Research Ideas
Wireless Authorization
Authorization
Or, who's the Dick on your wifi?
must see presentation! (single signon to blog ‘sphere’)
-
-
-
-
-
Connection access != “authorized”
businesses, schools, govt, etc
Community wifi?
any ‘secure’ and ‘free’ wifi service
how can i help others w/o making self vulnerable?
default bcast ssid, no encryption
best practices available?
many software ‘out of the box’ apps available
-
Complicated Security
‘hotspot’ systems often
proprietary
limited
no single ‘payment’ plan, reusable
mobility and roaming, different cities?
protocols, requirement for user
“i just want to connect and check email”
wireless card stardards, chipsets
EAP, RADIUS, infrastructure requirements
Dynamic Authorization
temporal access time
security posture of network changes, revoke access
mission systems needed, allow access
varying degress / rings of trust, allowed access
requires some 802.1x and/or firewall filtering
Authentication mechanisms
secret: password, pki, ssl
transmit: email, sms
identity: MAC address, pki, ipsec
how many ways can I authenticate?
what devices supported?
how extensible is it to other user reqs?
Enable privacy as well?
great anonymous mobility - but location tied to AP
often unencrypted, anyone can read the traffic
dns, http images, text
local hijacking attacks
IPv6 support any of this? (anonymous IPs)
Password Management
always access online, but secure for the users?
usb drive, where to store the keys?
Personal Info Mgmt
11: Civil Penalties for Noncompliance with the Privacy Act
The Privacy Act also imposes civil penalties on violators who:
Unlawfully refuse to amend a record
Unlawfully refuse to grant access to records
Fail to maintain accurate, relevant, timely and complete data
Fail to comply with any Privacy Act provision or agency rule that results in an adverse effect.
ID & Auth
Identification and Authentication in MANET, P2P and Groups
Secure association and transport of keys
PGP, PKI/CA based models,
SSH-based host keys
Key continuity management (in ssh host keys? PKI and PGP certs?)
-
Secure Information dispersial - anonyminity?
Other Ideas
Security & Privacy
From the IEEE Security CFP
Access Control and Audit
Anonymity and Pseudonymity
Authentication, including Phishing
Automated and Large-Scale Attacks
Biometrics
Commercial and Industrial Security
Data Integrity
Database Security
Denial of Service
Distributed Systems Security
Electronic Privacy
Information Flow
Intrusion Detection
Language-Based Security
Malicious Code
Mobile Code and Agent Security
Network Security
Peer-to-Peer Security
Secure Hardware and Smartcards
Security Protocols
Security Verification
Security of Mobile Ad-Hoc Networks