Chapter 5 - Network Access Control and Cloud Security

Network Access Control (NAC)

NAC systems deal with three categories of components:

image.png413x429

Network Access Enforcement Methods

Common NAC enforcement methods:

image-1.png412

Notes:

Authentication Methods

Commonly supported EAP methods:

Notes I:

image-2.png416x329

Notes II:

image-3.png417x389

Notes III:

EAP Message Content

Authenticator

Authentication exchange

Authentication process

Authentication server (AS)

Authentication transport

Bridge port

Edge port

Network access port

Port access entity (PAE)

Supplicant

image-14.png360x292

Notes:

Common EAPOL Frame Types

EAPOL-EAP and EAPOL-Key caries EAP message

Frame Type Definition
EAPOL-EAP Contains an encapsulated EAP packet.
EAPOL-Start A supplicant can issue this packet instead of waiting for a challenge from the authenticator.
EAPOL-Logoff Used to return the state of the port to unauthorized when the supplicant if finished using the network.
EAPOL-Key Used to exchange cryptographic keying information.

EAPOL MSG Content

image-15.png362x447

EAP & Radius Messages

image-16.png364x515

Cloud Computing

"A model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model promotes availability and is composed of five essential characteristics, three service models, and four deployment models."

image-17.png355x320

Notes:

image-18.png356

Notes:

Cloud Computing Reference Architecture

"The NIST cloud computing reference architecture focuses
on the requirements of “what” cloud services provide, not a
“how to” design solution and implementation. The
reference architecture is intended to facilitate the
understanding of the operational intricacies in cloud
computing. It does not represent the system architecture of
a specific cloud computing system; instead, it is a tool for
describing, discussing, and developing a system-specific
architecture using a common framework of reference."

image-19.png373x273

Notes:

Cloud Provider

Cloud Provider (CP)

Cloud Security Risks and Countermeasures

Abuse and criminal use of cloud computing:

Malicious insiders

Insecure interfaces and APIs

Shared technology issues

Data loss or leakage

Account or service hijacking

Unknown risk profile

Data Protection in the Cloud

Multi-instance mode:

Multi-tenant model:

Notes:

Privacy and Security For Storage Services

image-20.png478

Two encryption scenarios for cloud computing.

image-21.png472x361

Cloud Security As a Service (SECAAS)

Notes:

Native Hypervisor

image-22.png319x290

How many people can shared a single CPU?

Main Cloud Security Approaches

Summary