Securing Networks with RMON

Remote Monitoring (RMON) is a specific SNMP Management Information Base (MIB) for remote monitoring and management of network equipment. MIB is standardized at the IETF as RFC 20216 and RFC 28197. It transforms every RMON-capable network device into a remote protocol analyzer. Different pieces of information can be collected:

• Host. Related to each host discovered in the network by keeping MAC addresses captured in promiscuous mode.

• Matrix. Used for conversations between sets of two addresses.

• Upper-layer protocol. Some RMON implementations understand IP, IPv6, UDP, TCP, and can collect information about hosts and conversations for those protocols.

• Packet capture. An RMON device can even capture packets to allow for remote sniffing.

RMON has filters (to analyze only specific frames) and alerts (to generate SNMP traps on specific events).

The Cisco Network Analysis Module (NAM) is an implementation of RMON available for Catalyst 6500, as well as for some routers, such as Cisco 2800 or 3800 Series. The NAM has a built-in web interface, which includes several Java applets.

NOTE NAM is beyond the scope of this book; however, a few details are given on NAM to focus on its use to detect worms and DoS attacks.

A specific Switched Port Analyzer (SPAN) must be configured to forward all frames to the NAM module. Alternatively, a VLAN access control list (ACL) with the capture feature can forward traffic to the NAM.

NOTE For more information on ACLs, see Chapter 16, "Wire Speed Access Control Lists."

Example 15-4 describes such a SPAN configuration to copy all traffic sent and received on VLAN 1 to the NAM located in slot 3.

Example 15-4 SPAN Configuration for NAM

IOS(config)# monitor session 1 source vlan 1 both

IOS(config)# monitor session 1 destination analysis-module 3 data-port 1 IOS# show monitor

Session 1

Type :Local Session

Source Ports:

RX Only: None

TX Only: None

Both: None

Source VLANs:

RX Only: None

TX Only: None

Both: 1

Source RSPAN VLAN:None

Destination Ports:analysis-module 3 data-port 1

After the NAM works, the built-in web application can get a graphical representation of the analyzed traffic. Figure 15-4 immediately shows that protocol Server Message Block (SMB) (actually, TCP port 445) is, by far, the most active protocol on the network.

Because this SMB traffic is measured at about 20,000 packets per second (pps), it is probably a DoS or a worm running on this port. The Sasser worm is a good candidate to explain this unusual behavior. NAM could have been configured to send an alert when a single protocol exceeds the threshold.

This use of NAM is similar to the use of NetFlow; however, NAM can provide more details on an existing attack or worm with the use of the capture function.

Figure 15-5 clearly indicates that server 10.48.99.134 is under a SYN flooding with random source IP addresses. Indeed, all packets that have been captured are TCP SYN, and all were sent to the same destination IP address, 10.48.99.134, which is the victim.

Figure 15-4 NAM Detects a High Volume of SMB Traffic

Cisco System

NAM Traffic Analyzer

Help 1 Logout 1 About 1

'setup 1— i Reports

Captur

e Alarms

a (111

in

* Overview ♦■1TB * Voice * Hosts * Conversations *

VLAIM • DiffServ

* Response Time • Port Stats *

You Are Here: ♦ Monitor > Apps

TopN Applications Chart

• Per-Second Data: as of Fri 02 Mar 2007,15:0

6:41 GMT

-

E Auto Refresh

O Current Rates © TopM Chart O Cumulative Data

Date Sourc

s| ALL SPAN v Variable: Packets/s v

■2S

ket

s/s

et

EH

Hüüü

g 12.00-h 9.006.003.00-0.00^

n

Protocol mobipmgr ■ 139-50

/ •

__________________

/

■ clearcase

■ tacaos xns-auth

■ hostname

■ Ire nbt-name

M

c m

Figure 15-5 NAM Capture Function for a SYN Flooding

Figure 15-5 NAM Capture Function for a SYN Flooding

Because NAM can go deeper and actually captures data, it can even dig in to a TCP payload, as Figure 15-6 shows.

The built-in application can decode the captured packets to get the URL (in this example, /capture/settings.php) and display the actual HTTP headers (as shown at the bottom of Figure 15-6). This might be useful to analyze the DoS or the worm attack to derive a mitigation technique.

Figure 15-6 NAM Decode Function for an HTTP Packet

Figure 15-6 NAM Decode Function for an HTTP Packet

Continue reading here: Protecting the Infrastructure Using ACLs

Was this article helpful?

0 0