Home > Security Tips > Threat Monitor > Hidden endpoints: Mitigating the threat of non-traditional network devices
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

THREAT MONITOR

Hidden endpoints: Mitigating the threat of non-traditional network devices


Mark Kadrich, Contributor
07.03.2008
Rating: -4.50- (out of 5)


Threat Monitor
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


In 2003, printers using Windows as the embedded OS were known to propagate Blaster, a worm that crippled hundreds of thousands of computers. Given the advancement of antimalware software and network intrusion detection and prevention (IDS/IPS) systems, one might assume that things have gotten better -- but one would be wrong.

More IP-enabled devices and bridges have hit the market in recent years, allowing just about any device, even if it only sports a lowly serial port, to gain access to an enterprise network. Such devices are becoming inviting new destinations for attackers who may have an interest in simply disrupting business within an organization, or perhaps pilfering sensitive data before it ever reaches the network.

The reality is, these devices exist on the network in large numbers today, and not only are there precious few safeguards for many of them, there's even less security awareness surrounding them. In this tip, we'll review some of the most notable non-traditional network endpoints, examine why they pose a risk, and discuss how to mitigate that risk.

Printers
Starting with the most (for now) ubiquitous of "hidden" devices on your network, we'll look at the humble IP printer. Many printers have multiple onboard interfaces, including HTTP and telnet. Default passwords are rarely changed since printers usually get expedited through the IT department on their way to the hungry group of users waiting to deplete the printer's toner.

Few realize how quickly one can wreak havoc on the local network by, for example, setting a printer's IP address to the gateway or DNS server. This opens the door for a denial-of-service attack. Although a similar process could be conducted via any old PC, most security administrators don't think about the printer being the culprit in such a way, since it doesn't have a keyboard.

Physical access devices
It's common today for physical access controls to be run over



the enterprise network. One such vendor's marketing blurb highlights how the physical access gateway (PAG) can use power over Ethernet (PoE) to power badge readers and locks. The PAG also supports network discovery and boasts "ease of controllability" through a built-in Web server. These PAGs also have the ability to store up to 250,000 credentials in an "encrypted cache." Making matters worse, proximity card reader vendors are now using the network to upgrade and configure these devices. One vendor says that its product's operating parameters, such as "door open" time, are downloaded to the reader from a host computer. That means an attacker may be able to hack the doors from the safety of the lobby.

Web-based security cameras
Another interesting device is IP-based security cameras. These little darlings have been with us for a while and allow for cheap video surveillance. Unfortunately, some of these gems have built-in Web servers so that anyone can access the video from anywhere on the network. While vendors seem to think that it's a nice feature to enable anyone to access a security device, security pros probably disagree. It seems to me that if I could get on their network, I could see when the place was empty and safe to rob.

Here's your Twinkie…and a virus
And what is the newest threat to your network? Vending machines! There are companies that offer conversion kits that allow cash-only machines to accept credit cards, debit cards and new contactless cards!

Think about the ramifications -- such a machine could suddenly be susceptible to a man-in-the-middle attack, allowing an attacker to collect customers' credit card information. These devices lack any kind of software security check, and conversion vendors have been mum on any form of network access control (NAC).

For those that have to worry about retail networks, there are also point-of-sale machines to worry about, not to mention specialty devices such as pin vending machines, which sell pre-paid cell phones, cable TV subscriptions, concert tickets and debit cards, which all have GPRS, Wi-Fi and Ethernet connections to servers!

Security strategies for non-traditional network devices
So, what do you do to safeguard all of these devices? There are five key steps:

Finally, please change the default passwords on all network-enabled devices! Also, make sure that unused protocols are disabled so that there aren't multiple ways to reconfigure the devices.

About the author:
Mark S. Kadrich is president and CEO of The Security Consortium, an independent product-testing and comparison group that offers in-depth reviews and evaluations of security products and vendors. A 20-year veteran of the information technology industry and a recognized expert on endpoint security, he authored the Addison-Wesley book Endpoint Security and is a noted industry speaker.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Threat Monitor,   NAC and Endpoint Security Management,   Client security,   Enterprise Network Security,   Information Security Threats,   Emerging Information Security Threats,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Threat Monitor
How to defend against rogue DHCP server malware
When BIOS updates become malware attacks
Mac OS memory flaws pose challenges for enterprise endpoint protection
Cybercrime and threat management
How to find and stop automated SQL injection attacks
Short-lived Web malware: Fading fad or future trend?
Security book chapter: The Truth About Identity Theft
How to use (almost) free tools to find sensitive data
How to block adult websites from enterprise users by logging content
Are Windows Vista security features up to par?

Client security
How to defend against rogue DHCP server malware
Symantec offers endpoint protection management, monitoring services
Sophos integrates encryption into endpoint security
Quiz: Endpoint security on a budget
How to find sensitive information on the endpoint
Trend Micro gets more competitive with BigFix deal
CA steers DLP towards access, identity management
CA to acquire Orchestria for DLP
Microsoft to embed data classification, strengthen ties with DLP
Diverse mobile devices changing security paradigm

Emerging Information Security Threats
Antispyware buying guide for Indian enterprises
ATM malware lets attackers take over machines
FTC shutters rogue ISP for hosting malicious content, botnets
The failing war against cybercriminals
White House cybersecurity czar faces major hurdles
Cybercrime and threat management
The Pipe Dream of No More Free Bugs
Face-off: Who should be in charge of cybersecurity?
Federal efforts to secure cyberinfrastrucure
Adobe working on patch to correct new zero-day flaw

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
brute force cracking  (SearchSecurity.com)
buffer overflow  (SearchSecurity.com)
Crash Course: Spyware  (SearchSecurity.com)
email spoofing  (SearchSecurity.com)
phishing  (SearchSecurity.com)
rootkit  (SearchMidmarketSecurity.com)
social engineering  (SearchSecurity.com)
Wired Equivalent Privacy  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts