Firewall Wizards mailing list archives

Re: Securing a wireless network


From: Tony Rall <trall () almaden ibm com>
Date: Fri, 29 Oct 2004 18:19:37 -0700

On Friday, 2004-10-29 at 15:55 AST, <chris () compucounts com> wrote:
The network in question is in a public high school (hence 'so-called
place of business').  The users are faculty, staff, students, and any
hobo around the corner with a laptop and a wireless card.  We have next
to no control over end user devices, because almost everybody brings
their own.  The networked computers are almost entirely Windows based;
we don't care about the half dozen Macs.

There is very little concern for traditional security in this
environment.  Confidentiality is not an issue and quite frankly, I would
welcome a MITM attack - it would be something new around here.
Accounting is based on IP address - 1 year leases.  Those with enough
knowledge to bypass the http proxy and this "accounting" method are also
(usually) smart enough to not look at porn in front of their teachers.
Although there have been some exceptions to this (funny!!).

The general idea here is that if you know enough to bypass our lack of
security, you deserve to do so.  Best practices?  Don't start - These
are the wishes of a school system completely unwilling to change.
Nobody has any sense of security around here.

My only goal is to make sure the laptops that go in and out of here on a
daily basis don't bring every strain of Bagle, Netsky, Sasser or herpes
into this place.  I would rather enforce the use of condoms than preach
abstinence in vain and play doctor every day.

**

So far, I've gotten several suggestions about Cisco's Network Admission
Control and the Cisco Trust Agent.  I'm looking into this and it looks
promising.  Hopefully someone in engineering has a cisco account so we
can download the goodies.


Is this really only related to wireless "connections"?  I think most of 
the issues apply to wired connections also.

It's still not clear to me what the full intention is?
1. protect clients from each other
2. protect clients from the Internet
3. protect the Internet from the clients
Perhaps all 3 are appropriate.

Regarding controlling wireless access - if this isn't done at layer 2 you 
have no way to protect the wireless machines from each other.  That means 
that mechanisms such as vpns are not a full solution.  For this high 
school, if you want to keep the hoboes off the network, probably wep is a 
decent tool.  (Is wep breakable?  Yes.  Is wep useless?  No.  I would call 
it useless if someone with a standard machine and software could access 
your net within minutes of being within radio contact - they can't do it 
at all with normal software, and even if they have the special purpose 
software it takes hours or days to break wep/128.)

One worthwhile objective should be to minimize what I call "client-side 
dependencies".  In other words, avoid requiring special software on the 
users' machines just so that they can use your network.  I think that 
rules out things like CTA.  I prefer to handle network security as much as 
possible from the side of the infrastructure (filtering, scanning, etc.).

A network IDS/IPS appears to provide a pretty good answer here.  If you 
simply want to detect (and perhaps take special action) base on malicious 
traffic, an IDS should do the job.  The action could be simply to alert 
the network admin (and let them deal with it manually), or it might be to 
knock the user off the network (which might be going to far in this school 
environment).

An IPS could block the malicious traffic, but allow other traffic from the 
same machine.  It has the added difficulty that it must be placed in-line 
with the traffic path.  But if that can be accomplished, it is probably 
the simplest way to keep most bad stuff from spreading on your net.

Tony Rall
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: