Network Logging and Monitoring
Company networks should be protected against employee accidental or intentional actions, and basic and advanced cyber threats that originate from attackers outside your company. Basic threats utilize known signature-based malware that can be detected and stopped by properly arranged network and endpoint security defenses, including intrusion prevention systems, secure web and email gateways and antivirus platforms. Advanced Persistent Threat (APT) attacks commonly target organizations that handle high-value information or have valuable intellectual property. Advanced threats typically cannot be detected by traditional signature-based defenses. They often employ zero day attacks whereby they target a weakness in software that is unknown to the vendor and exploit it before the vendor becomes aware and develops a patch. Once developed, the patch should be quickly downloaded onto all operating systems, applications and devices that utilize the software.
After a network is breached, malware can be intended to immediately damage or steal information or it can be designed as an APT attack, which is a sophisticated cyber-attack that stays undetected for long periods of time and spreads across the network to steal IT administrator access credentials and gain access to high-value servers and databases containing sensitive data. The attacker will incorporate malware containing a remote administration tool (RAT), which enables the attacker to take control of the compromised system and establish an outbound connection to a command-and-control server operated by the attacker.
Given the range of threats that must be protected against, in addition to properly designing your network to maximize your efforts to block potential threats, it is also equally important to have the capability to be able to quickly uncover, identify and mitigate threats by incorporating network logging and monitoring tools.
Network logging and monitoring of the activities of the network applications and devices helps confirm systems are operating as expected and helps to detect and alert of problems so necessary actions can be taken to correct them. The logs can then be used to provide the detailed information needed to verify, quantify and recover from a security incident. In addition, routine review of logs can also help identify anomalies or trends that were not detected by the scanning devices and discover any security holes opened through your network intentionally by attackers or unintentionally such as disabled or unused suspicious services that may be enabled by mistake.
Network logging and monitoring services
To continuously monitor network security, your system devices should be equipped with logging capabilities. Because understanding and analyzing logs of company network traffic requires a high level of experience and expertise, it is recommended you work with your cyber security providers to develop and implement network logging and monitoring strategies.
Contracts with security providers should define the scope of monitoring and logging services required and scheduled reporting. Best practices include the ability to monitor and log attempts to access your network that have been stopped by your firewalls or intrusion prevention systems and unauthorized or suspicious traffic within your network that have been detected or stopped by your security devices or controls. They should also be required to immediately alert if any breaches are detected.
Response plan
The logs should be reviewed regularly with the provider, Chief Information Security Officer (CISO) and IT security team. To begin, the logs will be used to create a baseline metric of your network and normal network traffic patterns. As additional logs are developed, they can be used to compare any irregularities against the baseline.
When any vulnerability is discovered, it is essential that designated personnel and a process are in place to ensure it is properly tracked and remediated in a timely fashion.
Audit logs
The logs should be stored for a predetermined specified time period in the event a follow-up investigation is required. As an example, a typical firewall log entry should include a date, time stamp, source address, destination address, and other details about a suspicious connection.
Operating systems, network security appliances, and software can generate other unique logging data. Examples of the type of log reports include:
- Unauthorized external users attempting access to your network.
- Unauthorized internal users attempting access to restricted files.
- Logs of malicious connection attempts or virus attacks being detected by your Intrusion Detection Systems (IDS) or rejected by your Intrusion Prevention Systems (IPS).
- Large amounts of information transfers from and within the network, including server to server, server to client, client to server, or network to network.
- Large amounts of information appearing in places where it shouldn’t exist.
- Sensitive information being transferred externally.
- Administrator access or data transfers from unexpected devices, personnel or times of day.
- Files on your network that you did not authorize.
- Logs of packets being rejected by your firewall.
- Attempts to transfer data from your network to blacklisted sites or IP addresses such as, countries you don’t have business relations with or known malicious command and control (CnC) Internet domain sites.
- Information being sent using encryption algorithms and/or digital certificates not commonly used by your company.
- Event log entries showing antivirus and firewall stop and restart commands.
Response plan
When a network security device triggers an alert, it is important to respond quickly to verify the source of the associated attack. After determining the root cause, gauge the material impact of the attack to assign appropriate IT security resources. When the threat has been designated as critical, mitigate it immediately by configuring host and or network security settings to stop the attack and to prevent future attacks. This process may be as simple as patching the target system or shutting down a port on a server. When the attackers’ path has been shut down, the final step is eradicating the threat by determining whether any other hosts have been compromised and to what extent. The attack may have spread laterally. Determine which additional hosts have been compromised and repair and restore them.
Security Information and Event Management (SIEM)
Due to the variety, size and complexity of the logs important to information security, Security Information and Event Management (SIEM) technologies are recommended to efficiently aggregate, maintain and query logs spanning the many network sources. This service can be purchased and/or managed for your company by a security provider.