Five network ‘sleepers’

Feature
Feb 25, 20087 mins

Testers hadn't expected much from these products and technologies, but now find them quite promising

Testers highlight Mu Security Mu-4000, Packeteer iShaper, Radware Linkproof, SonicWall unified threat management and Cisco NetFlow technologies.

Mu Security‘s Mu-4000 Security analyzer

Product basics: The Mu-4000 allows for testers to analyze a network product or application for known and unknown security vulnerabilities in a repeatable way.

Tester: Tom Henderson, principal researcher, ExtremeLabs

Tester’s take: In the labs, we get asked to assault various products for fun, but mostly profit. We’ve used different tools, including self-made packet assault tools. Some of the self-made tools do things such as emulate distributed denial-of-service attacks, TCP-SYN attacks and so on. We had an appliance from a small company called Mu Security on the shelf for a while. At first, we hesitated to use it because it had a limited repertoire in some of the areas we needed — specifically in DNS. Then it upgraded the software, and the world changed a bit.

The Mu-4000 works by using known and conjured attacks, and then keeps the results in a database, allowing us to analyze failures. What’s resulted is our ability to take a given device, be it a server, switch, router or any other device that connects via Ethernet, and subject it to an automated sequence of tests. At the end, instead of finding a failure, we can usually tell exactly what cracked the device. Instead of a siege-assault where we know we blew something up, we get a graduated indication of where and, often, what did the trick. It’s not a totally perfect system, and it still requires using a deliberate methodology to attack a device. But what we get is an analysis of predictable failure points. You’d be amazed at what devices crack under what kinds of pressure with what kinds of attacks — we now look at Gigabit Ethernet switches in an entirely new way; we’d thought them largely invulnerable, but now know quite differently.

The software still has some rough edges, but Mu Security is onto something that we can’t find in products from competing vendors. Programmable non-destructive penetration testing just got a little easier.

Of note: The “Mu” in the product name stands for “mutate the protocols,” company founders say. That is, the goal is to discover how network equipment subjected to the Mu-4000 copes with the twists, turns and distortions of applied attacks.

Read how the Mu-4000 helped in a recent standalone intrusion-prevention-system test and in the IPS portion of a unified threat management test

Netflow (or IPFIX)

Product basics: NetFlow isn’t a product, but a Cisco technology that records TCP/IP connections going through routers or other network devices and then sends the flow data off for analysis. IPFIX, for IP Flow Information Export, is the IETF equivalent.

Tester: Rodney Thayer, independent network security consultant

Tester’s take: I used to look at NetFlow as quirky protocol that companies such as Arbor Networks used for intrusion-detection system stuff, and only in extremely large networks. So I always thought, ‘Oh well, that’s nice if I ran AT&T’s ISP business.’ I ignored it otherwise. But I’ve recently had some people asking me to look at the technology for reviews and I’ve done some research on the standards activities and talked to users, and it seems to me that if we actually use this flow technology we could do a whole bunch of good things in network management and security. For example, it watches the network flows so you can see things such as peer-to-peer traffic, Skype and who’s using your network a lot that you didn’t think was. Used properly, it could do worm protection and stuff like that.

This has made me look at the IPFIX working group, and all the vendors that play in it, and start finding vendors to chase. Some companies have been plugging along using this, like Q1 Labs and Arbor Networks. This is not some new technology that just showed up last year. I had looked at this stuff before thinking about IDSs and IPSs, but it hadn’t dawned on me that it would be useful for some of the kinds of things we’re doing now with looking for botnets and worms, and for endpoint security, ‘monitor your network’ kinds of stuff. I haven’t yet found a population of vendors treating it that way. But it looks like people are going toward that, and there are smaller vendors selling some software solutions – seems like there’s an emerging marketplace.

So for endpoint security, I’m looking into whether I could use this protocol in some machinery to do the equivalent function provided by switches and other devices that do Storm control. If you get a virus outbreak on your desktop, these products will figure this out and shut down ports and do that kind of containment. I think you could do that with NetFlow.

Of note: Thayer says that, “as a geek,” he wouldn’t be surprised to see somebody inventing an IDS that does anomaly detection but uses flow information instead of techniques in use now.

Read more about it.

Packeteer’s iShaper 400

Product basics: The iShaper 400 combines application visibility and QoS, CIFS and protocol acceleration, data compression and caching in a single platform.

Tester: Robert Smithers, CEO, MiercomTester’s take: We were surprised by iShaper’s small footprint and easy learning curve. The iShaper is two boxes in one. On one side it uses all of Packeteer’s rich history in packet shaping and on the other it provides a full-blown Microsoft server for DNS, print and file-storage services. We were amazed by the iShaper 400’s efficient use of packet shaping and its ease of use. (Compare Application Acceleration and WAN Traffic Optimization products.) 

Of note: Microsoft and Packeteer jointly announced the creation of the iShaper as part of a wider partnership involving technology and marketing.

Read more about it. 

Radware’s Linkproof 1000

Product basics: This multi-WAN switch provides uninterrupted access to data centers, remote locations, Web sites and the Internet by re-routing network traffic during primary WAN outages.

Tester: Robert Smithers, CEO, Miercom

Tester’s take: This is a solution for allowing smart use of multiple WAN links. In tests where we hammered the LinkProof 1000 with 100 concurrent VoIP calls, it maintained an impressive 100% of the VoIP connections during a simulated outage of the primary WAN by automatically re-routing them to a secondary WAN link. (Compare Application Acceleration and WAN Traffic Optimization products.) 

Of note: The product’s Health Monitoring Module can perform 19 types of network health checks.

Read more about it.

SonicWall’s SonicWall PRO 5060

Product basics: The PRO 5060 is a multiservice security platform

Tester: Joel Snyder, senior partner, Opus One

Tester’s take: I had anticipated that the SonicWall device would be in the dregs of my unified threat management test. The company has been so focused on the SMB market that most people have written it off as not worth considering in the enterprise. However, when I got its UTM box into my test lab and went through the criteria that we had decided were important to enterprise adoption of UTM, the SonicWall product did extraordinarily well. The most impressive part was its stream-based antivirus scanning, which caught viruses that no other UTM firewall — even those scoring higher overall — caught. (Compare Unified Threat Management products.) 

Of note: Since the UTM test took place, SonicWall introduced a new multiservice platform, the E-Class Network Security Appliance series. Snyder has been putting review units through their paces in his test lab.

Read the test. Join the discussion on all-in-one firewalls.