Better Networks Through Policy

Back in the Fall of 2003, PSU was still considering its wireless plans. Things were moving slowly, and the decision makers seemed to be looking for answers in the wrong places. I’d been agitating for better answers, a simpler solution, lower costs, and more progress. My criticism landed me on the hot seat, and I was soon asked to be more constructive. My answers are in this presentation, the accompanying handout, and a handout for a followup meeting.

At the time, the networking staff was leaning towards a proprietary 802.1x-based authentication scheme that required specific client software and had limited hardware support. The package was rather pricey, would have required additional client software and hardware purchases, and was restrictive in its support of student computers. At an institution that supports over 7000 users, most of whom purchase and maintain their own equipment, the plan seemed to have a lot of shortcomings. I wanted the school to look at the Wireless ISP model, and consider the options used there. I also wanted the networking folks to explore network security over-all, rather than just wireless security, as most network threats affect wired and wireless networks in similar ways.

I no longer work in the IT shop, where I was a sys admin at the time, but this presentation and my arguments may have been successful. The school selected a commercial captive portal authentication system, just like the WISPs. A lot has changed in the wireless market over the intervening year, but I’m offering the presentation here anyway.

Secure Networks

Presentation to
Plymouth State University
IT Systems & Networking Staff
Fall 2003

Security By Isolation

[graphic slides removed, see PDF]

Networked, But Isolated

  • Group computers according to users and their activities
  • Aggressive firewalling as appropriate by group
  • Limit access to networks by group association
  • Also to consider: NAT and NoCatAuth

Policy Based Networking

  • Update our old ideas of ‘private’ and ‘public’ networks
  • Make the logical structure of our network match our access and security policy
  • Develop mechanisms to support and enforce this policy

Network Vulnerabilities

Attack Vectors

  • Attacks originating outside our network
  • Attacks originating from within our network on targets here or elsewhere
  • Man-in-the-middle; interception (sniffing) and manipulation of data en-route

Attacker Profiles

  • The Vandal
    Denial of service, random damage, data loss
  • The Brigand
    Uses our resources in support of greater crimes
  • The Thief
    Data theft or manipulation

From Whom Are We Vulnerable?

  • We fear miscreants and hackers
    …but…
  • Every user, authorized and unauthorized, is a potential threat
  • Threats from ‘authorized’ users, while perhaps less likely, are more directed

Who Are We Trying to Serve?

  • Thousands
  • About 7,000 Faculty, Staff and Students now have computer accounts and privileges here Do we trust every one of them? So…
  • Any decisions about network security must be made with the recognition that we have a huge number of un-trusted users.

WEP

WEP Vulnerabilities

  • WEP is shared encryption…
  • No matter how you distribute it or how often you change the key, all ‘authorized’ WEP users can see and sniff all other WEP ‘encrypted’ traffic

WEP Vulnerabilities

  • …And you don’t even have to crack it…
  • WEP encrypted traffic is sent with IP information in the clear Packets can be intercepted, re-addressed, and re-sent through the AP to a host on the wired network The AP does the decryption, allowing even unauthorized users to easily sniff traffic

Is There An 802.11 Standard That Works?

  • There is lots of activity to find a real solution to WEP’s failures, but…
  • Interoperability is two to three years away What Can We Do Now?
  • First, we must recognize that many of the risks of wireless also exist on our wired network
  • And, yes, wireless will always be less secure than wired communications
  • With that in mind, let’s figure out how to secure our entire network

Reading Room

  • Wireless Hacks by Rob Flickenger O’Reilly Press, 2003
  • Network Magazine CMP United Business Media Remember to be conscious of context Most of the work and reporting is directed to corporate users

Solutions

Similar Service Models

  • Because of the number and types of customers we serve, we’re more like a public service, a utility, an ISP
  • We should look to WISPs — wireless internet service providers — for solutions

The WISP Model

  • Low minimum requirements for client software and hardware — 802.11b wireless with recent browser
  • Use ‘clientless’ authentication — enter credentials in secure web page
  • Depend on application layer security, warn customers to do the same
  • Is secure enough to prevent abuse and theft of service

What Is NoCatAuth?

  • An open-source captive portal for network authentication and client management.
  • Integrates DHCP, firewall, and authentication services.
  • Uses web browser interface to take credentials, changes firewall behavior based on authentication. Looks for and reports ARP spoofing.
  • Free for client and server; requires no additional client configuration.

1 Comment(s)

  1. Pingback by MaisonBisson.com » Blog Archive » WiFi In Public Spaces on September 15, 2005 9:45 am

    [...] I wasn’t leading the wireless charge at the time we were investigating a campus-wide installation, and I’m even further from it now, but I wrote a few posts that addressed the needs and concerns we face: The Wireless Security Landscape, Wireless Vulnerabilities, Better Networks Through Policy, and What For Wireless?. [...]

Comments RSS TrackBack Identifier URI

Leave a comment

 

User contributed tags for this post:

wep sex (249) - sex wep (160) - sex arp (153) - wep tv (153) - WEP COM (100) - arp sex (97) - tv5 sex (95) - WPA swf (67) - sex tv5 (59) - PHP SWF Charts crack (55) - sexgirls (54) - sex wep tv (30) - sex arpe (30) - wep vulnerabilities (30) - sex arp com (28) - wpa crack swf (28) - arap sexk (26) - better sex com (24) - wep sex tv (24) - wep crack swf (23) - crack man world com (22) - sexgirls tv (21) - wepsex (21) - php swf crack (21) - crack PHP SWF Charts (18) - sex wep site (18) - WWW SEX ARP COM (17) - wpa crack (16) - be better networks (15) - tv6sex (15) - arp com (15) - sexy wep (14) - wep swf (14) - swf sex (14) - free wep sex (13) - arp sex com (13) - sex tv 1 tv (13) - wep tv sex (12) - nocatauth wired (12) - captive portal crack (12) - wep sex com (12) - www tv5 sex (12) - crack wep swf (12) - arab wep (11) - unauthorized parkour (10) - free sex wep (10) - sex tv 5 (10) - wired captive portal (10) - www.tv5 sex.com (10) - nocatauth demo (10) - www sex 1 tv (10) - sex.tv5 (10) - www tv5 sex com (9) - sex arab com (9) - crack (9) - wepte sex (9) - sex swf (8) - free wep tv (8) - opensource captive portal (8) - arab sex-wep com (8) - www.sex arp.com (8) - tvsex (8) - better networks (7) - arab sex wep.com (7) - arap sex wep com (7) - sex wep com (7) - wep sex free (7) - crack NoCatAuth (7) - tv5 sex com (7) - www.wep sex.com (7) - arab sex wep (7) - wireless man pdf (6) - google wep com (6) - sex wep camp (6) - wep sextv (6) - wpa swf hacking (6) - wep sexgirls (6) - nocatauth vulnerabilities (6) - wep com sex (6) - PHP SWF Charts key (6) - tv6 sex (6) - sex tv1 (6) - wep crack video (6) - http://www google com/ (6) - wifi captive portal with authentication required (6) - hacking nocatauth (6) - swf Charts crack (6) - wep 4sex (6) - wireless captive portal (6) - tv5.sex (6) - nocatauth wpa (6) - www.sex.arp.com (5) - sexs arp (5) - sex arpe vedeo (5) - arpe sex (5) - SEXGIRLS.TV (5) - www.tv5.sex (5) - de wep com (5) - sexywep (5) - better (5) - arap.sexk (5) - WWW WEP TV COM (5) - commercial captive portal (5) - crack world com (5) - tv wep sex (5) - nocatauth security (4) - captive portal wired network (4) - tv arp com (4) - crackman world com (4) - captive portal security (4) - wep sexy (4) - nocatauth wired network (4) - wired for sex com (4) - wep sexs (4) - swf wifi crack video (4) - wep crack utility (4) - PHP SWF Charts cracked (4) - www sex arp tv (4) - tv on wep (4) - sexarpe (4) - top wep tv (4) - ARAP SEX WEP (4) - open source firewall captive portal (4) - wep key van wifi home network (4) - sex wep sites (4) - WWW WEP TV.COM (4) - wired network threats and solutions (4) - crack man world (4) - wep com 2 (4) - crack wpa swf (4) - arab sexs fre (3) - nocatauth hacking (3) - tv6sex film (3) - captive portal for wired network (3) - php swf licence crack (3) - crack captive portal (3) - wep tv sexy (3) - www.wep.tv (3) - TV Hot com (3) - arp.sex (3) - sex.arpe (3) - free captive portal (3) - sex video wep (3) - google wep (3) - swf wep (3) - Wired Network Security (3) - sex 1 TV (3) - sexgirls hot com (3) - arp sexy (3) - my wep com (3) -