CIP-005-5 R1.5 Spring CIP Audit Workshop
April 14, 2016 Scott Pelfrey, CISA, CISSP, GISP, MBA Senior Technical Auditor
CIP-005-5 R1.5 Spring CIP Audit Workshop April 14, 2016 Scott - - PowerPoint PPT Presentation
CIP-005-5 R1.5 Spring CIP Audit Workshop April 14, 2016 Scott Pelfrey, CISA, CISSP, GISP, MBA Senior Technical Auditor CIP-005-5 Part 1.5 Learning Objectives Terminology Discussion of IPS/IDS & firewall Questions Answered
April 14, 2016 Scott Pelfrey, CISA, CISSP, GISP, MBA Senior Technical Auditor
Forward Together • ReliabilityFirst
2
Forward Together • ReliabilityFirst
3
Forward Together • ReliabilityFirst
4
Forward Together • ReliabilityFirst
5
Forward Together • ReliabilityFirst
6
unauthorized users, malware, viruses, etc.
security related
‒ Keeps “directory” of TCP connections ‒ Only allows incoming traffic for “known” connections ‒ May also keep track of TCP sequence numbers as well
Forward Together • ReliabilityFirst
7
device (Transient devices)
‒May be vulnerable to IP address spoofing, source route attacks & tiny fragment attacks ‒Vulnerable to TCP/IP protocol bugs
Forward Together • ReliabilityFirst
8
Forward Together • ReliabilityFirst
9
Forward Together • ReliabilityFirst
10
‒ Resident on one system ‒ Monitors only that system’s activity ‒ Can detect both Internal / External intrusions
‒ Monitors particular network segments or devices ‒ May be inline (as part of another net device)
mirrored port)
Forward Together • ReliabilityFirst
11
‒ Analyze records for match with current rules or signatures ‒ Requires constant updates for protection ‒ Issue: only knows known intrusions, new intrusions may not be found
‒ Builds profile or keeps thresholds ‒ Matches incoming packets to profiles or thresholds ‒ Issue: May have false positives during “extreme” events
Forward Together • ReliabilityFirst
12
Corporate Network
Forward Together • ReliabilityFirst
13
Forward Together • ReliabilityFirst
14
Forward Together • ReliabilityFirst
15
connections
methods
Forward Together • ReliabilityFirst
16
Host-Based IPS
Forward Together • ReliabilityFirst
17
Forward Together • ReliabilityFirst
18
Forward Together • ReliabilityFirst
19
Forward Together • ReliabilityFirst
20
Forward Together • ReliabilityFirst
21
Forward Together • ReliabilityFirst
22
Forward Together • ReliabilityFirst
23
Forward Together • ReliabilityFirst
24
Forward Together • ReliabilityFirst
25
Forward Together • ReliabilityFirst
26
Forward Together • ReliabilityFirst
27
Forward Together • ReliabilityFirst
28
Forward Together • ReliabilityFirst
29
Forward Together • ReliabilityFirst
30
Forward Together • ReliabilityFirst
31
Forward Together • ReliabilityFirst
32
Forward Together • ReliabilityFirst
33
Forward Together • ReliabilityFirst
34
Forward Together • ReliabilityFirst
35
Forward Together • ReliabilityFirst
36
Forward Together • ReliabilityFirst
37
Forward Together • ReliabilityFirst
38