GCN Home > 09/24/07 issue
A knack for network security
The emerging technique of network access control offers a way to secure networks with precision
By David Cassel, Special to GCN
Story Tools:
When Glenn Haar, an information technology resource manager at the Idaho Tax Commission, started in the computer business, the job was all about the mainframes a fairly easy job compared with todays duties. You used to have one person who took care of this system which hardly ever changed, he said from his office in Boise.

These days, however, the same job requires looking after more than 60 servers, which are constantly [failing] and needing maintenance, he said. That turned everybody into mechanics and turned them away from being oriented towards service for the user.

We realized we had to move people out of constantly having to fix things, he added.

Any new approach that would help him better manage all those resources would be of value. So for the task of securing the network, Haar and his team looked into an emerging technique called network access control.

Wed dabbled in intrusion protection before, Haar said, but everything we were doing, we were adding on. You reach a point where you realize you need to look at the big picture.

NAC can help IT shops address security from such an elevated stance.

NAC defined
In the broadest sense, NAC is simply a way of controlling access to the network based on security policies. When a new device tries to log on to a network, it is, in effect, interrogated. The machine must have the latest patches installed, and its antivirus software must be up-to-date. Network administrators can also add their own conditions for entering the network. Only those machines that meet all the qualifications are allowed on the network.

Such control can be administered from several different places. For instance, agent software on the networks endpoint devices can perform a self-check connecting to a network. NAC can also be administered from the network equipment itself by a server or even the networks routers and switches.

Its an interesting time for it because there are so many approaches and a lot of big vendors are putting out some interesting approaches, said Phil Hochmuth, a senior research analyst at the Yankee Group. NAC products seem to come from one of three types of vendors those offering operating systems, those that offer network hardware and those that offer security products.

Which one will dominate? I think its up in the air, Hochmuth said. NAC is still an emerging field, and with so many competing choices, network administrators will define NAC based on their individual needs and on which vendor they talk to first.

For Microsoft shops, the first stop may be the Redmond giant itself. When Microsoft finally ships Windows Server 2008, it will include the companys Network Access Protocol (NAP) for checking and enforcing access policies for devices connecting to the network. Microsoft describes NAP as a lightweight version of NAC, though one that could meet the basic requirements of many environments.

Gaining momentum
Unfortunately, Microsoft isnt expected to ship until February 2008 and the shipping delays are slowing down NAC adoption, said Lawrence Orans, a research analyst at Gartner. But theres good news, too. In a surprising move in May, Microsoft pledged that its NAP would become interoperable with the architecture of the Trusted Computing Group, an industry standards group whose members include Intel, IBM and Sun Microsystems. Microsofts NAP will use a new protocol that should make it interoperable with other vendors offerings in this space.
Microsoft technologists are pretty quick to admit that IT shops that need more robust NAC capabilities should look elsewhere. One obvious company to look to is Cisco, one of the largest vendors of network equipment.

Ciscos going to go after solving the NAC problem based on the network, said David Graziano, Ciscos manager of federal security. Thats our biggest strength.
Cisco offers its own network appliance for NAC. When you connect with your [virtual private network], it links to the NAC appliance, which will actually scan your device, Graziano said. It performs a posture check on the endpoint device, using Ciscos agent software installed on the laptop.

One of Ciscos biggest strengths is the way it handles guest computers, Graziano said. The appliance can check whether the user is working on the government-furnished equipment provided for the job and, if not, route guests and other unmanaged users onto a guest virtual local-area network. There, the device is checked against the Windows Service Update Service. If it isnt fully patched, well put a splash screen up that said youre out of policy, and we need you to do these things, Graziano said.

The screen provides remediation instructions the latest release number for their antivirus software or patches that are missing with pointers for download locations. You dont have to call a help desk, Graziano said. The instructions can even offer a choice of how to perform the remediation, for those who prefer using McAfees Hercules software over the Windows Update server.
Ciscos appliance also offers role control limiting users to the parts of the network appropriate for their position and it has the ability to check for a smart card when authenticating.

The company also is working on a plug-in that can verify whether users have taken compliance testing or indicated their agreement to specific policies. And this feature may come in handy for one hurdle all government agencies must cross passing the yearly Federal Information Security Management Act audit. Ive heard a FISMA auditor will walk into a conference room and plug in a laptop. If they can access your network, youll get a lower score, Graziano said. A fully deployed NAC implementation with compliance checks built in would go a long way toward passing that audit.

Cisco has almost 80 percent of the LAN switch market, Hochmuth said. If youre looking to take an infrastructure approach to NAC, it would be tough to not look at that.

Field agents
Although controlling NAC from network devices makes sense, placing agents that can allow or deny access on the machines logging in can be powerful, too, Hochmuth said.

To this end, Symantec will introduce its NAC agent in the September release of its antivirus software, to be called Symantec Endpoint Protection.

Rich Langston, a Symantec NAC product manager, said a very large number of people in the world who run Symantec antivirus software can get started with that easy-to-deploy solution without deploying any additional hardware.

The agent approach keeps NAC simple. You dont have to upgrade your network to get a lot of new features, Langston said. Benefits can be obtained just with this software on the guys computer. Rather than worry about having the network quarantine the user, the endpoint can quarantine using the agent itself. All you have to do is turn on this feature and make the rules.

Bundling the agent is just a sign of the times, Hochmuth said. Theres a movement to make NAC more of a standard checkbox item.
Thats what Symantecs doing. Langston hopes the companys move will encourage a wider adoption of network access controls. Because of the fact that its built in, itll be easier for people to decide to deploy it. I really expect this to provide the tipping point for NAC.

Before connecting to the network, Symantecs NAC agent checks the device for up-to-date patches and antivirus software, and it can also be easily customized to carry out additional tasks.

One of the things thats unique to our offering is the ability for the end-user administrator to make up any kind of rule he wants, Langston said. Lets say you have an application that runs on all your desktops, and theres a known security vulnerability. You can make sure everybody upgrades to the next version.

Noncompliance activates a firewall built into the agent, allowing the user to perform remediation while blocking communication with others on the network. The agent can even be used for device verification. Sometimes users will put watermarks on the computer that they can then look at and deduce that the system was installed by the IT department, he said.

But what if a connecting device doesnt have the agent deployed? Like the other solutions, Symantecs NAC agent can handle unmanaged users. Wed rather use an agent, Langston said. For your guests and anything else that can accept an on-demand agent, it comes down from a Web page. Its Java-based you say run, and we do an assessment. Or we can scan the device from the outside and determine if its a fax machine and let it on.

The agent is just one of Symantecs NAC solutions, which also include a gateway and different mechanisms on the LAN. Symantec can use an 802.11x protocol to create an authentication infrastructure on your Ethernet switch or wireless access point. When you plug into that Ethernet jack, that switch will ask your PC questions and will verify your answers with an authorization server, Langston said.

The gateway solution allows network administrators to examine files and registry settings to check a devices compliance. We have a GUI that you use to create these rules, Langston said. Its sort of like writing a script. You set up a rule that said IF and you say what and then THEN [take this action]. Some customers run a Visual Basic script that scans configuration files and performs any needed remediation. Its just as common for users to use these tools to check for the presence of software thats not supposed to be running.

Out-of-band
Mirage Networks illustrates yet another approach to NAC the out-of-band deployment. We plug into a port on the switch, and we watch, said Greg Stock, the companys president and chief executive officer. Because its out-of-network, its also switch agnostic, said Chief Technology Officer Grant Hartline.

This approach has an additional benefit. Such a software solution doesnt just scan for previously identified threats; it also monitors the network for suspicious behavior. We think its the only way to stop a threat, Hartline said. Malware can be quickly identified just by watching for tell-tale activities such as rapid propagation, bad packets and spoofing. We catch 99 percent of the rapidly propagating threats before they ever infect a device, Stock said, because they tried to infect an unused IP address. We dont just monitor the used devices, we monitor every IP address.

Addressing malicious software is important, Orans said. A lot of the NAC solutions and projects we hear about are people simply checking the configuration of the PC does it have the latest patches and antivirus signatures? Organizations will spend a lot of money on NAC and if theyre not looking for malware on the PC, you can still have some kind of zero-day attack and have problems on your network.

Gartner has been advising network administrators to check connecting devices for a recent scan by antivirus software or Microsofts Malicious Software Removal tool. They should also look at the programs installed in the registry and the running processes and be sure to monitor network traffic.

AT&T is selling a managed service to many government customers using Mirage Networks technology, Hartline said, and their solution can also integrate its alerts into the console of IBMs ISS Proventia Management SiteProtector.

In short, there are a lot of vendors selling a lot of different kinds of network access control, Orans said, so it requires a clear set of requirements. Dont approach NAC first by googling NAC and picking a list of vendors. You want to decide what you need first.

Hochmuth agreed that the choices can be bewildering. The biggest issue IT people are having with NAC is just defining what it is what you can get out of it and what can it do for you. Theres no real standard way to do it.

Common sense in Boise
When it came time to find a NAC solution that would cover five branch offices, Haar faced down the NAC choices with some experience. He looked for ease of management as one of the chief requirements.

I dont know about other places, but Im not getting more human resources, he said. I knew there was going to be administrative overhead, but I wanted it to be as small as possible so we could focus on protecting the customers data.
This requirement helped eliminate at least one vendor, one that ultimately proposed a dual solution that involved one setup for the agencys main office and one for its five branches.

Wed have to maintain two solutions, Haar said, and develop the technical understanding of how to maintain two solutions. Im sitting there going, Good luck with that. That just increases our care-and-feeding requirement and doubles our knowledge requirement.

The IT department spread out the selection process over three months to get a proper overview of the choices. Eventually, the agency settled on McAfees Network Access Control software, due in no small part to the management console.

Its extremely critical that youre not going to spend the rest of your life trying to manage this thing, Haar said. The McAfee console offered links for more information about new vulnerabilities and patches, including information from the Common Vulnerabilities and Exposures Web site.

It gives you the connective tissue, he said. It gave you the workbook you needed to actually solve the problem. If youve done this long enough, you realize you have to understand whats going on underneath.

To test the software, Haar created a small-scale pilot program involving the 30 people in the IT group, the people we knew we could bother, he said. They found the early glitches. My system would get a message saying I was a rogue system, Haar said. After some corrective configuration, though, the software looked to be up to the job, and after the 2007 tax season had passed, the agency deployed it to production use.

As Idaho has learned, NAC can be installed relatively painlessly with careful planning. The trick is to define a reasonable scope, Graziano said. Ive seen rollouts where the scope is so large that they never even get [the system] implemented. Theyre trying to solve too many problems at the same time.
So with NAC, its best to take on a little bit of the network at a time. But when youre done, you can have your entire network locked down. Not a bad deal.

More news on related topics: Communications / Networks, IT Security, Enterprise Architecture