Untitled record
23 claims: 14 independent, 9 dependent
- 1CLAIMS !.System (or method or computer program product) for securing a local area network including identifying at least one Transparent rogue device. Note:the term “device” is intended to include any hardware device which may have been compromised, and is connected to a network such as a LAN hence may attack a device to be protected which is connected to the same network.
- 11A Secured PHY that will interconnect only with partnering PHYs that have the same level of layer 1 security and not with PHY’s that do not have the same level of layer 1 security.
- 12A method for providing a PHY, the method comprising:Providing a secured PHY that will interconnect only with partnering PHYs that have the same level of layer 1 security and not with PHY’s that do not have the same level of layer 1 security, the providing including embedding technology described herein at chip-level.
- 13Processing circuitry comprising at least one processor and at least one memory and configured to perform at least one of or any combination of the described operations or to execute any combination of the described modules.
- 14Apparatus substantially as shown and described herein.
- 15Apparatus substantially as illustrated in any of the drawings.
- 16A method substantially as shown and described herein.
- 17A method substantially as illustrated in any of the drawings.
- 18A computer program product substantially as shown and described herein.
- 19A computer program product substantially as illustrated in any of the drawings.
- 20Any suitable combination of the systems shown herein.
- 21Any suitable combination of the methods shown herein.
- 22Any method which is a generalization of or which includes or incorporates, the specific methods shown and described herein.
- 23Any apparatus which is a generalization of or which includes or incorporates, the specific apparatus shown and described herein.
Independent claims14
86 paragraphs, as filed
Background And Summary
LAN security is a major concern for any corporation or organization which possesses a Local Area Network. Corporate data, sensitive software, and personnel information are all accessible via the corporate network and must be protected from unauthorized intrusion and access.
The traditional approach to LAN security has focused on perimeter security - preventing outside intrusion into the corporate LAN via such solutions as firewalls, authentication mechanisms, etc. ”
The technology usually used for LAN security is mostly known as NAC (Network Access Controller) or NAS (Network Access Server).
A traditional network access server (NAS) is a server that performs authentication and authorization functions for potential users by verifying logon information. In addition to these functions, NAC restricts the data that each particular user can access, as well as implementing anti-threat applications such as firewalls, antivirus software and spyware-detection programs. NAC also regulates and restricts the things individual subscribers can do once they are connected. Several major networking and IT vendors have introduced NACproducts.
NAC is ideal for corporations and agencies where the user environment can be rigidly controlled. An example is a network for a large university with multiple departments, numerous access point s and thousands of users with various backgrounds and objectives. ”
All NAC and NAS share the same problem - they examine the network traffic and entities from their MAC layer, starting from layer 2 of the OSI layer model (Figure 1). Potential attackers can try to manipulate MAC layer information (for example - manipulating a MAC address to a one authenticated by the 802. lx protocol), but most NACs use advanced authentication schemes and machine learning that detect MAC address manipulations. Nevertheless there is still a significant segment of the network structure that is not probed - the Physical layer, layer 1 of the OSI layer model (Figure 1). As attackers are aware of this fact, they try to find alternative paths to the organizations asset by inserting active devices (inline to the targeted device that was originally physically connected to the switch as shown in Fig. 3) that are Transparent- meaning they go undetected by existing monitoring, probing and intrusion detection tools. They ate connected In1 lone through a legitimate LAN connection but cannot be identified or detected ,as their effect may be compared to that of adding a new passive copper cable. Attackers actually make use of existing technology, as provided by companies like Proxicast and illustrated in Figure 4. The original purpose of devices like the PoketPort 2 (other examples are various Raspberry Pi variants, Mikro Tik(mAP),Pwnie Express (Pwn Pro) GLI net (GL-MiFi) etc.) was to provide an easy way of connecting remote sites without the tedious network configuration associated with it, all the user has to do is to connect a cellular USB net stick, basic configuration, and you are ready to go! All traffic running through this virtual cable will be re-routed through an internet switchboard (managed in this case by Proxicast). Attackers can take these devices, create their own switchboard (as this is a simple socket based communication scheme), all that is left is to insert the devices to the organizations network - the attacker may choose any location within the network to deploy these tools, preferably in as covert as possible. An illustration of such a deployment is illustrated in Figure 5.
Certain embodiments of the invention provide successful identification of those Transparent devices by deep physical finger printing analysis as described in Fig. 6,, the term physical is applied because the analysis looks into layer 1 parameters, and deep because we go into very specific details and parameters of this network connection. The term fingerprinting is used due to the fact that the combined physical specifics are uniqe and can be used as an identifiers similar to human finger prints where the system of the present invention may determine the existence and exact port location of a specific Transparent device . Once a specific port has been identified as having a transparent device, there are several options - first, notify the customers SIEM (Security and Information Events Management) or the NAC (Network Access Controller) or isolate the port independently. The common procedure is to move the suspected port to an isolated VLAN for further investigation. The third option would be less common, as the customers do not want their ports being managed by two entities(NAC and the proposed solution) in parallel. Interface protocols between the proposed solution and the NAC/SIEM would usually be RESTful API, SYSLOG and SNMP.
Brief description of drawings
Figs. 1-10 are attached.
Fig.l - OSI 7-layer model
Fig.2 - Zoom in on the PHY layer
Fig. 3 - An attack scenario illustration using a VCM devices
Fig. 4 - A picture of one of the possible transparent devices
Fig. 5 - An example for the intended original use of the transparent devices
Fig. 6 - Example flow for deep physical finger printing analysis
Fig. 7 - Example flow of incorporating jamming signals to aid in the detection process
Fig. 8 - Flow of aggregated insight resulting in a detection indication
Fig. 9 - Example of the terms Remote and Local with respect to the switch
Fig. 10 - An image illustrating a jammer dropping the cellular connection used for the transparent device.
Detailed Description of Embodiments
Typically, the detection algorithm relies on at least one insight gained from an auto negotiation process.
Autonegotiation may include any procedure by which two connected hardware devices share their capabilities regarding transmission parameter/s they have in common; the connected devices then choose a transmission mode they both support e.g. the highest performance transmission mode they both support.
''Autonegotiation is an Ethernet procedure by which two connected devices choose common transmission parameters, such as speed, duplex mode, and flow control. In this process, the connected devices first share their capabilities regarding these parameters and then choose the highest performance transmission mode they both support. In the OSI model, autonegotiation resides in the physical layer. For Ethernet over twisted pair it is defined in clause 28 of IEEE 802.3. Autonegotiation was originally defined as an optional component in the Fast Ethernet standard. It is backwards compatible with the normal link pulses used by 10BASE-T. The protocol was significantly extended in the gigabit Ethernet standard, and is mandatory for 1000BASE-T gigabit Ethernet over twisted pair.
One can gain information about the various parameters of the PHY through the Mil register interface. For example, The media-independent interface (Mil) was originally defined as a standard interface to connect a Fast Ethernet (i.e., 100 Mbit/s) media access control (MAC) block to a PHY chip. The Mil is standardized by IEEE 802.3u and connects different types ofPHYs to MACs. Being media independent means that different types of PHY devices for connecting to different media (i.e. Twisted pair copper, fiber optic, etc.) can be used without redesigning or replacing the
MAC hardware. Thus any MAC may be used with any PHY, independent of the network signal transmission media.
The Mil can be used to connect a MAC to an external PHY using a pluggable connector, or directly to a PHY chip which is on the same PCB. On a PC the CNR connector Type B carries Mil bus interface signals.
The Management Data Input/Output (MDIO) serial bus is a subset of the Mil that is used to transfer management information between MAC and PHY. At powerup, using autonegotiation, the PHY usually adapts to whatever it is connected to unless settings are altered via the MDIO interface. An example would be the information carried in the link advertisement register which indicates what are the capabilities of the remote PHY link partner, in the attack scenario discussed in this application, the transparent device has a different set of capabilities that differ from that of the PC or printer which are actually connected at the end of the line.
Deep Finger Printing (DFP)
DFP is a process operative to characterize a complete set of parameters describing a given device's layer 1 behavior e.g. using operation/s shown in the flow described in Fig. 6. The detection algorithm typically starts out with analog parameters which are most difficult for a potential attacker to duplicate - as they are derived from the specific communication channel characteristics, they manifest in the form of specific equalizer coefficients which are used for channel waveform corrections.
Other analog parameters may include impedance and/or termination values in Ethernet transformers which are part of the PHY in most cases and typically can be measured only at this level.
Timing response parameters are also used for specific device identification, in a similar manner used by switch vendors where cable diagnostics functionality is embedded in their management interface. One of the familiar terms is called TDR (Time Domain Reflectometer) as in the example described in the following link https://community.spiceworks.com/how to/24277-using-cisco-cable-diagnostics
In addition, information that is advertised by the link partners (the remote side connection with respect to the switch local port connection), known as Advertisement registers can also be used to identify a specific PHY in a given link.
http ://www, microchip .com/forums/m979258 .aspx
The specific settings configuration through the Auto-negotiation process between the switch port and the transparent device which is connected directly to it,are dependent on the two link partners each pair can generate a different settings or behavior - this is why the two ends of the connection needs to be monitored (not only the local PHY but the remote PHY as well).
In order to lower possible false positive indications an additional layer of screening may be applied as part of the analysis process (as illustrated in Fig. 6 and Fig. 8) - by using additional layer 2 data this layer typically cross correlates the layer 1 information with layer 2 (and above) information. The MAC address, IP, QoS, TTL and other parameters can be obtained by network traffic sniffing, and correlated with the layer 1 extracted data (as an example - the MAC address extracted from layer 2 monitoring identifies the device to be of specific vendor and type, data that can be compare with the ACTUAL behavior and advertisement data that is extracted through the remote PHY querying. As the transparent device does not change the layer 2 information (for example the MAC address), we can see an example that the expected device should behave like a 10Gb NIC of an IBM server while the registers (read from the transparent device) are indicating a different setup as they are set by the transparent device's capabilities. So, a true distinction is achieved between a true transparent mode device and an existing legitimate device that just had some of its configuration altered alternatively or in addition, some transparent devices use networking chips (IC) that are of lower grade of performance, some can only process packets of certain types and structure, while dropping unsupported ones. As an example - illustrated in BCM5718 Programmers Guide , Figure 57 page 267. https://docs.broadcom.com/docs/1211168564147
The proposed solution can make use of this fact, by injecting specific packets to specific ports The injection is carried out by a command from our application to the managed switch with the suspected port, the switch has the capability of sending specific packet pattern to a specific port. The result of such packet injection will be read out by our application and will be compared with the expected result. The proposed solution verifies that the injected packets have reached their destination - we can determine by reading the relevant counter register the likelihood of an intermediate networking IC located in-line on a specific port connection
The overall grade of risk per specific port/switch is determined by the server (application), based on several indication (some of them are threshold crossings and some specif values). The overall weights calculation in still not detailed at this stage.
Embedded Silicon Functionality
The technology described for establishing a secured layer 1 PHY connection herein can be embedded at chip-level (silicon level), thereby to provide a new generation of Secured PHYs that will interconnect only with partnering PHYs that have the same level of layer 1 security.
Once the security feature are part of the networking IC (chip) ,this may be achieved by integrating this feature as part of the chip's VLSI design, a policy will be applied as part of the network buildup (but implemented at chip level) that devices will interconnect only when they can assure that their link's counterpart which they are connected to, is verified and considered to be safe. Similar to the way where two terminals communicate only when the share the same level of security / encryption),
Reference Database
As more servers are deployed an aggregated database of devices which includes the specific layer 1 profiling details of every Ethernet device is collected. This information is then used to crosscorrelate and/or compare new PHY occurrences with known ones ,if it correlates than we can mark it as having a high level of security compared with those which don’t which may be marked as unknown risk level When the application logics correlate we may look at a vector of parameters and see if the overall relationship between the parameters are as in the original template that exists in the database. When we compare, we take the specific values by themselves and evaluate the differences thus providing an additional verification step in approving and validating new Ethernet connections (as illustrated in the later stages in the flow described in Fig. 6).
Outbound link detection
As some of the transparent devices (like the PocketPort 2 in Figure 4) require an outbound channel that will allow them to bypass monitored external links (i.e., through the enterprises internet connection) - some make use of a cellular net stick, a WiFi USB dongle, or any other proprietary communication equipment. As WiFi connections are easy to monitor, and have limited range, potential attacker would prefer using a cellular connection.
In some sites, for example a highly confidential facility, most chances are that one cannot walk in with a cellular phone or modem, but if one is working for a pharmaceutical company they may allow the use of cellular phones. This policy dictates the feasibility of enforcing a no-wireless policy , turning, in the later case, the surrounding wireless spectrum to a jungle of signals, where the detection of a specific cellular connection is almost impossible.
Our proposed method may employ strong (value of jamming signal is determined on the specific dimension and construction material of the building and usually vary from IWatt to lOOWatts) RF jamming transmission in the following flow - the server will be connected to an external jamming unit, that will transmit the jamming signal to its antenna covering a specific floor area).that will force an abrupt link disruption - the jamming pulse doesn’t have to be a long one, and may be just long enough to cause the link to be dropped (1-2 sec.), causing the link to drop (if it is connected through a cellulat connection)״ by monitoring the switches links and how fast they bounce back to full operation one can determine which ports are likely to be wired directly and which use a cellular/WiFi/other wireless modem for its connection, meaning if the link was established by direct wireline communication or a wireless one (assuming the case that the network owner is not using wireless extensions). Timing properties are used here as well, as the additional networking equipment delays the response time (when one ARP pings a port that is connected through a wireless extension, its response time to that ping will be greater compared with the case of being directly connected through a wired connection only).
As illustrated in Fig. 10 the transparent device attack uses two devices that work in a Virtual Cable Mode when the wireless connection between the devices is disturbed, the Ethernet link will be disconnected until the internal wireless modems in the transparent device reconnects to the wireless network (which can be cellular based which will take more time, or a WiFi based network) Additional insight may be obtained by using higher level commands. All actions are carried out by our application, communicating with the end equipment, in most cases it would be the switching infrastructure, but could also be the end-point PC's as wll (as in the NIC case described above) that cause the remote side (as described in Fig. 9) to turn off its port (momentary NIC disable). Thus, if the remote side (the PC's NIC) is directly connected to the switch, the local port (the switches port) will lose its link, whereas if the remote port is connected through a transparent device, the local port will still hold the link. Thus, giving a command that causes the remote side to turn off its port provides an (additional) indication for existence of a transparent device at the port in question: whether, following that command, the local port lost its link (suggesting no transparent device) or did not lose its link (suggesting existence of a transparent device).
Below is an example of data read from a switch through its management interface -the switch's vendor, model, configuration and more important the Mil registers (generated by the command show controllers ethemet-controller gigabitEthernet 1/0/1 phy which return a list of all supported registers in a given port this information is used as one of the data sources for the deep finger printing algorithm.
Example cisco WS-C3850-24T (MIPS) processor with 4194304K bytes of physical memory.
Processor board ID FOC2029U141
Virtual Ethernet interfaces
Gigabit Ethernet interfaces
Ten Gigabit Ethernet interfaces
2048K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
250456K bytes of Crash Files at crashinfo:.
1609272K bytes of Flash at flash:.
OK bytes of Dummy USB Flash at usbflashO:.
OK bytes of at webui:.
Base Ethernet MAC Address : d4:2c:44:62:29:80
Motherboard Assembly Number : 73-16297-05
Motherboard Serial Number : FOC20291LE7
Model Revision Number : ABO
Motherboard Revision Number : AO
Model Number : WS-C3850-24T
System Serial Number : FOC2029U141
Switch Ports Model SW Version SW Image Mode * 1 32 WS-C3850-24T 03.07.04E cat3k_caa-universalk9 INSTALL
Configuration register is 0x102
Switch#
Switch#
Switch#show controllers ethemet-controller gigabitEthemet 1/0/1 phy
Gil/0/1 (gpn: 1, port-number: 1)
0000: 1140 Control Register
0001 : 7949 Control STATUS
0002 : 0141 Phy ID 1
0003 : 0ED4 Phy ID 2 : 0001 0001 0100 0000 : 0111 1001 0100 1001 : 0000 0001 0100 0001 : 0000 1110 1101 0100
0004 : 01E1 Auto-Negotiation Advertisement : 0000 0001 1110 0001 0005 : 0000 Auto-Negotiation Link Partner : 0000 0000 0000 0000 0006 : 0004 Auto-Negotiation Expansion Reg : 0000 0000 0000 0100 0007 : 2001 Next Page Transmit Register : 0010 0000 0000 0001 0008 : 0000 Link Partner Next page Registe : 0000 0000 0000 0000 0010 : 3870 PHY Specific Control : 0011 1000 0111 0000 0011 : 8000 PHY Specific Status : 1000 0000 0000 0000 0012 : 6400 PHY Specific Interrupt Enable : 0110010000000000 0013 : 0040 PHY Specific Interrupt Status : 0000 0000 0100 0000
The solution as described herein may be implemented as illustrated in any of the drawings, e.g. As a stand alone server appliance or as a stand alone application running on a designated or shared server (e.g. On perimeter or a virtual machine).
The term “rogue” is intended to include a behaviour e.g. Malicious behavior of a device e.g. Malicious networked device, which may be achived by being transparent to monitoring tools.
References to LANs herein may alternatively be replaced by “WAN” or another networks, according to certain embodiments.
References e.g. for texts in italics above:
http://searchnetworking.techtarget.com/definition/network-access-control http://www.analog.com/media/en/technical-documentation/application-notes/EE-269.pdfhttps://en.wikipedia.org/wiki/Autonegotiation https://en.wikipedia.org/wiki/Media-independent interface
Features of the present invention, including method steps, which are described in the context of separate embodiments may also be provided in combination in a single embodiment. Conversely, features of the invention, which are described for brevity in the context of a single embodiment or in a certain order may be provided separately or in any suitable subcombination or in a different order.
Any or all of computerized sensors, output devices or displays, processors, data storage and networks may be used as appropriate to implement any of the methods and apparatus shown and described herein.
The invention includes but is not limited to the embodiments recited in the following claims:
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
Numbers
- Publication
- 254573
- Publication, DOCDB
- 254573
- Application
- 254573
- Application, DOCDB
- 254573
Titles2
- Hebrew
- ???? ???? ????? ????? ???? ?????? ??? ?????? ??????? ??????? ??????? ???? ?? ???????
- English
- SYSTEM METHOD AND COMPUTER PROGRAM PRODUCT FOR SECURING A LOCAL AREA NETWORK FROM THREATS INTRODUCED BY ROGUE OR MALICIOUS DEVICES
