SECURITY MANAGEMENT PLATFORMS FOR ASSESSING THREATS TO AN INTERNAL NETWORK
Introduced here are threat detection systems configured to assess security threats to an internal network, which may be associated with an organization. A threat detection system can include one or more scanning mechanisms and a security management platform. The scanning mechanism(s) can probe at least one Internet Protocol (IP) address by transmitting a query designed to elicit a response, and then create probe data from any responses received from the at least one IP address. The security management platform, meanwhile, can acquire local netflow representative of traffic that crossed a perimeter of an internal network, examine the local network to detect public communication activities, and evaluate a risk posed by the public communication activities based on the local network and the probe data.
1 . A system for assessing security threats to an internal network associated with an organization, the system comprising:
one or more scanning mechanisms deployed on a first network,
wherein each scanning mechanism is configured to
probe at least one Internet Protocol (IP) address by transmitting a query designed to elicit a response, and
create probe data from any responses received from the at least one IP address; and
a security management platform configured to
acquire local netflow that includes all traffic that crossed a perimeter of a second network during a certain time interval,
examine the local netflow to detect public communication activities, each public communication activity involving an internal IP address that resides on the second network and an external IP address that does not reside on the second network, and
evaluate a risk posed by the public communication activities based on the local netflow and the probe data.
2 . The system of claim 1 , wherein the first network and the second network are different networks.
3 . The system of claim 1 , wherein the first network is the Internet, and wherein the second network is the internal network associated with the organization.
4 . The system of claim 1 , wherein each scanning mechanism is further configured to:
examine traffic originating from, or directed to, each external IP address involved in a public communication activity to determine which services are running each external IP address.
5 . The system of claim 4 , wherein said examining includes analyzing content of a header of a data packet included in the traffic.
6 . The system of claim 4 , further comprising:
a honeypot server configured to isolate an attempt to gain unauthorized access to a cyber asset residing on the second network; and
a firewall deployed along the perimeter of the second network,
wherein the firewall is configured to
receive a communication from a particular external IP address,
determine that the communication represents an incoming scanning attack, and
prevent a breach of the second network by deflecting the communication to the honeypot server.
7 . The system of claim 6 , wherein the security management platform is further configured to:
acquire global netflow that includes all traffic having a certain characteristic that traversed the first network during the certain time interval,
filter the global netflow to obtain traffic involving one or more IP addresses associated with the honeypot server, and
determine that the traffic includes an attempted scan by a bot.
8 . The system of claim 7 , wherein the security management platform is further configured to:
examine the attempted scan to identify a characteristic of the bot, and identify all internal IP addresses presently involved in communicating with the bot.
9 . The system of claim 7 , wherein the security management platform is further configured:
examine the attempted scan to identify a characteristic of the bot, and
identify a public communication activity involving the bot and a command-and-control center based on the characteristic.
10 . A computer-implemented method for estimating risk posed by a public communication activity involving an internal Internet Protocol (IP) address that resides on an internal network and an external IP address that does not reside on the internal network, the method comprising:
acquiring, by a security management platform, probe data from one or more scanning mechanisms deployed on the Internet,
wherein each scanning mechanism is configured to probe at least one Internet Protocol (IP) address by transmitting a query designed to elicit a response from a certain service, and
wherein the probe data includes a first response provided by the internal IP address and a second response provided by the external IP address;
evaluating, by the security management platform, a risk posed by the public communication activity based on the probe data;
determining, by the security management platform, that the risk exceeds a certain threshold; and
transmitting, by the security management platform, an instruction to a firewall deployed on a perimeter of the internal network,
wherein the instruction instructs the firewall to prevent a future breach of the internal network by deflecting an incoming communication from the external IP address to a honeypot server.
11 . The computer-implemented method of claim 10 , further comprising:
acquiring, by the security management platform, local netflow that includes all traffic that crossed the perimeter of the internal network during a certain time interval.
12 . The computer-implemented method of claim 11 , further comprising:
examining, by the security management platform, the local netflow to identify all public communication activities involving the external IP address.
13 . The computer-implemented method of claim 11 , wherein said acquiring comprises:
acquiring, by the security management platform, global netflow that includes all traffic having a certain characteristic that traversed the Internet during the certain time interval; and
filtering the global netflow to obtain the local netflow.
14 . The computer-implemented method of claim 10 , wherein the security management platform resides on a computer server that is communicatively coupled to the internal network.
15 . A system comprising:
one or more scanning mechanisms deployed on the Internet,
wherein each scanning mechanism is configured to
probe at least one Internet Protocol (IP) address by transmitting a query designed to elicit a response, and
create probe data from any responses received from the at least one IP address; and
a security management platform configured to
acquire local netflow that includes all traffic that crossed a perimeter of an internal network during a certain time interval,
examine the local netflow to detect a public communication activity involving an internal IP address that resides on the internal network and an external IP address that does not reside on the internal network,
determine that a risk posed by the public communication activity exceeds a certain threshold, and
notify a firewall deployed along a perimeter of the internal network that future communications received from the external IP address should be deflected to a honeypot server.
16 . The system of claim 15 , wherein the honeypot server is configured to isolate attempts to gain unauthorized access to a cyber asset residing on the internal network.
17 . The system of claim 15 , wherein the firewall is configured to, upon receiving a communication from the external IP address, deflect the communication to the honeypot server to prevent a breach of the internal network.
18 . The system of claim 15 , wherein the security management platform is further configured to:
add the external IP address to a blacklist associated with a botnet; and
monitor botnet activity by identifying all public communication activities involving any external IP address included in the blacklist.
19 . The system of claim 18 , wherein the security management platform is further configured to:
update the blacklist on a periodic basis by removing those external IP addresses that have not been involved in any public communication activities for a certain period of time.
20 . The system of claim 15 , wherein the security management platform is further configured to:
examine traffic originating from, or directed to, the external IP address to determine which services, if any, are running on the external IP address.