john_cox
Senior Editor

Texas A&M probes traffic for assaults, faults

News
Jan 10, 20053 mins

Texas A&M University has improved the network management and security for its sprawling wireless and wired campus network with an application that sifts through traffic for abnormalities or irregularities.

By identifying patterns and dissecting them, the application, named QRadar, gives the university’s network managers a clear view of what’s really happening for all devices and protocols on the network. The software lets operations staff quickly detect worms, peer-to-peer traffic, port scans, and other signs of both cyberattacks and equipment malfunctions.

Getting that level of detail across an entire network is difficult without software like this, according to Willis Marti, associate director of computing for Texas A&M in College Station. “Other tools are too narrowly focused. They’re either vendor-specific or protocol-specific,” Willis says.

The software, from Q1 Labs, is marketed as a tool for creating a network security overview by surveying and displaying network behavior and traffic patterns as they take place. Texas A&M uses Version 3.0, released last May. In November, Q1 Labs released Version 4.0, which has been reworked to easily accept new mini-programs to add specific features. The first of these is QRadar-ICX (for Isolate, Contain and eXtinguish), which is designed to start countermeasures to block threats such as a denial-of-service attack, port scan or a rogue wireless LAN (WLAN) access point.

The university’s network, which uses primarily Cisco and Alcatel gear, is huge, covering what Marti says is the geographically largest U.S. campus, including more than 200 buildings, an airport and a rail line. There are 45,000 students, 16,000 faculty and staff members, and 60,000 end-user ports, of which about 38,000 are active at any time. About 58% of the net is 100M bit/sec switched Ethernet. About 300 WLAN access points give wireless coverage in selected public areas.

All this makes for a natural focus on security.

“We force users to use a VPN and authenticate” before gaining access, Marti says. Rounding out the security framework are:

  • Cisco VPN servers.

  • A campus Lightweight Directory Access Protocol server for authentication.

  • A distributed intrusion-detection system from SourceFire.

  • An in-house program called NetSquid to block infected hosts.

  • At the border, a homegrown packet-based firewall dubbed “Drawbridge.”

To get a view of his network’s activity, Marti used an open source tool, Multi Router Traffic Grapher, which collects data via SNMP requests to routers and other network hardware, and generates graphs of network utilization as Web pages.

“But we didn’t have anything that could synthesize a picture of everything” on the network, Marti says.

QRadar creates that overview by gathering traffic data via sensors called QFlow Collectors (or via Cisco IOS’ NetFlow), funneling it to the QRadar Classification Engine on a server, where it can be viewed via the QRadar Console application on a PC. The collectors can use a network tap or attach to a mirrored port on a switch or router.

“It can’t look at every link in every place,” Marti says. “We have it look at our residence halls, the campus [network] border and our remote-access connections.”

The server software creates a baseline of normal or customary network behavior. For example, the business office typically might have lots of SQL queries to a database. If an FTP file transfer mars that pattern, QRadar flags that event and sends an alert to administrators.

Network administrators can configure the Classification Engine with a set of rules reflecting their specific knowledge of, in this case, the university’s network. “You can set up a rule that says ‘a lot of IRC traffic out of a given subnet is an anomaly,’ ” Marti says.

john_cox

I cover wireless networking and mobile computing, especially for the enterprise; topics include (and these are specific to wireless/mobile): security, network management, mobile device management, smartphones and tablets, mobile operating systems (iOS, Windows Phone, BlackBerry OS and BlackBerry 10), BYOD (bring your own device), Wi-Fi and wireless LANs (WLANs), mobile carrier services for enterprise/business customers, mobile applications including software development and HTML 5, mobile browsers, etc; primary beat companies are Apple, Microsoft for Windows Phone and tablet/mobile Windows 8, and RIM. Preferred contact mode: email.

More from this author