Understanding network segmentation

View as Markdown

runZero multi-homed asset detection

Network segmentation is a critical security control for many businesses, and verifying that segmentation works can be hard, especially across large and complex environments. Common checks, such as reviewing firewall rules and spot testing from individual systems, only go so far, and thorough testing, such as running full network scans from every segment to every segment, can be time intensive and is difficult to justify on a regular basis.

For businesses subject to the PCI DSS requirements, validating cardholder data environment (CDE) segmentation is part of the security audit process. The PCI guidance on scoping and segmentation describes a common CDE administration model.

runZero’s network bridge detection is opportunistic and far from perfect, but it may point to places where segmentation is broken and cut down on surprises in your next security audit.

Using the bridge report

The bridge report shows external networks in red and internal networks in green. Instead of a typical network map, the view shows possible paths through the network by way of multi-homed assets. To keep the graph readable, it omits assets where runZero detected only a single IP address.

Zoom in to see asset and subnet details. Click a bridged node once to highlight the networks it connects to, and a second time to open the asset page. Click a network once to highlight its connections to bridged nodes, and a second time to run a CIDR-based inventory search.

Bridge detection helps you validate network segmentation and confirm that an attacker can’t reach a sensitive network from an untrusted network or asset. Examples include laptops plugged into the internal corporate network while also connected to a guest wireless segment, and systems on an untrusted network, such as a coffee shop’s wireless network, that also have an active VPN connection to the corporate network.

runZero detects network bridges by looking for extra IP addresses in responses to common network probes (NetBIOS, SNMP, MDNS, UPnP, and others), and it reports bridges only when at least one asset has multiple IP addresses. Typical hardening steps, such as desktop firewalls and disabled network services, usually keep runZero from detecting multi-homed assets.

Using the asset route pathing report

Platform

Network misconfigurations and multi-homed machines can undermine network segmentation. On the runZero Platform, the asset route pathing report lets you visualize potential network paths between any two assets in an organization.

The report graphs multiple potential paths by combining IPv4 and IPv6 traceroute data with subnet analysis of detected multi-homed assets. It needs no access to the hosts or network equipment. This method finds unexpected paths between assets that existing security controls or reviews may overlook.

With a view of potential paths, you can verify whether a low-trust asset, such as a machine on a wireless guest network, can reach a high-value target, such as a database server within a cardholder data environment (CDE). The report exposes potential network segmentation violations and openings for an attacker to move laterally from one segment to another.

For an interactive Layer-2 and Layer-3 topology of every asset in the current scope, open the Network Map.

Updated