Home > Security Tips > Risk Management Strategies > Watch out for hotel broadband vulnerabilities
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

RISK MANAGEMENT STRATEGIES

Watch out for hotel broadband vulnerabilities


Frederick Avolio
02.27.2002
Rating: -4.12- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   




I remember the first time I walked into a hotel room and found an Ethernet drop. It was at TISC (tisc.corecom.com) Fall 1999 in Boston, at the Seaport Hotel. Now, it's almost commonplace to find high-speed access to the Internet. But does it present any new or different vulnerabilities? Perhaps. I'd like to take a look at the potential trouble spots and offer some suggestions for mitigating them.

I remember well the expectation with which I connected up to that Ethernet port. After I found that I could indeed access the Internet, my e-mail and so on, I had a thought. I clicked on "Network Neighborhood." I clicked on "Entire Network." And there I found names of workgroups. First on the list was my own, "Avolio." But there were also others. Among them, I remember "Workgroup" and "Raptor." Raptor was the name of one of our competitors in the firewall market. Can you imagine what I did next?

Nothing. But I could have...

Vulnerabilities

These vulnerabilities are very much the same as for someone using a cable modem from home. The problem is, people are used to using telephone dial-ups from hotels, so even if they are careful at home (if they even have a broadband connection), the security-mindedness does not carry over. A dial-up connection in the hotel is not easily exploited. Hotel broadband is much different. For one thing, there's the "network neighborhood" problem I mentioned above. Windows boxes are constantly begging any device that will listen to talk SMB (server message block). If the road warrior's laptop is set up to normally work at home or in an office without password restrictions in the "shares," the information is vulnerable to theft. For another thing, a person is more likely to leave his computer connected all the time to such a connection (unlike on a telephone connection).

It's so *convenient* (there's a word that should send shivers up the spines of security folks). It's just like at home! Now, while asleep, the kid in the room next door (or the industrial spy -- it *does* happen, you know) has all night to find the PC and exploit any holes that might exist.

If the hotel broadband system is set up for "instant use" -- so the user may leave the PC configured with the same settings, as at home or the office -- the situation is only slightly better. The "network neighborhood" will probably not show any other computers, but the data communication is still vulnerable to packet sniffing. And the PC may still be vulnerable to connection-based attacks.

Suggestions

First, your security policy covering remote access should cover remote access from hotels with broadband Internet access. If you have a policy about connecting to and from other people's networks (from clients' sites, Internet cafe, etc.), you can expand it to include this.

Next, if you are going to allow such access (and, of course you are), the traveler needs to be equipped with extra protection. Antivirus software should go without saying. So I won't say any more on that. But consider the following defensive mechanisms to protect notebook PCs on hotel networks.

A personal firewall is an inexpensive first line of defense. It should keep the PC from inviting attack from "neighbors," as well as making sure no unauthorized services are running on the PC (really, there should be none). Many travelers would have already heard of and considered these in relation to their home broadband use. They not only make sure that only policy-sanctioned services are allowed to run on the PC and be accessible from outside, they also act as host intrusion-detection systems. It would be most useful if 1) your policy stated that the user may not tamper with the PC firewall configuration and 2) that the software detected the inevitable user tampering.

Encrypted connections will keep the traffic from being snooped. Grabbing packets off of the Internet backbone is a formidable task. Sniffing them off of a hotel network is easy. You can go the VPN route, encrypting everything between the remote PC and the enterprise network and remote PC. The VPN solution used should ensure that when the PC is connected to the enterprise, no connection to the rest of the Internet is allowed, so there is no chance of IP packets being forwarded between the Internet and the enterprise network.

If a VPN is not feasible, an SSL-encrypted Web-based connection to minimal services, such as e-mail, might be an acceptable next choice. In this case, a username and password is often used to authenticate access. Though the connection is encrypted, this is susceptible to a guessing attack. Though you will get pushback from the "bean counters," marrying this kind of access to strong user authentication -- via hardware- or software-based token, or browser-based certificates, for example -- is a security win.

One final thought: I have discussed broadband access from hotels. I hope it is obvious that similar concerns, and so safeguards, should be employed from home or Internet cafe

Related article

Lisa Phifer of Core Competence, Inc. (www.corecom.com) addressed the challenges of VPN access over broadband connections in hotels in the Feb. 8, 2001 issue of ISP-Planet. You can read it at: http://isp-planet.com/technology/remote_access_conundrum-3-1.html

About the author
Fred Avolio is the president and founder of Avolio Consulting, Inc., a Maryland-based corporation specializing in computer and network security and dedicated to improving the state of corporate and Internet security through education and testing.

Fred is also a member of searchSecurity's team of experts who are available to answer your security questions. Peruse the answers Fred has provided to frequently asked questions, or submit a question of your own: http://searchsecurity.techtarget.com/ateAnswers/0,289620,sid14_tax285450,00.html


Related book

Broadband Internet Connections: A user's guide to DSL and cable
By Roderick W. Smith
This book explains basic broadband configuration, demonstrating in detail how to configure your system to get the most out of it. It also provides a pragmatic guide to Internet security by addressing important topics such as assessing risk and methods and tools for reducing risk.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Risk Management Strategies,   NAC and Endpoint Security Management,   Secure Remote Access,   Enterprise Network Security,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Risk Management Strategies
How to justify information security spending on cloud computing
How to protect distributed information flows
Black box and white box testing: Which is best?
Breach prevention: How to keep track of data and applications
Information security management hype: Debunking best practices
Monitoring program data and internal controls for risk management
Cloud computing security: Choosing a VPN type to connect to the cloud
Cloud computing security: Routing and DNS security threats
Cloud computing security model overview: Network infrastructure issues
How to align an information security framework to your business model

Secure Remote Access
Endpoint protection best practices manual: Combating issues, problems
Best Mobile Data Security Products
Perimeter defense in the era of the perimeterless network
Securing the intranet with remote access VPN security
What security software should be installed on Internet café computers?
Information security book excerpts and reviews
Diverse mobile devices changing security paradigm
Cisco warns of security appliance flaws
How to configure NAP for Windows Server 2008
Can home PCs provide a way for viruses and spyware to enter a corporate LAN?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
authentication  (SearchSecurity.com)
RADIUS  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts