Solutions

Document a network that cannot be stopped

On critical infrastructure, a tool that wants a change window, an agent or a permanent outbound internet path is ruled out before anyone evaluates it. NacTrack asks for no window and no agent, and for one outbound flow: periodic licence validation, which we name rather than leave unsaid.

The model

Why the model fits this context

Collection is read only, from the management network. Nothing is installed on the devices and the data plane is untouched.

Collection, analysis and reporting need nothing but your own network. The vulnerability catalogue and updates transfer by file. The licence does have to reach our service from time to time.

The result is what sector audits ask for: a dated inventory, a hardening posture per device with the rule and the extract that triggers it, and the list of hardware past vendor support.

  • No change window needed
  • No agent, no reboot
  • No outbound flow of your data
  • Encrypted disk, appliance on site
  • Dated, exportable findings
Old hardware

Old hardware is not the exception here

  • At a port, on a rail network or an energy network, a device installed twelve years ago is a normal device.
  • It works, it is in production, and it will be replaced when there is a reason and a budget.
  • That is exactly the hardware that documents itself worst and exposes the fewest modern interfaces.
  • It is also the most likely to be past vendor support without anyone having noted it.
  • Command line collection reaches it without difficulty. An approach built on modern programming interfaces does not see it at all.
  • Telnet stays accepted where SSH is not available, because refusing to collect that device would leave it out of the inventory.
The perimeter

What leaves the room, and what does not

On critical infrastructure the question is not whether the tool is useful, it is what it puts across the boundary. This is the complete list.

Perimeter diagram: your data stays on your side, only four flows cross the boundaryOn the left, what stays with you: configurations, inventory, topology, compliance results, credentials and reports. None of these cross the boundary. Four flows do cross it: licence validation, outbound and periodic, the only one that cannot be removed; remote support access, outbound and closed by default; the vulnerability catalogue and product updates, inbound, optional and transferable by file.Your sideCollected configurationsInventory and topologyCompliance resultsDevice access credentialsReports producedOutsideLicensing serviceVendor supportTHE PERIMETERLicence validationPeriodic, cannot be removed. Without it, read only after a long window.Support accessClosed by default. You open it, you close it.Vulnerability catalogueOptional, can be transferred by file.Product updatesTriggered by you, can be transferred by file.

Your side

  • Collected configurations
  • Inventory and topology
  • Compliance results
  • Device access credentials
  • Reports produced

Outside

  • Licensing service
  • Vendor support

THE PERIMETER

  • Licence validationoutbound, required, Periodic, cannot be removed. Without it, read only after a long window.
  • Support accessoutbound, optional, Closed by default. You open it, you close it.
  • Vulnerability catalogueinbound, optional, Optional, can be transferred by file.
  • Product updatesinbound, optional, Triggered by you, can be transferred by file.

Nothing on the left crosses. The only flow you cannot remove is licence validation, and the table below repeats it row by row.

See what a first collection reveals