UBIqube Secure Technical
UBIqube Secure Technical
Nov 08
Agenda
• About UBIqube
2
About UBIqube
3
Addressing the Services Market Opportunity
5
About UBIqube
6
About UBIqube
Unified Lifecycle
Simplicity Convergence
Solution Management
7
Service Provider Solution Suite
Differentiator : Simplicity
Differentiator : Convergence
Monitoring • Silver
services • Gold
• Alerting
• Detailed Reports
Managed
• CME/CUE
Voice • UC500
• Dial Plan, Groups
• Self Care
Managed
Security • IPsec VPN
• Firewall
• IPS/IDS
• Content Filtering
Security
Networking Deploy
VoiP
Manage
and Test
Provisioning Improve
Staging
Monitor
Creation and
Respond
Monitoring Reporting
11
Service Provider Solution Suite
Solution Introduction
12
Service Provider Solution Suite
Solution Description
13
Service Provider Solution Suite
Solution Modules
VSOC
Webportal
SEC Engine Event Tracker Archive PKI
14
UBIqube Technology Platform
CMDB
• Oracle databases
15
UBIqube Technology Platform
• Event Tracker
– Logs and events collector
– Handle syslog and flat files flows
– A built in analysis engine provide logs classification and
analysis
– Load balance the events to a set of reporting engine
– Upon the severity of the event, the engine triggers
alerts.
16
UBIqube Technology Platform
SEC Engine
17
UBIqube Technology Platform
18
UBIqube Technology Platform
Profile 1
Profile 1
Profile 2
21
Service Provider Solution Suite
Service Depth
Local Log
Archiving
LAN/DMZ
Services
Legal
Requirement
22
Service Provider Solution Suite
ISP Backbone
Traffic Customer 1
Traffic Customer 2
Management
23
Service Provider Solution Suite
Lack of SP trust
ISP #1
Customer
ISP Backbone Network
ISP #2
SmartSOC
Service Agent
24
Service Provider Solution Suite
ISP #1
Customer
ISP Backbone Network
ISP #2
Service Provider
Service Management Customer Self-Service
Integrator Service Reporting, Monitoring
management
25
Agenda
• About UBIqube
26
Managed VPN Services
Overview
27
Managed VPN Services
LAN-2-LAN VPN
Mesh VPN
• Dynamic Configuration Change Control
– Automatic propagation of configuration
Updates (eg new Device set up)
28
Managed VPN Services
LAN2LAN VPN
29
Managed VPN Services
Remote Access
30
Managed VPN Services
Redundancy
31
Managed VPN Services
QoS
32
Managed VPN Services
QoS
33
Managed Security Services
Overview
• Managed Security
– Firewall
– IDS/IPS
– Anti-Virus
– URL-Filtering
– Anti-Spam
34
Managed Security Services
Firewall
• 3 cookie cutters
– Soho profile
– Private DMZ profile
– Public DMZ profile
35
Managed Security Services
Firewall
Firewall Profiles
• Filter outgoing connections
(inside/DMZ to outside)
36
Managed Security Services
Firewall
37
Managed Security Services
IPS/IDS
• IDS/IPS profiles
– Configure one deploy many
38
Managed Security Services
IPS/IDS
39
Managed Security Services
• Generates Alerts
– Lots of Syslog messages
– Needs centralized collection and presentation
40
Managed Security Services
IPS/IDS
41
Managed Security Services
Anti-Virus
42
Managed Security Services
Anti-Virus
• Anti-Virus/Spyware profiles
– Configure one, deploy many
• Monitor traffic
– Globally or subsets of traffic (recommended services http,
ftp, smtp, pop3 …)
• 3 cookie cutters
– Normal Anti Virus Profile (optimized performances)
– High Anti Virus Profile (scan all files)
– Paranoid Anti Virus Profile (scan all files recursivelly, update
frenquently, block all upon failure)
43
Managed Security Services
Anti-Virus
44
Managed Security Services
Anti-Spam
• Anti-Spam
– To much spam in the inbox impacts employee
productivity
– Prevent spam with very low false positives
• Anti-Phishing
– Phising can lead to Identity company or personal
credentials theft
– Prevent financial loss by adding protection against
phishing attacks
45
Managed Security Services
Anti-Spam
46
Managed Security Services
URL-Filtering
47
Managed Security Services
URL-Filtering
48
Managed Security Services
Vulnerability Assessment
49
Managed Security Services
Vulnerability Assessment
50
Managed VoIP Services
51
Managed VoIP Services
52
Managed Monitoring Services
Overview
• Asset Management
– Software and hardware inventory
– Licence management
53
Managed Monitoring Services
54
Managed Monitoring Services
55
Managed Monitoring Services
56
Managed Monitoring Services
• Availability
– Real-time availability testing
– After 6 consecutive failures, an
alert is generated
• Incoming/outgoing Traffic
– Monitor link saturation
– Plan for QoS
• Uptime
– Time since last reboot
– Distinguish Network and Router
problems
• CPU Load
– Diagnose usage anomalies
– Proactively propose upgrade
57
Managed Monitoring Services
• Network Latency
– Monitor quality of ISP
connection
• IKE statistics
– VPN tunnels statistics
– Identifies VPN module failures
• QoS statistics
– Per traffic class statistics
– Monitor forward and drop
traffic
• IPS statistics
– Monitor the number of IPS
events
– Sorted by Device or Profile
58
Managed Monitoring Services
• Custom graph
rendering
• Threshold alerting
59
Managed Monitoring Services
• Security DashBoard
– Online alert reporting
overview.
– Event History per
category
• IPS, Firewall
• Content Filtering
• Logs
– Top 5 :
• Device top 5 of the
week/month : most
attacked Devices
• Alert top 5 of the
week/month : the
most frequent alerts
60
Managed Monitoring Services
Log Analysis
– Compute weekly summary reports
– Aggregate the logs events on a per day basis
– Customize the logs with human readable information
61
Managed Monitoring Services
Alert Generation
– Discard the event (marked as false positive)
– Generate an email alerting
62
Managed Monitoring Services
63
Asset Management Services
64
Asset Management Services
License Management
65
Managed Monitoring Services
• Configuration Backup
– The running configuration of each device is downloaded
and saved every night
– Stored for 6 months
– Locate illicit manual modifications
66
Supported Devices and available services
Managed Devices
67
Summary
68