Showing posts with label Metadata. Show all posts
Showing posts with label Metadata. Show all posts

Thursday, November 18, 2010

Cyber security artists need the right tools

It has become evident to me that cyber security is an art, and like any other art, it has artists who need the right tools.
At Qosmos, we work with cyber security teams who protect very sensitive networks. These security analysts typically work in a Security Operations Center (SOC), monitoring traffic and checking for suspicious activity, such as:
  • Services or encrypted traffic on non-standard ports 
  • Referring URI, which can be used to detect Phishing software loading partial content from a real site
  • Many (hundreds) of “IP gets” from black-listed countries
  • Specific malware file names (e.g. shell.exe)
  • Suspicious malformed traffic
Best practice cyber security filters out known threats with COTS cyber security products (AV, Firewalls, etc.) and focuses investigation and analyst time on 1% suspicious traffic only. So, what tools do the analysts need?
  • Information feeds in the form of logs and traffic metadata
  • Search and analysis capabilities
Logs are the obvious source of information to investigate potential security breaches. But a recent trend is to complement these logs with communications metadata, representing an additional source of real-time information.

Examples of communications metadata which are relevant for cyber security:

The advantages of metadata:
  • Not only do good metadata complement logs, they are also MORE valuable than full packet payloads to identify patterns! As someone said to me: “sometimes, you can’t see the forest (situational awareness) for the trees (packet payloads)”
  • In addition, metadata require less storage than full packet capture which means that historic info can be kept for longer time periods (months) than full packet capture: this means much stronger investigative capabilities.
  • Metadata also enables much faster forensic search, with the ability to search 2TB of data in less than 2 minutes!
  • Finally, metadata can be used to index flows and packet contents
Example of a best-of-breed cyber security tool case
A tool case can be built on Qosmos + Splunk. In this case, Qosmos does the protocol decoding up to Layer 7, providing complete visibility of all network traffic and applications, independently of ports. The extracted protocol metadata is indexed by Splunk in addition to log information. Splunk is then used for search, statistics and GUI.

Example of Searching for Suspicious Network Activity by using Qosmos + Splunk
 


Let’s give cyber security artists the tools they need to exercise their art!

Jerome

Friday, April 17, 2009

Breaking the high speed barrier

I have recently had several interesting discussions with solution vendors who are faced with the serious challenge of making their systems work at multi-Gbps line rates. To break this “high-speed barrier”, they can either 1) spend considerable time and resources redeveloping their products to work at higher speeds, or 2) optimize their solutions with the help of Network Intelligence.



The challenge is especially acute for vendors in the mobile data environment, where bandwidth is growing at an exponential rate. Vendors who sell (for example) mobile service quality monitoring need to continue offering the same level of functionality at speeds in excess of 1 Gbps. However, it is not as easy to do well at high speeds what they used to do well at lower speeds… Of course, some vendors may be tempted to reduce functionality in order to handle the increased bandwidth, but this is not an option : it is clearly not an acceptable solution for mobile operators and their clients.

So how can Network Intelligence accelerate existing mobile solutions?

As we all know, mobile data traffic is literally exploding, due to the combination of new iPhone-type handsets, new broadband infrastructure (3G, HSDPA, HSUPA) and attractive pricing schemes. At the same time, video streaming, P2P, and social networking applications consume a large percentage of this traffic, pushing bandwidth at the core of mobile networks to multi-Gbps. This creates a need to generate useful data at workable bandwidths, and only retain essential information (e.g. IP metadata or IPDRs) for lower priority services (P2P, etc.).

Example 1: TroubleShooting

In order for customer service to respond to customer complaints, mobile operators often need to check service quality for certain subscribers. In this case, a Qosmos probe can filter selected IMSIs and forward only relevant traffic to an existing troubleshooting solution, at manageable speeds. No change is necessary to the existing solution.

Example 2: Subscriber Knowledge

Mobile operators carry massive amounts of data traffic from services outside their walled-gardens. This traffic can represent more than 90% of total traffic (see this Webcast for a concrete example). To optimize networks and service offerings, MNOs require better network intelligence to answer questions like: what mobile devices are being used (PC/handheld)? Which applications drive data growth? What are user the behavior patterns? All these questions can be answered with Qosmos Network Intelligence technology.

Example 3: Lawful Intercept

Beyond mobile solutions, similar challenges exist in the area of Lawful Intercept, where many intercept probes have not been designed to handle very high bandwidth. Here again, Network Intelligence technology saves the day by processing the high-bandwidth raw traffic and carrying out optimized dispatching of information to an existing lawful intercept system that can continue to process efficiently.

In summary, Network Intelligence technology can be used to enable existing solutions to continue performing efficiently even at very high speeds! Even though total bandwidth exceeds several Gbps, the traffic selected for forwarding can be handled easily by existing applications. The benefit for solution vendors: by adding a layer of Network Intelligence, they can avoid costly development and continue to sell existing solutions even as bandwidth grows exponentially!

I should also point out that our approach is different from “load balancing” provided by some suppliers, since Network Intelligence implements smart traffic filtering based on deeply embedded criteria (e.g. IMSI, MIME type, email sender, etc.), and can generate CDRs even for discarded traffic.

Jerome

Monday, March 9, 2009

The Power of Metadata

Metadata is information about communication: who communicates with whom, how, when, and where. For example VoIP caller/called party, Email / Webmail sender / receiver / subject, IM contact list / status / sender / receiver, route update in routing protocol, etc.

With the exponential increase in IP communications, metadata has a great untapped potential for mapping communication patterns, especially for protection purposes as in the case of lawful intercept. It also solves the problem of ballooning storage requirements. In fact, the metadata approach may even be the ONLY way to handle lawful intercept in the future!

So the opportunity is to leverage metadata for intelligence gathering, for ex. to reconstruct links between people, to understand which virtual IDs the same person is using (starting from physical IP/IMSI) or to identify intentionally hidden information (“the Dark Web”).

However, IP communication metadata is not readily available on operator servers, or resides on third-party Web servers, outside the control of a given telco (think P2P,social networking, etc.). Therefore, metadata has to be extracted directly from the network.

So how can buyers of LI solutions leverage IP metadata?

  1. Use the rich set of information available with IP metadata to build completely new types of intelligence solutions - as a complement to content-focused solutions. This gives a better understanding of potential threats (the macro-view)
  2. Take advantage of more computer-based information processing 1.5 billion Internet users, thousands of Web applications… the number of analysts cannot increase at the same rate as the number of IP communications, the number of Web applications and the amount of content generated > need to think differently?!
The solution is to implement automatic detection of suspicious behavioral communication patterns and create real-time view of the threat situation based on continuous streaming of metadata and network information. There is also an opportunity to minimize storage and post-processing time by extracting significant information and structuring it as soon as each metadata is available

Long live metadata!

Jerome

 
© 2009 Network Intelligence Technology. All Rights Reserved | Powered by Blogger
Design by psdvibe | Bloggerized By LawnyDesignz