Better Networks Through Policy

Back in the Fall of 2003, PSU was still considering its wireless plans. Things were moving slowly, and the decision makers seemed to be looking for answers in the wrong places. I’d been agitating for better answers, a simpler solution, lower costs, and more progress. My criticism landed me on the hot seat, and I was soon asked to be more constructive. My answers are in this presentation, the accompanying handout, and a handout for a followup meeting.

At the time, the networking staff was leaning towards a proprietary 802.1x-based authentication scheme that required specific client software and had limited hardware support. The package was rather pricey, would have required additional client software and hardware purchases, and was restrictive in its support of student computers. At an institution that supports over 7000 users, most of whom purchase and maintain their own equipment, the plan seemed to have a lot of shortcomings. I wanted the school to look at the Wireless ISP model, and consider the options used there. I also wanted the networking folks to explore network security over-all, rather than just wireless security, as most network threats affect wired and wireless networks in similar ways.

I no longer work in the IT shop, where I was a sys admin at the time, but this presentation and my arguments may have been successful. The school selected a commercial captive portal authentication system, just like the WISPs. A lot has changed in the wireless market over the intervening year, but I’m offering the presentation here anyway.

Secure Networks

Presentation to
Plymouth State University
IT Systems & Networking Staff
Fall 2003

Security By Isolation

[graphic slides removed, see PDF]

Networked, But Isolated

  • Group computers according to users and their activities
  • Aggressive firewalling as appropriate by group
  • Limit access to networks by group association
  • Also to consider: NAT and NoCatAuth

Policy Based Networking

  • Update our old ideas of ‘private’ and ‘public’ networks
  • Make the logical structure of our network match our access and security policy
  • Develop mechanisms to support and enforce this policy

Network Vulnerabilities

Attack Vectors

  • Attacks originating outside our network
  • Attacks originating from within our network on targets here or elsewhere
  • Man-in-the-middle; interception (sniffing) and manipulation of data en-route

Attacker Profiles

  • The Vandal
    Denial of service, random damage, data loss
  • The Brigand
    Uses our resources in support of greater crimes
  • The Thief
    Data theft or manipulation

From Whom Are We Vulnerable?

  • We fear miscreants and hackers
    …but…
  • Every user, authorized and unauthorized, is a potential threat
  • Threats from ‘authorized’ users, while perhaps less likely, are more directed

Who Are We Trying to Serve?

  • Thousands
  • About 7,000 Faculty, Staff and Students now have computer accounts and privileges here Do we trust every one of them? So…
  • Any decisions about network security must be made with the recognition that we have a huge number of un-trusted users.

WEP

WEP Vulnerabilities

  • WEP is shared encryption…
  • No matter how you distribute it or how often you change the key, all ‘authorized’ WEP users can see and sniff all other WEP ‘encrypted’ traffic

WEP Vulnerabilities

  • …And you don’t even have to crack it…
  • WEP encrypted traffic is sent with IP information in the clear Packets can be intercepted, re-addressed, and re-sent through the AP to a host on the wired network The AP does the decryption, allowing even unauthorized users to easily sniff traffic

Is There An 802.11 Standard That Works?

  • There is lots of activity to find a real solution to WEP’s failures, but…
  • Interoperability is two to three years away What Can We Do Now?
  • First, we must recognize that many of the risks of wireless also exist on our wired network
  • And, yes, wireless will always be less secure than wired communications
  • With that in mind, let’s figure out how to secure our entire network

Reading Room

  • Wireless Hacks by Rob Flickenger O’Reilly Press, 2003
  • Network Magazine CMP United Business Media Remember to be conscious of context Most of the work and reporting is directed to corporate users

Solutions

Similar Service Models

  • Because of the number and types of customers we serve, we’re more like a public service, a utility, an ISP
  • We should look to WISPs — wireless internet service providers — for solutions

The WISP Model

  • Low minimum requirements for client software and hardware — 802.11b wireless with recent browser
  • Use ‘clientless’ authentication — enter credentials in secure web page
  • Depend on application layer security, warn customers to do the same
  • Is secure enough to prevent abuse and theft of service

What Is NoCatAuth?

  • An open-source captive portal for network authentication and client management.
  • Integrates DHCP, firewall, and authentication services.
  • Uses web browser interface to take credentials, changes firewall behavior based on authentication. Looks for and reports ARP spoofing.
  • Free for client and server; requires no additional client configuration.

1 Comment(s)

  1. Pingback by MaisonBisson.com » Blog Archive » WiFi In Public Spaces on September 15, 2005 9:45 am

    [...] I wasn’t leading the wireless charge at the time we were investigating a campus-wide installation, and I’m even further from it now, but I wrote a few posts that addressed the needs and concerns we face: The Wireless Security Landscape, Wireless Vulnerabilities, Better Networks Through Policy, and What For Wireless?. [...]

Comments RSS TrackBack Identifier URI

Leave a comment

 

User contributed tags for this post:

wep sex (248) - sex wep (155) - wep tv (153) - sex arp (152) - WEP COM (100) - arp sex (96) - tv5 sex (94) - WPA swf (67) - sex tv5 (58) - PHP SWF Charts crack (55) - sexgirls (54) - wep vulnerabilities (30) - sex wep tv (30) - wpa crack swf (28) - sex arpe (28) - sex arp com (28) - better sex com (24) - wep crack swf (23) - crack man world com (22) - wepsex (21) - arap sexk (21) - sexgirls tv (21) - php swf crack (21) - wep sex tv (20) - crack PHP SWF Charts (18) - WWW SEX ARP COM (17) - sex wep site (17) - wpa crack (16) - tv6sex (15) - be better networks (15) - arp com (15) - sexy wep (14) - swf sex (14) - wep swf (14) - sex tv 1 tv (13) - arp sex com (13) - free wep sex (13) - www tv5 sex (12) - crack wep swf (12) - captive portal crack (12) - wep tv sex (12) - nocatauth wired (12) - wep sex com (12) - arab wep (11) - free sex wep (10) - wired captive portal (10) - sex.tv5 (10) - nocatauth demo (10) - unauthorized parkour (10) - www.tv5 sex.com (10) - sex tv 5 (10) - www sex 1 tv (10) - sex arab com (9) - crack (9) - www tv5 sex com (9) - wepte sex (9) - sex swf (8) - opensource captive portal (8) - tvsex (8) - free wep tv (8) - www.sex arp.com (8) - arab sex-wep com (8) - www.wep sex.com (7) - arab sex wep.com (7) - crack NoCatAuth (7) - better networks (7) - wep sex free (7) - sex wep com (7) - arap sex wep com (7) - wpa swf hacking (6) - wep crack video (6) - google wep com (6) - PHP SWF Charts key (6) - wifi captive portal with authentication required (6) - wep sexgirls (6) - swf Charts crack (6) - arab sex wep (6) - tv5 sex com (6) - wireless man pdf (6) - sex tv1 (6) - wireless captive portal (6) - nocatauth wpa (6) - nocatauth vulnerabilities (6) - http://www google com/ (6) - tv6 sex (6) - sex wep camp (6) - wep sextv (6) - wep com sex (6) - tv5.sex (6) - hacking nocatauth (6) - www.tv5.sex (5) - de wep com (5) - www.sex.arp.com (5) - crack world com (5) - arap.sexk (5) - sexs arp (5) - arpe sex (5) - sexywep (5) - WWW WEP TV COM (5) - commercial captive portal (5) - sex arpe vedeo (5) - SEXGIRLS.TV (5) - WWW WEP TV.COM (4) - crackman world com (4) - tv on wep (4) - www sex arp tv (4) - swf wifi crack video (4) - wep sexy (4) - crack man world (4) - PHP SWF Charts cracked (4) - sex wep sites (4) - captive portal security (4) - wep key van wifi home network (4) - wired for sex com (4) - crack wpa swf (4) - wep sexs (4) - wep crack utility (4) - tv arp com (4) - nocatauth security (4) - ARAP SEX WEP (4) - open source firewall captive portal (4) - top wep tv (4) - wep com 2 (4) - captive portal wired network (4) - wired network threats and solutions (4) - nocatauth wired network (4) - better (4) - tv wep sex (4) - wep tv sexy (3) - arab sexs fre (3) - SexGirls More (3) - TV Hot com (3) - swf wep (3) - google wep (3) - Wired Network Security (3) - php swf licence crack (3) - php swf chart crack (3) - sex 1 TV (3) - my wep com (3) - wep site (3) - nocatauth hacking (3) - tv6sex film (3) - sexgirls hot com (3) - free captive portal (3) - wep t v (3) - captive portal for wired network (3) - www.wep.tv (3) - sexarpe (3) - arp sexy (3) - sex video wep (3) -