Now in your network environment just consider what one of your users with an empty iPod, access to a USB port and bad intentions could get away with . . . chills you to the marrow, doesn’t it? And when you think of it, the whole idea of any I/O devices on PCs being available when they aren’t actually needed is pretty dumb. So what’s a sysadmin to do?
Last week we discussed the wonders of the Keyspan USB server, which raises an interesting topic: How do you control what gets plugged into your PCs?
Just think; you have a gazillion PCs, all with some combination of serial, parallel, infrared, Firewire and USB ports. Not to mention 802.11 wireless cards, writable CD drives, floppy disks and hard disks. Think about it; each port and device is a potential major security hole.
Now in your network environment just consider what one of your users with an empty iPod, access to a USB port and bad intentions could get away with . . . chills you to the marrow, doesn’t it?
And when you think of it, the whole idea of any I/O devices on PCs being available when they aren’t actually needed is pretty dumb. So what’s a sysadmin to do?
Well, we just found an interesting answer: DeviceLock from SmartLine. This system, which works under Windows NT, 2000, XP and Server 2003, lets you block unauthorized users from using all the devices we listed above and many other plug-and-play devices.
DeviceLock also lets you control device access by time of day and day of the week, and you can define a whitelist of USB devices that authorizes access to specific devices regardless of any other settings.
A particular advantage for all network administrators who have users who insist on “accidentally” overwriting disks is the ability to set devices to read-only mode and prohibit formatting. You also can remotely flush unsaved file buffers – something that is crucial with removable media.
DeviceLock is oriented toward corporate use because you can install and uninstall it automatically (DeviceLock supports Windows Remote Install facility) and manage all device control remotely.
We found DeviceLock easy to deploy and the management quite easy to use. When you make changes to user-access rights they happen almost immediately, and you can set access rights in batch mode so a network-wide policy can be implemented, effectively, with one click.
Defeating DeviceLock isn’t easy if you don’t have administrative privileges, and even when you do, simply ripping out the DeviceLock driver won’t give you access to blocked devices. It will just remove the ability for the management tool to reconfigure access. The bottom line is that so long as your users’ PCs are configured properly in the first place, you should be able to thwart all but the most-skilled hackers.
So now you’ve got all those devices locked down, what about all those TCP/IP sockets? Given the staggering number of applications that use TCP/IP communications for code or data updates, instant messaging, peer-to-peer file sharing or any of the other countless purposes the industry invents, there is a good argument that some kind of firewall on each user’s PC is not just a good idea.
You probably will not be surprised to learn SmartLine also offers a system called PortsLock to do just that. Unlike many workstation products, PortsLock can be centrally managed, much like DeviceLock.
Incidentally, you cannot control access to devices connected to last week’s Keyspan USB server with DeviceLock because connections to the server are through User Datagram Protocol (UDP) and TCP, which requires a firewall such as PortsLock.
PortsLock is a firewall with user-level access control, again, for NT, 2000, XP and Server 2003, and lets permissions be set on TCP/IP connections that use UDP, TCP, IP or Internet Control Message Protocol.
For defined users or groups you can block access to specific connections; set allowed or denied IP addresses; control incoming and outgoing connections; control communications access by time of day and day of the week; monitor TCP/IP activity on remote computers in real time; and – again like DeviceLock – install the system on remote computers.
The strength of PortsLock is its centralized management, and our only complaint is that when PortsLock and DeviceLock are installed they should share an interface – indeed, they really should be plug-ins for the Microsoft Management Console.
DeviceLock pricing starts at $35 for a single computer, and PortsLock costs $50 for a single PC.
We would be very interested to know what you think of these tools and how seriously you take the issue of your users being a threat. Tales of constraint to gearhead@gibbs.com.




