Steps you can take now to help reduce data breaches

Opinion
Feb 9, 20095 mins

* Sophos security analyst shares tips on what network managers can do to help prevent data breaches

Sophos security analyst Michael Argast shares his tips on what network managers can do to help prevent data breaches. With a little diligence, you can bolster your network security to help prevent the loss or compromise of sensitive data.

As a follow-up to my story on preventing data breaches, I talked to Michael Argast, a security analyst with Sophos, to get his tips on what a network manager can do to help prevent data breaches. Data protection is everyone’s responsibility, but a company’s IT workers have a deeper responsibility because there are so many tools and techniques at your disposal. With a little diligence, you can bolster your network security to help prevent the loss or compromise of sensitive data.

Encryption

Data encryption is an obvious tool that can safeguard sensitive data. Argast cautions, however, that encryption isn’t just for USB keys and portable devices; it also should be used for the entire transmission path of the data. He cites the recent Heartland data breach, where the data was encrypted at most points. However, there was one point in moving the data around where it wasn’t encrypted, and the intruder exploited this vulnerability.

Argast recommends you pay close attention to encryption standards and how they are deployed on infrastructure devices. “Encryption standards can be cracked,” says Argast. “Look at WEP. When it was cracked, many devices could be upgraded to WPA version 1, which gave extra life to devices and lowered the cost of infrastructure replacement.” He advises that you make sure your infrastructure devices are programmable so you can upgrade them as standards are broken.

NAC

Argast calls NAC a “dark horse” because it’s talked about but not widely deployed. “NAC can help with cutting off rogue access and enforcing the compliance of endpoints,” says Argast. “Malware can enter your network from just one unpatched desktop. NAC can really help control that.”

802.1x is a natural partner with NAC, according to Argast, because it allows a user to authenticate at the port level. Even if someone gets physical access to your network, they can’t simply plug in and have access – they still need to authenticate. He says this could prevent a situation like someone dropping a sniffer onto a switch.

Logs

For many organizations that experienced data breaches, there was a problem using forensics to track back to quantify and qualify the data that was stolen. With this in mind, logging all events is important. Argast recommends you take your logs off-box so they can’t be tampered with by an intruder. If someone is smart enough to penetrate your network, he may be smart enough to remove or disguise his trail. This is harder to do if you store your logs someplace where they can’t be compromised.

Network management

Argast says that out-of-band network management is common in the telco industry but it isn’t a broadly used technique in general businesses. It should be, however, for organizations that want to improve security. “You should have access to a secure management network that is out-of-band from your production network,” says Argast. “This makes it harder for an intruder to get into your infrastructure through a weak link or a social engineering attack. For example, if an intruder gains access to a switch, he can sniff all the traffic that goes by. Restricting access to that switch through an out-of-band management path will reduce the threat.”

Security competence

In recent years, many organizations have outsourced a good portion of their IT operations. Argast recommends that companies retain security competence in their internal staff. “These are the people who will truly understand the business risks and the value of the data,” he says. “You should retain your security competence as it relates to endpoints and the network.”

Data isolation

If your organization has data that is particularly sensitive, you should isolate the network holding that data. Argast advises, “Separate the valuable data from the day to day working environment. You can use tripwires to detect if someone is trying to penetrate to the sensitive area and close down the intrusion.”

Penetration testing

The people who built and maintain the network aren’t necessarily the best people to evaluate its security posture, says Argast. He recommends you find a “white hat” security professional to conduct penetration testing. A security professional is specifically trained to think about vulnerabilities and how they can be exploited. He can view the network from a hacker’s perspective.

Threat awareness

Anyone who is serious about maintaining network security should get plugged into the security community. There are several security newsgroups that share information about emerging threats. You need to be aware of rapidly changing threats in order to be proactive with your risk mitigation. Among the groups or alert programs you can join are: CERT, US-CERT, Insecure.org, the Microsoft security newsgroups, and Kaspersky Lab’s VirusList. Argast points out that Sophos has good information on its Web site, particularly the SophosLabs blog. And of course, you should subscribe to the Network World Security Alert newsletter and we’ll keep you posted on critical happenings.

A word of warning is in order when it comes to surfing the Internet to learn about threats. It’s possible that your foray onto security sites might mean that your movements get tracked and you may actually attract attacks to your network. This is especially true if you delve into a “dark site” that is heavily used by hackers.

Holistic approach

Above all, Argast agrees with my assertion in my other data breach article: an organization needs to take a holistic approach to data protection. IT professionals can do quite a lot to help prevent breaches, but you can’t work alone. Argast recommends bringing together people who don’t normally work together on a daily basis to share ideas and risk mitigation knowledge.