home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Network Computing Blog
Lead NAC Analyst:
Mike Fratto
Mike Fratto


:: More analysis, strategies and news at our
NAC Immersion Center


:: Subcribe to This Blog's
RSS Feed
SPECIAL EVENT BLOGS:
BrainShare 2008

IMMERSION CENTER BLOGS:
Network Access Control
Virtualization
Application Performance Optimization
Data Center
Data Privacy
802.11n
SOA/Web Services

MORE TOPCS:
Security
Wireless
Application Infrastructure
Collaboration
Network and Systems Management
Network Infrastructure
Storage and Servers
Enterprise Applications
Business Strategy
Personal Technology
Podcasts
NWC Inc
NWC Labs
Techno-Oddities

MORE GREAT BLOGS
Ars Technica
bMighty
Boing Boing
Geek.com
InformationWeek
IT Toolbox
TechCrunch



NAC Immersion Center Blog

May 28, 2008
Companies Don't Need NAC. They Need PAC.
By Mike Fratto

PAC, as in personal access control. Getting unauthorized access to a company's assets is often child's play, and security pros know that. Guys like Steve Stasiukonis, CEO of Secure Network, and Ira Winkler, CEO of ISAG, can regale you with stories of literally walking into supposedly high-security buildings like they walk into the grocery store. The underlying flaw is often people. These two gentlemen look like nice guys, and they are. But if Steve and Ira were morally challenged, they could the steal the shirt off your back.

No matter the physical controls in a building -- cameras, card readers, man traps (vestibules with two locked doors), guards checking ID cards, etc. -- walking into a building is often simpler and cheaper than trying to hack your way in. What is scary is that even though companies have well-defined procedures for handing out ID cards, a smile and reasonable story can subvert the whole process.

Stasiukonis was telling me about a recent penetration test his company went on. I didn't ask who and he didn't volunteer the company name. As part of the penetration test, Steve actually got an employee ID issued to him and then he got contractor ID's for his crew. He entered a secure data center and learned the network architecture from the IT staff, including their future plans. He listened in on meetings, videotaped presentations, and wandered undetected into the CEO's office.

The crumbling of this company's physical access controls began with getting a badge. Stasiukonis wasn't properly vetted before getting a badge. Once he had a badge, making him an authorized employee, the internal controls failed to keep him and his team from information and places they probably shouldn't have been in the first place. This story is very much analogous to the limitations of current NAC technologies, namely, once you have access to the network, there isn't enough access control to restrict what a malicious user can do.

I don't think Stasiukonis tried to get authorized network access -- he didn't need it -- but if he tried, there is no reason to think he would have failed. NAC, whether you are looking at network admission control, which is primarily focused on admitting hosts to the network, or network access control, which focuses on admitting hosts to the network and then regulating the services a host can access once connected, simply fails if your company improperly vets access requests.

A number of vendors, like Bradford Networks, Cisco, and Great Bay Software, are developing or selling guest sponsorship products that allow an employee to sponsor guest network access, similar to how employees can get a temporary guest pass to enter a building. From a business process point of view, that sounds like a great idea. Let the central IT department define the policies that employees can sponsor, grant sponsorship privileges to employees, and you can off-load the management burden from IT to someone else. But given the overwhelming evidence demonstrating how easy sweet-talking a building badge from an unsuspecting employee is, getting network access won't be that much more difficult.

Granted, few companies, compared to all companies, need to run highly secure facilities. Doing so is unnecessary and cost-prohibitive. Many companies' goals may be more modest. They simply want to control guests accessing the network. Regardless, before embarking on a NAC deployment, spend the time thinking through all the requirements and processes that you will need to enable your goals.

If your goal is to treat guests differently from employees, then how will you determine a guest user or computer from a company-owned asset? How will a guest be authorized to get a pass onto the network, and who is responsible for doing that? If your goal is more fine-grained access control, perhaps determining access based on a user role or group membership, then where is that information stored, who is responsible for defining who is a member of each group, and what will you do about conflicts that occur when a user is a member of two potentially conflicting groups? It all comes down to defining a process, educating people about the process, and then implementing a product that supports your process.

-- Posted at 11:29 AM in NAC Immersion Center





This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.








Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
IWKBTN
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek ReportsInformationweek MagazinebMightyByte and SwitchDark ReadingDigital Library
Intelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. Dobbs
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoSoftware ConferenceNoJitterMobile Connect
Black HatGTECEnergy CampMashup CampStartup CampCloud Connect
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungCable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoOptical ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev Pro
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights