Make BitDefender? Hati-hati!! Baca: http://j.mp/9nM4X7 http://koprol.com/s/3FzN
59 minutes ago by pepoluan on topsyZDNet is available in the following editions:
In this issue of Industry Insider, ZDNet's David Berlind says just because your company hasn't deployed wireless networks doesn't mean you shouldn't be concerned with at least one form of wireless security: prevention of rogue access points.
Indeed, when it comes to the threat matrix associated with wireless security, there are many issues demanding attention: everything from keeping unauthorised wireless users off wireless local area networks (WLANs) to making sure that the traffic flowing through a WLAN is encrypted in a way that keeps the payloads safe from prying eyes.
Although most wireless security solutions target organisations that have deployed wireless networks, there is a class of solutions that target all companies -- even those that haven't deployed wireless networks. These solutions detect the existence of rogue access points. (An access point is a transceiver that connects devices on a wireless LAN to the wired infrastructure. A rogue access point is not authorised by an organisation's IT department for operation.) Setting up an access point is child's play. In addition to plugging the access point into a power source, all one has to do is connect one end of an Ethernet cable to an available Ethernet port, connect the other end to an access point and voila! A new Wi-Fi WLAN is born.
Not all rogue access points are malicious. Until my IT department found out about it and asked me to shut it down, I ran a rogue access point for almost two years (long before Wi-Fi was popular). So early was it in the history of Wi-Fi, that the software for setting up, managing, and securing my Lucent-based 802.11b WLAN was both proprietary and not very user friendly. Knowing that hardly anyone was using Wi-Fi at the time, I didn't bother securing it. Eventually, the company standardised on a single vendor's technology for deploying and securing WLANs and, knowing about my access point through the grapevine, the IT department saw my rogue WLAN for what it was: a back door that bypassed all of the hard work and planning that went into building a secure Wi-Fi network.
Nick Miller, CEO of wireless management solution provider Cirond, put the problem in simple terms. "Companies spend thousands upon thousands of dollars and man-hours on network security," said Miller, "and all it takes is a $30 access point to render that investment useless."
Why set up a rogue access point in the first place? I can imagine at least three scenarios that could result in rogue access points. The first of these is where people with wireless networks at home and at work are having difficulty with home-work interoperability. Though software is making it easier to move back and forth between the two, I've had this problem and I also know that the easiest solution is to have the same kind of access point in both locations.
In the second scenario, people have a wireless network at home, but none at work. Once people catch wireless fever at home, they want it at work, too. If, for security or budgetary reasons, their company's IT department is unwilling to provide it, many overzealous workers are willing to install one for themselves.
In the third scenario, someone outside the organisation -- usually someone with malicious intent -- gains access to a physical Ethernet port on the company's network and surreptitiously connects an access point to it. Depending on where that port is (for example, underneath a desk in an unused cubicle), such "deployments" can easily escape physical detection.
The last two scenarios are particularly noteworthy since they could introduce wireless security problems to companies that have, for whatever reasons, no deployments of wireless technology.
So high on the radar is the rogue access point problem that a demonstration involving the surreptitious installation and subsequent detection of one was included in Cisco CEO John Chambers' Networld+Interop keynote speech. Cisco is one company of many that offer methods and products for detecting rogue access points. In fact, finding a solution isn't the challenge. The challenge is in finding a solution where you don't pay for functionality that you already have.
At Networld+Interop, I spent time with executives from Cirond and Lockdown Networks, both of which offer hardware-based solutions for locating rogue access points. Whereas Lockdown Networks sees rogue access point detection as a part of the larger problem of vulnerability management (wired or wireless), Cirond sees it as a part of the larger problem of wireless network management. Both companies' offers demonstrate how it's impossible to get everything you might need -- vulnerability management, rogue access point detection, and wireless network management -- in a la carte fashion from best-of-breed vendors.
Even the vendors are somewhat challenged when it comes to the positioning of the product. Cirond's Miller explained how the company's flagship product, WiNc Manager (which includes rogue access point detection), is having its name changed to AirPatrol -- the name also used for the company's mobile (as opposed to stationary) rogue access point detection solution.
Prior to the change, the company mostly emphasised WiNc's ability to demystify the management of Wi-Fi security. One of WiNc's strengths is in its ability to roll out uniform security settings (WEP keys, key rotation schemes, SSIDs, channel assignments, etc.) to heterogeneous Wi-Fi infrastructures that involve access points from multiple vendors. Whereas the evolving 802.11 specifications include standards for such settings as encryption and network identification, there are no standards when it comes to the user interface on the management software used to change those settings. As a result, deployment of access points from multiple vendors can easily result in the usage of just as many applications to manage them. WiNc can manage them all from one console.
But, as rogue access point detection became equally if not more important than WiNc's other functions, Miller was compelled to change the product's name.
Unfortunately, if you want rogue access point detection from Cirond, the only way to get it a la carte is by buying the mobile product. Otherwise, for the stationary, more industrial strength version, you must take it with the rest of the management product, which may include functionality you already have covered (especially if you've standardised on a single vendor for access points).
Like Cirond, LockDown sells a piece of hardware for detecting rogue access points. It costs US$5,000. But to get it to work, you need to own LockDown's $10,000 vulnerability assessment solution called LockDown Auditor (or, its bigger sister LockDown DataSafe). Vulnerability management, an important part of layered security, involves constant testing all systems for known weaknesses or improper security settings. Like LockDown, most of the numerous solutions for automating the vulnerability assessment process feature a central collection point for vulnerability assessment results. In as much as the discovery of a rogue access point is one of those results, a central collection point like LockDown Auditor or LockDown DataSafe is necessary for collecting data from the detection sensor (a.k.a. LockDown Wireless).
When a network management product overlaps a wireless management product, which overlap a rogue access point detection product, which overlaps a vulnerability assessment product, which overlaps an intrusion detection system and so on, an IT manager's selection process becomes more complicated. While the solutions themselves looked great, I lament the buyer's dilemma. These days, it's getting harder and harder to find extremely focused, best-of-breed products that do one thing and do it extremely well.
biography
David Berlind is an editor with ZDNet.com.
Make BitDefender? Hati-hati!! Baca: http://j.mp/9nM4X7 http://koprol.com/s/3FzN
59 minutes ago by pepoluan on topsythe ugly side of socmed marketing... companies, beware! http://j.mp/cIqelG http://koprol.com/s/3FyS
1 hour 7 minutes ago by pepoluan on topsyForeign LBS players need local tie-ups for commercial success in the region. http://tinyurl.com/yco936k
1 hour 42 minutes ago by zdnetasia on twitterPersonal Finance Software - Productivity Software - Mac - Free ...: SEE Finance. Personal finance manager featurin... http://bit.ly/a38bXY
2 hours 31 minutes ago by alisha204 on topsyFor BitDefender antivirus users, check out what the company said regarding its bad security update: http://bit.ly/cYTGug
2 hours 47 minutes ago by zdnetasia on twitterAsia not ready for zero-client computing, says analyst. http://bit.ly/cALkZB
2 hours 48 minutes ago by zdnetasia on twitterFor BitDefender antivirus users, check out what the company said regarding its bad security update: http://bit.ly/cYTGug
3 hours 15 minutes ago by kevinzdnetasia on topsyAsia not ready for zero-client computing, says analyst. http://bit.ly/cALkZB
3 hours 26 minutes ago by vivianzdnetasia on topsyFour news blogs today, from Inside India, Msia Explorer, Mister Tech and Tech Legal. Do check them out. http://www.zdnetasia.com/blogs/
3 hours 34 minutes ago by zdnetasia on twitterRead my blog post on getting the most from your Nexus One: http://www.zdnetasia.com/blogs/m...
1 day 32 minutes ago by mistertechblog on twitterRT @3wconsulting: Whitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oY9f
1 day 46 minutes ago by LeesaAT3W on twitterWhitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oYbA
1 day 47 minutes ago by itemployment on twitterWhitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oYbz
1 day 47 minutes ago by brucemills on twitterZdnetasia.com Estimated Worth $178,365 USD. Daily Ad Revenue:$244 USD, Daily Views:81,445 Pages... - http://www.haplog.com/www.zdneta...
1 day 30 minutes ago by Haplog on twitterThe receivers don't transmit back to the satellite. Unless there is a phone line attached to the receiver, they don't have any wa...
2 days 12 minutes ago by bessellbrowne on Apple to join the geolocation craze?whatever little understanding I have we 'll only progress toward end of the world if we use HPCs to lenthen life of human being. Huma...
2 days 19 minutes ago by abhi32002@gmail.com on High computing promises elixir of lifeThanks for the knowledgeable article on SDDs. Allas...when all this reasearch will happen in Indian Universities. Hope the new bill on Fo...
2 days 31 minutes ago by abhi32002@gmail.com on APAC HPC users eye solid-state drivesIt was a good article. This brings a good opportunity for Indian IT firms to come up with new solutions in this field. HPC can become a b...
2 days 50 minutes ago by abhi32002@gmail.com on High computing most-wanted job in AsiaCOL KR DHARMADHIKARY(RETD) its very late to reply the link, but if it is still alive and looking for opportunity, i would like to know th...
2 days 48 minutes ago by deb021280 on Education takes off in rural India, helped by PCsHigh performance computing (HPC) most-wanted job in Asia http://bit.ly/9vFC3i (via @zdnetasia) #singapore
3 days 4 minutes ago by mySingapore on twitterRT @zdnetasia: EMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. (cont) http://tl.gd/i5jjd
3 days 53 minutes ago by mistymaitimoe on twitterEMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. http://bit.ly/9etOZW
3 days 57 minutes ago by zdnetasia on twitterAsian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08 via @zdnetasia
3 days 13 minutes ago by asiapacsolution on twitterAsian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08
3 days 27 minutes ago by zdnetasia on twitterall of sg's isps have been practising compulsory invisible proxy for all home subscribers at their backend since many years back alre...
4 days 31 minutes ago by melvinchia on Web filters mean bad news for businessit is not to good for china.
Proactol
Very good explanation of JMX
5 days 21 minutes ago by Babith B on Managing applications with JMXThe reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.
5 days 25 minutes ago by lonemavericks on diggsAnother ZTE story....
5 days 27 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G licenseWe at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.
5 days 486035 seconds ago by sarah Jane on Companies' outsourcing spend to increaseI agree with you. The iSiVaL is super portable and TVs can't expand their image size. I recorded a video that might bring some ideas to...
5 days 30 minutes ago by Jesse B Andersen on Buying a projector? Try an LED TV insteadhermm... he deserved it.. he shud not talk abt sensitive things like tat, well, he shud think twice before saying all those things, event...
5 days 8 minutes ago by ... on Facebook user charged in MalaysiaPassword manager tools are potential security threat. Criminals who hack into the computer can use the password manager to log onto any s...
6 days 9 minutes ago by ohanae on What defaults should random password generators use?I've found the cross platform utility unetbootin to be rather handy for this kind of thing as well.
6 days 43 minutes ago by Jim on Use Live USB Creator to install Fedora 12 from a USB stickThanks for the article. I think the debug command has an "\" after "C:" it should say w32tm /debug /enable /file:C:\l...
6 days 43 minutes ago by Roger Biefer on Manage time accuracy with W32TmThe Desktop Virtualization Revolution is here!
Find our more with Citrix Simplicity is Power
2010 IT Salary & Skills Report
Find out the salary range of IT professionals. Join activeTechPros for free access to the report.
The Internet Show 2010, 21-22 Apr 2010, Singapore
FREE admission for visitors who pre-register online. Register Today!