Home > Security Tips > Tech Tips > Thwarting Hacker Techniques: Securing remote access points
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

TECH TIPS

Thwarting Hacker Techniques: Securing remote access points


Vernon Haberstetzer, Contributing Writer
02.25.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Hackers love poorly configured remote access points, and why shouldn't they? Many times it can be an open door into a network without having to fuss with firewalls and intrusion detection/prevention systems [IDS/IPS] at the Internet border. The fact is, most networks have remote access points, and most of those access points don't employ decent security. Access points most often come in the form of dialup modem banks and VPN concentrators, and it doesn't take much to discover the phone number or IP address.

Most remote access points require only a static userID and password to log on to the network. If your remote access point doesn't require strong authentication you should probably count on the fact that somewhere out there an employee or vendor has setup a remote connection to your network with a saved userID and password. This means your network is available to anyone who opens that connection, including your employee's neighbor whose computer was used to check e-mail a month ago, and that vendor's employee who quit last week and took all his clients' remote access passwords with him.


Best security products of 2004
Information Security magazine and research partner evaluated 1,239 products to come up with the year's best at securing networks.

Webcast: Policy compliance for end-point devices
The corporate network is no longer a single, wholly owned infrastructure. The age of virtual computing and the increasingly remote, distributed workforce means there are many untrustworthy devices trying to access the network every day.


To remedy this problem, it is best to implement some type of strong authentication, requiring a userID and a single-use password or biometric. RSA Security is one of the largest suppliers of remote access keychain tokens, which generate a single-use passcode every 60 seconds. Your vendors could be required to call your operations department to obtain a passcode for remote access, thus adding another layer of security when dealing with outsiders. By implementing a strong authentication system, saved passwords will no longer be an issue for remote connections.

Additionally, most remote access points don't inspect the remote computer for viruses or hacking software, and they usually don't watch the network traffic coming from such computers. If a user with a virus-infected PC or a hacker were to remotely log on to your network with such software, your network could be on the receiving end of a server compromise or a virus outbreak. To help prevent malicious activity from entering your network from a remote access point, it is best to have an IDS or IPS sitting inline between your remote access point and your internal network. Such a system should be capable of catching network-based attacks from hackers or hybrid viruses. Some systems will even prevent users from connecting to your network if their antivirus software is not up-to-date. It is also best if you can limit the ports allowed into your internal network.

By giving some attention to the authentication process and the traffic coming from remote users, you will greatly reduce the risk of your remote access points being a source of unwelcome company.

Missed part of this series? Check out the archive.

About the author
Vernon Haberstetzer, president of security seminar and consulting company i.e.security, has seven years of in-the-trenches security experience in healthcare and retail environments.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Tech Tips
Trends in enterprise identity and access management
The 5 A's of functional SAN security
Effective storage security policies
Smart options for safeguarding stored data
Outfox SOX: How to make regulations work for you
Thwarting Hacker Techniques: Signs of a compromised system
Thwarting Hacker Techniques: Wireless security basics
Thwarting Hacker Techniques: Internet data manipulation
Roberta Bragg's 10 Windows hardening tips in 10 minutes
Thwarting Hacker Techniques: Combating social engineers

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts