11.07.2015 Views

Yale University ITS Information Security Office - Zoo - Yale University

Yale University ITS Information Security Office - Zoo - Yale University

Yale University ITS Information Security Office - Zoo - Yale University

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Yale</strong> <strong>Information</strong> <strong>Security</strong><strong>ITS</strong> AcademicComputing System(ACS) Pantheon<strong>ITS</strong> ACS Aleks Margan notices break-in.Aleks pages the Univ. ISO via beeper.• We investigate.• We assess damage.• We determine onlyone machine affected.We shut down Minerva and swap in a freshlyinstalled “hot spare” machine as Minerva.• We meet with <strong>ITS</strong> TP& ACS directors.• We decide to shut theBanner student Web.We shut down the “Banner” studentinformation system Web interface.• Users logging in onthe Pantheon & <strong>Yale</strong>Web server areprompted to changetheir password.Incident HandlingAnatomy of an incident“Minerva” October 14 1997 “Break-In”• We plan shutdown andswap with fresh “hotspare” system.• We contact <strong>ITS</strong> Dir.• We decide to force apassword change.• We prepare a statement.• We force students whologin to change theirpasswords in two weeks.• Other users (E-Mail) aregiven a grace period.ISO dissects attack during the night of 10/14-15.Prepares CERT & <strong>Yale</strong>CERT reports.• Minerva infosec audit.• Evidence of intrudersessions (w/accounts &programs and source ofattacks) found in logs.Pantheon <strong>Security</strong> Review and Prevention Steps• Solaris OS patchprocedure audited &reviewed.Follow Through Actions• <strong>Yale</strong> Police notified.They contact FBI.• Other Internet sites &<strong>Yale</strong> admins notified.• Offending network’s IPaddress blocked.Aftermath• Log files secured.• Press releases to andinterviews with <strong>Yale</strong>Daily News and <strong>Yale</strong>Herald.•Tripwire softwarespecified and installedon Pantheon systems.• Banner studentsystem re-enabled.• Pantheon Kerberizedlogin and E-Mail accessto be promoted in 1998(encrypted auth & data).

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!