Program/Track A/A.2/Methodology For Operational Monitoring Of Information Security Of Large-Scale Networks With Dynamic Adaptation Of Scanning Intensity
Methodology For Operational Monitoring Of Information Security Of Large-Scale Networks With Dynamic Adaptation Of Scanning Intensity
Andrey Minyaev, Artem Kulichkin, Sameh Alkattan
15m
In conditions of large-scale networks (hundreds of thousands of nodes, multiple VLANs, layer /8 address spaces), classical agentless information security control schemes based on periodic "full" scans face a contradiction: increasing the depth of analysis (service versions, banners, OS, vulnerabilities) dramatically increases cycle time and impact on infrastructure, while reducing intensity impairs the efficiency of identifying new assets and anomalies. The guidelines for continuous security monitoring document the need to select monitoring frequencies and metrics that are adequate to the risk and acceptable impact on operation. The article proposes a methodology for operational monitoring of information security of large-scale networks based on agentless scanning with dynamic adaptation of intensity (speed, depth and frequency) in a closed control loop. The methodology combines a two-phase architecture (rapid exploration through a limited number of ports and subsequent in-depth refinement of services only for detected targets), and a risk-based distribution of the "scan budget" between segments/assets, taking into account network/scanner load, segment criticality, the "prescription" of the last check and the criticality of identified vulnerabilities (according to CVSS v3.1 as a standardized metric of severity). According to the testing of the author's agentless monitoring system, a significant reduction in the scan cycle duration is achieved while maintaining the depth of analysis and controlled impact on the infrastructure: an increase in the completeness of detection of active nodes by 15–20%, the accuracy of comparison with the "white list" up to 95% and a reduction in false alarms by 25–30% compared to one-time inventory scans.