|
You are hereHome » NANOG Meeting Presentation Abstract
|
|
NANOG Meeting Presentation Abstract
Life on a University Network: An Architecture for Automatically Detecting, Isolating, and Cleaning Infected Hosts | Meeting: | NANOG30 | |
Date / Time: | 2004-02-10 2:30pm - 2:50pm | |
Room: | Symphony Ballroom II - IV | |
Presenters: | Speakers:
Eric Gauthier, Boston UniversityEric Gauthier is currently the senior Network Systems Engineer for Boston University\'s Office of Information Technology. Prior to this, he worked as a network engineer for several regional and large-scale ISPs, including Exodus Communications. | |
Abstract: | In fall 2003, many schools were unprepared in terms of network infrastructure and staff to deal with the overwhelming number of infected computers that suddenly arrived on their campus networks. This resulted in the shutdown of several University networks and an enormous strain on helpdesk staff. Over a single week in September, Boston University had approximately 10,000 students arrive on campus, 7,000 of whom arrived during the three-day Labor Day weekend. As with most schools, many of these computers were either exploitable or already infected with a wide variety of worms and viruses. Why did Boston University have a relatively quiet \"move-in\"?
Using shareware tools and some minor in-house coding, Boston University deployed a system that detects, isolates, and quarantines most vulnerable systems when they attach to the network for the first time. After the hosts are active on the campus network, the host can be returned to this quarantine if it is subsequently found to be infected or fails an active vulnerability scan. While quarantined, all web queries are redirected to an informational web site that has customizable information, including a self-help guide and tools to patch and clean the host.
This talk will detail the infrastructure, systems and software used to build this network registration and quarantining system, the modifications that were needed, its successes, its failures, and some thoughts on where to go next. | |
Files: | An Architecture for Automatically Detecting, Isolating
Eric Gauthier Presentation(PDF)
| |
Sponsors: | None. | |
Back to NANOG30 agenda. NANOG30 Abstracts- Making Sense of BGP
Speakers: Tina Wong, Packet Design; Van JacobsonPacket Design; .Cengiz AlaettinogluPacket Design; .
- Making Sense of BGP
Speakers: Tina Wong, Packet Design; Van JacobsonPacket Design; .Cengiz AlaettinogluPacket Design; .
- Making Sense of BGP
Speakers: Tina Wong, Packet Design; Van JacobsonPacket Design; .Cengiz AlaettinogluPacket Design; .
- Real-time Global Routing Metrics
Speakers: Jim CowieRenesys Corporation; .Andy T. OgielskiRenesys Corporation; .B.J. PremoreRenesys Corporation; .Eric A. SmithRenesys Corporation; .Todd UnderwoodRenesys Corporation; .
- Real-time Global Routing Metrics
Speakers: Jim CowieRenesys Corporation; .Andy T. OgielskiRenesys Corporation; .B.J. PremoreRenesys Corporation; .Eric A. SmithRenesys Corporation; .Todd UnderwoodRenesys Corporation; .
- Real-time Global Routing Metrics
Speakers: Jim CowieRenesys Corporation; .Andy T. OgielskiRenesys Corporation; .B.J. PremoreRenesys Corporation; .Eric A. SmithRenesys Corporation; .Todd UnderwoodRenesys Corporation; .
- Real-time Global Routing Metrics
Speakers: Jim CowieRenesys Corporation; .Andy T. OgielskiRenesys Corporation; .B.J. PremoreRenesys Corporation; .Eric A. SmithRenesys Corporation; .Todd UnderwoodRenesys Corporation; .
- Real-time Global Routing Metrics
Speakers: Jim CowieRenesys Corporation; .Andy T. OgielskiRenesys Corporation; .B.J. PremoreRenesys Corporation; .Eric A. SmithRenesys Corporation; .Todd UnderwoodRenesys Corporation; .
|
|