Wireless LAN networks are becoming mainstream. With the deployment of wireless network access in the workplace, the requirement for a more enhanced security design emerges. Wireless technology offers a more accessible means of connectivity. However, security issues are impeding further adoption of technology by end-users. In particular, the two issues limiting wider acceptance are authentication and encryption.This paper aims to provide basic background information about the wireless LAN security problems, discuss and investigate associated solutions, and identify some unsolved related challenges.
The poor state of security on the Internet calls for more effective ways to protect networked systems from attacks. One solution is to be able to counter attack with offensive capabilities. With attacker information available, companies find themselves in a dilemma-counter attack for immediate self-defense, retaliate for future deterrence, inform the appropriate law enforcement authorities, or do nothing. We examine justification for the hack back self-defense and deterrence arguments in the context Of current technology and legal framework. This paper extends discussion of issues surrounding using offensive capabilities for defensive purposes to the civilian/commercial Internet context beyond information warfare.
The United States is currently developing a national missile defense (NMD) system designed to protect its territory from attack by strategic (long-range) ballistic missiles. In September 2000, President Clinton decided to defer the NMD deployment decision to the next president. President George W. Bush reaffirmed his administration's commitment to deploying a ballistic missile-defense shield by ad...
A honeypot is a decoy computer system designed to look like a legitimate system an intruder will want to break into while, unbeknownst to the intruder, they are being covertly observed. Honeypots are effective precisely because attackers do not know if they are there and where they will be. However, honeypots are also a controversial technique; they essentially bait and capture intruders skirting the fine line between keeping attackers out of a network versus inviting them in. Little legal precedent has been established. Some see them as unfair entrapment tools while others see them as an effective data gathering and deterrence mechanism. This paper attempts to flush out the issues on both sides of a technique that may become ubiquitous in the future.
There is a distinct lack of basic understanding of user problems with current web technologies where the majority of electronic transactions occur at present. Our re sults show that a user's level of trust and risk are based on perceptions of website design that are significantly different based on prior knowledge. We report that corporations are already exploiting this result to maximize the use of supe rficial security cues that do not provide protection while minimizing investment in technological security solutions that do provide protection. Implications of this finding may help explain the measured increasing lack of Internet security and thus survivability of web-based information systems.
The state of security on the Internet is bad and becoming worse. One reaction to this state of affairs is a behavior termed "Ethical Hacking" which attempts to proactively increase security protection by identifying and patching known security vulnerabilities on systems owned by other parties. Ethical hackers may beta test unreleased software, stress test released software, and scan networks of computers for vulnerabilities. Previous work has emphasized ethical hacking as an altruistic behavior but we find ethical hackers act rationally, in self-interest, to secure systems that are within their own community (sometimes for pay)-networked systems are only as secure as the weakest system within perimeter defenses.
Because there is no single virtual private network (VPN) solution, it's critical to have a planning framework to ensure successful deployment. A VPN is virtual in that it has no corresponding physical network but rather shares physical circuits with other traffic. A VPN is private in that it isolates Internet traffic with routing and secures if with encryption. The use of "private" and "Internet based" to describe the same service appears to be an oxymoron, but we explain how VPNs manage to be both. Many choices will confront you in considering how to deploy a VPN. We briefly describe the core choices such as the different types of VPNs, encryption, firewalls, and how to accommodate legacy systems. Each distinct VPN solution has its own strengths, weaknesses, and price tag; IT professionals must weigh these characteristics against business requirements.
The authors present two complementary ways to deal with soft-ware aging. Their approach pro-actively reinitializes software to a known operating state, before failure occurs, or reactively reconfigures soft-ware after a failure such that service remains operational.
Information technology is redefining national security and the use of force by state and nonstate actors. The use of force over the Internet warrants analysis given recent terrorist attacks. At the same time that information technology empowers states and their commercial enterprises, information technology makes infrastructures supported by computer systems increasingly accessible, interdependent, and more vulnerable to malicious attack. The Computer Security Institute and the FBI jointly estimate that financial losses attributed to malicious attack amounted to $378 million in 2000. International Law clearly permits a state to respond in self-defense when attacked by another state through the Internet, however, such attacks may not always rise to the scope, duration, and intensity threshold of an armed attack that may justify a use of force in self-defense. This paper presents a policy framework to analyze the rules of engagement for Internet attacks. We describe the state of Internet security, incentives for asymmetric warfare, and the development of international law for conflict management and armed conflict. We focus on options for future rules of engagement specific to Information Warfare. We conclude with four policy recommendations for Internet attack rules of engagement: (1) the U.S. should pursue international definitions of "force" and "armed attack" in the Information Warfare context; (2) the U.S. should pursue international cooperation for the joint investigation and prosecution of Internet attacks; (3) the U.S. must balance offensive opportunities against defensive vulnerabilities; and (4) the U.S. should prepare strategic plans now rather than making policy decisions in real-time during an Internet attack.
We describe innovative new approaches to teaching information systems security that may be used individually or in combination. Information system security is a difficult course to teach and these approaches provide resources to both novice and experienced educators to enhance their courses. We conclude that more educational development work needs to done to uniformly improve information systems security education to counterbalance pressures for technical training over fundamental concepts and this paper provides a start by synthesizing the current state-of-the-art.
This paper compares firewall alternatives with virtual private network support appropriate for corporate applications. Two specific firewall solutions are compared highlighting corresponding security risks: (1) a firewall constructed using only open source software available for the Linux operating system and (2) a commercial firewall solution from Cisco using the Cisco IOS firewall feature set.
Whole system assurance is necessary since over-reliance on protection solutions for system components has actually contributed to the fragility of information systems when viewed as a whole. For instance, the use of authenticatio n and encryption to protect networked systems may actually add more vulnerabilities to the system as a whole than they eliminate. The goal of this research is to increase the survivability of information systems to underlying failures by focusing on reducing net system vulnerabilities and increasing net system restoration capabilities. Specifically we give examples of current projects that are in varying states of development.
This paper presents a layered VPN planning framework for organizations based on actual implementation experience. Specifically, we describe security issues corresponding to five distinct layers of analysis: (1) VPN technology; (2) firewalls; (3) legacy networks; (4) survivability; and (5) legacy applications. There is a broad spectrum of VPN options available with each having its own strengths, weaknesses, and vulnerabilities. It is anticipated that no single VPN solution will supplant others but instead a diversity of choices will continue to emerge thus increasing the value of an advanced planning framework.
Deploying VPNs (Virtual Private Networks), especially in a large-scale environment, requires much planning. Based on actual implementation experience, we propose a layered framework that can be used to distribute VPN deliverables among different workgroups. Despite the perception that a VPN is not a customizable solution, we conclude there is a broad range of VPN options available with corresponding trade-offs. This framework supports advanced planning to maximize trade-offs depending on individualized requirements.
Web-Cameras have gained wide spread popularity for a variety of purposes. Most of the available applications use the snapshot approach, where the camera is mounted in a certain position and the field of view is fixed. This paper describes a Web-Cam application that allows remote users to control the Field of View (Zoom and Telephoto), the position of the camera (two degrees of freedom), and customize a surveillance program (capturing frequency, camera position, and response based on motion detection). Technical Description Figure 1 shows the user interface for controlling the camera. The smaller image at the top defines fine camera movements along with zoom and telephoto controls. The image at the bottom allows absolute movements of the viewing area. A maximum motion on the vertical axis is 40 degrees and on the horizontal axis is 100 degrees. The camera used is a Cannon VC-C1 connected to a PC capture card. Figure 1: Web-camera User Interface
The use of virtual private networks is increasing rapidly primarily due to security concerns. As the result of analyzing actual corporate VPN strategies, we identify a common vulnerability we name “distributed weakness in VPNs”. Specifically we describe a simple routing attack that can be launched against VPN tunnel endpoints with significant implications. We close with a solution to protect against exploitation of this vulnerability