Liquid Telecom Network Security
Network Security - Availability Physical Infrastructure – PoP Site Security/Traffic Protection Logical – Device Hardening/Traffic Protection Processes – Fraud Management
Physical Security – PoP site Surveillance CCTV Fire Alarms Motion sensors and door alarms Lock and Key Alarm Response from security companies
Physical Access (Access Authorisation) Call site access agent Your information and purpose Duration of access Access codes
Other - Power UPS Generators
Logical – Device Hardening Securing Device Unauthorised Access (login) and attacks Terminal passwords Alpha-numeric with minimum length AAA remote authentication Password expiration
Logical – Device Hardening (cont.) Disable unnecessary services & features (e.g.http, telnet, ip redirects, pad, etc) Use secure protocols (SNMP v3, ssh) Control plane policing Traffic policing/shaping
Logical – Device Hardening (cont.) Shut unused interfaces Software patches Logging Network Monitoring & Management Systems behind firewalls
Traffic Protection – Physical & Logical Physical route diversity Logical protection (MPLS)
NMMS High Availability Behind firewall
DDoS Monitoring devices Fingerprints continuously updating Sends Alerts to interested parties Mitigation
Processes Work Order process flow
Experiences Login attempts DDoS Solution – black hole
Discussion/Questions