Technology Sectors

Market Sectors

Some common network vulnerabilities persist

Michael Markulec

By Michael Markluec

Browsing the daily news headlines, it is not surprising to read that yet another organization has suffered an IT security breach resulting in the theft of sensitive data. In fact, the increasing frequency of these attacks might lead some to conclude that they are inevitable, and that, despite the best efforts of network administrators and IT security personnel, these attacks can never be completely stopped.

While securing IT networks may often feel like a cat-and-mouse game in which IT security is constantly working to stay one step ahead of the hackers’ latest tricks, government agencies can avoid some basic vulnerabilities which we have found to be common among enterprise networks.  

One of the most common vulnerabilities is the incorrect or incomplete deployment of Intrusion Prevention / Detection Systems (IPS/IDS). In the majority of cases, the organization had not realized that a network segment in question existed or could be accessed without network traffic first passing through the IPS / IDS. To avoid this vulnerability, IT organizations need a comprehensive security strategy that includes technology which can proactively map the network and identify overlooked segments so they can be incorporated into the IPS / IDS system.

Related to the issue of poor deployments of IPS/IDS is the failure of vulnerability management (VM) tools to discover and probe all devices on all segments of a network. Many organizations have deployed VM tools to probe each device connected to the network, assuming that the tools can find all existing networks. In reality, vulnerability management tools, when used without network discovery technology, only evaluate devices for which an IP address can be obtained from a domain name server, or manually from the user of the tool. In addition to this limitation, VM tools do not identify the network perimeter or analyze connectivity to other networks. The risk is that, if a device is not included in the domain name server and the user is not aware of its existence, the device remains unknown, unmanaged and unsecured. 

Non-traditional IP devices pose another potential vulnerability, because they go far beyond the routers, printers and desktops of the past. Today, they include smart phones, point-of-sale (POS) devices and medical equipment, all of which generally require an IP address and network connectivity to function properly. As endpoints on enterprise networks, however, they often go unmanaged or unsecured and can potentially be exploited as unmanaged points of entry to the network.

Surprisingly, there are often many devices on an enterprise network which continue to respond to default credentials. For instance, a 2009 data breach investigations report by Verizon Business indicates that “more criminals breached corporate assets through default credentials than any other single method in 2008.” The same report found that “51% of the victims [of data breaches] were using vendor default passwords on systems that handle sensitive data.” External attacks exploit these vulnerabilities and gain access to networks through these weakest points of entry. Once an attacker gains access through SNMP, it’s possible to impersonate a trusted system, essentially operating “under the radar” to intercept sensitive data transmissions and even redirect network traffic -- often without triggering an alert from the existing security mechanisms because the unmanaged connection goes undiscovered in the absence of comprehensive, active network discovery. As a matter of policy, network administrators need to ensure that the vendor default passwords are changed on every device.

Unauthorized wireless access points (WAPs) present another common source for network vulnerabilities. Wireless devices are an increasingly essential part of the way companies operate in remote offices and retail locations, but if not properly secured, they can provide unrestricted access to the larger network infrastructure. Network security tools that only look at a fixed range of network addresses frequently miss rogue WAPs operating outside the expected IP address range and, therefore, can only be detected by network discovery tools capable of finding and identifying every point of access into or out of a network.

The presence of these common vulnerabilities demonstrates that enterprise networks would benefit from the addition of solutions that discover all devices, network segments and connections that ensure the security tools currently implemented on those networks have been properly configured.

Michael Markulec is chief operating officer of Lumeta, makers of IPsonar, a network discovery, mapping and network leak detection solution. Markulec can be reached at:

mmarkulec@lumeta.com 

 

Recent Videos

It's been a banner year for the Whitestone Group, according to John Clark, CEO of the facility security, asset/force protection and investigations...
Jeff Horne explains that Denver, CO-based Accuvant , Inc has two different businesses – the Value Added Reseller (VAR) side, in which it is one of...
GSN caught up with Dave Natelson for a quick interview at the Cocktail Reception at the 2011 Awards Dinner, before he learned that Nasatka had earned...
Ann Pickren discusses MIR3’s Mass Notification System that was awarded a Winner’s Trophy in GSN’s 2011 Homeland Security Awards Program. She explains...
Former Coast Guard Commandant Thad Allen, who served through a long and distinguished career in the United States Coast Guard and later answered the...

Upcoming Events

Event Details Dates of Event
SANS Monterey 2012 Jan 30 - Feb 4
2012 Adobe Government Assembly Feb 8
SANS Phoenix 2012 Feb 13 - 18
SANS Secure India 2012 Feb 20 - 25
The Airport Law Enforcement Symposium Feb 23-24, 2012 Feb 23 - 24
Physical Security: Introductory Applications and Technology Feb 27 - Mar 1
Conducting Corporate Investigations Feb 27 - 28
ISC CHINA 2012 (International Security Conference & Exposition CHINA) Feb 27 - 29
RSA Conference 2012 Feb 27 - Mar 2
SAP Public Sector Partner Exchange Feb 28 - 28
SANS Secure Singapore 2012 Mar 5 - 17
SANS Germany 2012 Mar 5 - 10
Homeland Security Finance Forum 2012 Mar 6 - 6
Basic Hands-On CAMEO Training Mar 12 - 14
ASIS Assets Protection Course: Principles of Security (APC I) Mar 12 - 15
SANS Mobile Device Security Summit 2012 Mar 12 - 15
Aviation Week's Innovation Challenge Showcase Mar 13 - 14
Symantec Government Technology Summit Mar 20 - 20
STI at SANS 2012 Mar 23 - 30
SANS 2012 Mar 23 - 30
The 9th Two Day Conference On Indian Medical Devices & Plastics Disposables Industry 2012 Mar 23 - 24
SANS Northern Virginia 2012 Apr 15 - 20
Active Shooter Apr 18 - 19
SANS AppSec 2012 Apr 24 - May 2
SANS Cyber Guardian 2012 Apr 30 - May 7
Telework Exchange Spring 2012 Town Hall Meeting May 2 - 2
5th Sample Prep - Sample Preparation for Virus, Toxin, & Pathogen Detection & Identification May 3 - 4
SANS Security West 2012 May 10 - 18
SANS Toronto 2012 May 14 - 19
Counter Terror Expo US May 16 - 17
CEIC 2012 (Computer and Enterprise Investigations Conference) May 21 - 24
SANS Rocky Mountain 2012 Jun 4 - 9
Data Center Brainstorm 2012 Jun 19 - 19
SANS Forensics and Incident Response Summit 2012 Jun 21 - 27
Vanguard Security & Compliance 2012 Jun 25 - 28
SANS Canberra 2012 Jul 2 - 10