Session 2: Network Access Control Flashcards

1
Q

What is Network Access Control?

A

Network access control, also called network admission control, is a method to bolster the security, visibility and access management of a proprietary network. It restricts the availability of network resources to endpoint devices and users that comply with a defined security policy.

One major difference between NAC mechanisms and 802.1X access control is that NAC require the placement of one or more agents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a potential weak point of NAC?

A

The trustworthiness of the agents. A compromised endpoint will try to appear like it is in compliance with security policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is TNC (Trusted Network Connect)?

A

An open architecture for NAC. Hierarchical set of attestations based on layering of trust.

Aims to fix the problem of rogue endpoints appearing like they are in compliance with security policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ETSI M2M

Name the Service Capabillity Layers from ETSI M2M (SCL)

A

Network SCL -> Gateway SCL -> Device SCL

Legacy devices can be connected to IoT trough Gateway SCL systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

CoAP: What security implementation settings does CoAP have?

A

no security, pre-shared keys, raw public key, X.509 Key certificates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is faster? Preshared Key DTLS or Public Key Mutual Authentication

A

Preshared Key DTLS is about one order of magnitude faster than PKMA. Usefull for low LowWPAN and low energy BLE.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly