4.2 + 4.3 authentication/wireless security Flashcards
WPA
Uses TKIP and RC4
WPA2
AES
CCMP
AES
CCMP
WPA2
TKIP-RC4
WPA
CCMP-AES
WPA2
ACLs are usually defined on the ___ or the ___ of an interface.
ingress
egress
ACLs are usually defined on the ___ or the ___ of an interface.
ingress
egress
What is EAP?
Extensible autheneticaiton protocol.
Authentication framework used for 802.1X, WPA, WPA2
TKIP
Integrity check
adds sequence counter, prevents replay attacks
replaced by CCMP
WPA
Integrity check
adds sequence counter, prevents replay attacks
deprecated standard
TKIP
RC4
Encryption algorithm
Replaced by AES
CCMP
encryption standard that replaced TKIP
used for WPA2
AES
replaced RC4
used for WPA2
AES
replaced RC4
used for WPA2
EAP-FAST
EAP Flexible Authentication via Secure Tunneling.
Lightweight authentication method
EAP-TLS
EAP Transport Layer Security.
Very wide adoption
EAP-TTLS
EAP Tunneled TLS
Supports other/older authentication protocols by using a TLS tunnel
PEAP
Protected Extensible Authentication Protocol
RSA
Encapsulates EAP in a TLS tunnel
Commonly implemented as PEAPv0/MSCHAPv2
MSCHAPv2
A database PEAP authenticates to, stores certificates.
WPA2-PSK / WPA2-Personal
Preshared key, chaning the key requires reconfiguration of all devices on the network.
WPA2-Enterprise / WPA2-802.1X
Authenticates users individually using using username/password with AAA/RADIUS server, no key.
Geofencing
Using GPS on mobile devices via a MDM to prohibit or allow access to a network based on location. Sometimes used for cameras, disabling them while inside building.
Define Authorization
Level of access granted based on ID and authentication.
Define Authentication
Validation of presented idenfitication.
Definite Accounting
evidence, login times, data sent/recieved, etc
Kerberos
Mutual authentication protocol used for SSO
What SSO related technology can prevent MiTM attacks and replay attacks?
Kerberos
When is local authentication useful?
When a AAA server is down/unavailabe.
Name 4 examples of certificate based authentication
Smart Card
CAC
PIV
802.1X
SIEM does what
Monitors/prevents unauthorized access to networks