SlideShare a Scribd company logo
1 of 9
Download to read offline
Router Defense




Cisco IOS security assessment tool

    Lightning talk day 2 - 2010
Operational security



Did you ever seen a Cisco network device with
           security BCP enforced?

« The network is more powerful than the node »
The network moves

           Network (re)design
          Configuration changes
      Compromised network devices
Network usage (Software update policy, devs
            plays with mcast)


        RouterDefense will adapt
 Recurrent assesment schedule for teh win
Threat base reference model
 Enterprise/Service providers networks agnostic
                IPv4/IPv6/MPLS

Cisco Guide to Harden Cisco IOS Devices (Cisco)
 Cisco IOS Switch Security Configuration Guide
                      (NSA)
            Tool's author experience

 0-dayz vendor EPIC FAIL proactive prevention
          (cisco-sa-20100707-snmp)
Features

Reads Cisco IOS config with a security mindset
      Management, control, data planes
  Stdout, HTML(5+CSS3), CSV, PDF output
           Three-tier architecture
           Router/switch scenarii
              IOS versioning
         CVSS base vectors scoring
                 138 tests
Demo
HTML output
Router Defense tool

  Written in python during spare time


wc -l *.{py,xml} | tail -1 | awk '{ print $1}'
                    9336

                Version 0.2

        Available at Google Code
http://code.google.com/p/routerdefense/
$ whoami

           Francois Ropert

          Topics of interest:
network protocols and devices security

       Feel free to ping6 me at:

    http://www(6).packetfault.org
              @pello

More Related Content

What's hot

Cisco asa cx firwewall
Cisco asa cx firwewallCisco asa cx firwewall
Cisco asa cx firwewallAnwesh Dixit
 
OpenStack at Cisco, June 2015
OpenStack at Cisco, June 2015OpenStack at Cisco, June 2015
OpenStack at Cisco, June 2015Lora O'Haver
 
[Cisco Connect 2018 - Vietnam] Long ton dc pss hyper flex
[Cisco Connect 2018 - Vietnam] Long ton dc pss  hyper flex[Cisco Connect 2018 - Vietnam] Long ton dc pss  hyper flex
[Cisco Connect 2018 - Vietnam] Long ton dc pss hyper flexNur Shiqim Chok
 
iSCSI for better or worse
iSCSI for better or worseiSCSI for better or worse
iSCSI for better or worseSteven Aiello
 
Flexible, simple deployments with OpenStack-Ansible
Flexible, simple deployments with OpenStack-AnsibleFlexible, simple deployments with OpenStack-Ansible
Flexible, simple deployments with OpenStack-AnsibleMajor Hayden
 
5 ways to use devops in product infrastructure management final
5 ways to use devops in product infrastructure management final5 ways to use devops in product infrastructure management final
5 ways to use devops in product infrastructure management finalPradeep Bohra
 
Cisco asa firewall
Cisco asa firewallCisco asa firewall
Cisco asa firewallIT Tech
 
Storage Visibility for Operations - A Ceph Story
Storage Visibility for Operations - A Ceph StoryStorage Visibility for Operations - A Ceph Story
Storage Visibility for Operations - A Ceph StoryDebojyoti Dutta
 
Presentation asa 5585-x next generation multi-service adaptive security app...
Presentation   asa 5585-x next generation multi-service adaptive security app...Presentation   asa 5585-x next generation multi-service adaptive security app...
Presentation asa 5585-x next generation multi-service adaptive security app...xKinAnx
 
OpenStack-Ansible Security
OpenStack-Ansible SecurityOpenStack-Ansible Security
OpenStack-Ansible SecurityMajor Hayden
 
Practical Security Monitoring with ELKStack
Practical Security Monitoring with ELKStack Practical Security Monitoring with ELKStack
Practical Security Monitoring with ELKStack Eguardian Global Services
 
CCNA Security 012- cryptographic systems
CCNA Security 012- cryptographic systemsCCNA Security 012- cryptographic systems
CCNA Security 012- cryptographic systemsAhmed Habib
 
BreakingPoint & Juniper RSA Conference 2011 Presentation: Evaluating The Juni...
BreakingPoint & Juniper RSA Conference 2011 Presentation: Evaluating The Juni...BreakingPoint & Juniper RSA Conference 2011 Presentation: Evaluating The Juni...
BreakingPoint & Juniper RSA Conference 2011 Presentation: Evaluating The Juni...Ixia
 
Migration to cisco next generation firewall
Migration to cisco next generation firewallMigration to cisco next generation firewall
Migration to cisco next generation firewallIT Tech
 
100%-ный контроль для 100%-ной безопасности
100%-ный контроль для 100%-ной безопасности100%-ный контроль для 100%-ной безопасности
100%-ный контроль для 100%-ной безопасностиАльбина Минуллина
 
Presentación - Cisco ASA with FirePOWER Services
Presentación -  Cisco ASA with FirePOWER ServicesPresentación -  Cisco ASA with FirePOWER Services
Presentación - Cisco ASA with FirePOWER ServicesOscar Romano
 
How to configure cisco asa virtual firewall
How to configure cisco asa virtual firewallHow to configure cisco asa virtual firewall
How to configure cisco asa virtual firewallIT Tech
 
Virtual Networking Security - Network Security
Virtual Networking Security - Network SecurityVirtual Networking Security - Network Security
Virtual Networking Security - Network SecurityEng Teong Cheah
 

What's hot (20)

Cisco asa cx firwewall
Cisco asa cx firwewallCisco asa cx firwewall
Cisco asa cx firwewall
 
OpenStack at Cisco, June 2015
OpenStack at Cisco, June 2015OpenStack at Cisco, June 2015
OpenStack at Cisco, June 2015
 
[Cisco Connect 2018 - Vietnam] Long ton dc pss hyper flex
[Cisco Connect 2018 - Vietnam] Long ton dc pss  hyper flex[Cisco Connect 2018 - Vietnam] Long ton dc pss  hyper flex
[Cisco Connect 2018 - Vietnam] Long ton dc pss hyper flex
 
iSCSI for better or worse
iSCSI for better or worseiSCSI for better or worse
iSCSI for better or worse
 
Flexible, simple deployments with OpenStack-Ansible
Flexible, simple deployments with OpenStack-AnsibleFlexible, simple deployments with OpenStack-Ansible
Flexible, simple deployments with OpenStack-Ansible
 
Cisco ASA Firewalls
Cisco ASA FirewallsCisco ASA Firewalls
Cisco ASA Firewalls
 
5 ways to use devops in product infrastructure management final
5 ways to use devops in product infrastructure management final5 ways to use devops in product infrastructure management final
5 ways to use devops in product infrastructure management final
 
Cisco asa firewall
Cisco asa firewallCisco asa firewall
Cisco asa firewall
 
Storage Visibility for Operations - A Ceph Story
Storage Visibility for Operations - A Ceph StoryStorage Visibility for Operations - A Ceph Story
Storage Visibility for Operations - A Ceph Story
 
Presentation asa 5585-x next generation multi-service adaptive security app...
Presentation   asa 5585-x next generation multi-service adaptive security app...Presentation   asa 5585-x next generation multi-service adaptive security app...
Presentation asa 5585-x next generation multi-service adaptive security app...
 
OpenStack-Ansible Security
OpenStack-Ansible SecurityOpenStack-Ansible Security
OpenStack-Ansible Security
 
Practical Security Monitoring with ELKStack
Practical Security Monitoring with ELKStack Practical Security Monitoring with ELKStack
Practical Security Monitoring with ELKStack
 
CCNA Security 012- cryptographic systems
CCNA Security 012- cryptographic systemsCCNA Security 012- cryptographic systems
CCNA Security 012- cryptographic systems
 
BreakingPoint & Juniper RSA Conference 2011 Presentation: Evaluating The Juni...
BreakingPoint & Juniper RSA Conference 2011 Presentation: Evaluating The Juni...BreakingPoint & Juniper RSA Conference 2011 Presentation: Evaluating The Juni...
BreakingPoint & Juniper RSA Conference 2011 Presentation: Evaluating The Juni...
 
Migration to cisco next generation firewall
Migration to cisco next generation firewallMigration to cisco next generation firewall
Migration to cisco next generation firewall
 
100%-ный контроль для 100%-ной безопасности
100%-ный контроль для 100%-ной безопасности100%-ный контроль для 100%-ной безопасности
100%-ный контроль для 100%-ной безопасности
 
Presentación - Cisco ASA with FirePOWER Services
Presentación -  Cisco ASA with FirePOWER ServicesPresentación -  Cisco ASA with FirePOWER Services
Presentación - Cisco ASA with FirePOWER Services
 
How to configure cisco asa virtual firewall
How to configure cisco asa virtual firewallHow to configure cisco asa virtual firewall
How to configure cisco asa virtual firewall
 
Kevin wharram
Kevin wharramKevin wharram
Kevin wharram
 
Virtual Networking Security - Network Security
Virtual Networking Security - Network SecurityVirtual Networking Security - Network Security
Virtual Networking Security - Network Security
 

Similar to Router Defense - BRUcon 2010

Introduction to Fog
Introduction to FogIntroduction to Fog
Introduction to FogCisco DevNet
 
Cisco Multi-Service FAN Solution
Cisco Multi-Service FAN SolutionCisco Multi-Service FAN Solution
Cisco Multi-Service FAN SolutionCisco DevNet
 
PLNOG16: IOS XR – 12 lat innowacji, Krzysztof Mazepa
PLNOG16: IOS XR – 12 lat innowacji, Krzysztof MazepaPLNOG16: IOS XR – 12 lat innowacji, Krzysztof Mazepa
PLNOG16: IOS XR – 12 lat innowacji, Krzysztof MazepaPROIDEA
 
Architecting Secure Web Systems
Architecting Secure Web SystemsArchitecting Secure Web Systems
Architecting Secure Web SystemsInnoTech
 
G rpc talk with intel (3)
G rpc talk with intel (3)G rpc talk with intel (3)
G rpc talk with intel (3)Intel
 
Daniel Pastrana 12-15-19
Daniel Pastrana 12-15-19Daniel Pastrana 12-15-19
Daniel Pastrana 12-15-19Daniel Pastrana
 
Putting Firepower into the Next Generation Firewall
Putting Firepower into the Next Generation FirewallPutting Firepower into the Next Generation Firewall
Putting Firepower into the Next Generation FirewallCisco Canada
 
Cisco Live! :: Introduction to IOS XR for Enterprises and Service Providers
Cisco Live! :: Introduction to IOS XR for Enterprises and Service ProvidersCisco Live! :: Introduction to IOS XR for Enterprises and Service Providers
Cisco Live! :: Introduction to IOS XR for Enterprises and Service ProvidersBruno Teixeira
 
Putting Firepower Into The Next Generation Firewall
Putting Firepower Into The Next Generation FirewallPutting Firepower Into The Next Generation Firewall
Putting Firepower Into The Next Generation FirewallCisco Canada
 
Cisco connect winnipeg 2018 putting firepower into the next generation fire...
Cisco connect winnipeg 2018   putting firepower into the next generation fire...Cisco connect winnipeg 2018   putting firepower into the next generation fire...
Cisco connect winnipeg 2018 putting firepower into the next generation fire...Cisco Canada
 
Cisco Connect Vancouver 2017 - Putting firepower into the next generation fir...
Cisco Connect Vancouver 2017 - Putting firepower into the next generation fir...Cisco Connect Vancouver 2017 - Putting firepower into the next generation fir...
Cisco Connect Vancouver 2017 - Putting firepower into the next generation fir...Cisco Canada
 
Jithesh_Sr Network Engineer
Jithesh_Sr Network EngineerJithesh_Sr Network Engineer
Jithesh_Sr Network EngineerJithesh reddy
 
KennethBaughResume_2015
KennethBaughResume_2015KennethBaughResume_2015
KennethBaughResume_2015Ken Baugh
 
Cisco Connect Halifax 2018 Putting firepower into the next generation firewall
Cisco Connect Halifax 2018   Putting firepower into the next generation firewallCisco Connect Halifax 2018   Putting firepower into the next generation firewall
Cisco Connect Halifax 2018 Putting firepower into the next generation firewallCisco Canada
 
Exploring the Final Frontier of Data Center Orchestration: Network Elements -...
Exploring the Final Frontier of Data Center Orchestration: Network Elements -...Exploring the Final Frontier of Data Center Orchestration: Network Elements -...
Exploring the Final Frontier of Data Center Orchestration: Network Elements -...Puppet
 

Similar to Router Defense - BRUcon 2010 (20)

Nagabhushana Rao P
Nagabhushana Rao PNagabhushana Rao P
Nagabhushana Rao P
 
Abdul Haleem Alimkhail
Abdul Haleem AlimkhailAbdul Haleem Alimkhail
Abdul Haleem Alimkhail
 
Introduction to Fog
Introduction to FogIntroduction to Fog
Introduction to Fog
 
Cisco Multi-Service FAN Solution
Cisco Multi-Service FAN SolutionCisco Multi-Service FAN Solution
Cisco Multi-Service FAN Solution
 
PLNOG16: IOS XR – 12 lat innowacji, Krzysztof Mazepa
PLNOG16: IOS XR – 12 lat innowacji, Krzysztof MazepaPLNOG16: IOS XR – 12 lat innowacji, Krzysztof Mazepa
PLNOG16: IOS XR – 12 lat innowacji, Krzysztof Mazepa
 
Architecting Secure Web Systems
Architecting Secure Web SystemsArchitecting Secure Web Systems
Architecting Secure Web Systems
 
G rpc talk with intel (3)
G rpc talk with intel (3)G rpc talk with intel (3)
G rpc talk with intel (3)
 
Daniel Pastrana 12-15-19
Daniel Pastrana 12-15-19Daniel Pastrana 12-15-19
Daniel Pastrana 12-15-19
 
AhmetCemilKaratas
AhmetCemilKaratasAhmetCemilKaratas
AhmetCemilKaratas
 
Jatinder Singh
Jatinder SinghJatinder Singh
Jatinder Singh
 
Putting Firepower into the Next Generation Firewall
Putting Firepower into the Next Generation FirewallPutting Firepower into the Next Generation Firewall
Putting Firepower into the Next Generation Firewall
 
Cisco Live! :: Introduction to IOS XR for Enterprises and Service Providers
Cisco Live! :: Introduction to IOS XR for Enterprises and Service ProvidersCisco Live! :: Introduction to IOS XR for Enterprises and Service Providers
Cisco Live! :: Introduction to IOS XR for Enterprises and Service Providers
 
Putting Firepower Into The Next Generation Firewall
Putting Firepower Into The Next Generation FirewallPutting Firepower Into The Next Generation Firewall
Putting Firepower Into The Next Generation Firewall
 
Cisco connect winnipeg 2018 putting firepower into the next generation fire...
Cisco connect winnipeg 2018   putting firepower into the next generation fire...Cisco connect winnipeg 2018   putting firepower into the next generation fire...
Cisco connect winnipeg 2018 putting firepower into the next generation fire...
 
Cisco Connect Vancouver 2017 - Putting firepower into the next generation fir...
Cisco Connect Vancouver 2017 - Putting firepower into the next generation fir...Cisco Connect Vancouver 2017 - Putting firepower into the next generation fir...
Cisco Connect Vancouver 2017 - Putting firepower into the next generation fir...
 
Cv letter page 2
Cv letter page 2Cv letter page 2
Cv letter page 2
 
Jithesh_Sr Network Engineer
Jithesh_Sr Network EngineerJithesh_Sr Network Engineer
Jithesh_Sr Network Engineer
 
KennethBaughResume_2015
KennethBaughResume_2015KennethBaughResume_2015
KennethBaughResume_2015
 
Cisco Connect Halifax 2018 Putting firepower into the next generation firewall
Cisco Connect Halifax 2018   Putting firepower into the next generation firewallCisco Connect Halifax 2018   Putting firepower into the next generation firewall
Cisco Connect Halifax 2018 Putting firepower into the next generation firewall
 
Exploring the Final Frontier of Data Center Orchestration: Network Elements -...
Exploring the Final Frontier of Data Center Orchestration: Network Elements -...Exploring the Final Frontier of Data Center Orchestration: Network Elements -...
Exploring the Final Frontier of Data Center Orchestration: Network Elements -...
 

Router Defense - BRUcon 2010

  • 1. Router Defense Cisco IOS security assessment tool Lightning talk day 2 - 2010
  • 2. Operational security Did you ever seen a Cisco network device with security BCP enforced? « The network is more powerful than the node »
  • 3. The network moves Network (re)design Configuration changes Compromised network devices Network usage (Software update policy, devs plays with mcast) RouterDefense will adapt Recurrent assesment schedule for teh win
  • 4. Threat base reference model Enterprise/Service providers networks agnostic IPv4/IPv6/MPLS Cisco Guide to Harden Cisco IOS Devices (Cisco) Cisco IOS Switch Security Configuration Guide (NSA) Tool's author experience 0-dayz vendor EPIC FAIL proactive prevention (cisco-sa-20100707-snmp)
  • 5. Features Reads Cisco IOS config with a security mindset Management, control, data planes Stdout, HTML(5+CSS3), CSV, PDF output Three-tier architecture Router/switch scenarii IOS versioning CVSS base vectors scoring 138 tests
  • 8. Router Defense tool Written in python during spare time wc -l *.{py,xml} | tail -1 | awk '{ print $1}' 9336 Version 0.2 Available at Google Code http://code.google.com/p/routerdefense/
  • 9. $ whoami Francois Ropert Topics of interest: network protocols and devices security Feel free to ping6 me at: http://www(6).packetfault.org @pello