CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-07-11
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 291
Rep Power: 3
lammbo has an average reputation (10+)
Default Credit Card Number Detection

My Security officer has recently asked me if there is any CP feature (SD, AI or WI) that will check packets to determine if they have credit card data. Apparently, the NetScaler guys were trying to sell him this module so we can lock down where CC data is allowed to route.

Are there any CP features that do this already?

Edit: In retrospect, I guess I should have started this thread in the SmartDefense section... Oh well.
__________________
There's no place like 127.0.0.1

Last edited by lammbo; 2008-07-11 at 13:38.
Reply With Quote
  #2 (permalink)  
Old 2008-07-11
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 582
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: Credit Card Number Detection

Quote:
Originally Posted by lammbo View Post
My Security officer has recently asked me if there is any CP feature (SD, AI or WI) that will check packets to determine if they have credit card data. Apparently, the NetScaler guys were trying to sell him this module so we can lock down where CC data is allowed to route.

Are there any CP features that do this already?

Edit: In retrospect, I guess I should have started this thread in the SmartDefense section... Oh well.
(moved to SmartDefense forum)
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
  #3 (permalink)  
Old 2008-07-12
Senior Member
 
Join Date: 2006-09-26
Posts: 822
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: Credit Card Number Detection

Quote:
Originally Posted by BarryStiefel View Post
(moved to SmartDefense forum)
Yes, there are many of vendors out there that sell these devices. It is also
called Data Loss Prevention (DLP) appliance. Most financial service companies
put this device "in-line" along the path before the traffics hit the outbound
Internet firewalls.

Keep in mind that there limitations as what this device can do. It can not
decipher any data that will traverse through an SSL or SSH tunnel, not
without difficulties.
Reply With Quote
  #4 (permalink)  
Old 2008-07-14
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Credit Card Number Detection

Quote:
Originally Posted by lammbo View Post
My Security officer has recently asked me if there is any CP feature (SD, AI or WI) that will check packets to determine if they have credit card data.
None that I am aware of, but it sounds like a good idea.
Reply With Quote
  #5 (permalink)  
Old 2008-07-15
Senior Member
 
Join Date: 2007-07-16
Posts: 625
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Credit Card Number Detection

At the CPX event in Phuket, CP mentioned that DLP solutions are on their roadmap, although they didn't specify what this actually meant. They also mentioned SSL interception technologies.

I'd get in touch with your local friendly SE and ask some questions/submit an RFE on this. I think I'd be a little concerned about the performance implications of such a thing.
Reply With Quote
  #6 (permalink)  
Old 2008-07-15
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 291
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Credit Card Number Detection

Thanks guys! I was certain that would be the answer and I appreciate the confirmation.

I am curious about 1 item though. I actually had the SSL conversation with my security officer before I posted the first entry. Is there a way to offload SSL on the firewall so the data is decrypted and can be inspected at the firewall? Is the firewall capable of storing those certs for decryption purposes?

If this is documented somewhere and you could point me in the right direction, that would be appreciated (I have the R65 doc bundle and will start poking through on my own as well).
__________________
There's no place like 127.0.0.1
Reply With Quote
  #7 (permalink)  
Old 2008-07-15
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 146
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: Credit Card Number Detection

Hi,
i had attended a McAfee conference sometime before and they have products for what you are searching for.
They have product DLP(Data loss prevention)you can set various policies in that even credit card number also.

The another product is there IPS/IDS, it has the ability to store the certificate and check the packets.

I hope this will help you.
Regards
Ranjit
Reply With Quote
  #8 (permalink)  
Old 2008-07-16
Senior Member
 
Join Date: 2007-07-16
Posts: 625
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Credit Card Number Detection

Quote:
Originally Posted by lammbo View Post
I am curious about 1 item though. I actually had the SSL conversation with my security officer before I posted the first entry. Is there a way to offload SSL on the firewall so the data is decrypted and can be inspected at the firewall? Is the firewall capable of storing those certs for decryption purposes?
Not yet.... but there are other products (BlueCoat....) that will do this. IMHO, it makes more sense to manage this on a Proxy device rather than a firewall appliance. Although the whole concept of SSL interception terrifies me just a little bit!
Reply With Quote
  #9 (permalink)  
Old 2008-07-16
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 291
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Credit Card Number Detection

Quote:
Originally Posted by Thorpuse View Post
Not yet.... but there are other products (BlueCoat....) that will do this. IMHO, it makes more sense to manage this on a Proxy device rather than a firewall appliance. Although the whole concept of SSL interception terrifies me just a little bit!
Thanks, I think that's where I heard about the SSL offloading... We had Blue Coat in here for a demo a few months back. As far as scary... only if I don't control the entire segment would I have issues with it. Since I own all the wires and equipment between, I have much less concern.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #10 (permalink)  
Old 2008-07-17
Senior Member
 
Join Date: 2007-06-05
Location: Canada
Posts: 190
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: Credit Card Number Detection

Quote:
Originally Posted by gavvys View Post
Hi,
i had attended a McAfee conference sometime before and they have products for what you are searching for.
They have product DLP(Data loss prevention)you can set various policies in that even credit card number also.

The another product is there IPS/IDS, it has the ability to store the certificate and check the packets.

I hope this will help you.
Regards
Ranjit
I concur with Ranjit. You should check out McAfee's (relatively) new DLP product. The demo that they showcase everywhere addresses this specifically and its pretty amazing
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:08.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0