{"id":9117,"date":"2022-10-05T13:50:15","date_gmt":"2022-10-05T20:50:15","guid":{"rendered":"https:\/\/www.wowrack.com\/blog\/?p=1860"},"modified":"2024-05-16T11:54:22","modified_gmt":"2024-05-16T04:54:22","slug":"networking-problems","status":"publish","type":"post","link":"https:\/\/www.wowrack.com\/en-us\/blog\/security\/networking-problems\/","title":{"rendered":"Helping a School District with a Network Problem"},"content":{"rendered":"\r\n\r\n\r\n<p>It's not uncommon for everyone to experience a network problem. As you can guess, everyday comes with a challenge whether it's recovering files or fighting of a ransomware attack.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\">What was the Network Problem?<\/h2>\r\n\r\n\r\n\r\n<p>A local school district was targeted by cybercriminals. With a lack of budget and holding the belief that school districts are not typically targeted for cyber attacks, the school did not have the manpower or proper security in place.<\/p>\r\n\r\n\r\n\r\n<p>Typically, cyber attacks happen on Friday nights or Saturday mornings to decrease detection. Also, they will typically attempt to break in right before a major operation, such as payroll, to add pressure to the situation. Like most hackers, the group initiated the attack late on a Friday night before payroll was due.<\/p>\r\n\r\n\r\n\r\n<p>As Saturday morning came around, they went to access the student information database only to find an advertisement for Ryuk- a type of ransomware notorious for targeting government, education, and health-sector entities.<\/p>\r\n\r\n\r\n\r\n<p>After doing some trouble shooting they discovered that the events happened as such:<\/p>\r\n\r\n\r\n\r\n<ul class=\"wp-block-list\">\r\n<li>DBA reports issues with server<\/li>\r\n<li>Ryuk found, management notified<\/li>\r\n<li>All windows Servers powered off<\/li>\r\n<li>Payroll database ok, switches disconnected<\/li>\r\n<li>Server backups unrecoverable<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p>Knowing that they had been hacked, the school district cut off their network and began to contact contractors for additional help with the issue at hand.<\/p>\r\n\r\n\r\n\r\n<p>We were contacted Sunday morning and we began to help them with recovering their files and repairing their network. Looking into the issue, we discovered that they were using a flat network.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">The\u00a0<strong>Issue with Using Only a Flat Network<\/strong><\/h3>\r\n\r\n\r\n\r\n<p>Essentially, a flat network only requires one switch to operate. A switch manages data flow in a network acting like a security door.<\/p>\r\n\r\n\r\n\r\n<p>As you can guess, this security door determines which users are allowed in and out of a network. The problem is that if someone can get past that one security door, they have full access to your network.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>How did you solve the Network Problem?<\/strong><\/h2>\r\n\r\n\r\n\r\n<p>Luckily the school district had a physical backup, which helped us rebuild what they had lost. We went and installed proper malware security and segmented their network to further heighten their cyber security.<\/p>\r\n\r\n\r\n\r\n<p>Working closely with their staff, we informed them of the backdoors they had open in their old network and gave them some best practice tips for keeping their network secure.<\/p>\r\n\r\n\r\n\r\n<p>Over the next several months we assisted them with recovering lost files and other tasks needed to help rebuild their network.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">Segmenting the Network Problem<\/h3>\r\n\r\n\r\n\r\n<p>Segmenting a network is a commonly used method to\u00a0build a secure network.\u00a0<\/p>\r\n\r\n\r\n\r\n<p>Essentially, when you segment a network, you add sub-networks. Within each new sub-network, you add a switch; or rather, a \"security door\". Each security door decides who stays and who goes between each sub-network.\u00a0\u00a0<\/p>\r\n\r\n\r\n\r\n<p>Now with more sub-networks in place, an attacker has to go over more hurdles to access the entire system. Essentially, if a hacker gets into their network again, it will then be contained to a single sub-network.<\/p>\r\n\r\n\r\n\r\n<p>After the incident was fixed, the school district acquired more funding and hired proper staff to run their network.<\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>It's not uncommon for everyone to experience a network problem. As you can guess, everyday comes with a challenge whether it's recovering files or fighting of a ransomware attack. What was the Network Problem? A local school district was targeted by cybercriminals. With a lack of budget and holding the belief that school districts are [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":12331,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"categories":[82],"tags":[1167,1180,1168,1163],"class_list":["post-9117","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-backup-ransomware-protection","tag-network-security","tag-ransomware","tag-security","post-wrapper"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/posts\/9117","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/comments?post=9117"}],"version-history":[{"count":0,"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/posts\/9117\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/media\/12331"}],"wp:attachment":[{"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/media?parent=9117"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/categories?post=9117"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wowrack.com\/en-us\/wp-json\/wp\/v2\/tags?post=9117"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}