Home >> Security >> Hacking and Viruses

How B.C. hospitals deal with Conficker

How B.C. hospitals deal with Conficker By:  Greg Meckbach On: 10 Nov 2009 For: Network World Canada Creator

The Kelowna-based Interior Health Authority has selected 3Com’s TippingPoint intrusion prevention system to monitor Internet traffic and prevent threats from coming into remote access sites



Email a friend   |  









Print   |   Text + / -   |  Add a Comment   |   Views: 1346   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




A year after the Conficker worm was first observed crawling through corporate networks, a Western Canada hospital administrator has installed an intrusion prevention system (IPS) to deal with such threats.

 

The Kelowna, B.C.-based Interior Health Authority, a part of the provincial government, includes 22 hospitals and other health facilities, including the cities of Kamloops and Cranbrook, plus 53 First Nations communities.

 

All of its network traffic goes through the main data centre, and in the past, its security system was designed to monitor traffic and detect threats, said Kris Jmaeff, IHA’s information systems security specialist.

 

Its security measures include Microsoft Corp.’s Forefront Client Security, plus a firewall from Check Point Software Technologies Ltd. of Redwood, City, Calif.

 

Jmaeff’s main concerns are viruses, Trojans, malware and data loss. When Conficker first surfaced, IHA had trouble identifying the machines that were infected, he said.

 

But then IHA started beta testing three IPS systems, including Sourcefire Inc. of Columbia, Md., IBM Corp.’s Proventia and TippingPoint, made by Marlborough, Mass.-based 3Com Corp.

 

IHA selected the TippingPoint 330 IPS appliance, which is designed to monitor traffic at up to 300 Megabits per second. 3Com says the 330 IPS can block a variety of threats, including worms, viruses, phishing and blended threats. It can also alert administrators to suspicious activity.

 

“We can see which machines are trying to connect to the internet,” Jmaeff said. “Any data that tries to leave our perimeter, we catch, we watch, we can stop and we can fix.”

 

“We provide a set of filters that catches all the permutations of Conficker,” said Craig Phelps, TippingPoint’s product marketing manager. “A firewall is really a port level (and decides) yes or no, should I let this traffic in through this port?’ We do deep packet inspection at Layers 1 through 7, crack open the payload and decide, is this a threat or not?”

 

Jmaeff said the ability to actually look at the payload of packets was one of the reasons IHA chose IPS. He added TippingPoint was selected partly because of the reports it can create.


Sign up for our Newsletters
Greg Meckbach Greg Meckbach Greg Meckbach is editor of Network World Canada and has worked for ComputerWorld Canada, Communications & Networking and Computing Canada.

Related Articles

Related Blogs

Comments (0)

No Comments!
You are currently not logged in: Register | Login

You must be logged in to submit a comment.