ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Mobile Devices

Getting the knack of NAC

Ofir Arkin, Insightix

Published: 18 Oct 2007 13:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment
Getting the knack of NAC

If implemented properly, network access control can significantly lower the overall security risks faced by an enterprise.

The basic premise of network access control (NAC) is that it allows only authorised and compliant devices to access and operate on a network.

Unfortunately, many NAC offerings are too complex to implement, expensive to acquire and easy to bypass. However, there are signs that this is changing.

Despite all the hype about NAC, the market today is moving forward, especially in terms of a more commonly understood definition of what an NAC solution is expected to provide. At the same time, enterprises are more aware of their needs. Based on their initial exposure to NAC projects, enterprises have established a clear demand for a strong technology that delivers a fast time-to-value at a reasonable cost.

However, in terms of closing the vulnerabilities that enable all the various available approaches to NAC to be bypassed, not much has changed.

Both existing and potential users are looking for less complex solutions

Real-time device detection is still a serious issue that has not yet been addressed. Most NAC solutions do not maintain real-time contextual information regarding the network and its elements. Simply put, without real-time network and element knowledge, achieving NAC is not possible.

The list of additional vulnerabilities is long. Some NAC solutions cannot even identify or prevent rogue devices from accessing a network, while others do not provide user authentication. Some are erroneously based on vulnerability scans to determine if a device complies with a defined access policy, while most rely on the switching infrastructure to provide a shared quarantine, such as a quarantine VLAN. These vulnerabilities create a situation for bypass opportunities from both the inside and outside.

Unfortunately, the outcome of these and other vulnerabilities is the fact that many of the NAC solutions that are being implemented now can be bypassed easily. Security through obscurity does not work — knowing less than 100 percent of the devices on the network and reacting to changes after they have occurred is simply not enough. If these vulnerabilities are not addressed NAC will merely offer compliance checks on known devices, rather than the intended network access controls to allow only authorised and compliant devices and users to access and operate on the network.

Both existing and potential users are looking for less complex solutions. This means that NAC deployments that involve changes to network architecture and the deployment of agents are no longer considered as options. The market wants easily implemented solutions that do not rely on the networking infrastructure to provide the NAC functionality — getting read/write access to the networking infrastructure is not a trivial issue.

NAC will fulfill its promise to lower the overall security risks of an organisation when the NAC process isolates all devices as they are being attached to the network, and when it allows a device access to the network only if it is authorised, its user is authenticated and it is compliant with the enterprise network access policy.

Ofir Arkin is the co-founder and chief technology officer of NAC provider Insightix.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
45 out of 45 people found this useful


Full Talkback thread

0 comments

More in this Special Report

Research: Mobile working on the increase

Research: Mobile working on the increase

An exclusive survey has revealed that nearly two-thirds of companies are seeing an increasing proportion of mobile workers more

Laptops are top choice for mobile working

Laptops are top choice for mobile working

When it comes to an all-round device for staying productive outside the office, you can't beat a notebook, according to research carried out by ZDNet.co.uk more

When open phones meet closed minds

When open phones meet closed minds

Opening up mobile networks and devices should go hand in hand with an overhaul of mobile security thinking more

Linux crashes the mobile party

Linux crashes the mobile party

Cutting costs by deploying Linux is a well-established strategy on the server and even the desktop, but what effect could it have on the cost of mobile computing? more

RIM boosts BlackBerry with Wi-Fi

RIM boosts BlackBerry with Wi-Fi

RIM has updated its popular business handheld with Wi-Fi capabilities, among other features more

Nokia E61i review

Nokia E61i review

Nokia's E61i offers better build quality, a digital camera and a slimmer profile than its predecessor, the E61. Current users of the E61, however, may not be convinced that such tweaks are worth the upgrade more

Mobile devices: A buyer's guide

Mobile devices: A buyer's guide

Businesses going mobile need to consider whether to buy notebooks, handhelds, smartphones or other mobile devices. Then there's the various wireless connectivity options, and the extra management burden on the IT department. We take a look at some of these issues more

Calling time on smartphone reboots

Calling time on smartphone reboots

It's bad enough that smartphones sometimes need rebooting, but add to that the wait before a phone call can be made, and it becomes clear there's a thorny issue manufacturers need to address more

What are the must-have mobile apps for business?

What are the must-have mobile apps for business?

Instant messaging, videoconferencing, and even enterprise CRM access are all being accessed by mobile business users according to the latest research from Rhetorik Market Intelligence more

A life coach in your pocket

A life coach in your pocket

Accenture Technology Labs wants to develop applications that will turn a mobile phone into a customised personal coach more

Broadcom claims lead over rivals with 3G chip

Broadcom claims lead over rivals with 3G chip

The company has announced an integrated 3G high-speed wireless mobile-phone chip which it claims puts it two years ahead of Qualcomm and others more

Bigger and better mobile screens coming soon

Bigger and better mobile screens coming soon

Nick Horton, head of business devices, Orange, says improvements to mobile displays and smarter form-factors are all on the cards in the next 12 months more

Featured White Papers

See All White Papers

Company/Topic Alerts

Create a new alert from the list below: