Educause Security Discussion mailing list archives

Re: Virus/Trojan/Worm in the Dorms


From: "James R. Pardonek" <pardonjr () PURDUECAL EDU>
Date: Tue, 6 Sep 2011 12:26:29 -0500

Our switches (Enterasys) allow for the application of ACLs.  That way if someone gets infected or tries to pull some 
funny stuff, we block at the port and the traffic goes nowhere. I’m sure other switches do the same.

 

Please let me know if there is anything additional I can assist you with to ensure the service you received today has 
been excellent. 

 

James R. Pardonek, CISSP CEH CPT

Assistant Director for Information Security and Assurance

Information Services

Purdue University Calumet

Hammond, Indiana

P: (219)989-2745

 

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Jeff Kell
Sent: Tuesday, September 06, 2011 11:43 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Virus/Trojan/Worm in the Dorms

 

On 9/6/2011 10:32 AM, James R. Pardonek wrote: 

It would be interesting to know and helpful for them if they had a switched network with switches that have some 
intelligence in their dorms.  We prevent this by not allowing traffic from student computers that source common ports 
such as DHCP or HTTP.


One of the points that I raised (in a longer private reply) was clarification of the "We contract with AT&T to provide 
internet service in our dorms" statement.  It sounded very much like many of the "outsourcing" solutions that have been 
proposed here from time to time, varying from a simple commodity pipe arrangement (here's your dedicated internet), to 
on-site CPE solutions (typically wireless or cable-box DOCSIS gear).  

If you are outsourcing in the former context, you likely have little control over the premise router unless you 
strictly contracted for the pipe only, so your blocking options may be limited.  In the latter, you have little control 
over any of it.  In either case, I'd lean on the provider for assistance.  

But even if the whole nine yards is outsourced, such an incident is likely damaging to your image or reputation as a 
university...

(Part of my fear of outsourced arrangements)

Jeff



Attachment: smime.p7s
Description:


Current thread: