Increasing Security with Net Flow Applications

Using a security-monitoring application, such as Cisco Security Monitoring, Analysis, and Response System3 (CS-MARS), makes using NetFlow easier and more readable. Indeed, CS-MARS can receive NetFlow export datagrams from multiple switches, and it can build graphs like the one shown in Figure 15-2. It can even have a rule that triggers an alert when predefined thresholds are crossed. Figure 15-2 shows baseline traffic, where the peak is simply the normal traffic increase during work hours.

Figure 15-2 NetFlow Data Displayed by CS-MARS

Figure 15-2 NetFlow Data Displayed by CS-MARS

At the bottom of Figure 15-2, there is some data regarding the Layer 4 protocols measured by NetFlow with normal traffic, such as HTTP (port 80), Simple Mail Transfer Protocol (SMTP) (port 25), Secure Sockets Layer (SSL) (port 443), and so on. The ratio between the night traffic (about 800 flows per minute) and the normal work-day traffic (about 3500 flows per minute), is about 1 to 4.5.

NOTE When a worm propagates or when a DoS attack occurs, network behavior is vastly different than usual. Therefore, there is no real need to fine-tune all CS-MARS thresholds (that is, to define the baseline with accuracy). In most cases, it should be enough to measure the amount of new flows per minute for a day, take the maximum and multiply it by 10 to be on the safe side and avoid the generation of false positives (false alerts).

CS-MARS detected the Sasser worm during its outbreak in early May 2004. Sasser exploited the vulnerability in the Microsoft Windows Local Security Authority Subsystem Service (LSASS) and aggressively propagated itself by using TCP port 445. The outbreak mainly happened on Saturday, May 1, and it was detected by the combination of NetFlow and CS-MARS, as Figure 15-3 shows.

Figure 15-3 NetFlow and CS-MARS Detect Sasser Worm

Figure 15-3 NetFlow and CS-MARS Detect Sasser Worm

Figure 15-3 is snapshot taken by a user during an actual worm outbreak; it has not been taken in a lab, hence, its its printed quality is less than ideal, but it is really a history landmark. Two main peaks can be seen on Figure 15-3:

• On the left. Normal HTTP traffic during work hours on Thursday.

• On the right. Sasser worm spreads during Sunday (main peak caused by a variant of Sasser called Sasser.B) until some PCs were either shut down, disconnected, or cleaned. Yet, another peak occurs on Monday when unprotected PCs joined the network and when yet another variant, Sasser.C, launched.

Hence, NetFlow and CS-MARS can detect an active worm and literally see whether the infection increases or decreases. Furthermore, CS-MARS can display the source IP addresses of all worm flows; this information can then help the IT staff make a list of infected machines.

NOTE The key factor to decide whether there is an unusual event is not the amount of traffic (in bps), but the rate of creation of new flows. The amount of traffic is not a true indication of an attack or worm.

Beside CS-MARS, other commercial tools exist, such as Arbor Networks PeakFlow/X© and noncommercial tools, such as flow-tools4 and cflowd5.

Continue reading here: Securing Networks with RMON

Was this article helpful?

0 0