设为首页收藏本站language 语言切换
查看: 1412|回复: 1
收起左侧

[书籍] CISCO self-Defending networks

[复制链接]
发表于 2025-7-30 13:25:25 | 显示全部楼层 |阅读模式
Cisco Security Best Practices

When the SQL Slammer virus hit last year, Cisco used the following six-phase implementation to prevent damage to its own network.

Preparation. People, processes, procedures, lines of communication, architecture, and automation tools all need to be in place before an event occurs. Security and networking teams must work together smoothly, with no contention over authority. A duty manager is available around the clock to make business decisions as needed, and engineers are empowered to take decisive actions. Professional relationships were established with Cisco's Product Security Incident Response Team; the Cisco Technical Assistance Center (TAC); Cisco Advanced Services; and ISPs, peers, customers that run other large networks. Cisco participates in FIRST. A detailed communications and escalation plan, facilitated by the operations group and used daily, is in place and well understood.

Identification. Use of Cisco and Cisco partner products and technologies (NetFlow on routers and switches exporting to Arbor Peakflow Traffic and Peakflow DoS anomaly-detection system) allows Cisco to know what is normal for its network, and what is abnormal (for example, unusually high numbers of UDP/1434 traffic flows) and potentially hostile.

Classification. Knowledge of Cisco's own network architecture, network traffic patterns, systems and input from Arbor/NetFlow instrumentation allows Cisco to quickly classify and scope threats.

Traceback. Instrumentation plus knowledge of the Cisco network allows Cisco to identify all presently visible and potential sources and vectors of the attack. This proves to be critical; in the case of Slammer, many organizations failed to account for indirect vectors, such as virtual private networks (VPNs) and laptops, that carried the virus into companies on Monday morning.

Reaction. Cisco immediately "dropped the shutters" through the use of ACLs at all Internet POPs worldwide. A well-designed, "bulkheaded" network allowed a pause so that Cisco could determine its follow-on actions. Knowledge of the virulence and threat level caused Cisco to push ACLs down to the desktop level in every Cisco facility worldwide, along with strategically placed ACLs in the Cisco WAN backbone. This ensured that Cisco wasn't affected on the following Monday. Operations teams provided focal point and bridges for all inter-group communications—network engineers didn't have to search for telephone numbers while dealing with mitigation. Thorough, complete, draconian, and pervasive ACLs were essential.

Postmortem. Cisco conducted daily followup sessions for two weeks to ensure that the threat was eradicated and to discuss lessons learned. Management issued the directive to prioritize and implement lessons learned in concrete, measurable ways, with meaningful followup to ensure future success.

游客,如果您要查看本帖隐藏内容请回复


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有账号?论坛注册

x
您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2026-8-29 00:08 , Processed in 0.063907 second(s), 10 queries , Redis On.  

  Powered by Discuz!

  © 2001-2025 HH010.COM

快速回复 返回顶部 返回列表