safeguarding oecd information assets frédéric challal head, systems engineering team oecd

13
Safeguarding OECD Safeguarding OECD Information Assets Information Assets Frédéric CHALLAL Frédéric CHALLAL Head, Systems Engineering Team Head, Systems Engineering Team OECD OECD

Upload: malcolm-skinner

Post on 12-Jan-2016

216 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Safeguarding OECD Information Assets Frédéric CHALLAL Head, Systems Engineering Team OECD

Safeguarding OECD Safeguarding OECD Information AssetsInformation Assets

Frédéric CHALLALFrédéric CHALLAL

Head, Systems Engineering TeamHead, Systems Engineering Team

OECDOECD

Page 2: Safeguarding OECD Information Assets Frédéric CHALLAL Head, Systems Engineering Team OECD

AgendaAgenda

Network SecurityNetwork Security Remote AccessRemote Access Anti-Virus ProtectionAnti-Virus Protection E-mail Content Filtering and BlockingE-mail Content Filtering and Blocking Possible Future Directions Possible Future Directions

Page 3: Safeguarding OECD Information Assets Frédéric CHALLAL Head, Systems Engineering Team OECD

Network SecurityNetwork Security

Private NetworkPrivate Network

ExternalExternalFirewallFirewall

InternalInternalFirewallFirewall

Internet DMZInternet DMZ

Extranet DMZExtranet DMZ

SITASITA

X25X25

InternetInternetInternetInternet

Page 4: Safeguarding OECD Information Assets Frédéric CHALLAL Head, Systems Engineering Team OECD

Network SecurityNetwork Security

2 levels of firewalls for access control2 levels of firewalls for access control 2 separate DMZs to protect sensitive 2 separate DMZs to protect sensitive

informationinformation Outgoing Internet access through Outgoing Internet access through

application relaysapplication relays Intrusion detection systems on both Intrusion detection systems on both

DMZsDMZs Vulnerability scanning on a regular Vulnerability scanning on a regular

basisbasis

Page 5: Safeguarding OECD Information Assets Frédéric CHALLAL Head, Systems Engineering Team OECD

Intrusion Detection SystemIntrusion Detection System

Network sensor watching for attack Network sensor watching for attack signaturessignatures

Responses to suspicious activity:Responses to suspicious activity: Connection terminationConnection termination Alerts sent by E-mailAlerts sent by E-mail Session recordedSession recorded Other …Other …

Page 6: Safeguarding OECD Information Assets Frédéric CHALLAL Head, Systems Engineering Team OECD

Remote AccessRemote Access

Exchange Web SQL

Page 7: Safeguarding OECD Information Assets Frédéric CHALLAL Head, Systems Engineering Team OECD

Remote AccessRemote Access

For portables and Outlook Web Access For portables and Outlook Web Access users to access the OECD network, users to access the OECD network, two-two-factor authentication based on:factor authentication based on: A PIN number (known by the user)A PIN number (known by the user) An authenticator (either hardware or An authenticator (either hardware or

software) software)

Also based on Windows authentication Also based on Windows authentication to access network resourcesto access network resources

Page 8: Safeguarding OECD Information Assets Frédéric CHALLAL Head, Systems Engineering Team OECD

Anti-Virus ProtectionAnti-Virus Protection

NetworkNetworkServerServer

Gateway &Gateway &FirewallFirewall

InternetInternet

Poi

nt o

f E

ntry

Poi

nt o

f E

ntry

Point of EntryPoint of Entry Point of EntryPoint of Entry

E-mail & E-mail & SMTP relaySMTP relay

ClientClient

Page 9: Safeguarding OECD Information Assets Frédéric CHALLAL Head, Systems Engineering Team OECD

Prevention And DetectionPrevention And Detection Anti-Virus products from 2 different Anti-Virus products from 2 different

vendors installed on:vendors installed on: Desktops and laptopsDesktops and laptops File ServersFile Servers E-mail ServersE-mail Servers SMTP RelaysSMTP Relays

Signature updates on a weekly basisSignature updates on a weekly basis Scanning on PCs and servers on a weekly Scanning on PCs and servers on a weekly

basisbasis User EducationUser Education Being Prepared Being Prepared

Basic Network SecurityBasic Network Security Standard Disaster Recovery ProceduresStandard Disaster Recovery Procedures

Page 10: Safeguarding OECD Information Assets Frédéric CHALLAL Head, Systems Engineering Team OECD

E-mail Content Filtering and BlockingE-mail Content Filtering and Blocking

Implemented after the ILOVEYOU Implemented after the ILOVEYOU virusvirus

SMTP relay level filtering of all SMTP relay level filtering of all incoming and outgoing Internet incoming and outgoing Internet messages:messages: Scan for virusesScan for viruses Block « program » attachments and Block « program » attachments and

HTML scripts for 2 daysHTML scripts for 2 days Search for « suspicious » text strings in Search for « suspicious » text strings in

subjectsubject

Reporting to managementReporting to management

Page 11: Safeguarding OECD Information Assets Frédéric CHALLAL Head, Systems Engineering Team OECD

E-mail Content Filtering and BlockingE-mail Content Filtering and Blocking

W32/Navidad

W32/Navidad-B

Page 12: Safeguarding OECD Information Assets Frédéric CHALLAL Head, Systems Engineering Team OECD

Possible Future DirectionsPossible Future Directions

Outsource detection and reporting of Outsource detection and reporting of network vulnerabilitiesnetwork vulnerabilities

SSL for Outlook Web AccessSSL for Outlook Web Access Use RTBL to prevent spammingUse RTBL to prevent spamming Content inspection on HTTP/FTP Content inspection on HTTP/FTP

downloadsdownloads

Page 13: Safeguarding OECD Information Assets Frédéric CHALLAL Head, Systems Engineering Team OECD

Comments and Questions?Comments and Questions?