SLIDE 1
3 Org Structure Politicians IT Network Structure 5 History of - - PowerPoint PPT Presentation
3 Org Structure Politicians IT Network Structure 5 History of - - PowerPoint PPT Presentation
3 Org Structure Politicians IT Network Structure 5 History of projects between CMU and the City Heinz College Information Systems & Management Public Policy and Management Penetration Test project last
SLIDE 2
SLIDE 3
3
SLIDE 4
5
- Org Structure
– Politicians – IT
- Network Structure
SLIDE 5
6
- History of projects between CMU and the City
– Heinz College – Information Systems & Management – Public Policy and Management
- “Penetration Test” project last year
– Technical exercise – Policy assessment and recommendations
SLIDE 6
7
- Initiated discussions with the CIO
- Review & approval by City Legal, CMU Legal,
- thers
- Volunteers installed a sensor at the primary
internet connection
SLIDE 7
8
- Network Situational Awareness class
– http://www.andrew.cmu.edu/course/95-855/ – Instructors:
- Tim Shimeall*
- Sid Faber
– Anonymized data
- MAWI, Internet 2, CDX
SLIDE 8
9
- Gain Network Situational Awareness
- Provide information back to the city
- Done in the blind
SLIDE 9
10
- Find Heavy Hitters
- Create a profile
- Eliminate bogons
- Monitor over time
SLIDE 10
11
- ACL / Least Privilege
- DNS
- Policy Validation
– Remote Access (Gotomypc) – Streaming Video
SLIDE 11
12
- Network Profile
– Scans – Client Web, Served Web – Servers as Clients – Email – DNS – NTP – Etc.
SLIDE 12
13
SLIDE 13
14
SLIDE 14
15
SLIDE 15
16
SLIDE 16
17
SLIDE 17
18
- Network Situational Awareness:
– Perceive: Network flow sensor – Comprehend: Network profile, leftovers – Project: What does this mean to me?
SLIDE 18
19
- All packets are innocent until proven guilty
– Profile by country – Scan traffic, inbound traffic
SLIDE 19
20
- Leveraging university, Limited resources
- External validation
– Support for external auditors
SLIDE 20
21
- Initial impression: too much data
- Dividing traffic led to identifying patterns
- Couldn’t really be done with full packet data
SLIDE 21
22
- Improve the sensor
– Instrument the cold spare – Instrument internally – Add metadata
- Add a security focus
- Add a geopolitical focus
SLIDE 22