Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

18
JARED BIRD [email protected] TWITTER: @JAREDBIRD Using Nagios as a Security Tool

description

Jared Bird's presentation on using Nagios as a security tool. The presentation was given during the Nagios World Conference North America held Sept 27-29th, 2011 in Saint Paul, MN. For more information on the conference (including photos and videos), visit: http://go.nagios.com/nwcna

Transcript of Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Page 1: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

JARED BIRD

JAREDBIRD@GMAIL .COM

TWITTER: @JAREDBIRD

Using Nagios as a Security Tool

Page 2: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Introduction

� Who is Jared Bird?

Page 3: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Reasons to care

� Prevent data theft

� Deter identity theft

� Avoid legal issues

� Protect brand

Page 4: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Similarities

Page 5: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Headlines

Page 6: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

“It wont happen to us”

� It can happen to anyone (even security vendors)

Page 7: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Uh Oh

� http://www.coresecurity.com – September 22, 2011

Page 8: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

What to protect

� Data

� Hardware

� Intellectual Property

� Brand

Page 9: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Threats

� Default configurations

� Website defacement

� Missing patches

� DNS redirection

� Unused services

� Unauthorized use

� Many, many more

Page 10: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Monitoring

� Automation

� Early detection

� Quick resolution

� Integrity

Page 11: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Default Configurations

� Default passwords

� blank sa account

� Once password is set, monitor with new credentials

� XI Auto-discovery check for insecure protocols

� Scheduled scans and output to Nagios

Page 12: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Web

� Monitor for defacement

� check_http –H www.yoursite.com –s “sekret”

� Checks for “sekret” string

� Check certificate

� check_http –H www.mysite.com –C 21

� Checks certificate for 21 days of validity

� DDOS alerts

Page 13: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Software Installed

� Check url for content (version)

� Ex: http://www.adobe.com/software/flash/about/

� Check for string “10.3.183.10”

� Manually update string

� Better way?

Page 14: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

DNS

� Have DNS entries changed?

� DNS hijacked

� High Impact

Page 15: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Unused Services

� Auto-discovery

� Check for insecure services

� Check for previously disabled services

Page 16: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Unauthorized Use

� LDAP check for account creation

� Syslog output from infrastructure

� Snort alert (snmp)

Page 17: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Other Uses?

� Monitor video cameras

� http://bit.ly/bY2tjd

� Ideas?

Page 18: Nagios Conference 2011 - Jared Bird - Using Nagios As A Security Tool

Questions?

Jared Bird

[email protected]

Twitter: @jaredbird

Thank You