Security Solutions [教程].ppt

  1. 1、本文档共47页,可阅读全部内容。
  2. 2、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
  3. 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载
  4. 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
查看更多
Why Wireless Security? Heiko Kratz Aruba System Engineer Agenda Security Threads… What Doesn‘t Work… Aruba Security Solutions Aruba at ?22C3“ Congress So why Aruba Wireless Networks? Documentation Links Security Threads Internal Security Threats 50-80% of Security Attacks Now Originate Within the Firewall Source: Computer Security Institute, FBI Key Vulnerabilities Open Ports Employees, Partners, Guests The $39 Threat (Unsanctioned WiFi) “Firewalling the Intranet” A LAN-speed firewall for every user Blocks rogue users Enables guest access to Internet Opens network only to authorized users Conventional Perimeter Security Various Threats on WLANs WLAN Discovery DOS Attacks Surveillance Impersonation/Man-in-the-Middle Intrusion (Client-Client, Client-Network) Rogue Detection and Containment A Myriad of Intrusion Tools Wireless Intrusion Detection is KEY What Doesn’t Work… Doing Nothing Wireless LANs are cheap and easily available If the IT department doesn’t deploy wireless, someone else will Thousands of dollars worth of network security can be bypassed by a single “Rogue” Access Point If your organizational policy is to allow no wireless, there must be a realistic mechanism to enforce that policy The Existence of Wireless LANs is a Security Threat – A Case Study RF Engineering Using directional antennas to direct and limit RF coverage does not work RF is invisible Physical environments change Lowering transmit power or placing access points (APs) away from outside walls to limit RF “leakage” does not work Set RF coverage to optimize user experience – not to control leakage SSID Cloaking Some APs offer a feature to hide the SSID (Service Set Identifier or “wireless network name”) in advertisements Hiding the SSID will discourage only the casual “war-driver” looking for free Internet access A person intent on network intrusion can run a simple tool to instantly reveal the SSID The SSID should never be treated as though it were a password M

文档评论(0)

lizhencai0920 + 关注
实名认证
内容提供者

该用户很懒,什么也没介绍

版权声明书
用户编号:6100124015000001

1亿VIP精品文档

相关文档