Jump to main navigation Jump to main navigation Jump to main content Jump to footer content

OSINTaaS - Shadowserver as a Service

HITS IS operates a state-of-the-art warning and information service, which is operated at the LRZ. For this purpose, extensive threat data from the Shadowserver Foundation is taken over as raw data in CSV format by HITS IS as an intermediary, evaluated, processed automatically and sent as a report to the responsible contact persons of the universities.

The HITS IS warning and information service offers the following added value for participating universities:

  • Automated processing of shadowserver reports in CSV format
  • Individually tailored reports on systems affected by vulnerabilities (mapping via IP address)
  • Instructions for network managers or system managers and users on how to deal with the reported vulnerabilities
  • Continuous expansion of the offer with new reports
  • Collection of statistics on reported/vulnerable systems during the recording period
  • Adjusting the report subscription (selecting and deselecting reports, adding new reports)

Scope of Services and Service Specifics

  • Send weekly specific vulnerability reports

 

Service Parameters

  • Configuration requests are carried out during normal office hours (Mon – Thu, 9 a.m. to 5 p.m. and Fri, 9 a.m. to 3 p.m.). Maintenance takes place in scheduled maintenance windows, these are currently Tue., 7:30 a.m. – 9:00 a.m. and Thurs., 7:30 a.m. – 9:00 a.m.

Report Option 1:

  • Sending the reports to a function email address

Report Option 2:

  • Sending of reports to defined recipients (assignment based on technical contact persons for IP addresses/ranges)

Requirements

  • Registration of public IP address ranges of the university with the Shadowserver Foundation, providing a HITS IS function email address.
  • https://www.shadowserver.org/what-we-do
  • Selection of the IP address ranges for which reports should be received, as well as designation of the report recipients (preferably function email addresses).
  • Selection of reports to subscribe to
  • Notification to HITS IS in case of changes (IP addresses, subscribed reports, report recipients)
  • Possibility of receiving encrypted e-mails (S/MIME, OpenPGP) by the report recipient and/or retrieval from a secure online storage
  • Remediation of reported vulnerabilities or active processing of received reports

 

User / Customers

This service is made available to the following categories of users.

 

User classNote
(1), (2)only for members of the Digital Network of Bavaria
(3), (4), (5), (6)not available for these customers

 

The service can be requested by CIO, CISO, ISB, or the data center management of the universities in the digital network via e-mail to informationssicherheit@remove-this.digitalverbund.bayern .