Slashdot Mirror


Securing University Residential Networks?

campusNetworkWatcher asks: "I work for a large University that allows wide open access to most of its networks. There is no firewall of any type, and this is not likely to change in the future. A problem spot I see are the residential networks. For the most part, it is filled with un-patched Windows machines run by non-security-centric users just waiting for the newest virus/worm/trojan. Recent events, and an onslaught of DMCA violations have caught the attention of my superiors (as well as his superiors), but there is little we can do once we track down a compromised machine. With a couple of exceptions, in a couple of departments, there is no group will to do desktop support of student machines. We can tell a user he or she is compromised, but lack the enforcement to make the user fix the problem. My group strongly advocates an open academic environment, but if the network is too open it may negatively affect the people we are running it for. I feel like this must be a problem for many other universities and was wondering how others have handled it (blanket port blocking of NetBIOS, established only traffic, or other options). I am looking for non-intrusive suggestions for protecting the network, while allowing as much access as possible to the students. Any suggestions?"

55 comments

  1. Re:Univ. of Twente? by tsa · · Score: 1

    Oops, here's a link

    --

    -- Cheers!

  2. Lame, but good enough. by vandel405 · · Score: 4, Interesting

    I know it isn't the best answer. But, it works pretty well against the average joe. At UC Berkeley pretty much every ethernet port is guarded with MAC based security. So now if you have a user acting like a bandwidth black hole, you can easily just drop them off the network, and tell them to fix it via web based email. When they do, they tell you, you let them back on.

    1. Re:Lame, but good enough. by mivok · · Score: 2

      Thats what they do at our university (Univeristy of Manchester, UK), but one thing I've always wondered, why not simply pull the plug at the switch? No worries about mac address spoofing (although if the router is configured to block all macs on a certain port, then I guess it wouldnt matter).

      In the terms and conditions, they also have a whole load of draconian rules such as, dont run servers of any kind without permission, dont use NAT.. etc.. etc.. which translates in practise to - 'do what you like, but if you screw up the network, prepare to face our wrath, oh, and by the way, kazaa is EEEEEVILLL'.

      The university also 'recommends' installing a virus scanner (as usual), but they actually provide one for you unser their site license. Of course you still have the problem of making students install it, but its one step further than many other places I've seen.

      With regard to worms etc, I dont see the problem with blanket blocking of certain ports from the outside, perhaps allowing access to those who requested it provided they could demonstrate that they were competent enough to regularly install updates/patches. I dont pretend to understand how to implement that however (ensuring that those with full access actually installed patches and kept up to date would be problematic, and then theres the problem of new attacks, making complete port blocking seem easier), but the suggestion is there.

      Ultimately, you need to come up with a solution which protects/limits those who dont know/care about securing their own computers (default case), while allowing 'power users' (assuming you want to cater for their needs, which from the tone of your post you do) to have restrictions lifted in the special case.

    2. Re:Lame, but good enough. by forsetti · · Score: 2, Informative

      To answer your first question, physically visiting the switch to physically pull the cable takes a lot more time (especially at physically large universities) than telneting to the router to kill the MAC.

      --
      10b||~10b -- aah, what a question!
    3. Re:Lame, but good enough. by Alan+Shutko · · Score: 1

      When I worked in a ResNet, we didn't just block the mac, we turned off the port on the hub. No worries about any spoofing. This required smart hubs, but I'm sure current equipment can do it just as well.

    4. Re:Lame, but good enough. by mivok · · Score: 1

      Yeah I guess, in the case of the halls of residence where I'm at, the distance between the admin and the switch is next to nothing, so I thought nothing of having him get a little exercise when removing somebodys net access. However, as has already been mentioned I think, it is possible to have the port disconnected remotely also (well it would be switched off.. although a nice little robot arm to do the unplugging would be pretty funky).

    5. Re:Lame, but good enough. by TheSHAD0W · · Score: 1

      Sounds good... At least, until your Trojan writers get smart and start messing with the drivers, switching MAC addresses randomly...

    6. Re:Lame, but good enough. by vandel405 · · Score: 1

      well, since its a one MAC per PORT if you switch MACs, the port shuts down.

      Sorry I waasn't clear -
      Jon

    7. Re:Lame, but good enough. by peterjhill2002 · · Score: 1

      Force users to register MAC, if caught stealing MAC/IP then ban user from network for some period of time (like a semester). Not that hard to do.

  3. Scan machines, and turn off ports by danielwright · · Score: 5, Interesting

    The school I go to has an effective policy: firstly, they routinely scan the entire campus network for vulnerable machines using nessus.

    If they find vulnerable machines, or if they detect that a machine has been compromised, they notify the owner, and if the problem is not corrected in an appropriate amount of time, turn off the connection at the switch. If that happens, the owner has to prove that the machine is fixed before they will turn it back on.

    Admittedly, this is a little draconian, but the other residents appreciate that the network isn't constantly congested with dos attacks from compromised machines in their dorm.

    1. Re:Scan machines, and turn off ports by walt-sjc · · Score: 1

      Yeah, and the way to do this is by checking the MAC address so the offendor can't just switch ports. If you wanted to be TRUELY EVIL, force them to use PPPOE... Heh Heh.... Hmm, Nah, I wouldn't want to push THAT on anyone (like the baby bells do...) It's a little TOO evil. :-)

    2. Re:Scan machines, and turn off ports by danielwright · · Score: 2, Informative

      > Yeah, and the way to do this is by checking the MAC address so the offendor can't just switch ports.

      It depends on what environment the computer is in. In a residence, the student has only one port available to him, so he'd have to pick up his computer and move to a friend's room to switch ports (and unless he's malicious, he won't do that). Faking a MAC address is much easier though - it's a simple software setting (how simple depends on your operating system).

  4. Block/Disconnect by Anonymous Coward · · Score: 1

    OK,

    I've been off the university student network for some years, but there are occurrences where the user is just disconnected from the network. A mail is sent to the user, the mailbox is monitored and from the moment the mail is checked, the user is disconnected.I guess that works as a motivation.

    They block almost everything and script the hell out of the logs AFAIK. Most common file sharing programs are detected and mails are sent out to the users, irrespective of what the content is on those programs (which is a bit too harsh).

    The network is almost down to simple browsing over http, even combined with sliding downstream limitation windows.

    I mainly quit because, due to increasing restrictions, it was getting pretty hard to have a decent server running with ssh/cvs/https. And that's worth a commercial service for me at twice the price.

    This is the other side of the medal, and pretty annoying for non-windows-browsing-only users.
    This almost makes a university network pointless (anyone can install a machine that is able to browse, and not being able to access your machine from other machines reduces it to M$ machines). I guess you can contact one of those sysadmins if you want to get BOFH scripts/blocks/advice.

    There are some reasons why such drastic decisions needed to be taken though (e.g. cable access for ssh was extremely slow and basically not usable, vi over ssh for programming is not really an option anymore). I think this is combined with putting the software to secure the machines (with howto's) available, bought by the university with student group licenses. I assume that, if no actions are taken on your network, you'll end up in a simular situation where the network gets saturated (and unusable).

  5. It's a problem, alright... by kruetz · · Score: 1

    I know at the uni I go to, at least one of the residential colleges (which shall remain un-named), they're still suffering from one of the outlook-exploit viruses that's over two years old! It's not Melissa or the I-Love-You, but something of that kind that the unpatched Windows boxes continue to pass around the college network, choking up bandwidth.

    I think that having sysadmin's regularly scanning all machines on the network for known exploits, and then sending them an email informing them how to patch their system is a good idea. If they haven't patched it inside, say, three days, then block their PC from accessing everything you can (eg, college email account, internet access, ...) until they do patch their PC.

    Also, disabling emails with .exe, .pif, .com extensions goes a long, long way. Okay, you need a firewall, but having a network such as yours that accesses the internet basically requires a firewall (at the very least!). You say you can't add one in the near future? Well ... you may be up shit creek. Seriously.

    --

    This sig intentionally left bla... dammit!
    Who's got the whiteout?
  6. It'd be unpopular as hell . . . by user+no.+590291 · · Score: 2, Interesting

    . . . but one thought is to use non-routable IPs inside the ResNet. Harder to attack a machine that can't be reached, with the added bonus of P2P only working for push transfers.

    1. Re:It'd be unpopular as hell . . . by Natalie's+Hot+Grits · · Score: 1

      This is not even a reasonable option. this effectively is a DoS to all yoru users requiring ident and other features that non-routeable IP's cannot do.

      Looking at my port forwarding rules on my router, if I were ever paying for access for a non routeable IP, I would stop paying immediately, especially since these students are paying hundreds of dollars per year in internet access (yes, the internet fee is directly included into the price of the room, per semester)

      --
      Two infinite things: your stupidity and mine. But I'm not sure about the latter. If my sig offends you, I'm sorry.
    2. Re:It'd be unpopular as hell . . . by user+no.+590291 · · Score: 1
      This is not even a reasonable option. this effectively is a DoS to all yoru users requiring ident and other features that non-routeable IP's cannot do.

      And what academic purpose does IRC, the only major service that requires ident, server? Anyways, ident certainly can be done by a proxy server for NATed machines.

      With respect to paying for service, yes, the students are--but schools aren't going to unbundle it--if they don't like what's provided, they're free to go to school elsewhere.

    3. Re:It'd be unpopular as hell . . . by Natalie's+Hot+Grits · · Score: 1

      That is the most ridiculous blanket statement I have ever seen.

      Anyway, what about those other services that need identd? just because they aren't used often, doesn't mean they aren't usefull. NATing everyone is the most retarted thing you could do, and no amount of rationalization is going to fix that.

      "Lets charge our students outrageous network fees with tuition, and then NAT the fuck out of them. That will sure put our network to some GREAT USE!!! wah00000!"

      If you want to effectively stop outsiders to not be able to get to your students computers, why not give them real IPs and filter certain ports at the router level to improve security. I have heard of people using protocol detection software to filter protocols and known exploits that are unwanted. At least then you will:

      1) do less maintenance work
      2) have less support costs
      3) have an actual working network that is usefull.

      Part of the cost of running a network and selling network access, which universities do, is to provide a usefull network with reasonable restrictions to reasonable people. What's next, are you going to start serving DOG FOOD at the school cafeteria because the kitchen staff is too fucking lazy to cook dinner????

      Get real.

      I'm sorry my friend, but your wrong, both technically and morally. NAT isn't going to stop the spread of viruses over your network. It isn't going to stop people from sharing files, and it isn't going to improve security any significant amount that couldn't be done with other means. All it is going to do is restrict usage for the only users on the network that are actually PAYING for the access.

      Security is a full time job. Ignoring the problem by denying access so you can take an extra cigarette break each day is not the solution, and isn't what network admins are hired to do.

      --
      Two infinite things: your stupidity and mine. But I'm not sure about the latter. If my sig offends you, I'm sorry.
    4. Re:It'd be unpopular as hell . . . by user+no.+590291 · · Score: 1
      What academic pursuit, precisely, are students restricted from when behind a NAT?

      And while your dig about "taking an extra cigarette break" each day might hurt if I were a university network admin, I'm not.

  7. Show them the software license. by stienman · · Score: 0, Offtopic

    Show them the software license, specicfically section seven which may or may not apply, and sections 11 and 12 which do apply:

    Section 7 (in part): If, as a consequence of a court judgment or allegation of patent infringement or for any other reason (not limited to patent issues), conditions are imposed on you (whether by court order, agreement or otherwise) that contradict the conditions of this License, they do not excuse you from the conditions of this License.

    Section 11 (all): BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION.

    Section 12 (all): IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

    So the straight answer is that the word indemnification does not occur in the license. Whether the license has no, little, or good indemnification should be judged by a lawyer. It seems as though the GPL protects those who wrote, modified, and distributed the programs in question from those who use the program, but doesn't seem to extend any special protections to those who use the program from their customers or other third parties.

    -Adam

    "I'm not a lawyer, but I play one on slashdot..."

    1. Re:Show them the software license. by sporktoast · · Score: 0

      Oops!

      I bet you meant to post this as a reply to this article.

      --
      In a related story, the IRS has recently ruled that the cost of Windows upgrades can NOT be deducted as a gambling loss.
  8. Registration by Apreche · · Score: 3, Informative

    Here at RIT there isn't much of a firewall either, but there are a few things they do for security.

    1) E-mail filtering. They wont prevent e-mails from getting to you, but if there is an e-mail that possibly has a trojan attatched, then that e-mail is sent to you as an attatchment to another e-mail that warns you "possibly a trojan here".

    2)Registration. In order to get an IP address you have to visit a website start.rit.edu or somethign like that. You use your school name and password to get your static IP address. Each person is only allowed 2 or 3 addresses. If your IP is doing something, they just look up who you are. If you have an unregistered device taking up an IP address then they cut your connection, which will make your roomate kill you.

    3)Free anti virus software, they give out anti-virus software to all users for free.

    4)Prioritizing, they have made other traffic higher priority than file sharing traffic. And they have blocked windows file sharing over the net, but it still works internally.

    5)School rules. The most effective security measure are the usage policies. If you are caught Hacking, you get in serious trouble. It would be almost like throwing your expensive years of college down the toilet. People who have insecure boxes full of viruses and trojans which are doing all kinds of things are discovered quickly by other users, who have personal firewalls, and are geeks. RESnet then "takes care" of them. Just port scanning another computer on the network can ruin you.

    --
    The GeekNights podcast is going strong. Listen!
    1. Re:Registration by oyenstikker · · Score: 2

      They also block incoming port 25 on resnet, presumably so we can't run open relays. Of course, I'd rather they block 25 out, and make us use their SMTP server to send out. (Or would this not fix the problem?) At any rate, I can't run my own mail server. And to make matters worse, RIT doesn't have SSL on their IMAP servers.

      --
      The masses are the crack whores of religion.
  9. Windows Solutions by haplo21112 · · Score: 0, Troll

    ADD to the Terms Of Service that Windows machines must be part of a domain. Create a domain to which you have the administrative control. Then deploy SMS. You now have control to send blanket upgrades and patches to all the machines. Periodically scan for machines that are not on the Domain, contact the offender, if they don't respond, pull the Plug on the network connection(actually if you have good switches all you really have to do is tell the port not to pass traffic.

    --
    Power Corrupts,Absolute Power Corrupts Absolutely, leaving one person(group)in charge is absolutely corrupt.
    1. Re:Windows Solutions by forsetti · · Score: 1

      Unfortunately, this means you then take responsibility for maintaining all of these machines, which can mean a huge workload. A massive patch push across many different hardware/software combinations is asking for trouble anyway.
      Patch push works great if all of your machines are similar in configuration, though.

      --
      10b||~10b -- aah, what a question!
    2. Re:Windows Solutions by jon+doh! · · Score: 1

      not just a huge workload, but wouldn't that also leave them open to some liability?

      what if a MS patch fails on someones machine, they are unable to get it to boot, and their term paper is on it?

      chances are if they're unsavvy enough to know how to run a patch on their own machine, they probably won't know how to pop out the drive and throw it in another box, are the network admins gonna do that for them?

    3. Re:Windows Solutions by Large+Green+Mallard · · Score: 1

      You're kidding right? You want a university's terms and conditions of use to require that administrative access to privately owned machines is given to the reznet admins?

      People like you are the reason that student unions/councils are a good idea.

  10. Null Routes by roachmotel3 · · Score: 1

    At my place of business, whenever an IDS detects a machine that's infected with something or other, we simply add a static route to one of our core routers saying "anything coming from this IP should be routed to the bit bucket". This route then gets redistributed throughout the network, preventing any packet leaving the machine from going anywhere past their local switch.

    It's dirty, and called the ROD (Route of Death), but it works -- the end user figures out really quickly somethings broken, and also realizes that they won't be taken off the ROD until they've fixed their machine.

    You can also use it to block one person at a time, rather than whole blocks of people or services.

  11. Telnet to switch by hackwrench · · Score: 1

    but you can telnet to switches too.

  12. No firewall? Interesting... by Anonymous Coward · · Score: 0

    Would you be so kind as to post which university you work for? A few collegues of mine would be happy to offer you a "free security analysis"

  13. let them police themselves by imsmith · · Score: 2, Insightful

    I work on a small college network (~1000 users) and have set up the residential network as a seperate network with routes to the academic network and the Internet. Access to academic resources is controlled by router ACLs and LDAP authentication.

    We monitor usage with ntop and nessus and post the names of the heaviest users of network capacity (but not the greatest security violations). If the community has a problem with the activity of the user, they can deal with that through the student government. The school lets the students have a pretty free environment, but it does force an authentication for outbound Internet traffic and enforces a ban on duplication of college provided services (like DNS and SMTP servers).

    This has worked well for about a year and a half without much trouble and has let the residential network maximize the capacity of their their 10Mbs network and its T-1 uplink.

  14. Firewall acomodation only by SomethingOrOther · · Score: 1

    At my university the main campus network isn't behind a firewall and is wide open to the net (at least, not any firewall worth speaking of).

    However, the accomodation network (dorms / halls whatever you call 'em) is behind the great firewall of doom.

    The idea being the private machines in the acomodation network are the only machines in the entire university that the sysadmins have no controal over (and are likely to be lusers unpatched windows boxes). Thus only these are firewalled.

    Admitedly, my university takes this policy to extreams. In the accomodation network only ports 80 and 22 arn't blocked. Anyone wanting e-mail access or access to there home directorys has to SSH/SFTP to a unix box on the main campus network. This isn't as difficult as it sounds for windows using newbies. Many use graphical SFTP clients to get files and know how to SSH to a unix box to run pine.

    --
    Anyone quoted by a reporter knows how little they understand
    Don't believe what you read is the truth.
    1. Re:Firewall acomodation only by Natalie's+Hot+Grits · · Score: 1

      This is rediculous and since the students are paying out the ass for this access, really shouldn't be tolerated. Not only is this the most extreme use of a firewall to block access to PAYING USERS (yes, they pay a fucking fortune, more than 50/month they could be getting for DSL, included in the room fee) but it is just plain incompetance that any admin or policy would willfully do such a thing.

      --
      Two infinite things: your stupidity and mine. But I'm not sure about the latter. If my sig offends you, I'm sorry.
    2. Re:Firewall acomodation only by peterjhill2002 · · Score: 1

      First off, both of you need to learn how to spell, just had to say it.

      How do you know how much the students at this person's school are paying for network access? Do you have any idea how much that network access costs? $50 a month will not purchase you all of the core routing equipment so that you can get (at minimum) 10 mbps connections to all of the campus servers. When you buy DSL, what do you get? One connection. At a Uni you are connecting to potentially thousands of other computers at very high speeds.

      The fact is, if Universities did nothing about student P2P serving, they would not be able to buy enough commodity Internet bandwidth to keep up with the demand of all those home P2P users trying to download the latest movie. Throwing more BW just means more file sharing.

      Firewalling an entire campus is just plain silly. It would be like storing the crown jewels in a prison, there are just as many potential troublemakers on the inside as there are on the outside. If a firewall is deemed necessary, it makes more sense placing it as close to the sensitive machines as possible.

      The firewall mentioned above is a bit draconian. Our residence network allows the students to chose their own hostname, get a globally routable IP address and run (pretty much) any services they want, as long as they are not doing anything illegal or commercial. It can be said that running your own http server is educational, or better yet, writing some brand new server that does something cool and interesting.

    3. Re:Firewall acomodation only by Natalie's+Hot+Grits · · Score: 1

      "How do you know how much the students at this person's school are paying for network access? Do you have any idea how much that network access costs? $50 a month will not purchase you all of the core routing equipment so that you can get (at minimum) 10 mbps connections to all of the campus servers. When you buy DSL, what do you get? One connection. At a Uni you are connecting to potentially thousands of other computers at very high speeds."

      This is just my point. wether this school is private or public, the students are paying for at least half the bandwidth, directly(unless there are extreme circumstances where the state pays for it all). A university that has this student access policy is in effect giving something less than you could get with DSL, for a far far greater price. This is just plain silly, and having access to thousands of computers at high speed really doesnt make any difference if you can't access the outside world from your home PC in your dorm. Not to mention that it is impossible physically to get 3rd party internet service in a dorm (because of school policy and contracts in effect at most universities)

      --
      Two infinite things: your stupidity and mine. But I'm not sure about the latter. If my sig offends you, I'm sorry.
    4. Re:Firewall acomodation only by peterjhill2002 · · Score: 1

      What are you talking about? Where do you get the idea that "the students are paying for at least half the bandwidth" ?? Not all colleges/universities are state schools either. Not all money into a University comes from students. Most, if not all, departments do research where they receive money, usually from the government, but more and more from corporations. This money is then used by departments to pay for computing services. Sure the students contribute to the money available for these services also, but most Universities do not have a specific fee for "Internet Access" that they charge to students. Your idea that $50 will buy you a DSL connection probably means that you have no idea what is involved with a University Network. If every student had a dsl connection, and none had direct access to the University network, then every student would need to come into the University network via the commodity Internet connection to access their email, course web pages, student activity information pages. This would soon saturate the University Internet connection. After all you propose that DSL is a better solution.

      Something our University does not do, but some do, they purchase a separate Internet connection just for their dorm users. The housing departments pay the costs for it, if students complain about slow Internet connections, they can talk to the housing department.

      You get a heck of alot more for you money from a decebt University than you get from any ISP. Network Printers, computer clusters, web publishing systems, your own static IP plus the ability to pick your own hostname, wireless network access. These are all things that our university gives students for their money. I think it is pretty fair.

  15. Used to run one... long ago... relied on people. by _Eric · · Score: 1

    I used to run an engineering school's dorm network from 95-97. We enjoyed the school's connection, which was then dispatched to all rooms.

    We were students ourselves, but acountable for what happend on the residence, and the school had one plug to pull to shut us out of internet (literally).

    Our most improtant protection was simply about having people responsible. We had them sign a check of a big enough amount for a student that we would bring to the bank it they broke the loaned ethernet adapter of if they screwed up a lot.

    So basically, pressure on us got translated to the students by ourselve.

    By that time, security hole weren't that a big issue, and we just had to disconnect the visible warez. We also monitored MAC/IP matching, so we could pull the plug of the computer that fucked up easily, but that implied active monitoring (Ahhh the face of the guy to whom you say: "You were right changing your password today, but I found the previous one nicer...")

    On the other hand, it's not so easy for the schools to pull the plug, because on the long run, we were saving them the money from upgrading the school's computers. (I guess now in the USA having a computer is a requirement for the students).

  16. Re:tsarkon reports - teh futare of SLASHDOT fucker by Anonymous Coward · · Score: 0

    Seriously...I have been reading Slash for years and have never moderated...mainly cause I cant find it....will someone point it out to me real quick so I can mod this fuck down?

    I have looked and can never find how you mod up or donw. thx!

  17. Tut Systems SMS by Anonymous Coward · · Score: 0

    http://www.tutsystems.com/

    Supports subscriber isolation via broadcast scopes and/or unique vlan ids for every student, so it's very difficult for viruses to propagate by scanning computers on the local network, and compromised machines don't tend to hurt other local machines. Those accounts can also be disabled via a rule or an entry in a RADIUS server.

    Provides a RADIUS accounting log, with or without RADIUS authentication, and unique IP external IP for every user, so when a DMCA violation occurs, the network administrator can use the notice to find the offending student and shut him or her down if necessary.

    Is non-intrusive, accepting ethernet in and ethernet out, and supporting both static IP addresses and NATed addresses simultaneously.

    Students who have static IPs or real IPs via DHCP (this is configurable) can still run servers if they like, and students who aren't interested in this can be NATed, so students have as much access to the network as possible.

  18. Here at UMass... by leviramsey · · Score: 1

    I run Apache, and I get regular IIS-scans from hosts on the UMass net (128.119.0.0/16). A quick email to some acquaintances of mine at OIT netops and, afaik, the offending MAC addresses are blacklisted until they demonstrate that they're patched.

  19. Problem not always the Students by SpaFF · · Score: 1

    We have a bigger problem with faculty here at my school, especially with the ones that think they know what they are doing and have either installed Microsoft Server Applications (MSSQL, etc.) or Linux (Usually RedHat 6.2 or something equally outdated).

    We can't usually turn their ports off because they pitch a huge fit (and when faculty bitch it is felt more than the students) and we have a hard time fixing it because they are all very paranoid and will only let a tech come look at it when they are in their office (a rare occasion for alot of faculty).

    --
    -----BEGIN GEEK CODE BLOCK----- Version: 3.12 GIT d? s: a-- C++++ UL++++ P++ L+++ E- W++ N o-- K- w--- O- M+ V PS+ P
    1. Re:Problem not always the Students by peterjhill2002 · · Score: 1

      Sounds like your school needs to come up with a Terms of Service. We have no problem turning off access on any machine that is infected or impacting other users service with no good reason.

  20. Port Blocking and Jack Deactivations here by PeekabooCaribou · · Score: 1

    Here at the Rochester Institute of Technology, all Windows file sharing ports are blocked between the internal network at the Internet. I believe Mac ports are turned off as well (along with SMTP, to boot). Any user who is violating the network policy in some way, be it running some sort of illegal file server or unknowningly hosting something of the same sort, has their network jack deactivated.

    --
    "I'll say it again for the logic-impaired." -- Larry Wall.
  21. Use NAT... by Slashed+Otter · · Score: 2, Insightful

    Set-up the whole network behind a machine doing NAT. Users can use DHCP to connect. If a user wants to run a server, give them an static internal IP and assign an external IP and forward all traffic through to their box. That way, only those who want to except the reposibility for securing their machines need to worry about security. It also gives you the option of disabling the forwarding rules if a user gets compromised too often.

  22. You need to start by blocking NetBIOS by milspec74 · · Score: 2

    Your first step is to block NetBIOS from the Internet. For more information about the University of Connecticut's efforts to do so, check out this site: http://security.uconn.edu/windows_block.html. NetBIOS should not be allowed to traverse WAN links, and you need to work on the network managers at your school ASAP to convince them to block it. Once that block is in place you can move on to fancier methods (local policies, Nessus scans, IDS, etc), but until this is blocked everything else will have you chasing your own tail in circles cleaning up after a constant string of compromised hosts.

    If you are serious about this and want help, email security@uconn.nospam.edu and I am sure they will be glad to give you some advice. :)

  23. Re:tsarkon reports - teh futare of SLASHDOT fucker by Anonymous Coward · · Score: 0

    hi dumb cunt.

    - first you have to login

    - then you have to metamoderate and wait.

    - then once a shitload of people join after you do you can moderate.

    but if you "abuse" your moderation status, they put you on a blacklist, so only fucks that lick the "editors" [term used loosly because the editors are fat sexless biased unintelligent nerd geek assholes without real jobs]

    its called groupthink, censorship.

    so with that i say

    FUCK YOU YOU FUCKING GOD DAMN fucking FAG asshole bitch FUCKING PUKE. Fuck your little comment. Ill fuckig shove a hot curling iron in your ass and break your arm with an eastman baseball bat you fucking dumb bitch FUCKER.

  24. ResNet Management by _Splat · · Score: 1

    At my school, which has around 7000 undergraduates plus several professional schools, we employ several tactics to protect our network. We have a set of monitoring tools that detect abnormal network activity from viruses or machines that may have been compromised, as well as machines that are using unusally high amounts of bandwidth. We also have a system that requires registration of every MAC address on the residential network to a student's network ID, so every computer can be associated with a person. An attempt is made to contact them and tell them to correct the problem. If the problem isn't corrected, we shut off their port at the switch. We also keep record of their MAC address and ID, so if they attempt to change their MAC or connect their computer to another port, we can stop them. We leave their access off until appropriate disciplinary action has been taken or the virus/whatever is removed from their computers. In order to assist people who cannot clean their computers themselves, we have a few trained student consultants that can fix it for them, and ensure that they have virus protection appropriately set up.

    --
    -Splat
  25. Re:tsarkon reports - teh futare of SLASHDOT fucker by Anonymous Coward · · Score: 0

    OK tough guy, you didn't even come close to answering my question. All you did was curse.

    "then you have to metamoderate and wait". Not an answer.

    My question was...What is the process? Specifically, *HOW* do you add a point or remove a point from a comment?

    BTW, Your vocabulary is astounding.

  26. Re:tsarkon reports red alert fat sexless fag alert by Anonymous Coward · · Score: 0

    i am tough, and ill fucking kick your ass.

    yes, if you dont metamoderate, youll be bored waiting to moderate, so fuck off again.

    and fuckface, once you can moderate, every single fucking comment looks different because it has moderation tools RIGHT IN THE FUCKING COMMEN HEADER. how about that assfuck? or you could just read the FUCKING FAQ. dumb stupid bitch.

    and about my vocab. if you knew anything about TSARKON you would know, i can turn it on or off. i can be sly snarky intelligent ominous and astonishing when I WANT. not you fuck. i use toilet talk for you because your mentality is inferior and i will speak with language that you can understand fucking ASS BOITCH BIIIATCH so fuck you cunt casket cnucasket mediocritomaton slashbot fucking LOSER. fucking fucking loser.

  27. At my school.. by silvwolf · · Score: 1

    I work for the Housing Dept at my school, doing tech support. We're just responsible from the jack in the room out, don't deal with routers/switches or wiring in the walls. All the rooms just have one jack, so if both roommates want to get a connection, they have to use a hub or switch (we won't help them with those little Linksys router type deals).

    When Network Services (the folks that watch the routers/switches) find someone that is abusing the network, they just turn off the port. Sometimes they'll call the person, sometimes not. My dept then gets to listen to the kids complaining that their connection is dead. We'll tell them why, usually some virus sending out hundreds of emails, and that they need to clean their machine. How they do it is their business, we tell em to go to a computer store if they can't do it themselves. Then we'll send someone out to make sure its clean, usually by installing the school's corp version of Norton AV. Day or so later, and they are turned back on.

    People that are sucking down bandwidth w/ P2P apps will get a letter under their door. If it doesn't stop, they're turned off, and Network Services becomes pretty lazy about turning them back on.

    FWIW, every computer on campus, not just in the dorms, gets a private IP address.

  28. Where I work by Anonymous Coward · · Score: 0

    The residence life is a separate network, with a separate port on the firewall. If they want to use anything "special" on the main campus, they must VPN in. Of course we do port-blocking, private ip space for ORL (separate space from main campus) etc.... as a best-faith effort to block p2p crap and servers.

  29. Filter them all, let god sort them out by peterjhill2002 · · Score: 1

    Curious as to which University you work for and what your exact job is there...

    At CMU, we have a very nice perl script that we can use to add ACLs to our routers (Cisco 6509s) to block all traffic off the subnet to and from hosts who are infected or about whom we receive email from RIAA/MPAA/Random studio saying that they have been caught serving copywritten material. We force all users to register their MAC address with us, and all Residence network machines are using dhcp supplied static global IP addresses (static in that they do not change, not that they are manually configured). (see http://www.net.cmu.edu/netreg/ ). We are working on a very cool replacement for the ACLs that will allow a big red button, no ACLs and centralized killing of machines. Email me, and when the paper has been written up for the public, I can send a copy. I guarentee it is super cool ;-)

    We are not using 802.1x port security, since OS support is not there for everything, and we do not want to limit users. The one mac addr per switch port is not interesting, since that would also unnecessarily limit users.

    By filtering users off the network, we are giving them a reason to fix their machine. We do have a help desk and can walk users through various common problems, but do have a specific list of applications and OS's that we support. If it is needed to get things done for school, it is supported.

  30. LaBrea by F�an�ro · · Score: 1

    I know I am a bit late, but so far noboy else has mentionened LaBrea.

    This is a tool for linux and windows, that can even be run on a linux boot floppy on an unused pc.

    ""LaBrea is a program that creates a tarpit or, as some have called it, a "sticky honeypot". LaBrea takes over unused IP addresses on a network and creates "virtual machines" that answer to connection attempts. LaBrea answers those connection attempts in a way that causes the machine at the other end to get "stuck", sometimes for a very long time.""

    So, while this would be no foolproof protection for your users, it would stop many of the simpler attacs and slow the rest down, and you would automatically be notified if someone tried to scan the whole network or a new code red tried to propagate