Network Security
Part 2: Network System Security Recommendations
Introduction
For any organization that has embraced technology, data has become an invaluable asset that the organization cannot do without. As with the protection of other tangible assets, the protections provided to data assets should be commensurate with their importance to the organization. An effective information security strategy implements its safeguards after a careful analysis of potential threats and covering the bases as strongly as possible. The vulnerabilities that exist within the network will need to be identified and patched as soon as they are identified. A wide range of security measures will need to be implemented simultaneously within the system. These will include both hardware and software options as well as intensive security training for users of the system. Threat and risk assessment should not be a one-off activity at the installation of the system. Rather, it is continuous process that is cognizant of the evolving nature of information where newer threats are emerging every day. The most secure system then becomes one whose security strategy is meant to be proactive rather reactive.
Network System Security Recommendations
An effective firewall is one that will ensure that the traffic that gets through it is one that is safe and only originating from legitimate sources. An intrusion prevention system (IPS) will be required to both detect and prevent any potential threats and stem off attacks. A secure and robust network must have its components well configured if it is to effectively identify and fend off threats.
• Configuring the firewall – the firewall will be configured to identify all traffic that can be definitively traced to be within the company. It will have the capabilities to identify any traffic that does not come from within the company and effectively drop it. Hackers targeting a networking will usually attempt to do so by disguising inbound traffic to appear as if from a legitimate source. If data appears to be from a legitimate source, it has higher chances of gaining entry. But this is not always the case. With ingress filtering, a firewall is granted the capabilities of accurately determining whether that particular data is indeed from the source computer it claims to be from. Microsoft provides Windows Firewall for its operating and this will be the one in use for the firm. The firewall has a primary purpose of limiting communication between the network and the internet. However, this can limit functionality as there will be aspects of the network that will require accessing the internet. As such, there will be the need to configure exceptions. A notifications dialog will provide options for total blocking of a program, unblocking and a third option for when the administrator has not yet decided on whether to block or not. For the last option, the program will stay blocked. Under program exceptions, only a few of them will be granted that exception. This should include the web browser and the email client. Any other programs will be blocked from accessing the internet without the permission of the administrator. The scope of the excepted programs will then be limited to the firm’s network for added protection. All ports should be closed when not in use. Whether under TCP or UDP protocols, the ports to be provided with the exceptions are to be directly specified. The scope for the ports will also be limited to the local network [1].
• Configuring the router – as the gateway for internet traffic to and from the network, it is important that the configurations of the router are as robust as they can be. The web server and the email server will need to be accessed from the internet. This will require that port forwarding be configured first. Router manufacturers deliver them with default IP addresses and login credentials. If this default credentials are not changed by the end users, there is always the chance they could be used by hackers to access the router. As such, they must be changed once the router has been acquired. The security mode of the NETGEAR MR814 router will need to be set to the 64-bit WEP Wi-Fi encryption protocol that should provide adequate security for this network. Also, it is advisable to disable the Universal Plug and Play (UPnp) feature to keep out rogue devices and software. This will ensure only authenticated devices and software access the network. The password to be used should be long and include an alphanumeric and special character combination. Remote management is unnecessary for single premise firm and should be disabled. Permissions and access control should next be implemented to restrict access to the router to only authorized users and control the flow of information. As with other components of the network all activities of the router will be logged and sent to the syslog server [2].
• Setting up Microsoft Server 2012 – a big improvement on the Microsoft Server 2008 version, Microsoft Server 2012 will provide the firm with opportunities for centralized management and deployment of services and functions. The Active Directory will be installed from the server manager console. Access control will be managed under organizational units that will correspond with the firm’s various departments. Given that employees within the same departments will have close to similarly defined responsibilities, their access to company resources will then be governed under similar privileges. Server virtualization is to be implemented within the Windows Server 2012 environment. This will provide multiple virtual environments that can be used to run separate tasks and also for backing up company data. Virtualization should also do away with instances of application collisions and incompatibility issues within the system. Microsoft Server 2012 provides a system failover option that will ensure that the fail of one section of the system does not jeopardize the entire system. This is achieved by the virtualized systems that take over should any other break down [1].
• Configuring the intrusion prevention system (IPS) – the intrusion prevention should be configured under global settings that will have it that any rogue connections are dropped silently and in the background. Identifying potential threats will be set to spot protocol anomalies, server-side attacks, client-side attacks, operating system level attacks, and targeted malware attacks. By configuring flood protection in protocols like ICMP, and TCP SYN, anti-DOS attacks will be contained effectively. The intrusion prevention system is meant to operate automatically on its own for the most part. This should enable it to work at all times even outside normal business hours. However, it will important that the system regularly provide alerts to the network administrator who will then analyze the extent of the attacks. The alerts will consist of event logs that provide details on the nature of all the potential threats. The administrator will then be able to implement any measures to meet any emerging threats. Implemented on the perimeter of the system, the intrusion prevention system (IPS) will be able to monitor every communication in the system and identify the threats [3].
Addressing Identified Vulnerabilities
• Network backdoors – regular scanning and a network discovery tool will be needed to find any rogue access points within the network. Each and every device and software deployed within the network will require to be mapped and a baseline for their operations established. A network discovery tool should do this even without the input of the network administrator [3].
• Mobile and personal devices – should an employee wish to use their device for work responsibilities, they should be required to submit the device to the IT team who then go ahead and check its security features. Only after it is deemed secure will the user be allowed. As for company-issued mobile devices, an encryption program should be installed on all devices to secure not just the communication in and out of the device, but also the data stored within the device. There should be also for conditions placed by the firm on the use of the devices [3]. An example would be the requirement that employees only use the devices for company work only and not personal. They should also be regularly submitted to the IT team for inspections.
• Removable media – there should be a company-wide rule that no personal devices should attached to company computers. This regulation should work for the most. However, just in case, an up-to-date anti-virus program should be installed within the network to prevent any malware from infecting the network [3].
• Distributed denial of service (DDoS) attacks - these attacks are meant to push a system to its breaking point. To prevent the adverse impact of such attacks, the firm should conduct regular stress tests on its system to gauge its resilience. These tests will provide answers on how far the system can go under stress without breaking down. Any improvements on the system can then be done on the basis of the results [4].
• Security loopholes – for software and hardware that has been delivered by their manufacturers with loopholes in them, they should be swiftly patched. These patches are usually provided by the manufacturer after the loopholes have been identified. Also, the company should endeavor to only acquire software and hardware components from vendors that have secure track record [4].
References
[1] D. Rountree, Windows 2012 Server Network Security: Securing Your Windows Network Systems and Infrastructure. Newnes. 2013.
[2] D. Jacobson and J. Idziorek, Computer security literacy: Staying safe in a digital world. CRC Press, 2016.
[3] C.F. Endorf, E. Schultz, and J. Mellander, Intrusion detection & prevention. New York: McGraw-Hill/Osborne, 2014.
[4] S.C. Huang, D. MacCallum and D. Du, Network security. New York: Springer, 2013.