Vulnerability Assessment Penetration Analysis

A. Memo For Record: IDS upgrade or replacement

Summary of Events: The health care clinic’s network security appliance (combined router/firewall/wireless access point) was hacked and passwords were cracked. Configuration changes to this device opened the network to a Denial-of-Service (DoS) attack. The result of this attack prevented access to patient records and insurance claims as part of their daily routine. The network Intrusion Detection System (IDS) sensor had been previously disabled because of degradation of network performance caused by the device. No advanced notification of system degradation caused by the DoS attack was identified until employees were unable to use the network to perform the jobs.

IDS Definition: Network IDS is part of the external boundary protection and monitoring system.
Threats to the network from external sources are identified and reported using a management console.
With the sensor disabled attacks against the network can be accomplished undetected and reduce response time. “An intrusion detection system (IDS) is software that automates the intrusion detection process. An intrusion prevention system (IPS) is software that has all the capabilities of an intrusion detection system and can also attempt to stop possible incidents. IDS and IPS technologies offer many of the same capabilities, and administrators can usually disable prevention features in IPS products, causing them to function as IDSs.” An Intrusion Detection Protection System (IDPS) combines the functions of IDS and IPS into a single hardware/software application package. Sensors can be configured as passive and/or active. A passive IDPS sensor will look at traffic but cannot block or prevent attacks. An active IDPS sensor is designed to inspect all traffic and has to capability to block traffic hence respond to active attacks.

Denial-of-Service Defined: “A denial-of-service (DoS) is an action that prevents or impairs the authorized use of network, systems, or applications by exhausting resources such as central processing units (CPUs), memory, bandwidth, and disk space.” The hacker modified the firewall/router configuration allowed otherwise block addresses, protocols, and traffic. Allowing them to pass through the network security boundary and use up vital resources.

Recommendations: Upgrade existing IDS system verses replacement with a state of the art IDPS sensor. The current sensor was disabled because it was unable to actively filter traffic on the network without causing degradation. Normal causes of this is older equipment not capable of processing traffic fast enough to avoid degradation. Second limitation to IDS it only has the ability to monitor traffic and alert employee of an attack.

New IDPS sensors provide minimal to no degradation to network traffic and can be used as both active and passive device at the same time. In addition to monitoring traffic an IDPS sensor is capable of reacting to events in real time. All the features of an IDS sensor are present with the addition of automated attack responses and anomaly detection. State-of-the-art IDPS sensors use real-time daily definition updates and database threat comparisons to identify attacks. Like anti-virus programs that automate the process of definition updates, IDPS sensors use a similar process to keep the threat database current. Management applications automate the alerting and reporting process to aid in vulnerability assessments and real-time responses to threats. Baseline thresholds can be adjusted and configured to network specific needs rather than cookie cutter one configuration fits all methodology.

The recommendation would be to identify a costing solution for both an upgrade to the existing IDS sensor and the replacement cost for a IDPS. Short term solution is to get the IDS working and project a
IDPS solution as needed and budget allows.

Incident Prevention: In this case a working IDS system could have alerted key staff of an on-going
DoS attack. Steps to harden existing Router/Firewall devices to prevent password cracking will need to be implemented. A Vulnerability Assessment (VA) needs to be completed to identify weaknesses in the current network security configuration and suggest changes. A check list needs to be created that identifies the process of responding to a DoS attack.

VA should clearly establish Internet Service Provider (ISP) procedures that should be followed to request assistance during DoS attacks. Examine IDS or IDPS sensor configuration, alerting, and reporting processes. Network staff notification via email or phone during attacks using IDPS should be covered. Baseline system configurations, network usage, and log file audit processes should be reviewed. Use Internet health monitoring using known websites that provide statistics on latency. Create checklists on how to respond to attacks such as, DoS and have them in paper form for use during attacks. A crash book or continuity folder that provides all these items in one location that provides network topography, administrative password lists, configuration diagrams, emergency contact information, and established checklists/procedures should be included.

Conclusion: Having a plan on how to respond to problems or attacks against the companies network is the key. Documentation of how the systems are configured is critical to this process. Vulnerability
Assessments are designed to identify weaknesses and help to improve network security. A review of the system configurations, processes, and logs will help to determine threats and the associated risks to company assets. An IDS/IDPS sensor is a valuable device that works in conjunction with firewall, router, antivirus applications, and authentication/access lists (ACLs) to provide network security. Establishing checklists and/or procedures on how to respond to attacks, such as DoS are extremely important.
Hardening of equipment, password management, disaster recovery procedures, and restoral processes should be included in a comprehensive VA report. After a significant event or attack a review of these processes and procedures should analysis the effectiveness of this plan. Network security is best performed by providing layers of protection that work together to protect the network and associated

