One of the biggest threats facing enterprises are outsiders plugging directly into an Ethernet port and being granted instant, unauthenticated access to the network. This threat is especially common in hospitals where there is heavy use of computer systems mixed with untrusted outsiders roaming the halls. Shutting down unused ports is the traditional mitigation. Still this technique does not prevent plugging into an active used port (for example, a copy machine). 802.1X can mitigate this vulnerability.
An 802.1X implementation is comprised of three components:
What is 802.1X?
802.1X allows for authentication of a system/user at Layer 2 of the OSI model. This means authentication happens earlier in the protocol stack than typical. Users and systems authentication generally happen at Layer 3 over TCP/IP (the protocol at the heart of the public internet). 802.1X leverages a protocol called Extensible Authentication Protocol (EAP) to allow for authentication over Ethernet (the protocol that controls how data is transmitted as electricity over networking cabling and Wi-Fi). 802.1X will work on both physical and wireless networks but be sure not tp mistake 802.1X for 802.11, the wireless networking standard. How Authentication Works Typically:- Once plugging into an open port, the laptop requests a DHCP address. The system is then leased an IP address, DNS settings, and the default gateway. The user and system are not authenticated.
- Lack of authentication on the switch (Ethernet over Layer 2) allows any malware on the laptop to spreading on the network, and the user is free to probe or passively monitor network traffic.
- The authenticator (i.e. network switch) requests authentication information from the supplicant (i.e. software agent on the system). The authentication server verifies if the system should be granted access. If so, an IP addresses is leased using TCP/IP over Layer 3.
- Unauthorized/unauthenticated users are not leased an IP address.
- Thanks to no connectivity on the unknown system, malware cannot spread and the user cannot probe the network.
Understanding 802.1X in More Depth
802.1X is one of the best network security measures an organization can implement. It is important for the security professional to understand the technology before auditing it or recommending it.
An 802.1X implementation is comprised of three components:
- Supplicant: The supplicant is typically client software on the endpoint that understand the 802.1X protocol and one of the EAP types used in communicating with the authentication server. Supplicants forward credentials (username/password or digital certificate).
- Authenticator: The authenticator is usually a piece of networking equipment like a wireless access point or network switch. The authenticator opens the access on the port so the supplicant can communicate with the DHCP server and be leased an IP address if it successfully authenticates.
- Authentication Server: The authentication server checks the credentials supplied by the supplicant and either grants or denies access to the endpoint device. Most authentication servers use Remote Authentication Dial-In User Service (RADIUS) protocol, which might connect back to an LDAP server (e.g. Active Directory).
- Extensible Authentication Protocol (EAP)
- Network Access Control (NAC)
- Centralized Authentication Control Protocols (such as RADIUS, DIAMETER, and TACACS)
Earn Your CISSP
Interested in obtaining your CISSP and live in the Atlanta area? Risk3sixty is hosting a CISSP bootcamp, based on SANS world class information security training curriculum. Visit our events page to learn more!
Christian Hyatt
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)