1 StoneGate IPS 4.3 Technical OverviewJavier Larrea Jaspe April 15, 2017
2 ¿Qué es Stonegate IPS? High availability & performance IPSTráfico válido Protege: Aplicaciones Sistemas operativos Infraestructura de red Eficiencia de red Tráfico malicioso Spyware Stonesoft Intrusion Prevention System 10 Gigabit inline throughput High availability & clustering Solución escalable Gestión centralizada y distribuida Detección precisa y flexible Tráfico válido Adware Worms StoneGate IPS cleans the internal network while StoneGate Firewall and VPN provides perimeter protection and secure connectivity between branch offices. Spyware, worms, and peer-to-peer programs slow down network performance, which has direct impact to business operations. In today’s business environment where competition is hard and decisions have to be made fast, the business information is valuable for only a short moment in time. If the information is not available when it is needed then it hurts productivity. That means increased risk for the business. StoneGate IPS detects and stops network traffic abuse and reduces business risk. Protects vulnerable applications and operating systems Business-critical applications and servers must run 24 hours a day. If there is security vulnerability in the application or in the operating system then it should be fixed (patched) as soon as possible. But bringing down business-critical service for maintenance means lost revenue. Normally business-critical applications have scheduled maintenance windows every month, but that is too late because the security vulnerability is there right now and anybody can exploit it. The solution for this is to put StoneGate IPS in front of the application. It stops all exploits that are trying to use the vulnerability in business-critical applications or servers. Stops worms, P2P, and spyware There should not be worms, spyware, or peer-to-peer traffic in corporate network. StoneGate IPS can remove them from your corporate network traffic and therefore increase the network bandwidth available for your business operations. Ensures regulatory compliance Payment Card Industry Data Security Standard is one example of regulatory actions where organizations (in this case Visa and Master Card) try to reduce the risk associated with their main business. This standard requires that all merchants that store, process, or transmit cardholder data should use Intrusion Prevention Systems. StoneGate IPS fulfils the standard’s requirements and allows merchants to run their business in a clean environment. Accelerates incident handling StoneGate IPS stops attacks before they damage the target server, therefore eliminating incident costs. StoneGate IPS provides a large variety of information about attempted attacks and its Incident Management feature can be used to collect that information in one place. This information can be used to create Internet abuse reports so that system administrators of the attacking network segment are notified about attacks. This helps to prevent attacks happening again and is one way to inform responsible parties about the attack. Stops attacks against web applications Enterprises strive to offer flexible and easy-to-use services for their customers, partners, and employees. In many cases this means that customers have a web interface to critical core-business services. Although web access is a very convenient way for customers to access services it also presents a new risk to the core-business. StoneGate IPS will prevent attacks against these services and show what is going on in the DMZ area, thus reducing the risks. Low Total Cost of Ownership (TCO) StoneGate Management Center makes the everyday management and configuration of StoneGate products easy and cost effective. It offers unified management for StoneGate IPS, Firewall and VPN. Many features are designed for resilient and secure remote management. For example, automatic rollback from software upgrades or policy updates guarantees that the connection to remote devices is always available. There is no need to send engineers to remote locations because all administration tasks can be done reliably from a central location. This saves costs and simplifies enterprise security policy enforcement. Troyanos DoS AUP
3 StoneGate IPS ProtectionInfraestructura & Aplicaciones Rendimiento Eficiencia de red Detecta y previene Ataques contra aplicativos o S.O. vulnerables, switches, routers, … Worms Virus DoS y DDoS Accesos no autorizados Conteo de eventos y umbrales Permitiendo Protección perimetral Protección redes internas Virtual patching Modifica la necesidad de establecer frecuentes ventanas de mantenimiento Detecta y previene Detección de uso de aplicativos P2P Spyware, Adware y Malware Mensajeria, streaming, tunneling,.. Permitiendo Evitar la degradación del rendimiento de lar red Proteger el tráfico crítico Tener visibilidad de lo que ocurre
4 Arquitectura StoneGate IPSWhat: As a part of the unified management, the element database is shared between all the managed components and all tools. Advantage: Once an element is created, it is available everywhere in the unified management. Updating an element will update all configurations where the element is used, resulting less manual administrative work and human errors. All configuration information, including security policies, clustering, routing, multi-link and operating system are configured centrally and stored in the central repository. Benefit: Single backup of the whole system In case of a hardware failure on one of the security engines is the software installation and configuration push and activation Protected Communication No direct communication with the security devices All changes through the Management System All intra-system communications authenticated and encrypted (SSL)
5 Características StoneGate IPSVentaja Inline Attack Blocking & hibrid mode Bloqueo de conexiones proactivo en modo transparente y a la vez en modo pasivo Métodos de sensor precisos Eliminación de falsos positivos Correlación de eventos Mayor inteligencia en la detección Gestor de politicas de seguridad muy granular Permite hacer un tunning muy “fino”. Además permite realizar desde las configuraciones más sencillas a las más complejas de forma sencilla. Preemptive Protection Detección temprana de ataques, exploits o gusanos no identificados hasta el momento HTTPS protection v 5.0 Detección de tráfico malicioso en HTTPS Gestión centralizada Reducción de costes de implementación y manteniminento (TCO, TCA) en despliegues de sondas distribuidos Herramientas de gestión de la información Convertir datos en información comprensible y manejable High Availability Todos los elementos de StoneGate IPS disponen de esta capacidad evitando puntos de fallo. También tolerancia a fallos en hardware.
6 Configuraciones del SensorImplementación El sensor opera simultaneamente en modo IDS e inline IPS. 802.1q El sensor puede tener varios interfaces para captura de tráfico y modo inline.
7 Inline IPS filtrado L2-L7Inspection Rules Permit Terminate (no match) Existing connection under inspection... Allow (inspect) State Table Access Rules Allow Discard
8 Precisión en los métodos de detección StoneGate IPS Detection MethodsDe tráfico malicioso Validación de protocolo Detección DoS Detección de escaneos Correlación de eventos
9 Correlación de eventos Analyzer Detection MethodsCompresión de eventos (log flooding) Conteo y umbrales Correlación de eventos Detección de ataques complejos y/o exitosos Correlación Secuencias Alert Alert Correlación por grupos Event Group Correlation correlates specific events that occur in a defined sequence within events that occur within a given timeframe event 1, event 3 and event 2 occurred within 5 seconds -> correlation Event Sequence Correlation a given timeframe event 1, event 2 and event 3 occurred in this order within 5 seconds -> correlation
10 Gestión granular de políticas Inspection RulesDeep inspection and protection. Implementación rápida y flexibilidad Inspection Rules Política de inspección a nivel 7 Aquí se especifican la acciones que tomará el IPS (acept, terminate, altert, blacklist,…), en base al evento detectado Inspection Rules Defines how the network traffic is inspected and what actions are taken when detecting an anomaly. Attack attempt Protocol anomaly Identified application usage Scan detection DoS detection Login transaction Successful attack Inspection Rules/ Action: Terminate Permit Continue Options: log, alert, blacklist, recording opt., Terminate Action: active/ passive* (*) Terminate Active: Drop the violating packet and the following packets in TCP connection or UDP virtual connection. FTP and SIP are an exception in IPS 4.0.0: related connections are not dropped in case of terminate action. Terminate Passive: IPS logs the violation with “Action:Terminate (passive)” indicating that this connection would have dropped in ‘active’ mode. Passive terminate mode can be used for testing update packet content from possible false positives or customer’s own custom situations.
11 Gestion centralizada - SMC Hierarchical PoliciesMany concepts to keep your policies easy to understand Security policies are based on templates Policies follow the template changes automatically Main policy can contain jumps to Sub-Policies By using aliases you can use the same policy for several engines.
12 Gestion centralizada - SMC Efficient Policy ManagementMany tools to ensure your policies are up-to-date Rule Search tool helps you to find the rules Policy Validation tool identifies the potential problems with your policies Policy Comparison tool enables you to review the changes since the last upload Policy Snapshots enable you to review the old configurations per engine Rule meta data lets you know about the history of each rule
13 Preemptive protection Caso Downadup wormThe Downadup worm is nasty case. It has three spreading vectors and it can update itself. The attack vectors are: Exploit MS msrpc vulnerability. Brute force administrator password via connecting to $ADMIN share Copy itself to removable media such as USB sticks. When the removable media is connected to a computer, the worm will be run via windows autorun feature. The StoneGate IPS can block all attacks against the MSRPC vulnerability. In fact, we had a pre-emptive protection against this vulnerability. The fingerprint situation blocking exploits against vulnerability MS released in year 2006 also protected the MS vulnerability. So hosts protected by inline SGIPS with the default policy, cannot get exploited by the Downadup. The StoneGate IPS is also able to detect Brute Force attacks against Windows shares, such as the $ADMIN share. Although the default action for situation “Analyzer SMB Brute Force Attack detected” is an alert, it is possible to configure a black listing response to this situation, limiting the Worm’s brute force attempts. Switch StoneGate IPS Access Control + Inspection
14 HTTPS Inspection Protección de ataques contra servidor y contra cliente cifrados SSL Server & Client side protection Detección y bloqueo de ataques contra servidores HTTPS Inspección del tráfico SSL Requiere el uso de certificados en el IPS
15 Gestion centralizada - SMC Overview of installed baseWatching security from multiple perspectives, depending on the user type (Top management, NOC/SOC oeprator, etc.)
16 Gestión de la información Análisis recursivo de eventosLogs can be graphically filtered from high level perspective...
17 Gestión de la información One click details about relevant eventsDown to hexadecimal details, passing through human readable description of events, links to external sources, graphical representation of the connection.
18 Gestión de la información Summarizing data at different levelsDifferent type of reporting (automatic and interactive) depending on target audience
19 Gestión de la información Geographical Resolving of IP AddressesSee where the attacks are coming from View top rate statistics as a map and see where the IP addresses are located Map diagram type is available even with live Overview statistics View the city and country information directly in the log details Geolocation is resolved from internal database Queries do not open any new connections!
20 Gestión de la información Incident ManagementRegulatory compliance is achieved by keeping track of events and how they have been managed. This copes with audit trails and incident management system integrated in SMC
21 Gestión de la información Regulatory ComplianceImmediate information about system status, very useful to comply with international regulations like HIPAA, SOX, etc.
22 HA & Clustering Bypass Network InterfacesFailsafe inline operation Bypass NICs cambio a estado bypass en caso de fallo crítico Fallo eléctrico Fallo software (offline) Bypass disponible para todos los modelos IPS (2 x bypass NICs) IPS (4 x bypass NICs) IPS (8 x bypass NICs) Bypass operation with normal NICs (fail-close) and bypass NICs (fail-open): Sensor “Offline“ state means the same as when the engine box is powered off: With fail-open NICs = All traffic passes through With fail-close NICs = All traffic is blocked
23 HA & Clustering External HA/ Balanceo de cargaLoad balancing para IPS Inline HA y balanceo de carga para IPS Inline engines con Etherchannel Control de acceso e inspeccíon para redes core Cluster serie para la versión 4.2 Switch Switch Etherchannel StoneGate IPS Access Control + Inspection SGIPS in Etherchannel HA/Load balancing for Inline IPS operation using Etherchannel (port aggregation) Note! IPS engines are not forming a cluster (no state sync) but are working as individual sensors. Thus, both engines requires policy refresh separately. Switches must be configured to use session based load balancing in Etherchannel to get a full TCP/UDP stream for IPS engine inspecting the connection. SGIPS with External Bypass/ WireTAP Device High-Availability for inline Inline IPS using WireTAP devices. E.g. CriticalTAP™ WireTAP monitors the primary inline IPS. Switches to secondary inline IPS if the primary fails
24 HA & Clustering Inline IPS Serial ClusterEscalabilidad en el rendimiento de IPS Proporciona HA en inspección Mejora TCO 10Gbit networks Inline Serial Cluster One of the sensor nodes in IPS serial cluster inspects a connection, while others are in “soft-bypass” mode for the same connection. Load balancing decision is based on IP addresses and there is no state synchronization between the nodes available. If a node fails it switches to bypass state and load balancing filter is recalculated on rest of the nodes (bypass NICs mandatory).
25 Certificación ICSA Labs
26 StoneGate IPS Appliances H1 2009Appliance Model IPS-1030 IPS-1060/P IPS-6000/6100 IPS-6105 Targeted for Branch offices with Fast Ethernet networks Sites with fast external connectivity, DMZ’s, and internal networks where the amount of traffic is less than 600 Mbps Internal networks, Server segmets, Backbones, Core networks. 10 Gb Core networks. Performance (Mbit/s) 200 350/600 2000/4000 10Gbps Bypass interface pairs 2 4/8 1x10Gbps opc. 4 x1Gbps & 2x10Gbps Concurrent connections > New connections/s 15.000 40.000 > HTTPS inspection client/server Yes/Yes No HTTPS inspection performance 40Mbit/s 60Mbit/s na 1Gbit/s Appliance chassis 1U, short 3U
27 www.stonesoft.com [email protected]FIN