The new release focuses on information security: the logic of traffic processing rules has been updated, detailed logging at the backend level has been implemented, and integration with third-party software working with security policies and events has been improved.
Basis SDN shifts the management of an organization's network infrastructure (segmentation, routing, switching, etc.) from the “hardware” level to the software level, simplifying the implementation of complex network scenarios.
New tools for flexible network infrastructure configuration
Basis SDN 1.2 adds templates for the most popular services, including NTP, IMAP, RDP, etc., with pre-installed protocols and destination ports for quick configuration of typical security rules without manual parameter specification. These can be grouped with user-created services, which significantly simplifies the creation and modification of these rules for the customer's information security specialists.
Pre-installed and user-defined services
Basis SDN also allows creating services not only at the transport layer but also at the network layer, meaning IP protocols can be added to the created service by numerical identifier (e.g., 4 — IP-in-IP, 47 — GRE, 50 — ESPP, etc.). This provides additional flexibility to customers' network infrastructure, as they can use various specific protocols within their own network to solve specific tasks, for example, GRE allows creating a virtual tunnel for isolated transmission of IPv6 traffic within an IPv4 network.
Release 1.2 introduced security groups – universal objects to which ports, networks, IPv4 and IPv6 addresses, MAC addresses, and other infrastructure components can be added. The Basis SDN administrator can independently create such an object and then operate with it, for example, when configuring security policies.
Basis SDN Security Groups
Improved event logging for network activity monitoring
Entries in the security rules log of the updated Basis SDN contain more detailed information about the event: which rule triggered, trigger time, traffic type, protocol, source address and port, destination address and port, transport layer data, etc. This information simplifies the identification and analysis of anomalies within the organization's network for information security specialists.
Security rule log entry
The presence of profiles in Basis SDN provides the necessary flexibility for traffic logging. In a logging profile, you can manage the intensity of traffic logging for new and established sessions, as well as set the logging direction: incoming traffic only, outgoing traffic only, or bidirectional. Profiles are applied to security rules and traffic on the fly, without restarting.
Filtering entries in the Basis SDN security rules log is implemented via a special API. This approach allows specialists to search for necessary data in the log by their values, including searching within a port range, by subnet masks, etc. Such a search is much more effective compared to text-based search, since, for example, if a rule applies to a port range from 22 to 80, it can be found by any port within this range, and not only by the boundary values “22” or “80” as in text-based entries. A similar approach is implemented for the security rules themselves, which allows quickly finding the necessary rules and ensures high-quality integration with third-party solutions working with network security policies (NSPM).
Security policies and rules
For effective interaction of Basis SDN with modern SIEM solutions, security rule events are sent to external servers in RAW and CEF formats. Support for the CEF format eliminates the need for information security specialists to manually mark events, which significantly simplifies data processing. If necessary, customer specialists can additionally configure filtering of data transmitted from Basis SDN by the criticality level of the triggered rule. Corresponding settings are available for both the security rules log and the audit log.
Security rules log settings
“In the year since the presentation of Basis SDN, we have expanded the functionality of the solution to the level of world analogues and made working with it simpler and more convenient. In the new release, we did not just add a number of tools, but updated the logic of Basis SDN: implemented bidirectional rules, created several areas of their application, and streamlined inheritance between these areas. The resulting Basis SDN architecture is on par with world analogues and qualitatively surpasses solutions built on open source software,” noted Dmitry Sorokin, Technical Director of Basis.