On GameFAQs: Be a hero or be inFamous with our help

Eight daily steps to a more secure network

Tags: NETWORKING, Michael Mullins CCNA, MCP, security, network, Security Solutions Newsletter

  • Save
  • Print
  • Recommend
  • 7

Takeaway: While many companies have a 9-to-5 security staff, hackers don't punch a clock. However, your network can still remain secure in the 16 hours in-between—you just need to focus activities to provide maximum coverage for the network. Mike Mullins gets you started with a list of eight daily tasks in this edition of Security Solutions.

In today's connected world, hacking is a 24/7 business. Whether approaching it as a job or a hobby, hackers don't punch a clock.

While many companies don't have the budget for 24/7 security managers, that doesn't mean you should just give up on security. If your security staff, or your one security staff member, is on a 9-to-5 schedule, your network can still remain secure in the 16 hours in-between—you just need to focus activities to provide maximum coverage for the network.

Develop a methodical, comprehensive task list that provides the most efficient means of securing your network. To jump-start your planning, here are eight simple tasks you should make sure to check off every day.

In the morning

After arriving at work, get some coffee, check your e-mail, and do the following:

  1. Verify the current connections: There's nothing like catching malicious behavior while it's occurring. Inspect all the connections going through your firewall—both in and out. Look for anomalies and investigate them; this could include outbound FTP or inbound Telnet/SSH sessions. You're looking for things that aren't normal.
  2. Look at network traffic statistics: How much activity took place while you weren't there? What type of traffic was it, and what was the destination and source?
  3. Look at your antivirus logs: Did a virus hit your e-mail system last night? Are the antivirus signatures up to date?
  4. Read the security logs on your domain servers: Did the system lock out any accounts last night? Pay special attention to any accounts with administrator access. Verify that lockouts were human error—and not part of a breach attempt.
  5. Check for new security patches: Determine whether any of your vendors released patches for any software in your baseline. (If you don't have a baseline, I highly recommend developing one.) If a new patch is available, read the release notes thoroughly. Then, make a decision or recommendation whether to implement it now or wait for scheduled system downtime.

In the afternoon

When you arrive back from lunch, there's still a lot left to do:

  1. Meet and brief: Managers like to know what's going on, so don't wait for them to ask—tell them. Meet and brief on anything that occurred during the evening and the actions you've taken so far. This is also a good time to pitch new ideas; such as tools that could help you defend the network or staff training.
  2. Check more logs: Take an in-depth look at IDS and firewall logs. Who on the Internet is knocking on your door? What are they looking for? Who on the inside of your network is doing something they shouldn't be?. If you find unauthorized and/or illegal activity, report it immediately, and take action to stop it.
  3. Turn knowledge into action: Now that you know what went on while you weren't there, develop an action plan to prevent the behavior in the future. Do you need to adjust your firewall rules? Is your IDS catching and reporting the proper events? Do you need to archive logs to save space on your servers? Do you need to give a final briefing on any actions that occurred during the last 24 hours?

Final thoughts

A lot of companies don't run 24/7 security operations, and sometimes you might find yourself as the only person providing security for a network. While it's easy to get caught up in events and miss important items on your security checklist, you'll never know what you're missing if you don't create a list in the first place. Network security shouldn't be reactionary—don't wait for events to drive you into action.

The above list isn't complete, but it's a starting point. Create your own security to-do list that's specific to your organization's needs, and keep your security on track.

Miss a column?

Check out the Security Solutions Archive, and catch up on the most recent editions of Mike Mullins' column.

Worried about security issues? Who isn't? Automatically sign up for our free Security Solutions newsletter, delivered each Friday, and get hands-on advice for locking down your systems.

Mike Mullins has served as an assistant network administrator and a network security administrator for the U.S. Secret Service and the Defense Information Systems Agency. He is currently the director of operations for the Southern Theater Network Operations and Security Center.

  • Save
  • Print
  • Recommend
  • 7

Print/View all Posts Comments on this article

t trl145 | 11/10/06
Good question, with lots of good answers... "Mysterious | 11/10/06
Thank you for both the question and the answer DanLM | 11/10/06
Logs BIOSphereopts@... | 11/11/06
Manually scanning logs is silly sean@... | 11/13/06
I've been hacked...now what.. dlragsdale@... | 11/10/06
hmm DanLM | 11/10/06
more on my "victim" situation dlragsdale@... | 11/11/06
more on my "victim" situation dlragsdale@... | 11/11/06
legal unknown, technical = rebuild Krunkl3 | 11/11/06
I do have an option dlragsdale@... | 11/11/06
Install 2003! ashine@... | 11/13/06
Second That!! safesax2002 | 11/13/06
Thanks alot dlragsdale@... | 11/13/06
Suspicious Ping-Like light activites jmixmaster@... | 03/21/07

What do you think?

White Papers, Webcasts, and Downloads

Article Categories

Security
Security Solutions, IT Locksmith
Networking and Communications
E-mail Administration NetNote, Cisco Routers and Switches
CIO and IT Management
Project Management, CIO Issues, Strategies that Scale
Desktops, Laptops & OS
Windows 2000 Professional, Microsoft Word, Microsoft Excel, Microsoft Access, Windows XP,
Data Management
Oracle, SQL Server
Servers
Windows NT, Linux NetNote, Windows Server 2003
Career Development
Geek Trivia
Software/Web Development
Web Development Zone, Visual Basic, .NET

Popular IT Dojo Videos

advertisement
Click Here