transport mechanisms such as IP Security (IPsec) and Secure Socket Layer (SSL) virtual private networks (VPN), in addition to Layer 2 Tunneling Protocol (L2TP) tunnels.
• Data integrity: Hashing with message digest algorithm 5 (MD5) and Secure Hash Algorithm (SHA).
• Availability: Examples include redundancy with Hot Standby Router Protocol (HSRP) or Virtual Router Redundancy Protocol (VRRP).
• Privacy: Encryption and Network Address Translation (NAT). The eight security dimensions are illustrated in Figure 7-4.
Confused yet? X.805 is an overcomplicated approach. Cisco has tried to evolve it to make it more practical to use; however, X.805 is not a true end-to-end security framework and is even potentially harmful in the market and in standards.
Figure 7-4 ITU-TX.805 Security Dimensions
Figure 7-4 ITU-TX.805 Security Dimensions
|
Infrastructure Layer |
Services Layer |
Applications Layer |
||
|
• Routers |
• Voice over IP (VoIP) |
• Web Browsing |
||
|
• Switches |
• Quality of Service (QoS) |
|
||
|
• Firewalls |
• Location Services |
• E-Commerce |
||
|
• Servers and Workstations |
• Other IP Services |
• Mobile Web |
||
End-User Security Control/Signaling Security
End-User Security Control/Signaling Security
Management Security
• Access Control
• Authentication
• Data Confidentiality
• Communication Security
• Data Integrity
• Availability
SAVE introduces a roles-based approach for security assessment in a simple manner. Each device on the network serves a purpose and has a role; subsequently, you should configure each device accordingly. SAVE defines five different planes:
• Management plane: Distributed and modular network management environment.
• Control plane: Includes routing control. This is often a target because the control plane depends on direct CPU cycles.
• User/Data plane: Receives, processes, and transmits network data among all network elements.
• Services plane: Layer 7 application flow built on the foundation of the other layers.
• Policies: The business requirements. Cisco calls policies the business glue for the network. Policies and procedures are part of this section, and they apply to all the planes in this list.
These planes are illustrated in Figure 7-5.
Figure 7-5 Planes in SAVE
|
Data |
Control |
Management |
Services |
||||
|
t |
t |
t |
t |
||||
|
Policies |
|||||||
SAVE also presents security in two different perspectives:
• Operational (reactive) security
• Proactive security
This is illustrated in Figure 7-6.
Figure 7-6 Operational and Proactive Security
Improve your capabilities to react to security incidents.
Proactively prepare your infrastructure, staff, and organization as a whole. Learn about new attack vectors and mitigate them with the appropriate hardware, software, and architecture solutions.
You should have a balance between proactive and reactive security approaches. Prepare your network, staff, and organization as a whole to better identify, classify, trace back, and react to security incidents. In addition, proactively protect your organization while learning about new attack vectors, and mitigate those vectors with the appropriate hardware, software, and architecture solutions. You can achieve this balance using what you learned in Chapter 2, "Preparation Phase." The best practices described there help you to proactively prepare and protect your network and organization as a whole.
Continue reading here: IP Source Guard
Was this article helpful?