InfoSec from an ISP’s Perspective

Theo Baschak

BSides Wpg 2013-11-17

Online HTML5 Slides

Presentation source/download available at github.com/tbaschak/bsideswpg2013-ISPInfoSec

Who I Am

  1. Elected member on the Board of Directors for the Manitoba Internet Exchange (MBIX).
  2. Also involved with the creation and technical operations of the Winnipeg Internet Exchange (WpgIX).

Notable Projects

Overview

Knowing Your Network

Discovery

Monitoring Tools

Logging

Documentation

Problems? What Problems?

2011 Ubiquiti Worm

December 19, 2011 - A botnet-installing worm becomes very public, gregsowell.com, UBNT forums and full-disclosure

This worm targeted the widely popular Ubiquiti ISP platform, versions 3.6.1/4.0/5.x, and downloaded a botnet client to permanent storage on the affected device itself.

Spoofed Traffic & UDP Services

Automated Attacks

Significant BGP Events

  1. 2008 Pakistan Youtube Nullroute BGP Leak
  1. 2012 Bell/Tata BGP Leak
  1. 2013 Spamhaus DDoS

The Pirate Bay ‘Moves to North Korea’

As proof that they know how the internet works better than the authoritites chasing them, The Pirate Bay hijacks some North Korean networks, and injects them into a satellite BGP session in Cambodia.

Best Current Practices

BGP Filtering

Edge ACLs

Communication With Other ISPs

The End

Presentation source/download available at github.com/tbaschak/bsideswpg2013-ISPInfoSec