Information System – Security Assurance
Assignment 9
How does TACACS+ work?
TACACS+ represents an authentication, authorization, and accounting (AAA) protocol initially created for the United States of America defense or military (Liska, 2003). Its main aim was to initiate authentication to various network devices such as switches, firewall, and routers. Unlike RADIUS, TACACS+ separates the authentication and authorization functionalities. This attribute makes TACACS+ more flexible in the administrative access. TACACS+ is the acronym for Terminal Access Control Access Control Server (Liska, 2003). TACACS+ represents the derivative for the TACACS application implemented by the defense data network (DDN). TACACS+ is an enhancement of the TACACS application by the Cisco thus its implementation in network security as the Cisco Propriety Protocol. The main objective of TACACS+ is to offer a centralized database through execution of authentication. This is an indication that TACACS+ offers the three crucial aspects of security: Authentication, Authorization, and Accounting (AAA). Through Authentication, it is the responsibility of TACACS+ to determine users allowed to access the network. This is an indication that users must have the ability to prove that they are the entity they claim to be in order to gain access to the network.
TACACS+ has the ability to use username and password plus other security mechanisms such as one-time passwords. Authorization in TACACS+ is an illustration of the quantity or type of information that the user has access to while visiting the server (Mason & Newcomb, 2001). This is the use of IP address to address the issue of accessibility of information and applications. Accounting aspect of TACACS+ indicates that the security system has the opportunity to determine or monitor communications of the user while accessing the network. TACACS+ has the ability to track or monitor what the users did and the applications used during the access of the network system. Accounting adopts and implements the use of start and stop button to keep track on the users as they access the network. TACACS+ adopts the client-server model approach where the server experiences questioning sessions by the client then determines if the user passed or failed in the process of authentication (Carroll, 2004).
In what settings is it most likely to be found?
TACACS+ is likely to be in UNIX devices. This is because of the ability of the UNIX devices to communicate through forwarding user authentication information to a central point within the server, which is a common feature in the implementation of TACACS+. The central server can function as the TACACS database. TACACS+ is also common in Linux password files with relevant TACACS protocol support. Large business entities, college campuses, and defense agencies offer an ideal environment for the application of TACACS+ in relation with the protection of the network system.
How widespread is its usage?
TACACS+ unlike the other network protocols such as RADIUS is not widespread in its usage. This is because of the essence of much vulnerability with reference to external attacks or threat thus infection of the confidential information. TACACS+ is also a new protocol in the market of network security thus limitation in relation to the coverage level and size. Since it is a new product in the market, most users still do not trust its security measures in eliminating threats and malicious attacks that might destroy confidential information within the central server.
What are its advantages?
One of the main advantages of TACACS+ in the network security context is its ability to transform implementation of RADIUS. This is because TACACS+ is an extension or enhancement of RADIUS thus enjoys adoption of effective and efficient features of the former (Liska, 2003). TACACS+ also possesses the ability to extend or enhance the protocol of RADIUS in relation to meeting the needs of the contemporary network systems. TACACS+ adopts the use of TCP rather than UDP thus guaranteeing effective communication between the client and the central server. This indicates that TACACS+ is safe from network congestions and constant crash of the servers in its implementation to offer protection to the network systems. TACACS+ also has the ability to encrypt all data within the TACACS+ packet (Collora et al, 2004).
This is an advantage in relation to RADIUS protocol, which has the ability to encrypt passwords only. RADIUS lacks the capacity to protect data interception such as accounting information and username. TACACS+ also possesses the ability to execute unique forms of authentication, authorization, and accounting. This makes it applicable to use different servers to execute these functionalities effectively and efficiently. It is also possible for an administrator to determine the commands available for the user to run in the implementation of TACACS+ security system. This capability with reference to the level of control enables more controlled or managed access to numerous users within the network system. TACACS+ has the ability to perform its targets through generic proxy systems unlike other protocol systems such as RADIUS (Collora et al, 2004).
What are the disadvantages?
One of the main disadvantages of TACACS+ is the lack of extensive checking in relation to integrity. This would result into alteration of the accounting records during transmission thus fatal to the organization or business entity in the context. The only check in the TACACS+ protocol aims at ensuring the sum of the components within the packet. This is to make sure that the components match total size of the relevant packet (Collora et al, 2004). The other disadvantage of TACACS+ is the ability of the protocol to replay attacks during transmission. This would enable the protocol to duplicate information or accounting records thus evasion of detection. The capacity of the TACACS+ protocol to force session-id collisions puts the system at risk. This is through compromising the reply packets during the encryption process thus a weakness towards implementation of the TACACS+ as a network security protocol. Lack of padding can also allow external attackers to determine the lengths of the passwords thus a step towards hacking into the server or the networking system.
When would you recommend using it over RADIUS or Kerberos?
When choosing Authentication, Authorization, and Accounting (AAA) protocol within the Cisco-based network, it is ideal to adopt TACACS+ over RADIUS or Kerberos. I would recommend RADIUS or Kerberos if the network system does not use the Cisco devices thus minimal support to the TACACS+ protocol. I would also recommend RADIUS or Kerberos such as 802.1 X or virtual private networks. This is because RADIUS is a standard in relation to this environment.
Assignment 10:
First, Select one standard biometric technique (fingerprint, palm print, iris, facial features, and so on) and research the costs for having biometric readers for that technique located at two separate entrances to a building.
Standard biometrics makes use of the personal characteristics to protect the unauthorized entry to the user’s accounts. Indifferent to authentication based on the knowledge of the user, the standard biometrics use bases its mechanism on the features and characteristics of the individual (Komarinski, 2004). Fingerprint is one of the standard biometrics that many people prefer for the authentication of their belongings from a third party. The preference of fingerprints is due to the presence of the fingerprint scanners that analyze the fingerprint of the user. The fingerprint scanners works by giving information about the content of fingerprints (including the number of ridges and valleys that are always unique to every user). The ridges presented by the scanner represent the upper skin layer while valleys refer to the lower segments. The scanner also bring uniqueness to the user though identifying the regions where the ridges split and end, then converting them into a unique series of numbers (Vacca, 2007). The scanner then stores this unique information as a template. An individual may opt for using the static fingerprint scanner or the use of dynamic scanner depending on the preference and costs. The need to establish authentication at two separate entrances of the building will result to more cost as compared to when establishing it on one entrance. The user will have to cover the cost for the biometric reader in each of the entrances. This will force him or her to buy 2 pieces of biometric fingerprint scanner with each going to an average cost of US $70 arriving to total of $140.
Next, research ways attackers attempt to defeat this particular biometric technique.
Just like the passwords, attackers can also break through the security provided by the fingerprints. This technique of using fingerprints scanners for authentication is susceptible to attack by third party, especially when the user does not consider combining the authentication with other forms of identification. It is always easy for the attacker to lift a fingerprint from an object and then transferred it to cheat the reader. For instance, an attacker can easily lift the fingerprints from a glass then use it to gain access to the building (Vacca, 2007). This always occur when the user make use of the dynamic scanner rather than the static. The latter is always difficult to attack through this method because it involves the use of small openings that capture the prints; consequently, the attacker cannot easily access it (print). The user can avoid these occurrences using the fingerprint security in the presence of multifactor authentications or password.
Finally, how often will this technique reject authorized users while accepting unauthorized users, compared to other standard biometric techniques? Based on your research, would you recommend this technique? Why or why not?
The use of fingerprints, especially the lower cost ones, security is always susceptible to confusing between the unauthorized users and the authorized. This usually occurs as the result of the many finger characteristics, which the scanner would have to analyze and compare before identifying the authorized user. Consequently, this is a frequent occurrence in strategic places such as entrance of buildings, where the scanner has to operate on many parties. The confusion in determining the authorized user arises from the need for comparison between the many results. This is indifferent to the iris identification where there is the capturing of the eye image. This always presents a high level of uniqueness between people thereby only allowing the authorized to access the building. There is little modification on the image of the eye as compared to fingerprints, which is always a subject to external modification thereby confusing the scanner. The iris identification makes use of the laser beam that penetrates the eye providing the highest form of differentiating identities (Newman, 2009).
I would not recommend the use of fingerprint identification because it is much susceptible to attacks by unauthorized parties. The user can easily solve this limitation using the iris identification that is more secure than the fingerprint identification. This occurs because the fingerprints normally involve touching while the latter does not involve any form of touching. The touch is what allows attackers to lift the fingerprints from objects in the quest of tricking the scanner. Further, the use of fingerprints is unhygienic because it involves touch by different users (Newman, 2009).
Assignment 11/12
IP security (IPsec) will become increasingly popular as IPv6 achieves greater penetration.
Use the Internet to research IPsec as it relates to IPv6. What are its strengths? What are its weaknesses?
IPSec vs. IPv6
IPSec represents a framework designed in the form of open standards aiming at determining policies to offer maximum security to the network communication (Doraswamy & Harkins, 2003). IPSec also describes the processes or procedures vital to the enforcement of the policies in relation to securing the communication within the network server. Extensive application of IPSec enables organizations and individual users to obtain maximum data confidentiality, integrity, and authentication within the layer of the network. The aim of the architectural design of the IPSec is to offer maximum security for transmission in the IP layer in relation to both IPv4 and IPv6 environments. This is an indication that IPSec has the ability to offer high quality security for IPv6 and IPv4. IPSec proves to be a mandatory feature or component for the IPv6. This implies that the IPSec security design must enjoy support for all the IPv6 layers within the network market. The relationship between IPSec and IPv6 allows the latter to offer security services to the former during transmission thus safe communications within the network systems.
Strengths of IPsec
Universality
The use of IPsec is universal, making it be an international standard because of flexibility and power of IP (Kenyon, 2002). The universality of IPsec promotes the connection between the user and other users of different networks all over the world. The user is able to receive and transfer information from other networks thereby promoting the communication between different networks.
Scalability
The scalability of IPsec also allows its application in different global networks. The IPsec is such that it can fit in all networks regardless of the size thereby does not restrict the taste of users to a particular network. This helps the users in reducing the cost of operation since they would only need the presence of IPsec to access all global networks including LAN’s. The scalability of the IPsec promotes the flexibility of the user in using different types of global networks.
Network layer security
The IPsec posses the network layer security, which makes it avoid the effect of lower level data carrying protocols and transport technology. These activities always affect the performance of other forms of security applications. The IPsec is able to operate at low levels of the network making it less susceptible to the effect of such activities (Kenyon, 2002).
Application independence
The users can normally access many applications without exhibiting any problem from the provider. This arises because the use of IPsec does not always restrict users to certain applications. The user will only need the routing of a certain application to IP in order to make it compatible to IPsec. The users will not have to get troubled because of the non-predictable applications across a network since they will only need routing with IP (Paquet, 2009).
Weaknesses
Small packets
The presence of small packets usually triggers the performance of the network when using the IPSec. This situation occurs because the encryption process of IPSec generates large overhead whenever there is the transmission of small packets (Kenyon, 2002). This makes the IPSec to be effective only in the transmission of large packets hence a restriction to the users.
Complexity
IPSec presents the user with a larger number of application and applications. This makes the users of IPsec to be complex because the user will have to weigh options on which feature will suit their needs. The complexity of IPSec increases the chances for weaknesses in providing security, for example against the replay attacks (Paquet, 2009).
IP security (IPSec) Significance
Although part of the IPv6, IPSec is significant and required. This is because, in IPv6, its implementation occurs via AH authentication and ESP extension headers. It is ideal to adopt and implement IPSec-IPv6 as an advanced security system by the administrators. This would involve direct transformation of platform from the IPSec-IPv4 with minimal interference with the networks and relevant applications (Li et al, 2007). The importance and significance of IPSec-IPv6 is on the rise in the modern technological market. For instance, the United States of America deploys the IPSec-IPv6 systems within the defense department to ensure safety of the communication on their servers.
References
Mason, A. G., & Newcomb, M. J. (2001). Cisco secure Internet security solutions. Indianapolis, Ind: Cisco Press.
Liska, A. (2003). The practice of network security: Deployment strategies for production environments. Upper Saddle River, NJ: Prentice Hall PTR.
Carroll, B. (2004). Cisco secure access control server. Indianapolis, Ind: Cisco.
Collora, S., Corley, D., Leonhardt, E., Smith, A., & Cisco Systems (Firma comercial). (2004). Cisco CallManager best practices. Indianapolis, Ind: Cisco.
Doraswamy, N., & Harkins, D. (2003). IPSec: The new security standard for the internet, intranets, and virtual private networks. Upper Saddle River, N.J: Prentice Hall PTR.
Li, Q., Jinmei, T., & Shima, K. (2007). IPv6 advanced protocols implementation. Amsterdam: Elsevier/Morgan Kaufmann Publishers.
Newman, R. (2009). Security and access control using biometric technologies. Boston, Mass: Course Technology.
Komarinski, P. (2004). Automated Fingerprint Identification Systems (AFIS). Amsterdam: Academic Press.
Vacca, J. R. (2007). Biometric technologies and verification systems. Boston, MA: Butterworth- Heinemann/Elsevier.
Maltoni, D. (2009). Handbook of fingerprint recognition. London [etc.: Springer.
Kenyon, T. (2002). Data networks: Routing, security, and performance optimization. Amsterdam: Digital Press.
Paquet, C. (2009). Implementing Cisco IOS network security (IINS). Indianapolis, IN: Cisco Press.
