Current Issue


Table of contents

CD-ROM

Sys Admin and The Perl Journal CD-ROM version 12.0

Version 12.0 delivers every issue of Sys Admin from 1992 through 2006 and every
issue of The Perl Journal from 1996-2002 in one convenient CD-ROM!

Order now!

Sys Admin Magazine > Archives > 2006 > December
SysAdminMag.com

Using DNSBLs to Monitor Network Security

Luis E. Muñoz

Many email administrators are turning to DNSBLs -- DNS Block Lists -- as useful weapons in the arsenal against spam. There are DNSBLs covering many aspects of the security spectrum related to spam. A brief sample of the overall focus of the most common lists include:

  • Open HTTP proxies
  • Open SMTP proxies
  • Zombies or trojaned machines
  • Miscellaneous open proxies
  • Hosts that send spam to spamtrap addresses

These lists continue to grow despite the efforts of the community to educate the general public and, more importantly, the administrators responsible for the operation or security of the network. No matter how many security measures we implement in our network, the reality is that a lot of computers in the public network and in our datacenters, are compromised each day.

This article will introduce another useful application for the DNSBLs. I'll show how to use this valuable information source to diagnose and monitor the overall security level of a given network. I'll do so by generating a sort of "reputation" or index, based in the information collected from the lists themselves.

The code I will use for this, although simply an example, is available from the Sys Admin Web site:

http://www.sysadminmag.com 
            
The Lists

One of the first things to do is research the existing DNSBLs.




MarketPlace

Build IT Knowledge with Current & Trusted Content
Helps Employees Develop & Hone New Technical Programming Skills. Sign Up & Get Full Access.

Six Sigma Certification
100% Online-Six Sigma Certificate from Villanova - Find Out More Now.

Workflow Enabled Help Desk & IT Service Management
Automate service desk activities and integrate processes across IT. Learn more here.

WinDev 11 - Powerful IDE
Develop 10 times faster ! ALM, IDE, .Net, RAD, 5GL, Database, 5GL, 64-bit, etc. Free Express version

Wanna see your ad here?