Reputation scoring changes enterprise security game

News
Apr 3, 200910 mins

Scoring a sender's reputation is working for antispam services -- now the idea is to use that technique in the firewall

When it comes to personal and business relationships, a good reputation opens doors while a bad one slams them shut. And so it goes with enterprise security, too.

Slideshow: 10 breakthroughs in IT security

Over the past several years, e-mail and Web security companies have gotten quite adept at using behavioral data, collected via massive Internet traffic monitoring networks, to derive reputation scores for domains, IP addresses, messages and URLs. E-mail and Web security appliances then use the reputation scores to allow or prohibit connections — without ever having to dig into content.

Dozens of antispam and anti-malware vendors today offer reputation-scoring services for their products, and most are pretty decent, says security expert Joel Snyder, a senior partner at Opus One, a consultancy in Tucson, Ariz. Especially worth noting are Cisco Systems Inc.’s IronPort SenderBase, which it acquired in the 2007 purchase of IronPort Systems; McAfee Inc.’s TrustedSource, which it picked up in the 2006 acquisition of Secure Computing (which earlier had acquired CipherTrust, the original developer); and the open-source Spamhaus block list, he says.

In his testing, for example, Snyder has found the SenderBase reputation service, when set to block at recommended levels, averages an 88% spam catch rate with few false positives. In general, this catch rate isn’t as high as it is with content filters — in recent tests, for example, Snyder says he measured the IronPort content filter blocking 96% of spam. But content filters are doing heavy processing whereas reputation services aren’t.

Instead of digging into content, a reputation service simply looks up the score in the vendor database and makes a decision — connect, quarantine or drop, perhaps — on that alone. Most vendors offer pre-set rules, but users can modify those to be more or less aggressive about spam. In the case of SenderBase, for example, Cisco recommends blocking e-mail addresses that rate between -10 and -3 on a +10 to -10 scale. The scores themselves are determined by correlating dozens of attributes.

The ultimate protection is when reputation services and content filtering run with one another. “If you can [use a reputation service to] knock out 76% to 90% of the spam before it hits the content filter, then you have a big advantage in [the filter’s] performance.” Again citing recent test results, Snyder says the IronPort content filter’s block rate increases to 98% when fronted by a reputation service. Two percentage points might not seem like much, but when 90% of e-mail is spam, shrinking the volume by even a tiny fraction makes a big difference, Snyder explains.

So it should come as no surprise that reputation service providers are now concentrating on putting their scoring mechanisms into play elsewhere down the enterprise security line. McAfee, for instance, already uses its TrustedSource IP reputation service in its Secure Firewall (formerly Secure Computing’s Sidewinder) to allow or disallow connections. The database is fielding some 2 million queries a day from firewalls, reports Ken Rutsky, the company’s vice president of marketing.

By weaving reputation intelligence into perimeter devices, the hope among security vendors is that they boost the effectiveness and performance of firewalls and intrusion-prevention systems (IPS) — maybe even routers and switches — as much as they have for e-mail and Web security appliances.

Robert Boenne, a network engineer for Teachers Credit Union in South Bend, Ind., likes this idea, too. “I definitely see the potential in increasing the use of reputation-based controls. As long as we’re working with a vendor that makes sure valid traffic doesn’t get blocked and gives us the ability to make adjustments, it would make sense,” he says.

The reputation buzz

To Jamey Heary, a security consulting systems engineer and frequent security blogger, the integration of IP reputation services into all sorts of security hardware is the most exciting trend in security this year. What really jazzes him is the improved performance such integration promises, he says.

Heary uses e-mail security as one example. “The reputation lookup takes a fraction of the CPU cycles that a real scan of an e-mail would take through an antivirus, -spam or -malware engine,” he says. By some estimates, the lookup can run as much as 90% faster than processing through spam filters. As another example, he says offloading content processing from the IPS could cut bandwidth requirements by a third. “An enterprise that needs three IPSs and some load-balancing to get through all the data might just need one IPS if that IPS does the reputation lookup,” he says.

The integration of IP reputation services speaks to a layered, in-depth security strategy, according to experts.

Pat Peterson, a Cisco fellow and researcher who had been part of the SenderBase development team at IronPort, puts it this way: “We know there are dirty, filthy awful places on the Internet, like the Russian Business Network, which hosts an enormous amount of malicious content of all types. Why wouldn’t you want to inform your firewall, especially if you don’t routinely do business with Russian Web sites or you’re not a multinational company, that this network is out there and that 99% of the time it’s used for malicious activity?”

The same sort of logic applies to the IPS, which relies on signature files to determine access. “Knowing that a signature comes from a really good server or a really bad one will provide a far more high-fidelity indicator that the signature is good than just looking at the signature file alone,” Peterson explains.

Cisco hasn’t yet incorporated the SenderBase IP reputation service into its firewalls or IPSs, but such a move has been widely anticipated since the IronPort acquisition. The company has indicated related announcements would be forthcoming at this month’s RSA Conference 2009, and Peterson certainly suggests such integration is imminent. “We think it’s time to add some of these factors to the IPSs and firewall connections. Why should those devices be off on their own to make decisions if there’s a huge amount of reputation information that could be available to them?” he says.

That’s just what Don Bertier, chief security officer at Savvis, a St. Louis-based IT infrastructure services provider, has wondered. The company already uses Cisco’s reputation-based IronPort Web security appliances, and has discussed how adding a reputation database to its firewalls could reduce threats coming into the DMZ and Internet portals, he says. “I see reputation moving toward the perimeter, and we’re curious to see what Cisco will do to integrate it as a natural, enabled item on its firewalls.”

Alternatively, Bertier adds, “I could have a couple of my smart-guy engineers … manufacture some type of blacklist capability themselves, but to stay on top of that would take too much of their energy. Having the automation and seamless integration into a firewall would be much better.”

For his part, Opus One’s Snyder has been pondering just what an integrated reputation database would mean from the IPS perspective. He envisions three possibilities.

In the first and most-straightforward case, the reputation score would provide one more way of identifying which events need attention. “This wouldn’t affect the behavior of the IPS at all, but it would help the analyst be smarter about what to look at and what to ignore,” Snyder says.

In another scenario, an IPS would replicate the role of an e-mail or Web security gateway, thus reducing those devices’ processing burdens. While reducing the gateway loads on bigger networks could be a smart, easy thing to do, the volumes at smaller companies wouldn’t necessarily warrant the addition of a reputation-based IPS, Snyder says.

The third possibility is the most promising — but also the most difficult to do, he adds. In this case, the IPS would change its behavior based on an IP connection’s reputation, not just in response to spam or Web traffic. “For example,” he explains, “I might set the IPS to block traffic to anyone with a bad reputation. Or, I might say, ‘If you trigger a signature and your reputation is bad, then I’ll drop your packet’ or ‘If you trigger a signature and your reputation is good, then I’ll assume it’s a false-positive and I won’t drop your packet.'”

Until Cisco and others make their IPS-reputation integration plans clear, and then users start testing, Snyder sits on the fence regarding potential enterprise value. “Playing around with a reputation-based IPS is likely to do no harm for an enterprise, but the question I have is whether it will do any good.”

Pairing reputation and identity

One thing that is clear is that the network won’t be the stopping point for IP reputation services, according to industry watchers. “This is a lot bigger than firewalls or spam,” says Andreas Antonopoulos, an analyst at Nemertes Research.

For example, look at the synergy between reputation and identity, Antonopoulos says. Simply put, he says, “Reputation and identity work very well together, and reputation enhances identity.”

Cisco’s Peterson agrees, with a caveat. “The concept of going down to a more granular user reputation or online identity reputation is very powerful, but it’s still in its infancy. It’s definitely the way of the future, but it is a challenging problem for a couple of reasons,” he says.

One is making sense of all the myriad online identities — is ppeterson99@yahoo.com the same person as ppeterson99@linkedin.com, for example? — and applying reputation scores appropriately. Plus, IP reputation services providers can’t as readily collect behavioral information from proprietary social networking, Web mail or blogging sites.

Working with authentication services

Still others see an increasingly important role for reputation-like services in the authentication realm.

Think of this scenario: A hacker hijacks the identity associated with a reputable Web address, and the IP reputation service allows the connection because the score falls within the range allowed by the access policy. That could be bad. What’s really needed is not just reputation at the network level but also reputation-like access controls at the application layer, says Torsten George, vice president of global marketing at ActivIdentity Inc., a credential management company.

In other words, much like an IP reputation service, authentication software would collect attributes and determine risk scores. On top of normal authentication procedures, for example, the software would look at behavioral information and the IP address of the computer. Does the user normally only request applications during business hours, but now suddenly he’s doing so at 2 a.m.? Does the request typically come only from a desktop computer and now it’s coming from a notebook? This is the kind of reputation-like input needed for advanced authentication, George explains.

Keith Ward, director for enterprise security and the identity management program office at Northrop Grumman Corp., agrees. Reputation-like strong authentication already has become an imperative for the company, as well as for eight other aerospace and defense companies and the governments of the U.S., U.K. and the Netherlands participating in the federated Transglobal Secure Collaboration Program (TSCP).

As an example, he points to secure collaborative e-mail, a TSCP-developed specification supported by Northrop Grumman, Boeing, Lockheed Martin and the other participants in the federated environment. “The application, sitting on top of Microsoft e-mail, is secure and collaborative because it’s tied to the vetting and proofing of employees specified for participation in the federated environment,” he says.

The process is similar to reputation scoring. “If any of an employee’s attributes changes, we have an 18-hour window to notify everyone in the federated environment and change access control policies for physical building entry, logical applications or portal access,” Ward explains.

Clearly, reputation services are playing increasingly important roles in enterprise security, be it for spam and malware control, to safeguard at the perimeter or improve application access controls. And while much of this is new and unproven, IT security managers shouldn’t be put off. As Opus One’s Snyder says, despite the unknowns, “I encourage people to start playing with this stuff as soon as it comes out.”

Schultz is a freelance writer in Chicago. She can be reached at bschultz5824@gmail.com.