cais sensor distributed sensors network in brazilian nren
play

CAIS Sensor: Distributed Sensors Network in Brazilian NREN LACSEC - PowerPoint PPT Presentation

CAIS Sensor: Distributed Sensors Network in Brazilian NREN LACSEC LACNIC27 Regarding RNP Brazilian National Research and Education Network (RNP). Created in 1989. Implementing the first Latin American fiber network in 2005.


  1. CAIS Sensor: Distributed Sensors Network in Brazilian NREN LACSEC LACNIC27

  2. Regarding RNP • Brazilian National Research and Education Network (RNP). • Created in 1989. • Implementing the first Latin American fiber network in 2005.

  3. Regarding CAIS • Coordination CSIRT of Brazilian research and education network since 1997. • CAIS works in detection, resolution and prevention of network security incidents. Security Security CSIRT Security Vulnerability Incident Development Awareness Management Handling

  4. Motivations to create a CAIS Sensor network Rede Ipê, Brazilian academic network backbone. Built-in capacity of 347 Gbps Interconnects 1.911 units of RNP's Customers (Universities, Federal Institutes, Research Organizations). Highly diversified environment, regarding networks, technologies and maturity of customers’ security teams. Difficulties for efficient detection. * dados de 2015

  5. CAIS Sensor Requirements

  6. What is the CAIS Sensor?

  7. How does CAIS Sensor analyze traffic?

  8. How does CAIS Sensor work? Master Server Sensor (Suricata) + + Query Engine Engine Engine (Suricata) (Suricata) (Suricata)

  9. What does Master Server do? • Sensor management • Sensor’s system updates Master management • Statistics of malicious activities detected • Information about sensor’s Engines(Suricata) “health” • System general administration

  10. Regarding Engines(Suricata) • Engines(Suricata) Friendly user interface • Plug and play • Less technical knowledge required • Low maintenance and support • Send detections by email • Send statistics and status data • Update requests

  11. The CAIS Sensor(Screenshots) Main menu Quick Information Quick access dashboard tasks

  12. The CAIS Sensor(Screenshots )

  13. Engine(Screenshots) – Installation Menu • Network interface configuration. • Select network pickup interface. • Restart Services. • Use license configuration.

  14. CAIS Sensor Implementation 27 RNP Points of Presence 17 Customers 44 Sensors Installed

  15. Statistics – Average Analyzed Traffic

  16. Statistics Most attacked ports Malicious activity flow 9% 91% Incoming Outgoing

  17. Statistics - Main types of malicious activity detected DDoS Attempts(protocol xdmcp) 702.345 DDoS Attack (protocol NTP) 535.204 Malwares 236.985 DDoS Attack (protocol SNMP) 102.478

  18. Statistics – Types of detected events

  19. Statistics - Botnets XcodeGhost nicaze.net Zeus Kelihos PCRat/Gh0st Bladabindi/njrat Feodo Palevo Beacon DealPly

  20. Next Steps • Optimize reports • Integrate with other sources (URLs blacklist, IPs blacklist, others) • Increase number of sensors in educational institutions and RNP customers • Finalize and expand the partnership model

  21. Questions ?

  22. Thanks! RNP – Brazilian Educational and Research Network CAIS – RNP Incident Security Response Team Rildo Souza Yuri Alexandro Security Analyst Security Analyst rildo.souza@rnp.br yuri.ferreira@rnp.br

Recommend


More recommend