| By David Strom | Article Rating: |
|
| February 11, 2013 12:12 PM EST | Reads: |
594 |
On the Internet, no one knows you are a dog, but they certainly know your IP address. And there are a growing number of reputation management products that can track your address, interpret what you have been doing with it, and pre-screen your traffic if you are abusive. This is like stopping junk mail when the sender delivers it to the local post office before it enters the mail stream.
These services all operate the same way: the vendors deploy a bunch of sensors either at their customer’s sites or at major Internet peering points where they can examine traffic that is passing by. Each service screens for malware behavior, known virus signatures, and other anomalous actions. They then block all traffic from this IP address.
These services aren’t new, but they are getting more popular as they get more effective. Being proactive can save a lot of time, a lot of bandwidth, and provide a lot of protection before the bad stuff hits your corporate network.
When I was doing some work last month at Cisco with their intrusion prevention products, I saw how just turning on their reputation management tool (called Global Correlation) would stop more traffic than creating any other protection rule. It is a delicate balance. If you don’t have many malware signatures enabled, more traffic will slip through that sensor and will hit the reputation sensors and be blocked there. You have to ensure that both types of sensors work together to provide the best possible network threat protection.
There are several ways to get more familiar with reputation management. The easiest way to see what kind of information is being collected is to go to one of the reputation service management tools online. Cisco has its Senderbase.org, McAfee has its Trustedsource.org, and CommTouch.com has a third service. All are places where you can lookup particular domains and IP addresses and research what kinds of reputations they have and what traffic each vendor has observed coming from these domains. You can watch a screencast video that I did for McAfee from four years ago that shows how to use these services.
That is fine for one-off kinds of queries, but if you want to implement this type of protection on a consistent basis you will have to purchase a network security device. This typically involves using an intrusion prevention or unified threat management product from one of many vendors that build in reputation awareness. Apart from the usual suspects like Cisco, Blue Coat, Websense and others, there are a few other vendors on the landscape worth taking a closer look. These include Network Box, Alien Vault and Norse Corp.
Network Box is a managed UTM box that works with its own collection of malware sensors spread across the Internet and runs more than a dozen different anti-virus scanning engines. One nice feature is the product is geared towards VARs and managed service providers. I did a screencast video review that shows how it works.
Alien Vault ‘s Open Threat Exchange is building an open source intrusion detection system with built-in reputation management. They claim to have more than thirty different products that are part of the collection process.
Norse Corp. has two different products that can be deployed in this arena, IP-Venger and IP-Viking. Both make use of a very wide global sensor network to monitor and block threats. The IP-Venger service is a WordPress plug-in so you can stop malicious traffic and spammers proactively. I had some trouble with its beta version but it looked promising. A screen cap of its console is shown above.
As I said, this isn’t a new area, but one worth exploring if you aren’t familiar.
Read the original blog entry...
Published February 11, 2013 Reads 594
Copyright © 2013 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By David Strom
David Strom is an international authority on network and Internet technologies. He has written extensively on the topic for 20 years for a wide variety of print publications and websites, such as The New York Times, TechTarget.com, PC Week/eWeek, Internet.com, Network World, Infoworld, Computerworld, Small Business Computing, Communications Week, Windows Sources, c|net and news.com, Web Review, Tom's Hardware, EETimes, and many others.
- Cloud People: A Who's Who of Cloud Computing
- Windows Azure IaaS Reaches General Availability
- New Relic Q1 2013 Blazes Past Growth Targets and Reaches 40,000 Active Customer Accounts
- Portable Experimenter’s Platform, Powered by Raspberry Pi
- CollabNet And UC4 Announce General Availability Of Joint Enterprise DevOps Platform
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- AMAX Launches StorMax(TM) CFS, powered by IBM(R) General Parallel File System(TM) (GPFS(TM))
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- The Software Freedom Conservancy – Fundraising Campaign: Non-Profit Accounting Software
- Project Floodlight Grows to the World’s Largest SDN Ecosystem; Global Users, Contributors and Partners Innovating Using Open Source SDN
- New Relic Named Best Place to Work in the Bay Area for Second Year in a Row
- Mobility News Weekly – Week of March 17, 2013
- Cloud People: A Who's Who of Cloud Computing
- Windows Azure IaaS Reaches General Availability
- New Relic Q1 2013 Blazes Past Growth Targets and Reaches 40,000 Active Customer Accounts
- Portable Experimenter’s Platform, Powered by Raspberry Pi
- SUSE Receives Common Criteria Security Certifications
- Basho Announces Open Source Riak CS and General Availability of Riak CS Enterprise v1.3
- Granular Enforcement of Access to File Systems Featured in Latest Release of FoxT ServerControl
- CollabNet And UC4 Announce General Availability Of Joint Enterprise DevOps Platform
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- AMAX Launches StorMax(TM) CFS, powered by IBM(R) General Parallel File System(TM) (GPFS(TM))
- MicroStrategy Announces General Availability of MicroStrategy 9.3.1
- The Software Freedom Conservancy – Fundraising Campaign: Non-Profit Accounting Software
- Cloud People: A Who's Who of Cloud Computing
- Red Hat Named "Platinum Sponsor" of Virtualization Conference & Expo
- An Introduction to Ant
- Cloud Expo 2011 East To Attract 10,000 Delegates and 200 Exhibitors
- Google Web Toolkit: Finally Java Has Been Put into JavaScript!
- Cloud Expo, Inc. Announces Cloud Expo 2011 New York Venue
- AJAX World RIA Conference News - AJAX & RIA with Server-Side JavaScript
- Early Notes on GoogleApps
- President & CTO of 3tera Speaking Next Week at SYS-CON's Cloud Computing Expo November 19-21 in Silicon Valley
- Rating JRuby, Jython, and Groovy on the Java Platform
- Python Creator Guido van Rossum to Present the Next-Generation Python 3000
- Rackspace Cloud APIs Open Sourced


























