Security in Open Networks: A Contradiction in Terms?

Ralph Spencer Poore · Information Systems Security · 1993

As commonly implemented today, open networks provide little security. Indeed, some would argue that the very concept of secure open networks is a contradiction in terms. And unfortunately, there is plenty of evidence to support this view. The potential for abuse is enormous. User IDs and passwords traverse networks designed primarily to speed the interchange of information, not to provide security. Such legitimate diagnostic tools as datascopes, session monitors, and network sniffers can be misused to capture passwords and other valuable information. Hackers can download from underground bulletin boards software designed to exploit weaknesses in LANs. They may establish unauthorized gateways of their own, even going so far as to advertise them to an unsuspecting public as a valid, lowcost network service. How did we get to this point? And what can we do about it? The following sections are intended to answer these questions.

Read the paper · More papers on PaperTik