120
Benny Czarny President and CEO | OPSWAT, Inc.

What is NAC

Embed Size (px)

Citation preview

Page 1: What is NAC

Benny Czarny

President and CEO | OPSWAT, Inc.

Page 2: What is NAC

What is NAC?

Benny Czarny Benjamin Czarny

Page 6: What is NAC

Endpoints

Page 7: What is NAC

Control Endpoint Security

Health State

Page 8: What is NAC

Common NAC Use-Cases

Page 10: What is NAC

Create Business Segmentation

Page 12: What is NAC

Prevent Network Worms

Page 14: What is NAC

W32.Blaster.Worm WormExploits of DCOM RPC

vulnerability, no user interaction was required to spread.

DOS attack to Windowsupdate download site

Page 15: What is NAC

Control

Remote Access Users

Page 17: What is NAC

Health Insurance Portability and

Accountability Act (HIPAA)

Page 18: What is NAC

Protect Management's Ass

Page 19: What is NAC

Gartner estimates that this

market grew 87% from 2006 to a

total of $225 million in 2007.

Gartner anticipates approximately

100% growth in 2008 (3/08)

Page 20: What is NAC

$3.2 billion in 2010, up

from just $526 million in

2005

- IDC report (6/07)

Page 21: What is NAC

Source: 2006 Infonetics Research, Enforcing Network Access Control:

Market Outlook and Worldwide Forecast

Page 23: What is NAC

Common NAC Framework

Architectures

Page 25: What is NAC

Could be delivered as Software

Page 26: What is NAC

or Hardware

Page 27: What is NAC

NAC Concepts

Page 29: What is NAC

Common Network Detection

and Quarantine Technologies:

• ARP

• 802.X

• DHCP proxy

• Special Hardware

• SNMP

• Virtual Networks

• Frameworks (NAP,TNC)

Page 31: What is NAC

Check Endpoint Health

Page 32: What is NAC

Common Health Check Verticals

Page 33: What is NAC

• Many security applications

• Several operating systems

• Security applications keep changing

• Security application keep evolving

Health Agent

Technology Challenges

Page 35: What is NAC

Common Anti-malware control

• Features Activity

• Product and Signature Currency

• Threat history

• Authenticity checks

Page 38: What is NAC

Pre-Admission

Page 39: What is NAC

Post-Admission

Page 41: What is NAC

Common Remediation Actions

• Trigger AV real time protection

• Update AV

• Perform full system scan

• Patch endpoint

• Turn on firewall

• Block firewall port

Page 42: What is NAC

Source: 2007 BT INS IT Industry Survey

Page 43: What is NAC

Health Agent Technology

Page 44: What is NAC

via Network Monitoring

Page 45: What is NAC

<Server Name="etrustdownloads.ca.com" Port="80" Protocol="TCP">

<Http Secure="0">

<Request Type="GET">

<Path>/updates/eav/arclib/arclib.idx</Path>

<Path>/updates/eav/base/etrust_antivirus_base.idx</Path>

<Path>/updates/eav/drvupdi/drvupdi.idx</Path>

<Path>/updates/igateway/igateway.idx</Path>

<Path>/updates/eav/inoeng/ino_engine.idx</Path>

<Path>/updates/eav/eavlocgui/eavlocgui.idx</Path>

<Path>/updates/caupdate/caupdate.idx</Path>

<Path>/updates/eav/veteng/vet_engine.idx</Path>

<UserAgent Random="0">CAUpdate</UserAgent>

</Request>

</Http>

</Server>

</QueryInfo>

<UpdateProg>

<!-- updating -->

<Server Name="etrustdownloads.ca.com" Port="80" Protocol="TCP">

<Http Secure="0">

<Request Type="GET">

<Path>

/updates/eav/

<Format>STRING</Format>

.pkg

</Path>

<!--ie. GET /updates/eav/veteng/vet_incr_3492.pkg HTTP/1.0

<UserAgent Random="0">CAUpdate</UserAgent>

</Request>

<Response Encrypted="1">

<HttpVersion>1.0</HttpVersion>

<StatusCode>200 OK</StatusCode>

<ContentType>text/plain</ContentType>

</Response>

</Http>

</Server>

</UpdateProg>

Monitor Antimalware Update network signature

Page 46: What is NAC

Via Code Running on Endpoint

Page 47: What is NAC

• Browser plug-in

• Executable (process)

• Application

• Windows Service/Linux demon

• RPC Calls

Common Health Agent Technologies

Page 48: What is NAC

Health Agent Pre Admission

Post Admission

Post Admission afterreboot

Worksas Guest

Update Process

Browser Plug-in√ × × √

Executable√ √ × √

Application √ √ √ ×

Daemon√ √ √ ×

RPC√ √ √ ×

Page 49: What is NAC

Why should

Anti-malware companies

Partner with NAC?

Page 50: What is NAC

Interoperability = more BU$INESS

Page 52: What is NAC

Competitive Defense

Page 56: What is NAC

NAC Agent does not detect

Antimalware application

Page 57: What is NAC

User is directed to

Remediation Screen

Page 59: What is NAC

NAC Vendors

Page 60: What is NAC

Branding

Page 66: What is NAC

Be there or be

Page 68: What is NAC

Real Antivirus I look like an Antivirus

Page 69: What is NAC

Spoof Antimalware

digital Identity

Page 70: What is NAC

Spoof Binary Identity

Page 74: What is NAC

1. Endpoint connects to the network

2. NAP Client collects endpoint health state.

3. Endpoint health state is communicated to NPS

4. Security policy decision is passed to network infrastructure

5. Endpoint is grant/denied/quarantined access to the network

Page 75: What is NAC

Partner with Microsoft

Page 77: What is NAC

Develop SHA

Page 78: What is NAC

Develop SHV

Page 80: What is NAC

Market

Page 87: What is NAC

1. Endpoint connects to the network

2. TNC client collects endpoint health state.

3. Endpoint health state is communicated to TNC Server

4. Security policy decision is passed to network infrastructure

5. Endpoint is grant/denied/quarantined access to the network

Page 91: What is NAC

Market

Page 96: What is NAC

Slow adoption.

Page 97: What is NAC

Development Costs $

Page 98: What is NAC

Cisco NAC and

Other Frameworks

Page 99: What is NAC

1. Host assessment via OESIS Framework

2. Host info sent to Policy Server

3. Policy Server validates policy against application management server settings

4. Results are communicated to the network device infrastructure

5. Endpoint is grant/denied/quarantined access to the network

Page 100: What is NAC

Submit applications to

OESISOK™

Page 101: What is NAC

Upload Anti-malware Packages

Page 103: What is NAC

Get listed in the support charts

Page 108: What is NAC

$0 Development Cost

Page 109: What is NAC

“Cisco’s NAC Appliance holds a commanding

47% market share in the cluttered NAC”

- Network world

Page 111: What is NAC

only.

Page 113: What is NAC

Other OESISOK™ based

NAC Frameworks

Page 115: What is NAC

Other Options

Page 117: What is NAC

Future Development

Page 118: What is NAC

Enforcing Network Access by

Quality of Anti-malware applications

Page 120: What is NAC

Questions ?

Benny Czarny

CEO and Founder OPSWAT, Inc.