Talk With an Expert

Security improvement of a wide and heterogeneous set of network devices: a global approach

Security improvement of a wide and heterogeneous set of network devices: a global approach (PDF, 4.89MB)Published: 19 Feb, 2005
Created by:
Jean-Marc Millet

This case study describes the most interesting steps of a project to improve the security of a wide set (about one thousand) of network devices (switches, routers, firewalls) originated from many manufacturers. It is intended to describe a global approach which could be reused to tackle such situations. We will examine how to establish a security baseline through a network scan. Afterwards, we will estimate the risk on the organization induced by each family of network devices. This will provide the list of devices to secure in top priority. State of the art tools and best practices in configuration security hardening are then studied: Cisco devices with an improved version of the Router Auditing Tool (RAT), and Nokia firewalls through a security audit checklist, as no adequate tool has been found. Other types of devices will be handled by an ad hoc network scan, considered as the default control procedure. Other security aspects like user access management are also examined. Security compliance indicators have been defined to measure the progress towards more security. Finally we will outline remaining risks like value added servers (DNS, DHCP, Authentication) not yet controlled and new risks such as those induced by the use of security tools.