Session 2: Network Access Control Flashcards
What is Network Access Control?
Network access control, also called network admission control, is a method to bolster the security, visibility and access management of a proprietary network. It restricts the availability of network resources to endpoint devices and users that comply with a defined security policy.
One major difference between NAC mechanisms and 802.1X access control is that NAC require the placement of one or more agents.
What is a potential weak point of NAC?
The trustworthiness of the agents. A compromised endpoint will try to appear like it is in compliance with security policies.
What is TNC (Trusted Network Connect)?
An open architecture for NAC. Hierarchical set of attestations based on layering of trust.
Aims to fix the problem of rogue endpoints appearing like they are in compliance with security policies.
ETSI M2M
Name the Service Capabillity Layers from ETSI M2M (SCL)
Network SCL -> Gateway SCL -> Device SCL
Legacy devices can be connected to IoT trough Gateway SCL systems.
CoAP: What security implementation settings does CoAP have?
no security, pre-shared keys, raw public key, X.509 Key certificates.
What is faster? Preshared Key DTLS or Public Key Mutual Authentication
Preshared Key DTLS is about one order of magnitude faster than PKMA. Usefull for low LowWPAN and low energy BLE.