Security, Vulnerability Scanning Program, General Information
Introduction
This document details the security vulnerability program, common sources, tools, and policies used by Security for vulnerability management at the University of Illinois.
Technology Services scanning is a supporting service/control and does not replace the responsibility of service owners, support teams, and administrators to identify and manage vulnerabilities, exposure, and associated risks on their systems and services.
Program Goals
System Vulnerability Scanning
- Goal: Continuously probe university systems and networks for vulnerabilities and exposures such that the university has the most accurate and timely information.
- Goal: Provide service owners with access to accurate and timely vulnerability information.
- Goal: Perform timely scans of critical infrastructure including data centers.
- Service: Consult with stakeholders, service managers, and interested parties regarding: understanding results, understanding tools available, security scanning practices, planning/prioritizing remediation, validating results.
- Limitation: Scanning is currently performed on the University of Illinois Urbana-Champaign and University of Illinois Springfield wired networks.
Application / Web application Vulnerability Scanning
- Goal: Continuously probe university web applications for vulnerabilities and exposures such that the university has the most accurate and timely information.
- Goal: Provide service owners with access to accurate and timely vulnerability information.
- Goal: Perform timely scans of web application infrastructure.
- Service: Consult with stakeholders, service managers, and interested parties regarding: understanding results, understanding tools available, security scanning practices, planning/prioritizing remediation, validating results.
- Limitation: Application owners must follow and implement secure coding practices for proper remediation of application vulnerabilities. Cybersecurity, Code Risk Discussion Questions
Internal / External Vulnerability Reports
- Goal: Provide a source for Internal / External agencies to report vulnerabilities.
- Goal: Review, approve, and implement appropriate external reporting and scanning services.
- Service: Validate reports and forward appropriate information to service owners and stewards.
- Service: Respond to critical vulnerabilities with appropriate action sanctioned by university leadership.
- Service: Report overall state of vulnerability detection capabilities and known campus vulnerabilities to campus leadership.
- Limitation: Internal scanning may only be conducted on services / systems owned by the unit and must use approved security tools.
- Limitation: External reports vary in quality and validation requirements may exceed staffing resources.
Risk
Urbana campus and the Office of the CIO have approved network, system, and application scanning as a fundamental risk management practice. While scanning inherently carries some risk, efforts are made to limit impact to systems and services, and scanning tools and processes are regularly reviewed for effectiveness.
Vulnerability Scanning Practice and Tools
The below tools or services are commonly utilized as sources of vulnerability data on campus.
|
TOOL
|
DESCRIPTION
|
HOW TO GET/USE
|
|---|---|---|
| CrowdStrike Falcon sensor | Agent based threat and vulnerability detection | |
| CrowdStrike Network Scanning | Active network scans run continuously | Currently for Technology Services Security team use only |
| Nmap | Scriptable port scanner | Free tool; Can be downloaded, installed and used by responsible IT pros on any Linux or Windows computer |
| CrowdStrike EASM | Passive web application scanner run by CrowdStrike which continually scans for Illinois external assets | Privacy and Security will monitor vulnerability reports and communicate confirmed vulnerabilities to unit |
| OWASP Zed Attack Proxy (ZAP) | Web application vulnerability testing tool. Can be used with the Desktop Graphical User Interface or Docker. |
Free tool; Can be downloaded, installed and used by responsible IT pros. Documentation, including their Getting Started Guide, is available . |
- Scan reports are considered confidential and should not be shared with non-stakeholders unless authorized by the campus Chief Information Security and Privacy Officer.
- Vulnerability scans will be stored in the Security Office's logging environment for correlation with network based attacks.
Scanning Engine Source List
Technology Services maintains multiple vulnerability assessment technologies each targeting specific layer in the service delivery stack, though some degree of overlap exists in each.
Authorized scanning resources are listed below for general reference. This is a non-inclusive list as the vulnerability program needs it may use additional resources not listed here. External agencies both approved and not approved continuously scan our network for vulnerabilities. If you have questions about scanning activity from the any source, feel free to contact securitysupport@illinois.edu
|
ENGINE TYPE(S)
|
FQDN
|
IP/NET
|
NOTES
|
|---|---|---|---|
| Nmap, application scanning tools, etc. | scanner.opia.illinois.edu |
192.17.82.165 2620:0:e00:4008::5 |
Multipurpose security scanner, other tools used as needed |
| Crowdstrike Network Scanners |
CRWDSTRKSCAN[01-06].ad.uillinois.edu CRWDSTRKSCAN-UI (UIS scanner) |
192.17.170.4 192.17.170.5 192.17.170.10 192.17.170.11 192.17.170.13 192.17.170.14 10.64.1.90 |
Scanning servers |
| CrowdStrike EASM | --- | 52.8.221.60 13.52.148.107 52.52.20.134 |
Passive web application scanner run by CrowdStrike which continually scans for Illinois external assets |
| Shodan | census[1-12].shodan.io | † | †There are many shodan scanners, but they all should resolve to shodan.io addresses. Use the shodan web console to enumerate info found by Shodan. |
IT Security Standards and Controls Information
CrowdStrike network scans meet the controls regarding unauthenticated vulnerability scanning: Network Security - IT 03.10.1, Client Computer Security - IT 10.10.1, Server Security - IT 04.10.1
Installing the CrowdStrike Falcon agent is required for High Risk systems.
Detailed information about security controls can be found at: https://go.illinois.edu/securitycontrols
Recurring Scan Practices
Regular vulnerability scans are conducted to maintain accurate and timely vulnerability information for campus assets. These scans are conducted with the CrowdStrike network scanning platform. Administrators and stewards are responsible for reviewing critical scan results and are expected to remedy or mitigate exposures in a timely fashion.
Continuous Wired Network Scan-
Every wired device on the network is to be scanned at least monthly.
-
Current scanning covers 3,200 CDB asset groups and around 70,000 hosts.
-
-
Scanning is scheduled based on asset groups in CDB and notification is sent based on primary contacts.
- You can update your primary contacts in CDB by following the guide:
Networking, Contacts Database, How do I add remove or change info in CDB?
- You can update your primary contacts in CDB by following the guide:
-
The scan template has been determined to be the minimum required to get basic vulnerability information.
-
Devices disrupted by this type of scan are considered vulnerable by default as this indicates susceptibility to DoS or other style attacks.
-
-
Exceptions to scanning can be requested by completing this form: Scanning Exception Form
-
Devices not excluded or scanned manually with this profile will be considered compliant with IT04.10.1 IT03.10.1 and IT10.10.1 vulnerability controls.
-
If an IT Pro needs to cancel a currently running scan or the next scheduled scan, please reach out to SecuritySupport@illinois.edu
Contacts
For any questions please email securitysupport@illinois.edu.