Comment from email: Concerning Cybersecurity RFC
- Dominant language
- CSS
- Stars
- 59
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Description
Concerning Strengthening Cybersecurity of Federal Networks & Critical Infrastructure RFC:
Purpose: Cybersecurity Methods to Secure Localized Networks from the Internet and each other.
Keep it simple! Use Common Sense! Layered Protection
PHYSICAL LOCAL NETWORKS
Each Local network should be separated as follows:
1a. Break up your primary IT networks that connect to the internet
A Separate into complimentary network branches.
B. Allow only the protocols needed or used to communicate between the network branches and the Internet
C. See 1c. example 1: Network Separation (below)
D. See 2. Maintenance Network Sec c. (below) for a means to separate network protocols.
1b. How to Separate Local Networks
A. Sophos has some threat management appliances that are excellent for this purpose,
1. Easy to manage with an excellent alert system and easy to setup with full 24/7 support.
2. UTM (Universal Threat Management) >https://www.sophos.com/en-us/products/unified-threat-management.aspx<
B. This separation can be done less safely and less expensively with vlan technology in switches however
1. I recommend separate networks for each as the chance of technical programming error and /or security hole in software is greater than in hardware.
2. Physical Networks therefore are safer than the easier less expensive vlan technology software which runs multiple networks on top of each other sharing bandwidth on the same wire.
C. Convincing Company Executives to use separate hardwired networks is a hard row to hoe, but multiple networks separated and communicating only with necessary protocols is most secure.
1. If there is a network breach it is a network segment breach and not an entire network breach.
1c. Example 1: Network Separation
A. Data & Administrative Networks
1. ie AD, DNS, File Servers, Database Servers, Internal Mail Servers, Internal IIS Servers (https only), Virtual Machines, Storage, Etc
2. Duplicate, and cluster everything setup as High Availability and Backup
B. Phone and Communications Networks
1. VOIP Switches and Management Servers
2. Duplicate, and cluster everything setup as High Availability and Backup
C. Actual Intrusion Security
1. ie Video Recorders, physical security databases, video cameras, alarms, electronic door locks, electronic gate locks, etc
2. Duplicate, and cluster everything setup as High Availability and Backup
D. IT Development Network
1. Separated network(s) where all sorts of IT trial & error, learning. & development can take place without normal operation interference
E. Secure Wireless Networks
1. Again Sophos matches with UTM >https://www.sophos.com/en-us/products/secure-wifi.aspx<
2. Guests, IT, Mobile & Playtime Networks that have less security or are more likely to compromise other networks,
a. A place where personal things that happen can happen making the other networks more secure
b. All mobile phone should have antivirus and be encrypted (Sophos)
F. DMZ
1. a network "De-Militarized Zone", as it is called by the geeks.
a. It is merely a separation of servers that have unusual exposure to the Internet.
b. ie mail, ftps, https, etc
2. Duplicate, and cluster everything setup as High Availability and Backup
G. Honeypot Network
1. This Network(s) should be set up solely for the function of trapping and tracking unwanted network intrusion attempts
2. The Honeypot networks should be a fake duplication of the real network set up to look and act real
a. Even fake traffic to indicate normal operation.
2. Duplicate, and cluster everything setup as High Availability and Backup just as the primary IT networks are.
2. Maintenance Networks (Separated from the Internet)
1. Set up as OOBM (Out of Bank Management) and IPMI (Intelligent Platform Management Interface)
1. All network switches should be managed through OOBM.
2. Traffic on every port can be monitored through the OOBM port with a product called SolarWinds.
>http://www.solarwinds.com/<
a. Note: SolarWinds is too expensive for most small business but the development of this technology is straight forward and it should not be that expensive.
1) They need some competition.
b. An express version could be developed that would be sufficient for small business and even IoT (Internet of Things) on Home networks.
1) This is also a way to help secure IoT on any government, business or home network.
c. The SolarWinds traffic analyzer will isolate the protocols needed on each network so no one is guessing when limiting protocols between networks.
1) It seems that there are always protocols used that were not thought about so this is a way to isolate them and not take down a network when limiting protocols.
2. Through IPMI individual workstations can be managed and monitored if connected to a management network.
A. This is only available on new motherboards.
1. ie >https://www.supermicro.com/products/motherboard/Core/index.cfm<#1151
a. Only some of the boards at this link are IPMI compatible.
b. We always build our own computers to our own specifications to control things like IPMI, inventory for quick consistent replacement. and workstation repair ability & longevity.
3) OT Networks
A. Critical Infrastructure Should Be Totally Isolated from receiving IT and Internet data.
1. If it has to place information onto the other IT side of the network a complex method of one way communication can be set up.
a. We are setting this up now. If anyone reads this and needs to know how to accomplish this, contact me with credentials.
b. This is also the best way I know to secure IoT for any Government, Company or Individual network.
B. Separate isolate OOBM and IPMI Networks can be used to monitor the OT Networks
1. All OT network switches should be managed through OOBM separate from IT management network.
2. Traffic on every port can be monitored through the OOBM port with a product called SolarWinds.
>http://www.solarwinds.com/<
OTHER SECURITY MEASURES:
1. Layers of security are the best way to
A. Prevent then if/when breached
B. When Breached
1. Identify Problem
2. Isolate to Protect
3. Locate or Detect
4. Remove Threat or Otherwise Respond
5. Fix Damage or Recover
6. Follow Through to:
a. Locate Source and
b. Litigate & Isolate Source and/or Block Source
2. Setting Up Layers
A. Physical Local IT Network Separation
1. When needed turn on and off Administration logs such as DNS
a. Use to isolate what is coming in, what is going out during a threat intrusion attempt.
b. Use to Isolate where it originates.
c. This particular log will even catch the NSA's DNS Hack when they aren't supposed to be doing that.
B. UTM (Universal Threat Management) at Frontend
1. Active Alert System to Attempted Hacks
2. Isolate Countries where contact is unnecessary
C. Layer Security at the Endpoint
1. Firewall Endpoint w/ Sophos Endpoint
2. Antivirus / Malware Protection / Removal w/ Sophos Endpoint & Malwarebytes Concurrently
D. Continuous Backup with Clusters and HA
E. Regular Full Backup to Storage
F. Secondary Isolated Regular Full Backup & Isolate
G. Monitor Network Traffic
1. Critical Ports from OOBM and IPMI
a. Watch Traffic Norms w/ SolarWinds
b. Watch Network Changes w/ SolarWinds
ie unknown network connection and traffic on such port.
2. All ports watch for pattern variation.
H. Isolate OT Critical Infrastructure
1. One Way Connect to IT Network for Information Flow
3. Network Security Training
A. Network User Security and Network Awareness Training
1. Regular Updates as Information Changes
B. Network Administration Network Security Training
1. All Network Administrators must have proper clearance
2. All Network Administrators must be TRUSTED!
a. You have to trust administrators on any network
b. If they can't be trusted they can't be network administrators
4. Limiting Network Authority - Use Network Policy & Device Control
A. Limiting Users & Access w Policy
1. ie Windows Active Directory
B. Limiting Users through Software Control
1. ie Sophos Endpoint Device Control
2. ie Sophos Endpoint Application Control
5. Encrypt all functional data
A. Pro – Only authorized logins can see it.
1 Discourages hacking
B. Con – Don’t Lose the Key
1. A hacker only needs to find and change the key on a server to disrupt usability
2. Key should be kept separate on both as electronic media and hard copies in triplicate in 3 separate safes located at 3 different locations.
C. Encrypt
1. All Email (SPX Encryption is a simple usable form)
2. All Files
3. All Databases
4. Encrypt all Backups
5. Encrypt all Mobile Phones
Do this and you will have a pretty secure network and be able to know and understand the flow of information on it.
Regards,
David Pinkston
Manager
San Joaquin Refinery Co., Inc.
[2018SimplifiedOOBM-IPMINetworkOverview.pdf](https://github.com/GSA/modernization/files/1318875/2018SimplifiedOOBM-IPMINetworkOverview.pdf)
[2018SimplifiedNetworkOverview.pdf](https://github.com/GSA/modernization/files/1318874/2018SimplifiedNetworkOverview.pdf)
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.