Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

4/13/2015
11:00 AM
Steve Riley
Steve Riley
Commentary
Connect Directly
LinkedIn
RSS
E-Mail vvv
100%
0%

Better Together: Network Operations & Infosec

Getting networking and information security teams together in the same room is a critical step for companies that want to build a continuous information security culture.

The recent computer attacks against Anthem and Premera Blue Cross are the latest case studies that demonstrate the necessary convergence of IT and security operations. This is something information security professionals should welcome, even demand. In fact, the network operations team can be an information security department’s best resource for gaining understanding and insight into an organization’s security operations, which traditional security solutions and best practices alone cannot provide.

Understanding what “normal” network activity looks like is critical to quickly spotting suspicious activities that point to a malicious outsider or insider, or a mistake by an innocent employee that result in data theft or loss. However, bridging the gap between the Network Operations Center (NOC) and Security Operations Center (SOC) is not only a technology challenge, but also an organizational one. There are three keys to fostering this collaboration:

  • Eliminating the silos that separate both systems and personnel, 
  • Creating joint emergency response teams comprised of network operations and information security personnel, and
  • Implementing a long-term plan for how to constantly improve processes and training.

In the typical IT organizational chart, network operations is responsible for ensuring system performance and information availability, while information security focuses on protecting those systems and information stores from threats. Typically, as Rudyard Kipling wrote, “and never the twain shall meet.” However, the spate of high-profile breaches against large companies across retail, financial services, and healthcare over the last year show that must change.

In most of these cases, the companies were not aware they had been breached until a third party notified them. Although Anthem discovered its breach on its own after a database administrator noticed a query running with his account that he didn't initiate, that discovery wasn’t made until after the attacker had spent six weeks silently stealing information.

For an enterprise, the key takeaway is its critical need to be able to detect activities on the network that can lead to a data breach. That capability is diminished by the fact that security operations and network operations typically work in silos. That means security vulnerabilities have to be handled twice: first by the SOC, which has evidence of malicious activity but often no mechanism for actively stopping it, and then again by the NOC, which needs to wait for specific instructions from the SOC. Any time delay here creates advantages for an attacker.

Additionally, most technology systems and business applications work in their own silos and do not communicate with one another. Consequently, IT cannot streamline and automate information sharing or event correlation between security vulnerabilities and performance issues. Here are four steps to overcome this organizational hurdle:

Step 1: To maximize insight, foster teamwork
The first step is to acknowledge the value of the network team in security operations. Network engineers have visibility and access to forensic data that simply doesn’t exist in other parts of an organization. Once IT leadership acknowledges this, the next step is all about putting the tools and processes in place to integrate network resources into security processes. It sounds simple, but having a thorough understanding of normal is a critical factor in preventing potentially harmful activity on your organization’s network.

Step 2: Packet capture meet SIEM
Security teams should work to leverage the network team’s investments in packet capture agents, packet analyzers, NetFlow sources and deep packet inspection performance monitoring. Often these can be tightly integrated into a Security Incident Event Management (SIEM) system for high-fidelity visibility, and quick pivots into useful forensic data. It’s also worth noting how the Premera breach serves a reminder to information security professionals that joining forces with the network team does not obviate the need to continue traditional due diligence. Premera had failed to install the most recent security patches, opening the door to the attackers.

Step 3: Change the culture but hands off also applies
In terms of fostering collaboration, there should be clear roles and responsibilities across NOC and SOC teams, supported by well-defined “hand-offs.” Documenting them isn’t enough. You have to use them, analyze key weaknesses, and continuously improve them. Joint emergency response teams enable broader insight, increased tribal knowledge, faster artifact gathering, well-rounded analysis, and ultimately a stronger information security posture. Identify and appoint a strong leader who can rally the troops, and mold them into a cohesive team passionate about continuous improvement – not just compliance.

Step 4: Don’t accept the status quo
With a strong base to build upon, an organization should turn its focus to accelerating and improving its capabilities. Never be satisfied with the status quo. To optimize operations, leverage techniques from traditional continuous improvement strategies such as Theory of ConstraintsLean, or lessons learned from the DevOps movement.  Invest in training and skill development so your people are effective and empowered, break work down into smaller chunks so it flows smoother, automate to gain operational efficiencies, and measure risk, performance and quality of operations.

Threats are getting increasingly harder to discover, and attackers are more brazen than ever. Getting network operations and information security teams together in the same room for the first time will be a critical step for organizations that want to build a continuous information security improvement culture capable of defending against those threats.

Steve actively works to raise awareness of the technical and business benefits of Riverbed's performance optimization solutions, particularly as they relate to accelerating the enterprise adoption of cloud computing. His specialties include information security, compliance, ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
7 Truths About BEC Scams
Ericka Chickowski, Contributing Writer,  6/13/2019
DNS Firewalls Could Prevent Billions in Losses to Cybercrime
Curtis Franklin Jr., Senior Editor at Dark Reading,  6/13/2019
10 Notable Security Acquisitions of 2019 (So Far)
Kelly Sheridan, Staff Editor, Dark Reading,  6/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-12865
PUBLISHED: 2019-06-17
In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.
CVE-2017-10720
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi name. This application is installed o...
CVE-2017-10721
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet functionality enabled by default. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and settings, car ga...
CVE-2017-10722
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi password. This application is install...
CVE-2017-10723
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that an attacker connected to the device Wi-Fi SSID can exploit a memory corruption issue and execute remote code on the device. This device acts as an Endoscope camera that allows it...