- +
Doing Your Sums on . . . Build, Buy or Rent 05/11/2007 13:32:30
You’re trying to build a world-class IT team, but everyone’s going after the same talent pool. What mix works best? Should you grow your own, draft your players or barter your way to the line-up you want to field?CIOs should never forget that while new technologies have a maturity cycle, the maturity cycle for human beings in IT is even longer
If you have been reading about potential vulnerabilities in the new 802.11i security standard lately, stop fretting.
There's nothing inherently vulnerable about 802.11i per se (at least, not that we know of yet), except that the 802.1x authentication framework specified in 802.11i and its precursor, Wi-Fi Protected Access, revolves around the decade-old RADIUS authentication, authorization and accounting (AAA) protocol.
And the RADIUS protocol, which uses a shared secret authentication mechanism, is known to be subject to off-line dictionary attacks when not implemented as recommended by the relevant Internet Engineering Task Force (IETF) Requests for Comments (RFC). According to RADIUS experts, it sounds as though RADIUS has been "casually" implemented by many vendors and enterprises - at least when compared to IETF RFC recommendations.
IETF RFCs state that shared secrets should be as large and unguessable as a well-chosen password, and IP Security (IPSec) should be used to encrypt RADIUS shared secrets, for example. Since these recommendations often aren't followed, many common implementations are vulnerable to dictionary attacks.
"RADIUS has become the weak link in the [wireless] security chain," says Joshua Wright, deputy director of training at the SANS Institute in Bethesda, Md. Wright has co-authored an Internet-Draft, along with two security experts from Aruba Wireless Networks, to be submitted to the IETF. It recommends stronger language in RADIUS-related RFCs for protecting RADIUS communications, since so many security architectures now rely upon the protocol.
Lisa Phifer, vice president at Core Competence, a networking consulting firm, doesn't see the RADIUS issue as a huge deal, but acknowledges: "Increased use of 802.1x [part of 802.11i] has increased the use of RADIUS and, therefore, the threat level associated with this risk. Companies that haven't previously used RADIUS do need to be aware of existing risks and recommended practices."
Wright, however, observes that wireless LANs can exacerbate the RADIUS vulnerability in a couple of ways:
- Because wireless encryption keys are transported within the RADIUS protocol, if the RADIUS conversation between access point (AP) and RADIUS server is cracked by sniffing the LAN segment between the two devices, a hacker can decrypt wireless packets and authentication information, and gain access to both the wireless traffic and the network.
- If encryption/decryption takes place in many distributed APs, as opposed to a centralized device, there are many more potential places where a hacker could potentially crack the conversation.
- If a rogue AP goes undetected, a hacker could sniff, then passively decrypt, any Extensible Authentication Protocol credentials and Layer 2 encryption, then decrypt wireless traffic.
As best practices, Aruba recommends use of IPSec encryption for RADIUS communications, as currently recommended in IETF RFC 3579, and is recommending that the IETF amend the RFC to require it. Aruba also recommends centralized authentication and encryption in the data center (rather than storing shared secrets and keys in distributed access points).
Not surprisingly, Aruba's own WLAN architecture is set up this way. Other WLAN vendors that encrypt/decrypt in a centralized switch include Legra Systems and Symbol Technologies.
Craig Mathias, founder of Farpoint Group, a wireless consultancy, sums up the RADIUS/wireless issue:
"I think this is an example of a well-known class of security vulnerabilities, involving poor choices in keys (too short, alphanumeric, etc.) The right keys are long and binary, making a dictionary attack impossible. Note also this isn't really a wireless issue, but, since RADIUS is a network AAA system, it is often used on wireless LAN systems even where no authentication is used on the wired side. Thus the issue may be more obvious on wireless networks, especially since the sniffing required is very easy in that case."
Computerworld Buyer's Guide - Vendors Matched to this Article
Computerworld Member Login
Prioritizing Services with IT Service Management (ITSM)
Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)
To be repeated on:
Thursday 4th, September 2008
11:00am EST (Sydney Australia)
Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.
Attend and discover:
- How to deliver value to your business through ITSM
- Best practice ITSM implementation
- Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
- If service-oriented ITSM is best for your business
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Viva la Verticals! Key to Vendor Growth is Through Vertical Market Opportunities, Says IDC 2008-09-05 11:05:00+10
F-Secure delivers fastest protection in the online world 2008-09-04 16:50:00+10
NETGEAR expands ProSafe team as business-class products take off in SME market 2008-09-04 16:27:00+10
Rogue security apps dominate Fortinet's Aug 2008 IT threat report 2008-09-04 16:00:00+10
Adaptec Intelligent Power Management Reduces Storage Power Consumption Up to 70 Percent 2008-09-04 11:28:00+10
Market Trends: Multienterprise/B2B Infrastructure Market | Worldwide | 2008
Garner says global 2000 companies will double their multi-enterprise traffic in the next 5 years. Discover the key technology and business drivers that will enable this.









