Thursday, 2 February 2012

CMC3P22-P01-1001597B

IEEE 802.11i,  IEEE 802.11r, IEEE 802.11k and IEEE 802.11w   

IEEE 802.11i



The Group Key Handshake

The GTK used in the network may need to be updated due to the expiry of a preset timer. When a device leaves the network, the GTK also needs to be updated. This is to prevent the device from receiving any more multicast or broadcast messages from the AP.
 

IEEE 802.11r

The non-802.11r BSS transition goes through six stages:
  • Scanning – active or passive for other APs in the area.
  • Exchanging 802.11 Authentication messages (first from the client, then from the AP) with the target access point.
  • Exchanging Reassociation messages to establish connection at target AP.
At this point in an 802.1X BSS, the AP and Station have a connection, but are not allowed to exchange data frames, as they have not established a key.
  • 802.1X master key (PMK) negotiation
  • Key (PTK) derivation – 802.11i 4-way handshake of session keys, creating a unique encryption key for the association based on the master key established from the previous step.
  • QoS admission control to re-establish QoS streams
A fast BSS transition performs the same operations except for the 802.1X negotiation, but piggybacks the PTK and QoS admission control exchanges with the 802.11 Authentication and Reassociation messages.

 

IEEE 802.11k

 802.11k is intended to improve the way traffic is distributed within a network. In a wireless LAN, each device normally connects to the access point (AP) that provides the strongest signal. In a network conforming to 802.11k, if the AP having the strongest signal is loaded to its full capacity, a wireless device is connected to one of the underutilized APs. Even though the signal may be weaker, the overall throughput is greater because more efficient use is made of the network resources.

IEEE 802.11w   

Wireless LANs send system management information in unprotected frames, which makes them vulnerable. This standard will protect against network disruption caused by malicious systems that forge disassociation requests that appear to be sent by valid equipment.


Tuesday, 10 January 2012

Microsoft’s Active Directory Security Feature

Microsoft’s Active Directory Security Feature

Simplified user and network-resource management
Using Active Directory, you can build hierarchical information structures that make it easier for you to control administrative credentials and other security settings and that make it easier for your users to locate network resources, such as files and printers.
Flexible, secure authentication and authorization
Flexible and secure authentication and authorization services provide protection for data while minimizing barriers to doing business over the Internet. Active Directory supports multiple authentication protocols, such as the Kerberos V5 protocol, Secure Sockets Layer (SSL) v3, and Transport Layer Security (TLS) using X.509 v3 certificates, and security groups that span domains efficiently.
Directory consolidation
You can organize and simplify the management of users, computers, applications, and devices, and make it easier for users to find the information they need. You can take advantage of synchronization support through Lightweight Directory Access Protocol (LDAP)-based interfaces, and you can work with directory consolidation requirements specific to your applications.
Directory-enabled applications and infrastructure
Active Directory features make it easier for you to configure and manage applications and other directory-enabled network components.
Scalability without complexity
Active Directory scales to millions of objects per domain and uses indexing technology and advanced replication techniques to speed performance.
Use of Internet standards
Active Directory provides access through LDAP and uses a Domain Name System (DNS)-based namespace.


Monday, 9 January 2012

LDAP Security Feature


LDAP Security Feature

LDAP and especially OpenLDAP has a number of security features which at first (second and third) glance may be a tad daunting. Diagram below provides a perspective of the problem before diving into detail. It shows the various access methods and interfaces to an LDAP system and then describes some security issues and what methods are available to manage the risks involved. The purpose of this exercise is to determine either a set of security policies or implementation priorities.


Remote Communications : Remote communication security may or may not be an issue. If you provide unlimited (anonymous) access to non-sensitive LDAP data then the security issue is moot. Caution: In these circumstances you potentially become vulnerable to DoS/DDoS attacks through malicious LDAP query loads - so even this apparently trivial environment may need careful consideration.

Passwords : Securing passwords during communications should not be confused with securing them within configuration files or DITs. Even if you have secured all passwords within the configuration file or the DIT using a hash-method, such as {SSHA}, when a password is sent from a client to the server it is sent in the clear, hashed at the server and compared with the stored contents. Without any further action it can therefore be snooped (or sniffed depending on your predilection for these terms).

Note: When an entry containing, say, a userPassword attribute stored using, say, {CRYPT} is requested by a client it is not sent in cleartext but in its hashed (stored) form. However when access to that same entry is required the client sends the authenticating password in cleartext and clearly(!) if the login is successful the snooper can reasonably assume the cleartext password was correct!


X.500 Security Feature


X.500 Security Feature

The X.500 directory service is a global directory service. Its components cooperate to manage information about objects such as countries, organizations, people, machines, and so on in a worldwide scope. It provides the capability to look up information by name and to browse and search for information.

Security Feature

X.500 has evolved significantly, to encompass features not in the original X.500(1988) version. This has led to significant updates in the X.500 (1993) specification. Some smaller additions are also planned for X.500(1997). The major changes for X.500(1993) are:
  1. Sophisticated replication using Directory Information Shadowing Protocol (DISP). Replication of data is critical for providing a robust directory service. X.500 DISP provides this service, and gives a lot of flexibility for different replication configurations.
  2. Access Control. There is a standard and flexible mechanism for specifying access control. This is important to allow open and controlled management of data in the directory, especially when the data is replicated.
  3. Improvements to information model. There are a number of improvements to the X.500 data model, based on experience with X.500 (1988). These include attribute subtyping, which allows related attributes to be handled in a clean manner and operational attributes, which allow directory management attributes to be distinguished from user data.
  4. Administrative area model to help management. A mechanism is added whereby data can be grouped into administrative areas, and data (including access control) shared over this area by use of collective attributes. This is an important change for many operational environments.
  5. A number of small changes to the overall directory service.
On the outside, the X.500(1993) directory has not changed a great deal. There has been significant change to the internal operations and management features, which address serious service and deployment issues.

 Reference:

http://docs.oracle.com/javase/jndi/tutorial/ldap/models/x500.html

Thursday, 5 January 2012

GPRS Security Feature, Threats and Solution

GPRS Security Feature, Threats and Solution
General packet radio service (GPRS) is a packet oriented mobile data service on the 2G and 3G cellular communication system's global system for mobile (GSM). It provides moderate-speed data transfer, by using unused time division multiple access.
GPRS Security Feature
·         Identity Confidentiality
This is to provide privacy to the subscriber so it will be difficult to identify the person from thier signal over the radio and connections to the SGSN. It is also used to protect identity such as dialed digits and addresses.

·         User and signaling data confidentiality
This is derived by using function A3/8 as in GSM.

·         Authorization
It is a security service that ensures a party may only perform the actions that they are allowed to perform.

·         Availability
Data services are usable by the appropriate parties in the manner intended.
GPRS threats
Most common types of attack on availability would be denial of service attack. Below are some of the DOS attack.
·         DNS Flood
It can be flooded with either correctly or malformed DNS queries or other traffic thereby denying subscribers the ability to locate the proper GGSN to use as an external gateway.

·         DNS Cache Poisoning
An attacker to forge DNS queries or responses that cause a given user’s APN to resolve to the wrong GGSN or even none at all is possible. Sometimes it can prevent subscribers from being able to pass data at all.
·         Overbilling attacks
This is by a malicious mobile station that hijacks an IP address of another mobile station and invokes a download from a malicious server on the internet. Once the download begins, the malicious mobile station exits the session. The mobile station under attack, receiving the download traffic, gets charged for traffic it did not solicit. The same malicious party could execute this attack for the purpose of sending broadcasts of unsolicited data in the direction of subscriber cell phones. The effect is still the same, in that the subscriber is billed for  data that they did not solicited and might not have wanted.

GPRS solution
The fundamental issue with security is the lack of security inherent. Implementing IPSec between roaming partners and managing traffic rates, can eliminate a majority of the threats.

·         Overbilling Attack Prevention
Enables the firewall to of an attack. The firewall is then able to terminate the “hanging” sessions and/or tunnels, thus cutting off the unwanted traffic. As such, this prevents the GPRS subscriber from being “overbilled.”

Reference: