| Name of the Protocol | Description |
| WAP (Wireless Application Protocol) | This is an application communication protocol inherited from internet which is used by handheld devices, mobile phones, pagers and two way radios, smart phones, etc. WAP is supported by operating systems such as PalmOS, EPOC, Windows CE, FLEXOS, OS/9, and JavaOS. This protocol is capable of working with wireless networks such as CDPD, CDMA, GSM, PDC and TDM |
| TKIP (Temporal Key Integrity protocol) | This is a short term fix introduced to WAP which comes as a simple software/firmware upgrade. TKIP identifies all of the WAP weaknesses. This increase the IV (Initialization Vector) to 48 bits and first 4 bits indicate QoS traffic class while remaining 44 bits are used as a counter. TKIP generate new secret keys dynamically and use original secret key as a base. |
| SWAP (Shared Wireless Access Protocol) | This is developed by HomeRF Working Group for wireless voice and data networking for home environment. SWAP supports TDMA for interactive data transfer and CSMA / CA for high speed packet transfer. |
| EAP (Extensible Authentication Protocol) | EAP supports multiple authentication methods such as, token cards, smart cards, Kerberos, one time passwords, certificates and public key authentication. There are two EAP variations, · LEAP (Lightweight Extensible Authentication Protocol) – This is a proprietary protocol of Cisco which use dynamic Wired Equivalent Privacy (WEP) key that are changed with more frequent authentication between RADIUS server and clients. LEAP intends to provide secure authentication for 802.11 WLAN which supports 802.1x port access control. · PEAP (Protected EAP) – This is base on the Internet Draft (I-D) submitted by Cisco, Microsoft and RSA security to IETF. This relies on TLS to allow nonencrypted authentication types and encrypt all user sensitive authentication information. |
| LDAP (Lightweight Directory Access Protocols) | This is built on X.500 Directory services model and communication has two elements such as client-server and server-server. Few common LDAP server are, IBM DS Series LDAP Directory (AIX), Netscape Directory Server and OpenLDAP server (Linux), etc. |
| WRAP (Wireless Robust Authentication Protocol) | This is an encryption protocol standard for 802.11i and based on Offset Codebook (OCB) mode of AES. |
| HDTP (Handheld Device Transport Protocol) | This protocol is optimized for handheld devices and low performance networks and provide security features like, authentication, privacy and integration, counteracting playback attacks, etc. |
Wednesday, October 20, 2010
Wireless Protocols
Tuesday, September 28, 2010
Wireless Terminology
| Terminology | Description and common usage | Area of usage |
| 802.11a | ü An IEEE standard for wireless area network which operate in the 5 GHz. Wireless product must support 6,12, and 24 Mpbs data rate as well as this can go up to 54 Mbps. | ü This is used in 802.11a wireless networking |
| 802.11b | ü An IEEE standard support 11 Mbps of data rate and operating range between 2.4 GHz – 2.4835 GHz. This uses CSMA/CD for path sharing. These wireless devices suffer interference with other devices like, microwaves, codeless phones, etc which operate in same frequency. | ü This is used in 802.11b wireless networking |
| 802.11g | ü These devices operate range between 2.4 GHz – 2.4835 GHz and support data rate of 54 Mbps in most of the devices. These devices are backward compatible with 802.11b devices. These standard support better security such as WPA (Wi-Fi Protected Access), WPA2 with pre shared key or RADIUS server. | ü This is used in 802.11g wireless networking, Routers, laptops, |
| 802.11n | ü Latest IEEE standard which support bandwidth upto 600 Mbps. This standard support 2.4 GHz and 5 GHz band and backward compatible with 802.11a, 802.11b and 802.11g wireless standards. | ü This is used in 802.11n wireless networking, routers, laptops, PDAs and 802.11g and 802.11b devices which are compatible with 802.11n. |
| dBi | ü Decibel is the unit which measures the gain of wireless antenna. | ü Used in every standard due to its usage to measure the signal strength. |
| Antenna | ü Antennas are used to transmit and receive wireless signals from wireless bridge. Antennas are connected to bridge and bridge is connected to local area network. | ü Used in all standard. |
| Fresnel Zone | ü The area around the line of sight of WLANs which used to transmit signals between WLAN devices. This are should be free with disturbance for strong signals | ü Used in all the standards. |
| RADIUS | ü Remote Authentication Dial In User Service an authentication and accounting which used to authenticate dial in users usernames and passwords. This service is used by ISP (Internet Service Providers) | ü Used in all the standards when needed to authenticate. |
| WEP (Wired Equivalent Privacy) | ü This is a security layer which used by wireless network. WEP used shared key by source and destination devices to encrypt and decrypt communication. | ü PDAs, Wi-Fi areas, hotspots, WLAN, WPAN, |
| SSID (Service Ser IDentifier) | ü This is the public name which identifies the wireless network from other networks. | ü WLAN, WPAN, WMAN, etc. |
| PCMCIA (Personal Computer Memory Card International Association) | ü External peripheral device which is comes in size of a credit card. This can be fixed to laptops to get wireless connection. | ü Laptops, PCs |
| Access Point (A/P) | ü Help users to connect to WLAN or wired network. Mobile users are automatically shifted to next AP while they are on the move. | ü WLAN, WPAN, WMAN, etc. |
| WPA (Wi-Fi Protected Access) | ü Security mechanism better than WEP which provide better security. | ü WLAN, WLAN, WPAN, PDAs, |
| WLAN (Wireless Local Area Connection) | ü High frequency radio waves or infrared can be used for communication between nodes. In this Local Area Network used wireless transmission for communication. | ü |
| WWAN (Wireless Wide Area Network) | ü Similar to WAN except the implementation of wireless technology for communication. These enable users to interact with corporate email, applications and information as they do in the wired environment. | ü |
| WPAN (Wireless Personal Area Network) | ü With help of IrDA and Bluetooth we can communicate in a short distance such as 10m. This enabled personal area network which equipped with personal devices like, PDA, laptop and wireless printers, etc. | ü |
| WMAN (Wireless Metropolitan Area) | ü Wireless communication network which covers a metropolitan area which use multiple WLAN in the range of 50km. | ü |
| War Driving | ü This is a process of travelling around buildings to find out available wireless access points to gain access to networks and internet. Hackers use war driving to gain unauthorized access to corporate networks. | ü This can be used in any wireless network. |
RFID Implementation.
Implementation of RFID projects needs to be thoroughly planned and organized due to its nature of complexity, cost and needed expertise knowledge. First of all network administrator should have clearly identify the use case of RFID project. Planning, designing, and implementation of RFID project is based on the use case. Hence, meeting all the requirements of users is a great achievement but very difficult task for the implementer due to compatibility of hardware/software, environmental, budget, and organizational structural issues. When implementing RFID project minimum of below points needs to be adequately addressed.
Project objectives must be clearly defined and understood by the RFID team before hand doing anything. To understand clear objectives you need to identify why the organization is required to have RFID implementation, to serve what purpose. Whether it is trying to comply with some regulations or trying to improve productivity, efficiency or cost reduction in long run for their production environment or warehouse. This identification of reasons and setting objectives based on the facts you collected will help having smooth implementation process.
There should be a proper site survey to analyze the current infrastructure to identify places needs implementation of RFID. Selection of RFID product such as RFID tags, RFID readers, RFID antennas, etc need to be determined by the project team to suit the project budget. This is an area where there are lot of questions been rose. Your budget may not be enough to purchase required hardware devices such as RFID tags, RFID readers, etc with expected quality thus, this may leads to improper operation of devices when integrating, mismatch of your requirement or low quality of service. It is important to point out the disadvantages of having a fixed budget which cannot facilitate the organizational main purpose, thus get your budget approved for correct devices or else proceed with compromised budget, which is not recommended. On the other hand make sure your devices that are going to be purchased are well tested and have met quality and compliance standards in industry. There may be other RFID systems already in place in the organization or different system using radio frequency, in these conditions proper investigation should be carried out to identify the interferences that these existing systems may have on the RFID project you are going to implement.
Next step is to align your project to the organizational processes. Your organization’s business in the main concern, and this RFID implementation should benefit to the organization as a whole and improve the processes without adding burden. Due to new RFID implementation there may be a need to process/procedure realignments, adding new process/procedures, removing redundant processes/procedures, etc, which have to be well analyzed and adjusted to suit the business needs and implementation of RFID project.
Software configuration and integration of RFID devices play an important part in the RFID project. All the devices need to place in appropriate places as decided during the planning stage and configure software to connect all RFID devices and meet organization expectations. It is acceptable to start with the default configurations for general purposes applications. But fine tuning to get maximum accuracy and high performance needs well trained professional knowledge.
When all the things are in place monitor how interdependent components behave in the system. For instance all processes, equipments, software, and human aspect of the entire system needs to operate in collaboration to produce better result. Monitor all aspects to identify places where it needs adjustments to smooth the operation of RFID system to improve performance and efficiency.
One main aspect needs to address above all stages is education, awareness and training for users and manage the positive/negative resistance of users. People might have a misunderstanding of that implementation of RFID system will eliminate the human resources in the process which may results in loss of employment. If this situation cannot be managed diplomatically, this might result in a project failure with large amount of financial, and human resources wastage.
Applying RFID in real time or in line process just to serve the purpose of customer compliance is not going to give you a cost effective solution. But if the customer compliance is going to make huge difference in the market place than when it is not compliance, then the implementation is definitely going to give financial advantage. If the customer compliance is not going to add ad impact to your market place, then these are going to add some additional cost to the production due to its implementation of RFID tags. Thus, if the organization can find another a place where they can improve a production process, streamline warehouse operation, or improve logistic services, etc with the implementation of RFID system along with complying customer requirement, then the organization is reaping the true benefit of implementing RFID system.
Saturday, August 14, 2010
Perimeter defense strategies employed on various segments for an internal network.
One of the main aspects of security is to avoid, minimized or defend malicious activities as soon as it detects or take action before hand as appropriate. If this tasks can be achieved from the boarders of your premises and reduce the impact of the risk to the organization, it is the best method. Even though many of us have not considered perimeter defense in-depth, it is becoming very valuable defending strategy for any organization during incident breaches.
Safe-guarding organizational perimeter is an art and a science, which needs to identify all possible perimeter breaches in all the possible angles and applying best solution which balance the financial commitment of the organization and the amount of the risk that the organization can tolerate.
As a beginning of the defense strategy we must analyze the organization’s assets and their importance to the organization’s operation. Thereafter we should analyze and identify the risk factors involved and their impact to the business. When we are preparing the defense strategy consider above analyzed factors and find a balance between them. Deferent departments have different requirements as the defense strategy differ.
Reception area is the mostly frequently exposed area to the general public and there are limited numbers of measures that we can take to restrict access to this area. But in this scenario will look at the internal access to the area rather than the outside access. All internal work forces have basically given privilege of accessing the area since they are trusted by the organization than general public. This privilege can be misused by the employees with malicious intention. Reception area is equipped with important customer contact details, head of departments personal contact details, and access to whole contact detail of all major contacts. If an unwanted individual access these information they can exploit those detail and gain very valuable information. Even misuse of equipments like business telephone lines, international call facilities, can be dangerous and could tarnish the reputation of the organization. To prevent such occurrences taking place this area should be protected even from the internal staff by restricting access to only necessary people, placing the equipments in a secure manner by partitioning the area or separating access from visitors and internal staff.
Finance department should have a more restricted movement of internal staff as well. All organization information is stored in the place and manipulation, copying, or deleting this information has very drastic impact to the business. This could even take down the whole operation of the business and keep the organization out of operation for few days or forever. Free movement to this area by general public is generally restricted by any organizations, thus very marginal consideration is given by access from internal staff. This area’s access privileges can be controlled by company security policies for internal and external people. On the other hand restricting access by means of access controls like finger printing, facial recognition, proximity cards, ID cards, door access systems and monitoring cameras could be useful.
Wednesday, March 24, 2010
Why is it important to have disaster recovery and business continuity policy?
Business continuity plan (BCP) is the way in which an organization should recover and restore its organizational function within a predetermined time frame after a total or partial disturbance to its services during a disaster. These disasters can be earthquake, flood, natural disaster, terrorist attack, or any major event which cause a catastrophic event to the organization. In simple terms, BCP is a method of planning strategically to prevent or if possible manage the consequences of a disaster, as a result reduce the consequences to a limit that businesses can absorb.
BCP manual is a printed manual which is stored in a safe place (remote site) which contains names, contact numbers, crisis management staff and other staff details, venders, clients and details of offsite backup site to operate, other important legal documents and business documents, etc. Organizations should make sure their BCP manual is realistic and easy to follow in a crisis situation without adding another burden.
Disaster Recovery Plan is a map of how an organization gets recovered in the event of a major disaster and continues its business. This is a key component in an organizational business continuity planning. Business continuity plan has a broader scope than disaster recovering planning in an IT perspective.
Project Processes which should be followed when implementing IT Security projects
IT security project require well defined processes because omission and errors can leads to huge security holes. There are quite a lot of processes should define to implement a IT security project. These processes are briefly discussed below.
Acceptance criteria - These is predefined results which can be expected during the security project. These results are agreed y discussing with key stakeholders of the IT security project.
Risk management - you conduct a thorough risk assessment and threat assessment to identify the risk associated with the security project and define in which way those risk can be avoided, mitigate or transfer during and after the project.
Change management - Errors and omissions in security project is hard to avoid but keeping proper track of what went wrong, when, where, how and what measures you take should be properly documented to avoid countering or solve the risk and problems that could occur in future.
Communication procedure - Most importantly the communication has to be managing properly. Project’s key stakeholders and sponsors have to keep informed about the milestones of the project throughout the security project. The process of when, how, who to keep update and at what frequency should to known when starting the security project. Otherwise project manager and team will have a tough time what, when and whom to inform when the security project underway.
Quality management - Quality measured through testing and this should be clearly defined in your quality management procedure. What test methodologies to use, what modules to test, when to test, etc have to be defined in advance. Level of testing required for IT security projects is solely depend on the type of the security project and the severity of the impact to the organization.
Status reporting - Status of the project should be updated to project sponsors and key stakeholders when needed. This frequency of reporting can be agreed during the project requirement phase, where you can discuss the report type required and what frequency they needed.
Escalation procedure - If the issues cannot solved through the normal channels, you need to pass the issue to the next level in the escalation hierarchy to reach a solution. These escalation paths have to be identified accurately and defined clearly in case of an emergency to follow without causing any delay for the project.
Documentation - Every aspect of the project should be clearly documented. This documentation will greatly help in future when managing, monitoring and troubleshooting some errors in the project.
Approval procedures - Approval procedure should include who has the authority to approve for changes in the project. Mostly this will be the project sponsor who makes the decision about the security project. You cannot run here and there to see who should approve the changes in urgent situation. If these procedures are clearly defined, the unwanted delays could be avoided.
Deployment - Deployment procedure should include when and how the deployment should happen. Before the deployment all the affected parties must be informed in advance to avoid unwanted systems problems, this can be address in the communication plan.
Operational procedures - How the security system is monitored during the day to day activities and who is responsible for the maintenance and monitoring of the implemented system is mentioned in the operations procedure. It includes how to manage the security system and to whom to contact in case of any emergency, etc.
Training procedure - Users of the security system should be adequately trained to get the maximum use of the implemented security system. Through training you increase the awareness level of the users and make them responsible for the system, where they can report any suspicious activity.


