The Bell Labs Security Framework: Making the Case for End-to-End Wi-Fi Security
|
|
|
- Bonnie Moody
- 10 years ago
- Views:
Transcription
1 T E C H N O L O G Y W H I T E A E R The Bell Labs Security Framework: Making the Case for End-to-End Wi-Fi Security Wi-Fi technology has dramatically improved the flexibility and productivity of end users. At the same time, however, it has created serious security concerns for service providers and enterprise IT managers, risking exposure of critical data across a wide range of networks. What steps can you take to make sure that this critical data is protected? This white paper explores the security implications of wireless LAN from the perspective of enabling service providers to prepare their enterprise customers security in end-toend network environments; and delivers the insights necessary to identify gaps and recommend potential solutions in the security of various Wi-Fi standards, such as, (Wi-Fi rotected Access) 2, and (Wired Equivalent rivacy). Additionally, this paper explores the Bell Labs Security Framework, the foundation for security architecture standards ITU-T X.805 and ISO/IEC This framework delivers a comprehensive methodology for assessing and upgrading end-to-end network security across the enterprise analyzing end-to-end security at each stage of a WLAN s lifecycle: design, planning, implementation, and maintenance.
2 Table of Contents 1 Introduction 2 Bell Labs Security Framework Overview 2 Assembling a Comprehensive Security Model 3 Security Layers 3 Security lanes 3 Security Dimensions 3 Modular Methodology 4 Using the Bell Labs Security Framework to Secure Wi-Fi Networks 4 The Reference Architecture 5 Scope of the Analysis 5 Wi-Fi Threat Model 5 Wi-Fi Layers 6 Wi-Fi lanes 6 Applying Security Dimensions 6 Access Control 7 Authentication 7 Data Confidentiality 8 Data Integrity 8 Availability 9 Analysis Summary 10 Recommendations 11 For More Information 11 Sources 12 About the Authors 12 Ashok Gupta 12 Theresa Buthmann
3 Wi-Fi networks can transform an enterprise, freeing end-users from ties to a desktop computing setup and allowing them to be far more productive. A truly mobile enterprise would have a significant business advantage with the flexibility to shift strategies and realign its mission with the market far faster than its competitors. However, what s been missing from the vision of a mobile enterprise is a method to substantively evaluate the end-to-end security of Wi-Fi networks. There has been no truly satisfactory way to accurately appraise every security aspect of a Wi-Fi network and provide IT professionals with solutions that identify and correct Wi-Fi security shortfalls. The Alcatel-Lucent Bell Labs Security Framework, which is the foundation for security architecture standards ITU-T X.805 and ISO/IEC , offers a solution to this problem. The framework delivers a comprehensive methodology for assessing and upgrading end-to-end network security across the enterprise. Bell Labs is playing a big role in helping bring secure wireless connectivity to enterprises and government agencies with an understanding that to be truly effective, end-to-end security considerations must be evaluated and properly implemented at every stage of a network s lifecycle. Admittedly, performing a comprehensive security evaluation is a complex undertaking. The Bell Labs Security Framework makes it possible to evaluate one of the most vulnerable aspects of a Wi-Fi infrastructure the airlink. Furthermore, IT professionals can determine if data traveling across that link is adequately protected and, if not, what steps to take to assist in rectifying the situation. Introduction Despite the advantages that Wireless LANs (WLANs) bring to the enterprise, questions about wireless security have raised concern for companies considering its implementation. In addition to the myriad vulnerabilities of conventional wired networks, wireless networks also have a host of other vulnerabilities associated with the use of radio communication and mobile clients. In fact, wireless LANs lack even the most basic protection against unauthorized access a physical barrier. ackets are transmitted over the airlink, which makes it relatively easy to eavesdrop, intercept them, inject malicious payloads, or launch a DoS (Denial of Service) attack. Similarly, wired networks typically have some security measures in place, such as firewalls, IDS/IS (intrusion detection/protection system), proxy servers, and content security systems to protect the end-user device (e.g. laptop) and the information. But, when a device such as a laptop computer, generally protected in a wired environment, moves to an unprotected wireless network, such as a public hotspot, the protections simply vanish. As discussed later in this paper, most of the security vulnerabilities in Wi-Fi networks can be addressed with the available protocols and security mechanisms and a reasonably secure Wi-Fi network with an acceptable level of risk for most enterprises can be deployed. To achieve this, IT organizations need a mechanism that can analyze end-to-end security at each stage of a WLAN s lifecycle: design, planning, implementation, and maintenance. Now, a decade after WLAN technology first became generally available, they have exactly that the Bell Labs Security Framework, which facilitates secure network design and comprehensive end-to-end security analysis. The Bell Labs Security Framework was developed as an architectural framework for assessing and achieving end-to-end security for distributed applications. It provides the insight necessary to identify gaps and recommend potential solutions in the security of various Wi-Fi standards, such as, (Wi-Fi rotected Access) 2, and (Wired Equivalent rivacy). The Bell Labs Security Framework: Making the Case for End-to-End Wi-Fi Security Technology White aper 1
4 Bell Labs Security Framework Overview The Bell Labs Security Framework is a structured framework that drives the consideration of all possible threats and vulnerabilities that can jeopardize end-to-end network security. It fills a void in existing security standards by providing a holistic network security architecture that is applicable to end users, as well as the management and control/signaling infrastructures, services and applications. It can be used for assessing, planning, managing and maintaining secure computer and communications networks and was designed to furnish a methodical, organized way of addressing five threats classes to networks: Destruction of information and/or other resources Corruption or modification of information Removal, theft, or loss of information and/or other resources Disclosure of information Interruption of services Assembling a Comprehensive Security Model To ensure that each and every aspect of the network is covered from the security perspective, the Bell Labs Security Framework defines three layers, three planes, and eight dimensions that are used to determine if a network is vulnerable to any or all of the five threat classes listed above, and to pinpoint where such weaknesses exist (Figure 1). The following definitions apply to the framework s layers, planes and dimensions: Security layers are a series of enablers for secure network solutions such as infrastructure, services and applications, each having different security vulnerabilities. Security planes represent the various types of network activity such as management, control and end-user. Security dimensions are a set of security measures to assist in countering attacks at each layer and plane. Figure 1. The Bell Labs Security Framework Security Layers Applications Security Threats Vulnerabilities Services Security Infrastructure Security Access Control Authentication Non-Repudiation Data Confidentiality Communication Security Data Integrity Availability rivacy Destruction Corruption Removal Disclosure Interruption Attacks Security lanes End User lane Control lane Management lane Eight Security Dimensions 2 The Bell Labs Security Framework: Making the Case for End-to-End Wi-Fi Security Technology White aper
5 Security Layers The Bell Labs Security Framework defines three discreet security layers as follows: Infrastructure layer Includes the basic building blocks used to create the network, services, and applications. It comprises individual communication links and network elements, including underlying hardware and software such as access points, Wi-Fi access client. Services layer Focuses on services that end-users receive from networks such as Wi-Fi access. Applications layer Consists of network-based applications accessed by end-users. These applications are enabled by network services and are characterized by the end-user interacting with remote hardware or software in order to access information or perform a transaction e.g. , VN, etc. Security lanes The three security planes defined by the Framework correspond to the types of activities performed over the network management, control, and end-user activity. Some systems might implement one or more planes as a separate network, such as dedicated network for the management functions. Wi-Fi deployments typically share the same network for all three functional activities (planes). That lack of separation means that security incursions on all three planes must be dealt with simultaneously. Security Dimensions The eight security dimensions apply to both the security layer and the security plane extending beyond the network to include applications and end users. Each dimension represents measures implemented to counter threats and potential attacks. Access management or access control protects against unauthorized use of network resources; Authentication confirms the identities of each entity using the network; Non-repudiation proves the origin of the data or identifies the cause of an event or action; Data confidentiality or data security ensures that data is not disclosed to unauthorized users; Communication security allows information to flow only between authorized endpoints; Data integrity ensures the accuracy of data so it cannot be modified, deleted, created or replicated without authorization, and also provides an indication of unauthorized attempts to change data; Availability ensures that there is no denial of authorized access to network elements, stored information, information flows, services and applications due to network-impacting events; rivacy provides for the protection of information that could be derived from the observation of network activities. Modular Methodology To ensure comprehensive coverage of the network being analyzed, every unique combination of security layer and security plane, each called a module (as shown in Figure 2), represents a unique perspective for consideration of the eight security dimensions. The security dimensions of different modules have different objectives and consequently comprise different comprehensive sets of security measures. The basic methodology for analysis is to consider the threat model for each module and evaluate the effectiveness of security measures in each dimension. The Bell Labs Security Framework: Making the Case for End-to-End Wi-Fi Security Technology White aper 3
6 Figure 2. Modular form of Bell Labs Security Framework 1 Infrastructure Layer Services Layer Applications Layer Management lane Module One Module Four Module Seven Control lane Module Two Module Five Module Eight User lane Module Three Module Six Module Nine Access Control Authentication Non-Repudiation Data Confidentiality Communication Security Data Integrity Availability rivacy Eight Security Dimensions Using the Bell Labs Security Framework to Secure Wi-Fi Networks The Bell Labs Security Framework can be effectively used for the analysis of Wi-Fi networks by assessing the security controls available in the network in each of the eight security dimensions across each intersection of the layers and planes (modules). The Reference Architecture The reference architecture for this assessment is based on a typical Wi-Fi network used by enterprises and hot spot service providers and includes a set of access points (A), network access controller (NAC) and authentication server (AS) as shown in Figure 3. Figure 3. The reference architecture Mobile Station Access oint DHC Server Authentication Server (AAA) Mobile Station Access oint Network Access Controller Enterprise/ Service rovider Network DNS Server Application Servers 1 Modules 1-6 are included in the illustrative analysis in this paper. The Bell Labs Security Framework: Making the Case for End-to-End Wi-Fi Security Technology White aper
7 The A provides wireless access to laptops, DAs (personal digital assistants), and other mobile stations. It also supplies these devices with information about the WLAN and responds to requests from them. The main function of the Network Access Controller (NAC), commonly referred to as a WLAN Gateway, is to perform or assist with user authentication and to control network access. The NAC will not permit access to the network behind it unless the mobile station has been successfully authenticated and authorized. The NAC may integrate other functions, including NAT (network address translation), DHC (dynamic host configuration protocol) server, authentication server, and VN server, etc. The authentication server is critical to implementing advanced security standards such as 802.1x,, and /Robust Secure Network (RSN). It is responsible for user authentication and authorization and can optionally participate in the key management. The remaining components shown in the reference architecture are common to wireless and wired networks, and therefore are not discussed. Scope of the Analysis As indicated earlier, if the scope of the security analysis includes the end-to-end Wi-Fi network architecture and the entire framework is applied, vulnerabilities could be identified for every layer, plane and dimension. For the sake of simplicity, the scope of analysis in this paper is limited to wireless access only. All applications running on top of Wi-Fi access and other enabler services such as DNS, DHC, AAA etc are excluded from the scope of the analysis. The illustrative results shown in this paper are our assessment of the security for the typical WLAN architecture (Figure 3,) assuming no additional security controls are deployed in the network. The assessed degree of effectiveness of the security measures included in the Wi-Fi standards, across each security dimension against the framework s threat model is open to some variation depending on the exact network environment and the perception of threats. Wi-Fi Threat Model Every type of Wi-Fi attack could pose one or more threats, depending on intent and approach. Table 1 maps some popular Wi-Fi attacks to the threat model adopted by the Bell Labs Security Framework. Table 1. Mapping of major Wi-Fi attacks to Bell Labs Security Framework threats Bell Labs Security Framework-Defined Threat Destruction of information and/or other resources Corruption or modification of information Theft, removal, or loss of information and/or other resources Disclosure of information Interruption of service Methods of Attack A Intrusion key cracking, man-in-middle A Intrusion, key cracking, man in middle, MAC address spoofing, rogue devices, war driving, Layer 3 hijacking, ad-hoc networks A Intrusion, key cracking, man in middle, MAC address spoofing, rogue devices, war driving, Layer 3 hijacking, ad-hoc networks RF jamming, data flooding, Layer 2 hijacking, fake A, spoofed de-authenticate frame, FATA-Jack DoS Wi-Fi Layers The infrastructure layer of Wi-Fi networks consists of all components of the network, cables, interconnections and transmissions media (coverage space) e.g. access points, mobile stations, Wi-Fi gateway and servers hosting associated services like RADIUS, DNS, etc. The Bell Labs Security Framework: Making the Case for End-to-End Wi-Fi Security Technology White aper
8 The service layer in the case of Wi-Fi networks is composed of wireless LAN access services and other services enabling wireless access e.g. authentication, authorization, accounting (AAA), key management services etc. User applications running over the Wi-Fi network defines the application layer and is excluded from the scope of this analysis. Wi-Fi lanes Wi-Fi security standards do not address the management plane activities for the Wi-Fi networks. Signaling and controls associated with including RTS/CTS, fragment bursting, DRS (Dynamic Rate Shifting), DCF (Distributed Coordination Function), CF (oint Coordination Function), S (ower Save olling) defines the control plane. The interaction of end-users with Wi-Fi networks including the transmission of data constitutes the end-user plane. Applying Security Dimensions In the following sections, we will assess the effectiveness or the adequacy 2 2 and have similar of the controls available in each of the eight dimensions for all applicable security features, however, 2 can modules in an attempt to determine the relative strengths and weaknesses interoperate with the less secure, of, 2 2, and security standards. therefore the weaknesses of have a reflection on 2 in this analysis. We have performed the analysis for all eight dimensions and the summary results are tabulated in Table 7, but individual details are shown only for sample dimensions in context of Wi-Fi standards. The qualitative results for each dimension are tabulated using following legends: Access Control Original specifications, including, had no built-in access control mechanism thus larger Wi-Fi deployments used a WLAN gateway for service level access control. Based on this assumption, access control for the Wi-Fi service to the end-users has been rated as partially adequate x is the end-user access control mechanism for Wi-Fi service for,, and 2. Table 2. Wi-Fi Security standards coverage for Access Control Dimension Access Control Security Dimension Security lanes Security Layers Infrastructure Services 2 2 End-User X Control X X X X Management X X X X X X X X X Satisfactory Compliance artial Compliance Not addressed by the standard 2 2 and have similar security features, however, 2 can interoperate with the less secure, therefore the weaknesses of have a reflection on 2 in this analysis. The Bell Labs Security Framework: Making the Case for End-to-End Wi-Fi Security Technology White aper
9 Authentication, 2, and use 802.1x/EA for authentication. In contrast, employs either open or shared secret authentication, which uses the same static key used for encryption. Thus, authentication is rated partial. Authentication in other standards could also receive the same rating if a weak EA protocol like MD5 is selected for 802.1x. Authentication of control information across access points and other network elements (to support roaming) is only addressed in. As supporting other standards normally use proprietary mechanisms to exchange this information while roaming and validating the security of such implementations is out of the scope. Table 3. Wi-Fi security standards coverage for Authentication Dimension Authentication Control Security Dimension Security lanes Infrastructure Security Layers Services 2 2 End-User Control X X X X Management X X X X X X X X X Satisfactory Compliance artial Compliance Not addressed by the standard Data Confidentiality employs RC4 encryption for end-user data, but the implementation is very weak (24-bit initialization vector). also uses RC4, but implements a 48-bit initialization vector and other strong-security mechanisms. and 2 support AES (Advanced Encryption Standards), which offers the strongest encryption. Since does not define how control information is stored in network elements, some Windowsbased mobile stations store the key in the registry, which can be read remotely unless precautions are taken. Similarly, some Wi-Fi card manufacturers store the key in firmware if the card is lost or not disposed of properly, this can constitute a security risk. The other standards support key management features that automatically generate critical keys, rather than manually. Additionally, and 2 have the option of using re-shared Secrets Keys (SK). These standards only define the wireless interface. End-user data may appear unencrypted on the Ethernet ports, depending on the network architecture or the status of port mirroring. The Bell Labs Security Framework: Making the Case for End-to-End Wi-Fi Security Technology White aper 7
10 Table 4. Wi-Fi Security standards coverage for Data Confidentiality Dimension Data Confidentiality Security Dimension Security lanes Infrastructure Security Layers Services 2 2 End-User X Control X X Management X X X X X X X X X X Satisfactory Compliance artial Compliance Not addressed by the standard Data Integrity is relatively weak when it comes to protecting the integrity of end-user data because it both uses CRC32 (cyclic redundancy check 32) as its integrity check vector (ICV) and concatenates the predictable ICV to the wireless frame, making it easier to insert malicious frames. doesn t protect the integrity of control (header) data. uses Michael with key mixing both for end-user data and header to deliver stronger integrity protection. employs CBC-MAC both for data and header integrity protection. Table 5. Wi-Fi security standards coverage for Data Integrity Dimension Data Integrity Security Dimension Security lanes Infrastructure Security Layers Services 2 2 End-User Control X X Management X X X X X X X X X Satisfactory Compliance artial Compliance Not addressed by the standard Availability DoS attacks like RF Jamming, data flooding, and Layer 2 session hijacking, are all attack against availability. None of the Wi-Fi security standards can prevent attacks on the physical layer simply because they operate on Layer 2 and above. Similarly, none of the standards can deal with an A failure. The Bell Labs Security Framework: Making the Case for End-to-End Wi-Fi Security Technology White aper
11 Table 6. Wi-Fi security standards coverage for Availability Dimension Availability Security Dimension Security lanes Infrastructure Security Layers Services 2 2 End-User X X Control X X Management X X X X X X X X X Satisfactory Compliance artial Compliance Not addressed by the standard Analysis Summary The foregoing assessments demonstrate how Bell Labs Security Framework can be used to evaluate the security of Wi-Fi security standards. Armed with this information, enterprise IT managers can determine where security is less than adequate, which protocols are most vulnerable, and which do the best job. The next step is to bring security up to specification across the entire Wi-Fi network. Results in Table 7 illustrate relative security scores of the four Wi-Fi standards derived from the rigorous application of Bell Labs Security Framework for security assessment. Table 7. Relative security score for Wi-Fi standards 3 WiFi rotocol Standards Security Comparison and Comprehensiveness per Bell Labs Security Framework WiFi Standards Covered artially Covered Not Covered The table includes the assessment for all the eight dimensions, though the individual details are shown only sample Dimensions in the paper. The Bell Labs Security Framework: Making the Case for End-to-End Wi-Fi Security Technology White aper 9
12 Figure 4. Relative security provided in each Dimension by Wi-Fi standards Access Control Availability rivacy Authentication Non-Repudiation Data Integrity Data Confidentiality Communication Security 2 The data shown is generated by Bell Laboratories security technology Assigning a weighted value that reflects how successfully the standard addressed each dimension as shown in Figure 4, can create a more accurate picture of the security provided by these Wi-Fi standards and identifies the areas where the supplementary security measures are required to achieve the desired security posture. It quickly becomes evident that is the least secure standard not adequately addressing many of the dimensions. In fact, the Bell Labs Security Framework analysis reveals that security is inadequate for the enterprise or for service provider networks. In contrast, is demonstrably more secure than prior versions, delivering good coverage for all security dimensions. Still, there is room for improvement, particularly when it comes to availability and non-repudiation. 2, meanwhile, offers marginally less security partially due to accommodating the need to interoperate with its less secure predecessor considering that security is only as good as the weakest link. Recommendations It is apparent that relatively secure Wi-Fi networks can be designed, implemented, and maintained using either or 2. Simply implementing these standards, however, will not ensure end-to-end security for WLANs. In fact, it could leave major security gaps for availability and non-repudiation. What s more, neither of these Wi-Fi security standards addresses the management plane. Thus, additional security would have to be incorporated in the design, planning, and operation of these networks. For example, redundant access points and pre-authenticated roaming are needed to ensure high availability. The architecture and configuration selected for the wireless network must account for these shortfalls. In addition, wireless networks are part of larger wired network and end-to-end security must address the security of the associated wired network as well. 10 The Bell Labs Security Framework: Making the Case for End-to-End Wi-Fi Security Technology White aper
13 Centrally managed thin access points that can communicate with one another help secure information related to roaming clients and will improve the availability by dynamically adjusting the RF power level. Operational security measures such as site surveillance, as well as planning the Wi-Fi RF coverage area, can also improve availability by reducing the risk of attacks like RF jamming. Applying the Bell Labs Security Framework at each stage of the network lifecycle can ensure that all aspects of the network are evaluated for all applicable threats to achieve an end-to-end secure Wi-Fi network. Keep in mind that the scope of this paper addressed only the security assessment for the Wi-Fi airlink. However, the use of Bell Labs Security Framework could be extended to design and evaluate the security of your entire network, which is clearly a demanding task even with the requisite on -site staff resources. An undertaking such as this requires skill and expertise both in Bell Labs Security Framework and the networking domain. Alcatel-Lucent is the partner who is ready to help you leverage the Bell Labs Security Framework and ensure that your networks are designed, deployed and managed with the highest standards of security. For More Information Sources International Telecommunications Union, Telecommunications Standardization Sector, Security Architecture for Systems roviding End-to-End Communications, Rec. BELL LABS SECURITY FRAMEWORK, 2003, International Telecommunications Union, Telecommunications Standardization Sector, Security in Telecommunications and Information Technology, pg 1, December 2003, International Telecommunications Union, Telecommunications Standardization Sector, Security Architecture for Open Systems Interconnection (OSI) for CCITT Applications, Rec. X.800, 1991, ANSI/IEEE Std , 1999 Edition (R2003) art 11: Wireless LAN Medium Access Control (MAC) and hysical Layer (HY) Specifications. IEEE Std 2004 Amendment 6: Medium Access Control (MAC) Security Enhancements. Wi-Fi rotected Access An overview Department of Defense Directive number Use of Commercial Wireless Devices, Services, and Technologies in the Department of Defense (DoD) Global Information Grid (GIG); NIST S800-48: Wireless Network Security , Bluetooth and Handheld Devices; The Bell Labs Security Framework: Making the Case for End-to-End Wi-Fi Security Technology White aper 11
14 About the Authors Ashok Gupta Technology and Applications Research Group of Bell Labs. He has over twenty years of diverse experience in the field of enterprise IT Infrastructure, security, wireless, content delivery and MIS applications with various research organizations. His current areas of interest are end-point policy enforcement, and security of mobile devices and wireless networks. Some of the certifications he holds are CISS, CWS, M and CWNA. Theresa Buthmann Theresa Buthmann is the director of Wireless Solutions for Alcatel-Lucent Services. She leads the development of robust wireless solutions that balance the gains of productivity with concerns around security, quality of service, and cost. Buthmann applies the knowledge gained from holding several diverse positions within AT&T and Lucent Technologies in the CFO, marketing, and business development organizations to enable multiple facets of the wireless solutions business across many technologies including optical transport, VoI, Wi-Fi, in-building optimization, and mobile I. 12 The Bell Labs Security Framework: Making the Case for End-to-End Wi-Fi Security Technology White aper
15
16 Alcatel, Lucent, Alcatel-Lucent and the Alcatel-Lucent logo are trademarks of Alcatel-Lucent. All other trademarks are the property of their respective owners. The information presented is subject to change without notice. Alcatel-Lucent assumes no responsibility for inaccuracies contained herein Alcatel-Lucent. All rights reserved. SRV (10)
Draft ITU-T Recommendation X.805 (Formerly X.css), Security architecture for systems providing end-to-end communications
Draft ITU-T Recommendation X.805 (Formerly X.css), architecture for systems providing end-to-end communications Summary This Recommendation defines the general security-related architectural elements that
Deploying secure wireless network services The Avaya Identity Engines portfolio offers flexible, auditable management for secure wireless networks.
Table of Contents Section 1: Executive summary...1 Section 2: The challenge...2 Section 3: WLAN security...3 and the 802.1X standard Section 4: The solution...4 Section 5: Security...4 Section 6: Encrypted
Link Layer and Network Layer Security for Wireless Networks
Link Layer and Network Layer Security for Wireless Networks Interlink Networks, Inc. May 15, 2003 1 LINK LAYER AND NETWORK LAYER SECURITY FOR WIRELESS NETWORKS... 3 Abstract... 3 1. INTRODUCTION... 3 2.
Security Requirements for Wireless Local Area Networks
Information Technology Security Guidance Security Requirements for Wireless Local Area Networks Overview ITSG-41 March 2013 Foreword The ITSG-41 Security Requirements for Wireless Local Area Networks document
CS 356 Lecture 29 Wireless Security. Spring 2013
CS 356 Lecture 29 Wireless Security Spring 2013 Review Chapter 1: Basic Concepts and Terminology Chapter 2: Basic Cryptographic Tools Chapter 3 User Authentication Chapter 4 Access Control Lists Chapter
Industrial Network Security for SCADA, Automation, Process Control and PLC Systems. Contents. 1 An Introduction to Industrial Network Security 1
Industrial Network Security for SCADA, Automation, Process Control and PLC Systems Contents 1 An Introduction to Industrial Network Security 1 1.1 Course overview 1 1.2 The evolution of networking 1 1.3
The following chart provides the breakdown of exam as to the weight of each section of the exam.
Introduction The CWSP-205 exam, covering the 2015 objectives, will certify that the successful candidate understands the security weaknesses inherent in WLANs, the solutions available to address those
Security in Wireless Local Area Network
Fourth LACCEI International Latin American and Caribbean Conference for Engineering and Technology (LACCET 2006) Breaking Frontiers and Barriers in Engineering: Education, Research and Practice 21-23 June
Lecture Objectives. Lecture 8 Mobile Networks: Security in Wireless LANs and Mobile Networks. Agenda. References
Lecture Objectives Wireless Networks and Mobile Systems Lecture 8 Mobile Networks: Security in Wireless LANs and Mobile Networks Introduce security vulnerabilities and defenses Describe security functions
How To Secure Wireless Networks
Lecture 24 Wireless Network Security modified from slides of Lawrie Brown Wireless Security Overview concerns for wireless security are similar to those found in a wired environment security requirements
12/3/08. Security in Wireless LANs and Mobile Networks. Wireless Magnifies Exposure Vulnerability. Mobility Makes it Difficult to Establish Trust
Security in Wireless LANs and Mobile Networks Wireless Magnifies Exposure Vulnerability Information going across the wireless link is exposed to anyone within radio range RF may extend beyond a room or
Recommended 802.11 Wireless Local Area Network Architecture
NATIONAL SECURITY AGENCY Ft. George G. Meade, MD I332-008R-2005 Dated: 23 September 2005 Network Hardware Analysis and Evaluation Division Systems and Network Attack Center Recommended 802.11 Wireless
WIRELESS SECURITY. Information Security in Systems & Networks Public Development Program. Sanjay Goel University at Albany, SUNY Fall 2006
WIRELESS SECURITY Information Security in Systems & Networks Public Development Program Sanjay Goel University at Albany, SUNY Fall 2006 1 Wireless LAN Security Learning Objectives Students should be able
WLAN Security Why Your Firewall, VPN, and IEEE 802.11i Aren t Enough to Protect Your Network
WLAN Security Why Your Firewall, VPN, and IEEE 802.11i Aren t Enough to Protect Your Network 339 N. Bernardo Avenue, Suite 200 Mountain View, CA 94043 www.airtightnetworks.net Executive Summary Wireless
Security+ Guide to Network Security Fundamentals, Third Edition. Chapter 6. Wireless Network Security
Security+ Guide to Network Security Fundamentals, Third Edition Chapter 6 Wireless Network Security Objectives Overview of IEEE 802.11 wireless security Define vulnerabilities of Open System Authentication,
THE IMPORTANCE OF CRYPTOGRAPHY STANDARD IN WIRELESS LOCAL AREA NETWORKING
International Journal of Electronics and Communication Engineering & Technology (IJECET) Volume 6, Issue 9, Sep 2015, pp. 65-74, Article ID: IJECET_06_09_008 Available online at http://www.iaeme.com/ijecetissues.asp?jtype=ijecet&vtype=6&itype=9
Link Layer and Network Layer Security for Wireless Networks
White Paper Link Layer and Network Layer Security for Wireless Networks Abstract Wireless networking presents a significant security challenge. There is an ongoing debate about where to address this challenge:
Wireless LAN Security Mechanisms
Wireless LAN Security Mechanisms Jingan Xu, Andreas Mitschele-Thiel Technical University of Ilmenau, Integrated Hard- and Software Systems Group [email protected], [email protected] Abstract.
chap18.wireless Network Security
SeoulTech UCS Lab 2015-1 st chap18.wireless Network Security JeongKyu Lee Email: [email protected] Table of Contents 18.1 Wireless Security 18.2 Mobile Device Security 18.3 IEEE 802.11 Wireless
Potential Security Vulnerabilities of a Wireless Network. Implementation in a Military Healthcare Environment. Jason Meyer. East Carolina University
Potential Security Vulnerabilities of a Wireless Network Implementation in a Military Healthcare Environment Jason Meyer East Carolina University Abstract This paper will look into the regulations governing
All vulnerabilities that exist in conventional wired networks apply and likely easier Theft, tampering of devices
Wireless Security All vulnerabilities that exist in conventional wired networks apply and likely easier Theft, tampering of devices Portability Tamper-proof devices? Intrusion and interception of poorly
Wireless Security Overview. Ann Geyer Partner, Tunitas Group Chair, Mobile Healthcare Alliance 209-754-9130 [email protected]
Wireless Security Overview Ann Geyer Partner, Tunitas Group Chair, Mobile Healthcare Alliance 209-754-9130 [email protected] Ground Setting Three Basics Availability Authenticity Confidentiality Challenge
CS5490/6490: Network Security- Lecture Notes - November 9 th 2015
CS5490/6490: Network Security- Lecture Notes - November 9 th 2015 Wireless LAN security (Reference - Security & Cooperation in Wireless Networks by Buttyan & Hubaux, Cambridge Univ. Press, 2007, Chapter
Certified Wireless Security Professional (CWSP) Course Overview
Certified Wireless Security Professional (CWSP) Course Overview This course will teach students about Legacy Security, encryption ciphers and methods, 802.11 authentication methods, dynamic encryption
Industrial Communication. Securing Industrial Wireless
Industrial Communication Whitepaper Securing Industrial Wireless Contents Introduction... 3 Wireless Applications... 4 Potential Threats... 5 Denial of Service... 5 Eavesdropping... 5 Rogue Access Point...
PwC. Outline. The case for wireless networking. Access points and network cards. Introduction: OSI layers and 802 structure
PwC Outline Wireless LAN Security: Attacks and Countermeasures 1. Introduction 2. Problems with 802.11 security 3. Attacks on and risks to Wireless Networks 4. Defending wireless networks ISACA Hong Kong
WHITE PAPER. The Need for Wireless Intrusion Prevention in Retail Networks
WHITE PAPER The Need for Wireless Intrusion Prevention in Retail Networks The Need for Wireless Intrusion Prevention in Retail Networks Firewalls and VPNs are well-established perimeter security solutions.
Wireless Security with Cyberoam
White paper Cyberoam UTM Wireless Security with Cyberoam Robust, Fault-tolerant security is a must for companies sporting wireless networks. Cyberoam UTM strengthens the existing Wireless Security Architecture
Wireless VPN White Paper. WIALAN Technologies, Inc. http://www.wialan.com
Wireless VPN White Paper WIALAN Technologies, Inc. http://www.wialan.com 2014 WIALAN Technologies, Inc. all rights reserved. All company and product names are registered trademarks of their owners. Abstract
HughesNet Broadband VPN End-to-End Security Enabled by the HN7700S-R
HughesNet Broadband VPN End-to-End Security Enabled by the HN7700S-R HughesNet Managed Broadband Network Services include a high level of end-toend security utilizing a robust architecture designed by
Directives and Instructions Regarding Security and Installation of Wireless LAN in DoD Federal Facilities
Directives and Instructions Regarding Security and Installation of Wireless LAN in DoD Federal Facilities Wireless Infrastructure, Article 3-15-2012 The federal government recognizes that standards based
Directives and Instructions Regarding Wireless LAN in Department of Defense (DoD) and other Federal Facilities
Directives and Instructions Regarding Wireless LAN in Department of Defense (DoD) and other Federal Facilities Wireless Infrastructure, Article 12-29-2011 The federal government, and the Department of
WHITE PAPER. WEP Cloaking for Legacy Encryption Protection
WHITE PAPER WEP Cloaking for Legacy TM Encryption Protection Introduction Wired Equivalent Privacy (WEP) is the encryption protocol defined in the original IEEE 802.11 standard for Wireless Local Area
Wireless Networking for Small Businesses, Branches and Home Offices
Wireless Networking for Small Businesses, Branches and Home Offices Whether one believes in the Internet revolution or not, it is true that the Internet today has become an essential element in running
BSc (Hons.) Computer Science with Network Security. Examinations for 2011/2012 - Semester 2
BSc (Hons.) Computer Science with Network Security BCNS/09/FT Examinations for 2011/2012 - Semester 2 MODULE: WIRELESS NETWORK SECURITY MODULE CODE: SECU 3105 Duration: 2 Hours 15 Minutes Reading time:
802.11 Security (WEP, WPA\WPA2) 19/05/2009. Giulio Rossetti Unipi [email protected]
802.11 Security (WEP, WPA\WPA2) 19/05/2009 Giulio Rossetti Unipi [email protected] 802.11 Security Standard: WEP Wired Equivalent Privacy The packets are encrypted, before sent, with a Secret Key
WLAN Attacks. Wireless LAN Attacks and Protection Tools. (Section 3 contd.) Traffic Analysis. Passive Attacks. War Driving. War Driving contd.
Wireless LAN Attacks and Protection Tools (Section 3 contd.) WLAN Attacks Passive Attack unauthorised party gains access to a network and does not modify any resources on the network Active Attack unauthorised
Wireless Security and Healthcare Going Beyond IEEE 802.11i to Truly Ensure HIPAA Compliance
Going Beyond IEEE 802.11i to Truly Ensure HIPAA Compliance 339 N. Bernardo Avenue, Suite 200 Mountain View, CA 94043 www.airtightnetworks.net Wireless LANs are prevalent in healthcare institutions. The
Evolving Network Security with the Alcatel-Lucent Access Guardian
T E C H N O L O G Y W H I T E P A P E R Evolving Network Security with the Alcatel-Lucent Access Guardian Enterprise network customers encounter a wide variety of difficulties and complexities when designing
ADDENDUM 12 TO APPENDIX 8 TO SCHEDULE 3.3
ADDENDUM 12 TO APPENDIX 8 TO SCHEDULE 3.3 TO THE Overview EXHIBIT T to Amendment No. 60 Secure Wireless Network Services are based on the IEEE 802.11 set of standards and meet the Commonwealth of Virginia
Recommended IP Telephony Architecture
Report Number: I332-009R-2006 Recommended IP Telephony Architecture Systems and Network Attack Center (SNAC) Updated: 1 May 2006 Version 1.0 [email protected] This Page Intentionally Left Blank ii Warnings
A Closer Look at Wireless Intrusion Detection: How to Benefit from a Hybrid Deployment Model
A Closer Look at Wireless Intrusion Detection: How to Benefit from a Hybrid Deployment Model Table of Contents Introduction 3 Deployment approaches 3 Overlay monitoring 3 Integrated monitoring 4 Hybrid
Technical Brief. Wireless Intrusion Protection
Technical Brief Wireless Intrusion Protection Introduction One layer of the multi-layer wireless security solution provided by Aruba Wireless Networks is the ability to lock the air using wireless intrusion
Wireless security. Any station within range of the RF receives data Two security mechanism
802.11 Security Wireless security Any station within range of the RF receives data Two security mechanism A means to decide who or what can use a WLAN authentication A means to provide privacy for the
Ensuring HIPAA Compliance in Healthcare
The Intelligent Wireless Networking Choice WHITE PAPER Ensuring HIPAA Compliance in Healthcare Overview Wireless LANs are prevalent in healthcare institutions. The constant need for mobility among doctors,
NETWORK ACCESS CONTROL AND CLOUD SECURITY. Tran Song Dat Phuc SeoulTech 2015
NETWORK ACCESS CONTROL AND CLOUD SECURITY Tran Song Dat Phuc SeoulTech 2015 Table of Contents Network Access Control (NAC) Network Access Enforcement Methods Extensible Authentication Protocol IEEE 802.1X
Enterprise Cybersecurity Best Practices Part Number MAN-00363 Revision 006
Enterprise Cybersecurity Best Practices Part Number MAN-00363 Revision 006 April 2013 Hologic and the Hologic Logo are trademarks or registered trademarks of Hologic, Inc. Microsoft, Active Directory,
DOS ATTACKS IN INTRUSION DETECTION AND INHIBITION TECHNOLOGY FOR WIRELESS COMPUTER NETWORK
DOS ATTACKS IN INTRUSION DETECTION AND INHIBITION TECHNOLOGY FOR WIRELESS COMPUTER NETWORK ABSTRACT Dr. Sanjeev Dhull Associate Professor, RPIIT Karnal, Dept of Computer Science The DoS attack is the most
Wireless Networks. Welcome to Wireless
Wireless Networks 11/1/2010 Wireless Networks 1 Welcome to Wireless Radio waves No need to be physically plugged into the network Remote access Coverage Personal Area Network (PAN) Local Area Network (LAN)
Wi-Fi, Health Care, and HIPAA
AN AIRMAGNET TECHNICAL WHITE PAPER Wi-Fi, Health Care, and HIPAA WLAN Management in the Modern Hospital by Wade Williamson WWW.AIRMAGNET.COM This page contains no topical information. Table of Contents
INFORMATION TECHNOLOGY MANAGEMENT COMMITTEE LIVINGSTON, NJ WWW.LIVINGSTONNJ.ORG ITMC TECH TIP ROB COONCE, MARCH 2008
INFORMATION TECHNOLOGY MANAGEMENT COMMITTEE LIVINGSTON, NJ WWW.LIVINGSTONNJ.ORG What is wireless technology? ITMC TECH TIP ROB COONCE, MARCH 2008 In our world today, this may mean sitting down at a coffee
HIPAA Compliance and Wireless Networks. 2005 Cranite Systems, Inc. All Rights Reserved.
HIPAA Compliance and Wireless Networks White Paper HIPAA Compliance and Wireless Networks 2005 Cranite Systems, Inc. All Rights Reserved. All materials contained in this document are the copyrighted property
Deploying Firewalls Throughout Your Organization
Deploying Firewalls Throughout Your Organization Avoiding break-ins requires firewall filtering at multiple external and internal network perimeters. Firewalls have long provided the first line of defense
7 Network Security. 7.1 Introduction 7.2 Improving the Security 7.3 Internet Security Framework. 7.5 Absolute Security?
7 Network Security 7.1 Introduction 7.2 Improving the Security 7.3 Internet Security Framework 7.4 Firewalls 7.5 Absolute Security? 7.1 Introduction Security of Communications data transport e.g. risk
Tech Brief. Enterprise Secure and Scalable Enforcement of Microsoft s Network Access Protection in Mobile Networks
Tech Brief Enterprise Secure and Scalable Enforcement of Microsoft s Network Access Protection in Mobile Networks Introduction In today s era of increasing mobile computing, one of the greatest challenges
EVOLVING ENTERPRISE NETWORKS WITH SPB-M APPLICATION NOTE
EVOLVING ENTERPRISE NETWORKS WITH SPB-M APPLICATION NOTE EXECUTIVE SUMMARY Enterprise network managers are being forced to do more with less. Their networks are growing in size and complexity. They need
Agenda. Wireless LAN Security. TCP/IP Protocol Suite (Internet Model) Security for TCP/IP. Agenda. Car Security Story
Wireless s June September 00 Agenda Wireless Security ผศ. ดร. อน นต ผลเพ ม Asst. Prof. Anan Phonphoem, Ph.D. [email protected] http://www.cpe.ku.ac.th/~anan Computer Engineering Department Kasetsart University,
Best Practices for Outdoor Wireless Security
Best Practices for Outdoor Wireless Security This paper describes security best practices for deploying an outdoor wireless LAN. This is standard body copy, style used is Body. Customers are encouraged
All You Wanted to Know About WiFi Rogue Access Points
All You Wanted to Know About WiFi Rogue Access Points A quick reference to Rogue AP security threat, Rogue AP detection and mitigation Gopinath K. N. Hemant Chaskar AirTight Networks www.airtightnetworks.com
Windows 7 Virtual Wi-Fi: The Easiest Way to Install a Rogue AP on Your Corporate Network
A Whitepaper by AirTight Networks, Inc. 339 N. Bernardo Avenue, Suite 200, Mountain View, CA 94043 www.airtightnetworks.com 2010 AirTight Networks, Inc. All rights reserved. Introduction Last few years
Integrating Wired IDS with Wi-Fi Using Open-Source IDS to Complement a Wireless IDS/IPS Deployment
Integrating Wired IDS with Wi-Fi Using Open-Source IDS to Complement a Wireless IDS/IPS Deployment Table of Contents Introduction 3 Limitations in WIDS monitoring 3 Monitoring weaknesses 3 Traffic analysis
Network Security 網 路 安 全. Lecture 1 February 20, 2012 洪 國 寶
Network Security 網 路 安 全 Lecture 1 February 20, 2012 洪 國 寶 1 Outline Course information Motivation Introduction to security Basic network concepts Network security models Outline of the course 2 Course
Security Issues with Integrated Smart Buildings
Security Issues with Integrated Smart Buildings Jim Sinopoli, Managing Principal Smart Buildings, LLC The building automation industry is now at a point where we have legitimate and reasonable concern
SECURING ENTERPRISE NETWORK 3 LAYER APPROACH FOR BYOD
SECURING ENTERPRISE NETWORK 3 LAYER APPROACH FOR BYOD www.wipro.com Table of Contents Executive Summary 03 Introduction 03 Challanges 04 Solution 05 Three Layered Approach to secure BYOD 06 Conclusion
DATA SECURITY 1/12. Copyright Nokia Corporation 2002. All rights reserved. Ver. 1.0
DATA SECURITY 1/12 Copyright Nokia Corporation 2002. All rights reserved. Ver. 1.0 Contents 1. INTRODUCTION... 3 2. REMOTE ACCESS ARCHITECTURES... 3 2.1 DIAL-UP MODEM ACCESS... 3 2.2 SECURE INTERNET ACCESS
GSM and UMTS security
2007 Levente Buttyán Why is security more of a concern in wireless? no inherent physical protection physical connections between devices are replaced by logical associations sending and receiving messages
Analysis of Security Issues and Their Solutions in Wireless LAN 1 Shenam Chugh, 2 Dr.Kamal
Analysis of Security Issues and Their Solutions in Wireless LAN 1 Shenam Chugh, 2 Dr.Kamal 1,2 Department of CSE 1,2,3 BRCM Bahal, Bhiwani 1 [email protected], 2 [email protected] Abstract This paper
The Protection Mission a constant endeavor
a constant endeavor The IT Protection Mission a constant endeavor As businesses become more and more dependent on IT, IT must face a higher bar for preparedness Cyber preparedness is the process of ensuring
S E C U R I T Y A S S E S S M E N T : B o m g a r B o x T M. Bomgar. Product Penetration Test. September 2010
S E C U R I T Y A S S E S S M E N T : B o m g a r B o x T M Bomgar Product Penetration Test September 2010 Table of Contents Introduction... 1 Executive Summary... 1 Bomgar Application Environment Overview...
Network Access Security. Lesson 10
Network Access Security Lesson 10 Objectives Exam Objective Matrix Technology Skill Covered Exam Objective Exam Objective Number Firewalls Given a scenario, install and configure routers and switches.
Enterprise A Closer Look at Wireless Intrusion Detection:
White Paper Enterprise A Closer Look at Wireless Intrusion Detection: How to Benefit from a Hybrid Deployment Model Josh Wright Senior Security Researcher Introduction As wireless enterprise networks become
Advanced Topics in Distributed Systems. Dr. Ayman Abdel-Hamid Computer Science Department Virginia Tech
Advanced Topics in Distributed Systems Dr. Ayman Abdel-Hamid Computer Science Department Virginia Tech Security Introduction Based on Ch1, Cryptography and Network Security 4 th Ed Security Dr. Ayman Abdel-Hamid,
HIPAA Compliance and Wireless Networks
HIPAA Compliance and Wireless Networks White Paper 2004 Cranite Systems, Inc. All Rights Reserved. All materials contained in this document are the copyrighted property of Cranite Systems, Inc. and/or
Securing VoIP Networks using graded Protection Levels
Securing VoIP Networks using graded Protection Levels Andreas C. Schmidt Bundesamt für Sicherheit in der Informationstechnik, Godesberger Allee 185-189, D-53175 Bonn [email protected] Abstract
ICANWK406A Install, configure and test network security
ICANWK406A Install, configure and test network security Release: 1 ICANWK406A Install, configure and test network security Modification History Release Release 1 Comments This Unit first released with
STRATEGIC POLICY. Information Security Policy Documentation. Network Management Policy. 1. Introduction
Policy: Title: Status: 1. Introduction ISP-S12 Network Management Policy Revised Information Security Policy Documentation STRATEGIC POLICY 1.1. This information security policy document covers management,
Voice over IP (VoIP) Vulnerabilities
Voice over IP (VoIP) Vulnerabilities The Technical Presentation Diane Davidowicz NOAA Computer Incident Response Team N-CIRT [email protected] "Security problems in state of the art IP-Telephony
White paper. Testing for Wi-Fi Protected Access (WPA) in WLAN Access Points. http://www.veryxtech.com
White paper Testing for Wi-Fi Protected Access (WPA) in WLAN Access Points http://www.veryxtech.com White Paper Abstract Background The vulnerabilities spotted in the Wired Equivalent Privacy (WEP) algorithm
1.1 Demonstrate how to recognize, perform, and prevent the following types of attacks, and discuss their impact on the organization:
Introduction The PW0-204 exam, covering the 2010 objectives, will certify that the successful candidate understands the security weaknesses inherent in WLANs, the solutions available to address those weaknesses,
Privacy + Security + Integrity
Privacy + Security + Integrity Docufree Corporation Data Security Checklist Security by Design Docufree is very proud of our security record and our staff works diligently to maintain the greatest levels
ITL BULLETIN FOR JANUARY 2011
ITL BULLETIN FOR JANUARY 2011 INTERNET PROTOCOL VERSION 6 (IPv6): NIST GUIDELINES HELP ORGANIZATIONS MANAGE THE SECURE DEPLOYMENT OF THE NEW NETWORK PROTOCOL Shirley Radack, Editor Computer Security Division
COSC 472 Network Security
COSC 472 Network Security Instructor: Dr. Enyue (Annie) Lu Office hours: http://faculty.salisbury.edu/~ealu/schedule.htm Office room: HS114 Email: [email protected] Course information: http://faculty.salisbury.edu/~ealu/cosc472/cosc472.html
Best Practices for Deploying Wireless LANs
Best Practices for Deploying Wireless LANs An overview of special considerations in WLAN implementations As wireless LANs (WLANs) continue to grow in popularity, particularly in enterprise networks, the
SIP Security Controllers. Product Overview
SIP Security Controllers Product Overview Document Version: V1.1 Date: October 2008 1. Introduction UM Labs have developed a range of perimeter security gateways for VoIP and other applications running
Network Security. Security of Wireless Local Area Networks. Chapter 15. Network Security (WS 2002): 15 Wireless LAN Security 1 Dr.-Ing G.
Network Security Chapter 15 Security of Wireless Local Area Networks Network Security WS 2002: 15 Wireless LAN Security 1 IEEE 802.11 IEEE 802.11 standardizes medium access control MAC and physical characteristics
VOICE OVER IP SECURITY
VOICE OVER IP SECURITY February 2008 The Government of the Hong Kong Special Administrative Region The contents of this document remain the property of, and may not be reproduced in whole or in part without
NXC5500/2500. Application Note. 802.11w Management Frame Protection. ZyXEL NXC Application Notes. Version 4.20 Edition 2, 02/2015
NXC5500/2500 Version 4.20 Edition 2, 02/2015 Application Note 802.11w Management Frame Protection Copyright 2015 ZyXEL Communications Corporation 802.11w Management Frame Protection Introduction IEEE 802.11w
SERIES Y: GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL ASPECTS AND NEXT-GENERATION NETWORKS Next Generation Networks Security
International Telecommunication Union ITU-T Y.2740 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (01/2011) SERIES Y: GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL ASPECTS AND NEXT-GENERATION NETWORKS
Release: 1. ICANWK607A Design and implement wireless network security
Release: 1 ICANWK607A Design and implement wireless network security ICANWK607A Design and implement wireless network security Modification History Release Release 1 Comments This Unit first released with
