april 11, 20051 implementation of virtual lans for virus containment aaron soto april 11, 2005 in...
Post on 20-Dec-2015
220 views
TRANSCRIPT
April 11, 2005 1
Implementation of Virtual LANs for Virus Containment
Aaron SotoApril 11, 2005
In partnership with:New Mexico Tech
Information Services Department
April 11, 2005 2
Outline
• Problem Statement– What is a VLAN?– How can it help?
• Proposed Solution– Layout– Implications– Details
• Future Expansion
April 11, 2005 3
Problem Statement
• Universities are prone to viruses
• PCs are frequently not running AV software
• Staff constantly monitors network traffic
– Ports disabled if viruses are detected
• Students unable to clean / patch PC
– Without Internet, more effort is necessary
– Students frequently frustrated
April 11, 2005 4
Background: VLANs
SWITCH
April 11, 2005 5
Background: VLANs
SWITCH
SWITCH
April 11, 2005 6
Proposed Solution
• Implement two VLANs:
– Default: Quarantined, DHCP
– Secure: Safe, Virus-free, Static IP
• Automated tools can switch VLANs
• Traffic can be redirected/forwarded
– Allow sites like Windows Update, SARC, etc.
– Redirect other traffic to quarantined server
April 11, 2005 7
Current Layout
SWITCH 2
SWITCH 1
SWITCH 0
FIREWALL
IN-BUILDING
INTERNET
April 11, 2005 8
Proposed Layout: Overview
SWITCH 2
SWITCH 1
SWITCH 0
IN-BUILDING
INTERNET
QUARANTINESERVER
SECURE
DEFAULT
April 11, 2005 9
Proposed Layout: In-Building
IN-BUILDING 1 2 3 4 5 6 13 14 15 16 17 18
7 8 9 10 11 12 19 20 21 22 23 24
DEFAULT PACKET
SECURE PACKET
April 11, 2005 10
Proposed Layout: Backbone
INTERNET
QUARANTINESERVER
DEFAULT
SECURE
FIREWALL
April 11, 2005 11
Proposed Layout: Server
QUARANTINESERVER
DEFAULT
FIREWALL
• DHCP Server
• Apache Web Server
• IP Masquerading (ipChains)
April 11, 2005 13
April 11, 2005 14
Possible Implications
• Firewall– Forward traffic depending on VLAN tag
• Quarantine Server– Must be frequently re-evaluated to…
Be kept secure from viruses/worms Select valid traffic to forward
– Is not designed to take full load
• Switches– Must have VLAN support
April 11, 2005 15
Future Expansion
• Automated Port Activation Requests– Allow students to register with ISD online
Integration with Banner?
• Automated Virus Detection and Quarantine– Detect virus activity and switch VLANs
In progress
• More detailed communications– Specific information / instructions– Would require multiple VLANs
For a later stage
April 11, 2005 16
Implementation of Virtual LANs for Virus Containment
Questions?
Aaron Soto
(505) 835-5945