Select Security Components Based on Customer Needs
The security policy helps customers to select the security components necessary to keep equipment and data safe. If there is no security policy, you should discuss security issues with the customer.
Use your past experience as a technician and research the current security products on the market when selecting security components for the customer. The goal is to provide the security system that best matches the customer's needs.
After completing the following sections, you will meet these objectives:
■ Describe and compare security techniques
■ Describe and compare access control devices
■ Describe and compare firewall types
Describe and Compare Security Techniques
A technician should determine the appropriate techniques to secure equipment and data for the customer. Depending on the situation, more than one technique might be required. The sections that follow describe the different techniques to secure equipment and data.
Passwords
Using secure, encrypted login information for computers with network access should be a minimum requirement in any organization. Malicious software monitors the network and can record plain-text passwords. If passwords are encrypted, attackers would have to decode the encryption to learn the passwords.
As covered in Chapter 9, "Fundamental Security," a strong password should contain a mixture of numbers, special characters, and uppercase and lowercase letters and have a minimum number of eight characters total.
Logging and Auditing
Event logging and auditing should be enabled to monitor activity on the network. The network administrator audits the log file of events to investigate network access by unauthorized users.
Wireless Configurations
Wireless connections are especially vulnerable to access by attackers. Wireless clients should be configured to encrypt data.
Encryption
Encryption technologies are used to encode data being transmitted on a network.
Hash encoding, or hashing, ensures that messages are not corrupted or tampered with during transmission. Hashing uses a mathematical function to create a numeric value that is unique to the data. If even one character is changed, the function output, called the message digest, will not be the same. However, the function is one-way. Knowing the message digest does not allow an attacker to re-create the message. This makes it difficult for someone to intercept and change messages. Figure 16-4 illustrates the hash-encoding process. The names of the most popular hashing algorithms are SHA and MD5.
Symmetric Encryption
Symmetric encryption requires both sides of an encrypted conversation to use an encryption key to be able to encode and decode the data. The sender and receiver must use identical keys. Figure 16-5 illustrates the symmetric encryption process.
Figure 16-5 Symmetric Encryption
Asymmetric encryption requires two keys, a private key and a public key. A private key is required for writing a message, and a public key is needed to decode the message. The advantage of asymmetric encryption is that only the private key needs to be kept secret. Public keys can be distributed openly by e-mail or by posting them on the web. Figure 16-6 illustrates the asymmetric encryption process.
Figure 16-6 Asymmetric Encryption
Virtual Private Network
A Virtual Private Network (VPN) uses encryption to secure data as if it were traveling in a private, corporate LAN, even though the data actually travels over any network, for example, the Internet. The secured data pipelines between points in the VPN are called "secure tunnels." Figure 16-7 illustrates how a VPN is used to provide security.
Figure 16-7 Virtual Private Network
Describe and Compare Access Control Devices
Computer equipment and data can be secured using overlapping protection techniques to prevent unauthorized access to sensitive data. An example of overlapping protection is using two different techniques to protect an asset. This is known as two-factor security. When considering a security program, the cost of the implementation has to be balanced against the value of the data or equipment to be protected.
One example of a two-factor security technique is as follows:
Password (good protection) + Biometrics or Smart Card (good protection) = Two-Factor Security (much better protection)
Physical Security
Use security hardware to help prevent security breaches and loss of data or equipment. Physical security access control measures include the following:
■ Lock: The most common device for securing physical areas. If a key is lost, all identically keyed locks must be changed.
■ Conduit: A casing that protects the infrastructure media from damage and unauthorized access.
■ Card key: A tool used to secure physical areas. If a card key is lost or stolen, only the missing card must be deactivated. The card key system is more expensive than security locks.
■ Video equipment: Records images and sound for monitoring activity. The recorded data must be monitored for problems.
■ Security guard: Controls access to the entrance of a facility and monitors the activity inside the facility.
Network equipment should be mounted in secured areas. All cabling should be enclosed in conduits or routed inside walls to prevent unauthorized access or tampering. Network outlets that are not in use should be disabled. If network equipment is damaged or stolen, some network users can be denied service.
The security policy should specify the level of security required for the organization. Biometric devices, which measure physical information about a user, are ideal for use in highly secure areas. However, for most small organizations, this type of solution would be too expensive.
Data Security
You can protect data by using data security devices to authenticate employee access. Two-factor identification is a method to increase security. Employees must use both a password and a data security device similar to those listed here to access data:
■ Smart card: A device that can store data safely. The internal memory is an embedded integrated circuit chip (ICC) that connects to a reader either directly or through a wireless connection. Smart cards are used in many applications worldwide, like secure ID badges, online authentication devices, and secure credit card payments.
■ Security key fob: A small device that resembles the ornament on a key ring. It has a small radio system that communicates with the computer over a short range. The fob is small enough so that many people attach them to their key rings. The computer must sense the signal from the key fob before it will accept a username and password.
■ Biometric device: Measures a physical characteristic of the user, such as fingerprints or the patterns of the iris in the eye. The user is granted access if these characteristics match its database and the correct login information is supplied.
The level of security that the customer needs determines which devices to select to keep data and equipment secure.
Describe and Compare Firewall Types
Hardware and software firewalls protect data and equipment on a network from unauthorized access. A firewall should be used in addition to security software.
A hardware firewall is a physical filtering component that inspects data packets from the network before they reach computers and other devices on a network. Hardware firewalls are often installed along with routers. A hardware firewall is a freestanding unit that does not use the resources of the computers it is protecting, so there is no impact on processing performance.
A software firewall is an application on a computer that inspects and filters data packets. Windows Firewall is an example of a software firewall that is included in the Windows operating system. A software firewall uses the resources of the computer, resulting in reduced performance for the user.
Consider the items listed in Table 16-1 when selecting a firewall.
|
Hardware Firewall |
Software Firewall |
|
Freestanding and uses dedicated |
Available as third-party software and cost varies. |
|
hardware. |
|
|
Initial cost for hardware and software |
Windows XP operating system provides software |
|
updates can be high. |
firewall. |
|
Multiple computers can be protected. |
Typically protects only the computer it is |
|
installed on. |
|
|
Little impact on computer performance. |
Uses the CPU, potentially slowing the computer. |
Hardware and software firewalls have several modes for filtering network data traffic:
■ Packet filter : A set of rules that allow or deny traffic based on criteria such as IP addresses, protocols, or ports used.
■ Proxy firewall: A firewall that inspects all traffic and allows or denies packets based on configured rules. A proxy acts as a gateway that protects computers inside the network.
■ Stateful packet inspection: A firewall that keeps track of the state of network connections traveling through the firewall. Packets that are not part of a known connection are not allowed back through the firewall.
Continue reading here: Lab 1632 Configure Windows XP Firewall
Was this article helpful?