Feeds

A sysadmin always comes prepared: Grasp those essential tools

Help us scope the perfect IT admin's toolkit

Internet Security Threat Report 2014

+Competition We have prizes up for grabs. The first 30 people to sign up for a GFI Cloud free trial and add two or more devices to the console get a limited edition T-shirt from The Register. All signs ups that add two or more devices before this competition ends will be entered into a draw to win a 10-user licence of GFI Cloud’s AntiMalware Pack. Find the full competition T&Cs here.

There are certain tools that all sysadmins need. Some, such as the venerable ping, are so fundamental that their lack would be considered an oddity.

Others, such as backups, should by rights be deployed absolutely everywhere, yet incomprehensibly are not. Debating which tools are best is the blood sport of our industry.

I remember the carefree days before broadband. I built open-air lasers to carry unencrypted traffic at a blistering 9600 bps.

Obscurity really was security. Only a handful of people in my area at the time could recognise what those rigs were designed to do, let alone intercept the communications. The chances were vanishingly small that of any of them would do so for malicious purposes.

Broadband arrived. With it came new threat vectors along with a technology industry exploding in innovation. Some of the biggest names in the industry were caught unawares – Windows XP famously had a firewall that wasn't on by default.

Windows XP's Service Pack 2 changed all this and finally made Microsoft's pivot towards "security first" tangible to the customer. It has done yeoman's work since then, but the industry as a whole cannot say the same.

The companies behind major culprits such as Java, Flash, PDF readers and consumer broadband routers haven't cleaned up their act despite years of continued assault.

In very human fashion, the companies behind the "Internet of Things" machine-to-machine revolution are proving no better. They are repeating the mistakes of their predecessors, offering poor support and units that are vulnerable by default.

The world has changed since my little 9600 bps lasers and threat models have changed with it. Have our sysadmin's toolkits kept up?

Let's take a peek at the major categories and have you, the reader, submit your thoughts on which tools are the best for the job.

Perimeter threat detection

This is about more than just standing up a firewall and hoping nobody crawls through. It is about assuming that someone eventually will and deploying tools to detect this when it happens.

Intrusion detection and prevention systems (IDPS) exist in any number of forms to attempt to detect the untoward activity.

Basic IDPS systems are designed to be deployed to monitor individual services or servers. Fail2Ban is a popular example.

Other IDPS systems are designed to scan active network streams and typically come in the form of application layer gateways (ALGs). Today, these are commodities, easily found as physical or virtual appliances.

Perhaps the most pervasive IDPS technologies deployed today are web filtering and email filtering. These can include everything from ad-blocking and anti-malware to spam filtering or blocking undesirable content.

They can be installed as part of a firewall/ALG appliance but are increasingly deployed on a per-system basis as part of a cloud service that offers rapid-release threat signatures.

Working to block threats at the perimeter is the first, and easiest, step towards a functional modern IT deployment. A large number of things that can go wrong simply don't if the bad guys can't get past the edge defences.

Extant threat detection

No battle plan survives contact with the enemy. No matter how sophisticated and well implemented your perimeter defences, something will inevitably get through.

In addition, you will have to cope with privileged users abusing their privilege, Pointy Haired Boss syndrome and inadequate funding.

Extant threat detection has to include various types of hardware, software and network monitoring. It needs to detect failed equipment, but also unbalanced configurations and runaway resource usage. It needs to be able to find configuration issues ranging from open ports to improper Group Policy Objects.

Event log monitoring is the easiest path forward. Operating systems and applications are usually pretty good about logging when something goes pear-shaped.

ACL auditing needs to be considered. This ranges from file permissions and network ACLs through to application-specific rights allocation. The trick is to have software that can keep an eye on all the logs across all systems and filter signal from noise.

Anti-malware software needs to be centrally managed, with regular updates and proper installation verified.

If something goes wrong admins need to be notified; the first sign of trouble many admins get that a system has been compromised is not detection by the anti-malware application, but rather the unceremonious murder of said application by malware that got in under the radar.

Somewhere in here we need to add USB scanning and efforts to uncover clandestine IT.

In some cases, these items are different tools but they are converging. Even where the individual components of extant threat detection aren't collapsing into a single tool, unified management of the various tools in this category is increasingly pervasive.

Entropy assurance

This is a relatively new category in mass public consciousness, but it is increasingly important.

Entropy assurance tools have one job: to generate high entropy to secure system and service access and manage all of it in a human-compatible fashion.

Here we find tools such as password managers and certificate and key management systems. In today's world of custom silicon, GPGPU computing and massive Amazon cracking setups, entropy assurance apps are no longer optional.

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Docker's app containers are coming to Windows Server, says Microsoft
MS chases app deployment speeds already enjoyed by Linux devs
Intel, Cisco and co reveal PLANS to keep tabs on WORLD'S MACHINES
Connecting everything to everything... Er, good idea?
SDI wars: WTF is software defined infrastructure?
This time we play for ALL the marbles
'Urika': Cray unveils new 1,500-core big data crunching monster
6TB of DRAM, 38TB of SSD flash and 120TB of disk storage
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
Windows 10: Forget Cloudobile, put Security and Privacy First
But - dammit - It would be insane to say 'don't collect, because NSA'
Oracle hires former SAP exec for cloudy push
'We know Larry said cloud was gibberish, and insane, and idiotic, but...'
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.