Showing posts with label Remote Access Point. Show all posts
Showing posts with label Remote Access Point. Show all posts

27 July 2010

Why SCADA Networks Are Vulnerable To Attack - Part 3: Firewall Both Users AND Devices


Following a rise in the theft of payment card data, the Payment Card Industry (PCI) standards council was created by the top card brands to combat such crime. The resulting PCI Data Security Standard (DSS) defines mandatory security guidelines for use by all merchants and service providers that store, process and transmit cardholder data.

Wireless LAN security is a core component of these requirements. DSS v1.1 permitted the use of WEP encryption. Indeed, many retailers wanted to continue using the WEP devices they had already purchased, not because of the encryption scheme but to avoid the capital outlays required to replace WEP devices with higher security equivalents.

While WEP encryption is easily cracked, and was subsequently banned under DSS v1.2, an ingenious method was used to protect WEP devices so they could continue in service until DSS v1.2 was implemented. This solution protected the network without requiring any changes or clients added to the WEP devices. This solution holds great promise for the protection of SCADA, smart grid, and energy control systems.


Consider the humble bar code scanner. A workhorse of both point-of-sale (POS) and logistics systems, many scanners in use today rely on 802.11b/g Wi-Fi and WEP. Data from the scanners are passed via Wi-Fi to the enterprise network. If you crack WEP you therefore potentially open a back door into that network.

Integrating a stateful, role-based policy enforcement firewall into the wireless network slams shut this back door. By blacklisting unauthorized devices – not based on the port through which they entered the network but rather by the user and/or type of device - unauthorized users can be denied access to the rest of the network.

The firewall can distinguish between multiple classes of users, allowing one common network infrastructure to function as independent networks whose isolation is ensured by policy enforcement. Guest access is separate from POS which is separate from logistics, etc.


The elegance of this approach is that it can be retrofitted to existing networks – wired and wireless using a true overlay model - without any software clients or other changes to the devices being protected. It protects any devices from any manufacturers.

This same segmentation and policy enforcement scheme can be applied to wired and wireless sensors as soon as their data hit the IT infrastructure. Access rights, quality-of-service, bandwidth, VLANs – almost any parameter can be controlled and actively managed by the stateful, role-based policy enforcement firewall. It is to the benefits of this approach, used in conjunction with additional security enhancements, that we’ll turn in the next posting.

08 February 2010

Distance Learning Has Never Been Closer


One of the challenges of distance learning is how to replicate the "campus experience" for remote students. Doing so encourages collaboration with other students, and improves study opportunities, by leveraging the same electronic learning applications, library reference materials, and server resources as campus students enjoy.

It also builds school loyalty because if these services remain in place post graduation, it improves the chances of continued participation once students become alumni.

Providing secure access to your school's electronic learning resources is a challenge. Open access or password-controlled access won't protect against network attacks, password-sharing, or excessive
bandwidth consumption by mischievous students.

A secure virtual private network (VPN) requires your IT staff to load and manage client software on every device a student might wish to use. This is an on-going burden because incompatibilities may be introduced as students upgrade operating systems or other applications on their computers.

Virtual Branching Networking (VBN) solves distance learning connectivity and security issues. Using a small, very inexpensive device called a Remote Access Point (RAP), VBN enables remote students to connect securely to your data network.
RAPs enable students to use any IP-based devices with an Ethernet port or W-Fi - MacBooks, iPhones, iTouches, iPads, PCs, VoIP phones, printers - without loading any software clients.

A built-in firewall strictly enforces access policies set by your IT staff, and can even control how much bandwidth a student uses. All access policies are centrally managed and then pushed over the network to the RAPs. The same is true of software updates: they're pushed automatically to every RAP in the field.

New RAPs are shipped unconfigured. To connect one to your network the student pushes a button on the front of the unit and then enters the IP address of your data center.

A RAP controller in your data center then exchanges security certificates with the student's RAP and voila, the student is on-line. No IT staff involvement is required for this process to occur, meaning that it's possible to economically support a very large distance learning program without adding IT staff.


Since RAPs are shipped unconfigured, they can be sold or rented to students through your bookstore or by a third party with zero-touch involvement by your IT staff. If a student leaves your distance learning program, or fails to pay tuition, a simple change in the access policy will completely disable the RAP.

Alternately, when a student graduates the RAP settings can be changed to disable distance learning and enable Internet access using your alumni site as the home page.


VBN has been field-proven in enterprise teleworker deployments around the world, and is the ideal solution for distance learning applications of any size. To find out more please visit our Web site.