- Separate monitoring domain
- Hierarchical monitoring structure
Event monitoring and management can be divided into the need for real-time event monitoring and management and the need to perform analysis based on archived information (reporting). These functions can be handled by a single server, or the functions can be placed on separate servers to scale deployment. The number of sensors that should be forwarding alarms to a single IDS management console is a function of the aggregate number of alarms per second generated by those sensors.
Experience with customer networks has shown that the number of sensors reporting to a single IDS management console should be limited to 25 or fewer. These customers use a mixture of default signature profiles and tuned signatures. The number of alarms generated by each sensor is determined by how sensitively the sensor is tuned; the more sensitive the tuning, the fewer the alarms generated and the larger the number of sensors that can report to a single IDS management console.
It is essential to tune out false positives to maximize the scalability of the network IDS deployment. Sensors that are expected to generate a large number of alarms, such as those sitting outside the corporate firewall, should log in to a separate IDS management console, because the number of false alarms raised increases the noise-to-signal ratio dramatically and makes it difficult to identify otherwise valid events.
When implementing multiple IDS management consoles, implement either separate monitoring domains or a hierarchical monitoring structure.
Separate security monitoring domains can be used when separate security operations groups are responsible for different geographic areas or business units. In this implementation, there is no ability to monitor real-time activity across the entire enterprise; sensors send alarms only to the IDS management console in their geographic area or business unit. To offset lost functionality, implement a separate, centralized system for trend analysis and reporting, and have all IDS management consoles forward events to this system. This architecture is similar to a Manager of Managers (MoM) architecture.
5-14 Securing Cisco Network Devices (SND) v2.0 © 2006 Cisco Systems, Inc.
An effective hierarchical monitoring structure requires an alarm or event policy to distinguish and identify those alarms requiring a local, regional, or corporate-wide response. Local alarms indicate a small-scale, localized attack against a branch network or remote office. Regional alarms indicate an attack against several branch networks, telecommuters, or remote office networks within a given geographic region. Regional incidents can be escalated to a more corporate-wide audience if it is determined that additional resources are necessary. Corporate-wide incidents represent a broad, enterprise-wide attack from one or more sources. In the latter situation, an enterprise security incident response team must coordinate the response. Local security personnel in regional networks may require direction to effectively coordinate resources to contain the various incidents and restore overall network integrity.
© 2006 Cisco Systems, Inc. Securing Networks with Cisco IOS IPS 5-15
Two-Tier Hierarchical Cisco Security-MARS IPS Monitoring System
This figure shows a two-tiered hierarchical security monitoring system using the Cisco Security Monitoring, Analysis, and Response System (MARS) as an example. Cisco Security MARS can be deployed in a two-tiered architecture using a Cisco Security MARS Global Controller. The Cisco Security MARS Global Controller monitors two or more local zones. Each zone consists of a cluster of monitored devices (such as IPS sensors, firewalls, routers, and servers), and each zone is managed by a Cisco Security MARS Local Controller. The Cisco Security MARS Global Controller and Local Controller architecture has these advantages:
■ The architecture allows for centralized, distributed management of network topology.
■ A Cisco Security Global Controller manages multiple Cisco Security MARS Local Controllers (restricted by the license key), and each Cisco Security MARS Local Controller manages one zone.
■ The architecture lets remote sites view their own data while keeping data private between Cisco Security MARS Global Controllers and Local Controllers.
■ You can view the entire network from the Cisco Security MARS Global Controller.
■ You can use multiple Cisco Security MARS Local Controllers to isolate departmental functions.
5-16 Securing Cisco Network Devices (SND) v2.0 © 2006 Cisco Systems, Inc.
HIPS and Network IPS
This topic describes how HIPS and network IPS monitoring work.
This topic describes how HIPS and network IPS monitoring work.
HIPS audits host log files, host file systems, and resources. A significant advantage of HIPS is that it can monitor operating system processes and protect critical system resources, including files that may exist only on that specific host. HIPS combines behavioral analysis and signature filters. HIPS can also combine the best features of antivirus, network firewalls, and application firewalls in one package.
A simple form of HIPS enables system logging and log analysis on the host. However, this approach can be extremely labor-intensive. When implementing HIPS, the Cisco Security Agent (CSA) software should be installed on each host to monitor all activity performed on and against the host. CSA performs the intrusion detection analysis and protects the host.
A Cisco HIPS deployment using CSA provides proactive security by controlling access to system resources. This approach avoids the race to update defenses to keep up with the latest exploit and protects hosts even on day zero of a new attack. For example, the Nimda and SQL Slammer worms did millions of dollars of damage to enterprises on the first day of their appearance, before updates were even available; however, a network protected with a CSA stopped these attacks without any updates by identifying their behavior as malicious.
© 2006 Cisco Systems, Inc. Securing Networks with Cisco IOS IPS 5-17
Application
Application
Was this article helpful?
Read how to maintain and repair any desktop and laptop computer. This Ebook has articles with photos and videos that show detailed step by step pc repair and maintenance procedures. There are many links to online videos that explain how you can build, maintain, speed up, clean, and repair your computer yourself. Put the money that you were going to pay the PC Tech in your own pocket.
Post a comment