Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Investigating External Communications that use Untrusted Protocols

SUMMARY You can use a Policy Monitor question that is based on the known list of trusted protocols to monitor traffic in your DMZ. In most organizations, network traffic that crosses the DMZ is restricted to known and trusted protocols, such as HTTP or HTTPS on specified ports.

From a risk perspective, it is important to continuously monitor traffic in the DMZ to ensure that only trusted protocols are present. Use JSA Risk Manager to accomplish this task by creating a Policy Monitor question based on an asset test for actual communications.

Select an option to create a Policy Monitor question based on the known list of trusted protocols for the DMZ.

  1. Click the Risks tab.
  2. On the navigation menu, click Policy Monitor.
  3. From the Actions menu, select New Asset Question.
  4. In the What do you want to name this question field, type a name for the question.
  5. In the What type of data do you want to return drop-down list, select Assets.
  6. In the Evaluate On menu, select Actual Communication.
  7. From the Importance Factor menu, specify a level of importance to associate with your question.
  8. In the Time Range section, specify a time range for the question.
  9. In the Which tests do you want to include in your question panel, select have accepted communication to destination networks.
  10. In the Find Assets that panel, click destination networks to further configure this test and specify your DMZ as the destination network.
  11. Select and include the following inbound ports.
  12. In the Find Assets that panel, click include only so that it changes to exclude.
  13. Click ports.
  14. Add port 80 and 443, and then click OK.
  15. Click Save Question.
  16. Select the Policy Monitor DMZ question that you created, and then click Submit Question.
  17. Review the results to see whether any protocols other than port 80 and port 443 are communicating on the network.
  18. Monitor your DMZ question by putting the question into monitoring mode when the results are tuned.