BYOD Makes You Productive, and It’s Also Why Your NAC Deployments Fail

Network Access Control (NAC): everyone wants to do it, and the goals for most programs are noble.

It goes like this: By ensuring only authorized users and devices connect to the network, IT can help alleviate the risk of an intruder bringing a rogue device onto the corporate network, or avoid people connecting their personal devices riddled with malware to the corporate network and infecting corporate-managed devices. Sounds perfectly simple and reasonable, right?

Not quite. The BYOD trend means NAC is no longer a clear-cut issue. Because most IT departments don’t support or keep tabs on users’ personal electronic devices, they need to limit the amount of access users on their own devices have to the environment in order to protect the rest of the network. Users, in turn, argue that limiting their ability to use their own devices on their employer’s network limits the productivity gains made possible by BYOD. 

Traditional NAC employs several technologies working in tandem to provide a solution. A NAC server is deployed that will house the policies, while an agent is deployed on BYOD devices for integrity profiling. If there is a setting or software on a computer, NAC can interrogate the device and report back to the server. The routers will need to be set up with at least a couple of networks: one for fully compliant devices and another for guests. The access switches will be configured to send authentication requests to the NAC server when a device connects. Based on the results of the integrity checks on the host, the NAC server will configure the switches to connect the user either to the fully compliant network or the guest network.

Most NAC deployments fail. We are used to a networking environment where you connect your device and have full access to the network. When NAC is deployed the opposite is true; when your device connects to the network it usually has little to no access by default. Once the device has been interrogated and is compliant with the NAC profile, it may be granted more access.

For example, a NAC policy will often be configured to require specific anti-virus software running and up-to-date on the device, and if someone brings his or her personal computer to work it will be deemed non-compliant by NAC. The moment someone with enough clout can’t get on the network because of this, a flood of the exceptions to the NAC policy start to roll in to IT. The project soon fails.

NAC is yet another “firewall helper” – something to be added on next to a traditional firewall, similar to how standalone URL filtering or Intrusion Prevention Systems are. It is a complicated and expensive proposition to keep adding devices to the network when NAC policies are so easily discarded.

GlobalProtect from Palo Alto Networks offers a simpler approach that can more easily attain the same results leveraging existing infrastructure. GlobalProtect is the remote access VPN client with both SSL and IPSEC connectivity options. GlobalProtect can also be used to perform Host Integrity Posture (HIP) checks.

Consider:

  • You can ensure groups of users are properly defined in your directory server. The more levels of access you want to define, the more groups will need to exist on the directory server. The security appliance obtains the user and group information from the directory server for use in access control policy so it’s important to get this where you want it. This step is true for all NAC deployments.
  • You can decide on what “compliant” means. For example,
    • Fully compliant may mean the user is authenticated to the directory server, the device is connected to the directory server, the device has a certificate, and the device has your standard endpoint protection software running.
    • Partially compliant may mean the user is authenticated to the directory server and has the GlobalProtect software running. These will likely be users on their personal devices who installed GlobalProtect by visiting the VPN portal.
    • Non-compliant users will be users who are not authenticated and do not have the GlobalProtect software installed.
  • You can decide on the levels of access users will get depending on their endpoint posture. Much of this may already be accomplished if you are using User-ID in your Palo Alto Networks security policies. You may have three security policies, as in this basic example;
    • Access for authenticated and compliant users may include typical web browsing and full intranet access with email, file shares, CRM, and development systems.
    • Access for authenticated non-compliant users may include web-browsing and DNS to the Internet and email access internally.
    • Access for unauthenticated non-compliant users may include web-browsing and DNS to the Internet only.

When devices connect from outside the physical walls of the organization, or from inside one of the offices, the network will adapt to the user and device based on what it observes (or doesn’t observe).

This is a clear departure from deploying another NAC server firewall helper that needs to communicate and make dynamic changes to the switching infrastructure to be effective. In this use case we are using a centralized security platform with a single policy engine to identify users and devices and provide appropriate levels of access depending on who they are and what device they are on.

To learn more about how GlobalProtect can help you enable a NAC policy that gives users the freedom to use their own devices, yet still protects your network, please visit our GlobalProtect technology page.

[Palo Alto Networks Blog]

Cloud Security Alliance and Palo Alto Networks Release Security Considerations for Private vs. Public Clouds

By Larry Hughes, Research Analyst, Cloud Security Alliance

Cloud computing has the potential to enhance collaboration, agility, scale and availability, and provides opportunities for cost reduction through optimized and efficient computing.   The cloud trend presents a momentous opportunity to revisit not only how we think about computing, but also how we think about information security.

The Cloud Security Alliance (CSA) recently teamed up with Palo Alto Networks to produce a new whitepaper titled, “Security Considerations for Private vs. Public Clouds.”  For purposes of definition, a public cloud deployment occurs when a cloud’s entire infrastructure is owned, operated and physically housed by an independent Cloud Service Provider.  A private cloud deployment consists of a cloud’s entire infrastructure (e.g., servers, storage, network) owned, operated and physically housed by the tenant business itself, generally managed by its own IT infrastructure organization. 

While the title of the paper implies a primary focus on security, we took the opportunity to expand the conversation and incorporate a wider set of considerations including:

  • Business and legal topics, including contracts, service level agreements, roles and responsibilities, and compliance and auditing. We touch on the importance of establishing principal business and legal feasibility early on in the process, before investing too much in technical requirements.
  • Physical and virtual attack surface considerations including a look at vulnerabilities that are accessible to would-be attackers.
  • Operational issues, including data migration, change management, logging, monitoring and measuring and incident management and recovery and the roles they play in determining which cloud deployment makes the most sense for an organization.

Cloud security is one of the most critical considerations, regardless of whether the deployment is public vs. private. But security is not black and white and no two companies looking to deploy a cloud infrastructure do so for exactly the same reasons. Wise organizations will take the long view and invest in security accordingly. As Thomas Edison once said, “Opportunity is missed by most people because it is dressed in overalls and looks like work.”

On Tuesday, June 23, Matt Keil, Palo Alto Networks Director of Product Marketing for Data Center, and I will be hosting a webinar to discuss the white paper in-depth and look at security considerations for public and private clouds.  For more information and to register for the webinar, click here.

For more information on CSA, please visit https://cloudsecurityalliance.org.

[Cloud Security Alliance]

Simplify Policy and Device Management in Panorama 7.0

As part of our PAN-OS 7.0 release, you can now take advantage of many new Panorama features designed to simplify policy and device management. Read more about them in thePAN-OS® New Features Guide Version 7.0 or read on for features that were hand-picked by our staff as having the biggest impact.

Device Group Hierarchy and Template Stacks

Are convoluted and outdated rulebases hindering your productivity? Now, it’s easier than ever to set, group, and manage rules by creating nested device groups in a tree hierarchy—with lower-level groups inheriting the policies and objects of higher-level groups—and template stacks, which push the combined settings of multiple templates to firewalls. These panorama features empower you to organize firewalls based on function and location without necessitating a redundant configuration.

Read more >> Device Group Hierarchy and Template Stacks

Multiple Access Domains for Role-Based Access

As an administrator, your time is precious! That’s why we now enable you to control administrator access to information according to areas or levels of responsibility, providing you increased focus and context. Each Panorama Device Group and Template administrator can now have multiple access domains, each controlling access to device groups and templates, and each paired with an administrative role. This enables administrators to filter the Panorama web interface by domain.

Read more >> Role-Based Access Control

Import a Firewall Configuration into Panorama

If you’ve ever tried to migrate a configuration into Panorama, you might know that the process could be a bit tedious and complex. To alleviate this pain point, you can now import firewall configurations into Panorama and can also clone templates and template stacks. These features save you the effort (and headache!) of deleting, recreating, or renaming configuration elements when only a move or copy is needed.

Read more >> Firewall Configuration Import into Panorama

Log Redundancy Within a Collector Group

Logs provide visibility. They enable you to analyze and correlate network events so that you can detect and respond to threats effectively. In Panorama, you can now enable log duplication for a Collector Group to ensure that, if any one Log Collector becomes unavailable, no logs are lost: you can still display all the logs forwarded to the Collector Group and run reports for those logs.

Read more >> Log Redundancy Within a Collector Group

Can’t Get Enough of Panorama 7.0?

For more information about Panorama features in PAN-OS 7.0, check out the Panorama 7.0 Documentation page on the Technical Documentation Site, or select the 7.0 (under OS Version) and Panorama (under Product Category) facets on the Document Search page!

Happy reading!
Your friendly Technical Publications team

[Palo Alto Networks Blog]

US Executive Order on Information Sharing: A Government Security Leader’s Perspective

Recently, US President Barack Obama signed a new Executive Order to promote cyber security information sharing. As a government security leader and member of ISACA’s Government Relations and Advocacy Committee, I believe that this directive was significant because it demonstrates that government leaders can take bold steps to improve our security posture without an act of Congress. Some may argue that without legislative edicts, the new voluntary information sharing framework lacks the teeth to be successful. But I wholeheartedly disagree. As a longtime voluntary member of the Multistate Information Sharing and Analysis Center (MS-ISAC), I know from firsthand experience the value proposition of being part of an information sharing community, even one that is voluntary. If they build it, people will come, because in today’s threat-laden world, prompt access to actionable intelligence is vital.

So what does the Executive Order do? First, it elegantly expands the existing sector-based ISAC model to include regional and other information sharing constructs. In the order, all information sharing groups are collectively rebranded as Information Sharing and Analysis Organizations (ISAOs). The Executive Order also positions the National Cybersecurity and Communications Integration Center (NCCIC) to serve as the epicenter of ISAO information sharing. And finally, the order requires the adoption of consistent information sharing standards to be used by all ISAOs. Additional details can be found in the FAQ document on the White House website.

The US Department of Homeland Security is now soliciting feedback as it works to build out this new and vital link in our national security ecosystem. I am proud to report that I am one security leader who plans to belly up to the bar to lend my support because the more that we collaborate, the more secure we all will be.

As a member of ISACA, I am interested to hear your thoughts on this very important Executive Order.

Christopher P. Buse, CISA, CISSP, CPA
Chief Information Security Officer, MN IT Services

[ISACA]

Operation Lotus Blossom: A New Nation-State Cyberthreat?

Today Unit 42 published new research identifying a persistent cyber espionage campaign targeting government and military organizations in Southeast Asia. The adversary group responsible for the campaign, which we named “Lotus Blossom,” is well organized and likely state-sponsored, with support from a country that has interests in Southeast Asia. The campaign has been in operation for some time; we have identified over 50 different attacks taking place over the past three years.

Background and Findings

Unit 42 has linked more than 50 individual attacks across Hong Kong, Taiwan, Vietnam, the Philippines, and Indonesia to the Lotus Blossom group. These attacks share a number of characteristics, including:

  • They are against military and government targets
  • Spearphishing is used as the initial attack vector
  • They use a custom Trojan backdoor named “Elise” to gain a foothold
  • A decoy file appears during initial compromise with Elise, tricking users into thinking they opened a benign file

Attacks by the Lotus Blossom group rely heavily on the use of spearphishing emails that use enticing subject lines and legitimate-looking decoy documents to trick users into opening a malware executable they think is a legitimate document. This document is usually a personnel roster for a specific military or government office.

We believe that the Lotus Blossom group developed the Elise malware specifically to meet the needs of the attack campaigns, and we’ve observed three variants across 50 samples during the three-year period of these attacks. Elise is a relatively sophisticated tool, including variants with the ability to evade detection in virtual environments, connect to command-and-control servers for additional instruction, and exfiltrate data.

Operation Lotus Blossom is a prime example of how a well-resourced adversary will deploy advanced tools, over an extended time period, sometimes years, in order to reach its goals. In this case, the pattern of behavior suggests that the actors behind this group were nation-state sponsored, from a country with an interest in the government and military affairs of Southeast Asian nations.

Unit 42 discovered this attack using the Palo Alto Networks AutoFocus service, which allows analysts to quickly find correlations among malware samples analyzed by WildFire. Palo Alto Networks customers are protected from the malware used in Operation Lotus Blossom via WildFire and our Security Platform’s Threat Prevention capabilities (IPS signature 14358).

We recommend that other security practitioners review the Indicators of Compromise (IoCs) in the full report to ensure they have not been targets in this campaign, and add the appropriate security controls to prevent future attacks.

The full report on Lotus Blossom from Unit 42 can be downloaded here, which includes all IOCs.

Visit Unit 42 for new research and a full list of speaking appearances, as well to subscribe to updates.

[Palo Alto Networks Blog]

English
Exit mobile version