{"id":6174,"date":"2016-09-01T16:46:23","date_gmt":"2016-09-01T16:46:23","guid":{"rendered":"http:\/\/skylight.gr\/administrator_wordpress\/index.php\/2016\/09\/01\/nsa-and-potential-client-security\/"},"modified":"2016-09-01T16:46:23","modified_gmt":"2016-09-01T16:46:23","slug":"nsa-and-potential-client-security","status":"publish","type":"post","link":"https:\/\/skylight.gr\/index.php\/2016\/09\/01\/nsa-and-potential-client-security\/","title":{"rendered":"NSA and potential client security"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/upload.wikimedia.org\/wikipedia\/commons\/thumb\/8\/84\/National_Security_Agency_headquarters%2C_Fort_Meade%2C_Maryland.jpg\/1024px-National_Security_Agency_headquarters%2C_Fort_Meade%2C_Maryland.jpg\" border=\"0\" width=\"217\" height=\"168\" \/><br \/>The scope of this article is to create a strategy about a security mechanism for the staff of NSA that will use several features of Windows Embedded 8.1 and Bitlocker. The detailed analysis of these features will provide us a framework for a recommended strategy.<\/p>\n<p>  <!--more-->  <\/p>\n<p><em>Main discussion<\/em><\/p>\n<p>The security plan that we have to implement regarding the security of the staff\u2019s notebooks requires a study of the available solutions.\u00a0 The first measure is related to the prevention of any USB device. The USB filter in the Windows Embedded 8.1 is a feature that\u00a0 will help NSA to protect the USB input of their machines. This feature enables the connection of only trusted USBs to the system, so it can prevent from the use of any other USB devices.\u00a0 The characteristics of USB include class, vendor, product IDs and these IDs could define if the USB is going to be allowed to use or not.<\/p>\n<p>\u00a0<\/p>\n<p>The second security measure that we have to take, considers the remote management which is very important for the NSA staff. The remote management is implemented with the use of the Embedded Lockdown Manager which enables to manage your device remotely.\u00a0 If any problem occurs with the ELM then several\u00a0 Group policy settings have to take place; such as working as an administrator and setting a registry key to configure the remote management.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/upload.wikimedia.org\/wikipedia\/en\/thumb\/d\/da\/Windows_To_Go_-_Bitlocker.png\/300px-Windows_To_Go_-_Bitlocker.png\" border=\"0\" width=\"247\" height=\"183\" \/><\/p>\n<p>Another security measure that we have to take, is the remote management. Windows Embedded 8.1 includes the feature of the keyboard filter element which blocks the keyboard stroke combinations such as \u00ab Ctrl+Alt+Delete\u00bb. This security element can block physical hardware keys and prevent unauthorized activity on a device.<\/p>\n<p>At last but not least, Bitlocker is going to be used for some additional encryption. If the notebooks are equipped with a Trusted Platform Module (TPM), then Bitlocker will use the TPM to lock the encryption keys which protect the data. In this case, Bitlocker will prevent the access to the keyboard unless TPM verifies the state of the computer.<\/p>\n<p><em>Conclusions<\/em><\/p>\n<p>In general the protection of the NSA machines through the use of\u00a0 Bitlocker and Windows Embedded 8.1, seem to be a wise solution because they offer a variety of security mechanisms for the NSA staff. Of course, since always the human factor is a critical one for security, what remains to be taken into account is how the NSA staff will be trained to be\u00a0 aware for new security risks and of course to maintain the security of the system with possible patches and updates for\u00a0 these two key elements.<\/p>\n<p>\u00a0<\/p>\n<p><em>Bibliography<\/em><br \/>Description of the BitLocker Drive Preparation Tool&#8221;. Microsoft. September 7, 2007. Archived from the original on 2008-02-19. Retrieved 2014-10-24.<br \/>Kanthak, Stefan (21 August 2013). &#8220;Windows Embedded POSReady 2009: cruft, not craft&#8221;. Full disclosure (mailing list). Retrieved 2014-10-24.<\/p>\n<p>\u00a0<\/p>\n<p>Author: Vasileios Yfantis<\/p>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The scope of this article is to create a strategy about a security mechanism for&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"nf_dc_page":"","footnotes":""},"categories":[26],"tags":[],"class_list":["post-6174","post","type-post","status-publish","format-standard","hentry","category-food-for-thought"],"_links":{"self":[{"href":"https:\/\/skylight.gr\/index.php\/wp-json\/wp\/v2\/posts\/6174","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/skylight.gr\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/skylight.gr\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/skylight.gr\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/skylight.gr\/index.php\/wp-json\/wp\/v2\/comments?post=6174"}],"version-history":[{"count":0,"href":"https:\/\/skylight.gr\/index.php\/wp-json\/wp\/v2\/posts\/6174\/revisions"}],"wp:attachment":[{"href":"https:\/\/skylight.gr\/index.php\/wp-json\/wp\/v2\/media?parent=6174"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/skylight.gr\/index.php\/wp-json\/wp\/v2\/categories?post=6174"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/skylight.gr\/index.php\/wp-json\/wp\/v2\/tags?post=6174"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}