Controlling and Managing Security with Performance Tools

Similar documents
Auditing File and Folder Access

Becoming Proactive in Application Management and Monitoring

Protecting Data with a Unified Platform

Managing for the Long Term: Keys to Securing, Troubleshooting and Monitoring a Private Cloud

Mitigating Risks and Monitoring Activity for Database Security

Steps to Migrating to a Private Cloud

Protecting Data with a Unified Platform

Virtual Machine Environments: Data Protection and Recovery Solutions

Tips and Best Practices for Managing a Private Cloud

Data Protection in a Virtualized Environment

Maximizing Your Desktop and Application Virtualization Implementation

How Configuration Management Tools Address the Challenges of Configuration Management

Best Practices for Log File Management (Compliance, Security, Troubleshooting)

Why Endpoint Encryption Can Fail to Deliver

Streamlining Web and Security

Realizing the IT Management Value of Infrastructure Management

Developing a Backup Strategy for Hybrid Physical and Virtual Infrastructures

Real World Considerations for Implementing Desktop Virtualization

Account Access Management - A Primer

The Essentials Series: Enterprise Identity and Access Management. Authorization. sponsored by. by Richard Siddaway

The Next-Generation Virtual Data Center

Understanding & Improving Hypervisor Security

How to Install SSL Certificates on Microsoft Servers

The Essentials Series: Enterprise Identity and Access Management. Authentication. sponsored by. by Richard Siddaway

Eradicating PST Files from Your Network

Using Web Security Services to Protect Portable Devices

Beyond the Hype: Advanced Persistent Threats

Quickly Recovering Deleted Active Directory Objects

What Are Certificates?

The Business Case for Security Information Management

Active Directory 2008 Operations

Maximizing Your Desktop and Application Virtualization Implementation

Collaborative and Agile Project Management

Maximizing Your Desktop and Application Virtualization Implementation

How to Use SNMP in Network Problem Resolution

The Definitive Guide. Active Directory Troubleshooting, Auditing, and Best Practices Edition Don Jones

How the Software-Defined Data Center Is Transforming End User Computing

Tips and Tricks Guide tm. Windows Administration. Don Jones and Dan Sullivan

Managing Your Virtualized Environment: Migration Tools, Backup and Disaster Recovery

The Definitive Guide. Monitoring the Data Center, Virtual Environments, and the Cloud. Don Jones

The Art of High Availability

Desktop Authority vs. Group Policy Preferences

The Definitive Guide. Monitoring the Data Center, Virtual Environments, and the Cloud. Don Jones

The Evolving Threat Landscape and New Best Practices for SSL

Isolating Network vs. Application Problems

Dell InTrust Preparing for Auditing and Monitoring Microsoft IIS

The Definitive Guide. Active Directory Troubleshooting, Auditing, and Best Practices Edition Don Jones

How to Install SSL Certificates on Microsoft Servers

10 Must-Have Features for Every Virtualization Backup and Disaster Recovery Solution

Spotlight Management Pack for SCOM

Organized, Hybridized Network Monitoring

The Shortcut Guide to Balancing Storage Costs and Performance with Hybrid Storage

Dell Spotlight on Active Directory Server Health Wizard Configuration Guide

How to Install SSL Certificates on Microsoft Servers

Go beyond basic up/down monitoring

Malware, Phishing, and Cybercrime Dangerous Threats Facing the SMB State of Cybercrime

Dell Spotlight on Active Directory Deployment Guide

Top 10 Most Popular Reports in Enterprise Reporter

The Shortcut Guide To

Dell NetVault Backup Plug-in for SharePoint 1.3. User s Guide

Logging and Alerting for the Cloud

Transcription:

Security Management Tactics for the Network Administrator The Essentials Series Controlling and Managing Security with Performance Tools sponsored by

Co ntrolling and Managing Security with Performance Tools... 1 Why Performance Tools?... 1 How Do I Configure Security with These Tools?... 3 How Do I Audit With These Tools?... 4 Summary... 5 i

Copyright Statement 2010 Realtime Publishers. All rights reserved. This site contains materials that have been created, developed, or commissioned by, and published with the permission of, Realtime Publishers (the Materials ) and this site and any such Materials are protected by international copyright and trademark laws. THE MATERIALS ARE PROVIDED AS IS WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT. The Materials are subject to change without notice and do not represent a commitment on the part of Realtime Publishers its web site sponsors. In no event shall Realtime Publishers or its web site sponsors be held liable for technical or editorial errors or omissions contained in the Materials, including without limitation, for any direct, indirect, incidental, special, exemplary or consequential damages whatsoever resulting from the use of any information contained in the Materials. The Materials (including but not limited to the text, images, audio, and/or video) may not be copied, reproduced, republished, uploaded, posted, transmitted, or distributed in any way, in whole or in part, except that one copy may be downloaded for your personal, noncommercial use on a single computer. In connection with such use, you may not modify or obscure any copyright or other proprietary notice. The Materials may contain trademarks, services marks and logos that are the property of third parties. You are not permitted to use these trademarks, services marks or logos without prior written consent of such third parties. Realtime Publishers and the Realtime Publishers logo are registered in the US Patent & Trademark Office. All other product or service names are the property of their respective owners. If you have any questions about these terms, or if you would like information about licensing materials from Realtime Publishers, please contact us via e-mail at info@realtimepublishers.com. ii

Controlling and Managing Security with Performance Tools There are as many facets of computer security as there are attackers trying to get through your firewall today. And that s a lot. Each system that you re responsible for needs to be protected individually and as part of the whole. For example, to comply with many government and industry regulations, you can t just lock down the network perimeter or the desktop computer. Holistic systems to implement, manage, and monitor the system security and configuration must be put in place and then regularly audited with the collection, storage, and analysis of system logs. Records must also be kept and regularly reviewed that track changes to systems to ensure continuous compliance with corporate and industry policy. In the previous article, you read about using network inventories and maps to identify the resources on your network. That article also called out a technique for gathering the necessary data using an existing performance management infrastructure. In this article, I ll show you how to extend that technique beyond enumeration into the realm of systems management. You ll see why this is a valuable approach to consider, especially in smaller businesses and companies whose IT budgets are tightening daily. Why Performance Tools? It doesn t seem intuitive, at first glance, to consider performance management tools as useful for security management tasks. After all, performance management is all about measuring memory use and CPU cycles, restricting disk use, starting and stopping virtual machines, and so forth. That s the common perception. In fact, many administrators knowledge of performance management is limited to the built in Windows Task Manager (see Figure 1) or the free Process Monitor tool from Microsoft. But these are not true performance management solutions. 1

Figure 1: Task Manager is not a performance management solution. The reality is that performance management solutions are software suites that are deeply integrated within an entire infrastructure. These solutions tie in to core pieces of every system and component. The tight integration enables rich data reporting from across a workgroup, a data center, or a worldwide enterprise. And most performance management solutions have reporting tools that can give both instant summaries and detailed reports of what s happening on all systems. You can probably already surmise that, when the solution is configured to retrieve security data as well as performance data, the solution s functionality is extended to become a great security dashboard and reporting tool. That s the case with most performance suites today. Many IT professionals want centralized security analysis and reporting across an enterprise, so most software vendors in this space have enabled their systems to provide this feature either through simple customization or right out of the box. 2

How Do I Configure Security with These Tools? The feature that enables these solutions to work for security may already be obvious to you. The tools that you use for performance management don t just report on performance. They enable you to control it. Most performance management solutions have technology that enables, for example, restriction of virtual machine memory use per virtual machine. As an administrator, you first define the memory utilization parameters for a group of systems. Then the performance management tools configure the target systems to conform to your definition. The performance management system then verifies that the parameters have been applied, and reports success back to the reporting console. Finally, the settings are monitored over time to ensure compliance. When a situation occurs where the settings are not applied or adhered to, or a defined threshold is reached, the system takes action often in the form of an administrative alert. Alerts, monitoring, configuration management this sounds very much like a security management solution. So why can t we use this same technique to configure security settings? Well, we can! As I mentioned earlier, most performance management tools are already being extended to configure any part of a network operating systems (OSs), routers, switches, and so on. For example, one common tool in the industry is largely billed as an enterprise wide performance monitoring and management suite. Its marketing material mostly illustrates examples with virtual machine, OS, and switch management, with various plug in modules to extend functionality. But a brief look at the interface shows that the solution is much more of a generic configuration framework for configuring and monitoring heterogeneous systems. This same solution allows you to load configurations, execute custom scripts, and even back up, restore, apply, report on, and enforce configuration sets. On top of all that, the suite still does a great job of performance management (even providing a Web based version of the Task Manager that Figure 1 shows). This is exactly what you want in a security solution. The one facet that makes these solutions work is that most technology today can be managed through automated processes and controls. This automation spans the range of devices, OSs, applications, and even data. Virtually anything within the IT domain is subject to some level of automated management. And because a great deal of the management interfaces and techniques are almost identical, the tools allow some overlap and extension. Let s consider a very common example: disabling automatic logon for Windows computers. Most organizations have a standard for servers that disables automation logon to ensure that only administrators log on to the system. The user centric control for this setting is within Control Panel. But all this control does is change a registry value: Location: \HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name: AutoAdminLogon Value: 0=disable, 1=enable 3

This type of configuration change and enforcement is what performance management tools already do. They can usually be configured to set registry values like this and monitor for unauthorized changes. That last point is actually a big differentiator. There are a number of solutions in the IT space that enable server configuration automation. But many of them have limited reporting and monitoring capabilities. Although these configuration monitoring techniques may not be central to performance management (performance monitoring is far more important than configuration monitoring in that space), security management absolutely relies on auditing including configuration monitoring, reporting, and change control alerting. How Do I Audit With These Tools? Audit reports are critical to any organization impacted by government or industry compliance regulations. Most likely, your industry is impacted by one or more regulations, no matter where you work. And in the regulatory compliance space, proving consistent compliance with policy is often more important to an auditor than the policy itself. This is where performance management tools really shine. They are spectacular at monitoring system configuration over time and providing reports of virtually any detail level. This is a result of the deep integration mentioned earlier, and the flexible reporting framework that the tools provide. Auditing Without Configuration Management You should remember that using a performance management solution for system auditing can be done without using the same system for configuration. So if you use, for example, Group Policy to configure your Windows systems, you can still use these tools to audit that configuration. It is often easier to use the same tool for both tasks, but you re not restricted to that approach. There are typically two ways to audit security with performance management tools. The preferred method is to use built in security analysis functionality or a vendor supplied addon to report on security compliance. Many vendors supply a combination of customizable configurations and audit reports that validate the settings you choose. These can be changed to suit your specific security requirements and then deployed simply and reliably. The other method is to use custom scripts to apply and validate configurations. These scripts are often written in configuration oriented languages such as PowerShell. Many can be found on the Internet as samples or nearly complete examples. If your performance management solution doesn t have security management available as a vendor supplied option, you can almost certainly extend it to this task with custom scripting that applies and verifies the security configuration. 4

Summary Performance management and monitoring tools are amazingly flexible pieces of engineering. They perform their intended tasks very well, usually with little overhead and simplified administration. These powerful tools can also be repurposed to apply and report on security configurations. And using an existing technology in a new way like this can help many organizations get more bang for their existing IT buck. When you consider your IT security needs, remember that auditing is a key requirement for most organizations. If your performance management solution can be extended to report on, and enforce, audit requirements, your annual audit process will be far less painful. 5