Showing posts with label Aruba Networks. Show all posts
Showing posts with label Aruba Networks. Show all posts

November 30, 2010

Aruba Networks Airheads Technical Conference, Phuket, Thailand 2010

At a glance, about Aruba Networks Airheads Technical Conference, Phuket, Thailand 2010.

Venue: JW Marriott Hotel, Phuket Thailand
Date: 1 - 3 December, 2010

The Airheads Conference is all about Technology Directions and Roadmap: A detailed review of Aruba’s plans for the future. This conference focusing on a few topics as follows:

Designing Defensive Networks with WIPS
Overview of fundamental WLAN security concepts, update on recent threats, and discussion of best-practices for defending your networks. Including a discussion on Aruba’s overall security architecture.

Supporting Voice & Video over WiFi
Wireless LANs are becoming mission-critical networks supporting a wide variety of voice and video applications (including Microsoft OCS). This session covers best practices for design, implementation, management and monitoring to deliver reliable performance for voice and video applications.

Managing an Aruba Networks with AirWave
Focusing on using the AirWave Wireless Management Suite to configure AOS, measure network capacity, and monitor usage patterns. Including discussion and demonstrations of AirWave 7.0

Taking the WLAN Outdoors
An overview of key issues to consider when implementing an outdoor network for access, video surveillance and other applications. Includes discussion of core outdoor design principles, antenna selections, mesh network designs, and more.

Teleworking & Branch Scenarios
Workers need secure access to their network resources wherever they are: at home, in small remote offices, on the road. This session offers an in-depth look at Aruba Virtual Branch Network architecture and other solutions to address the needs of remote users.

A Least Privilege Approach to Security using PEF
An in-depth discussion of user roles, Aruba’s Policy Enforcement Firewall (PEF), and Wireless Intrusion Prevention (WIP) in Aruba’s new 6.0 software. The speaker will provide in-depth examples of how to protect corporate asset, isolate viruses and worms and more.

Designing Wi-Fi Networks for Density
As more users and devices connect to your network, how do you design your WLAN to assure performance and reliability? The best practices for designing high-density wireless networks – and discuss how to avoid common mistakes.

November 3, 2010

Polycom, Aruba now lead the Cloud Video Conferencing technology

Aruba Networks and Polycom announced on August 26, 2010 that they are teaming up to deliver video features to users via cloud computing. Aruba will provide its Virtual Branch Networking (VBN) solution to its users -- typically through its cloud-based offerings -- who can then utilize Polycom's telepresence, videoconferencing and voice communications solutions.

Aruba said the joint solution will reduce the time, cost and network engineering needed to deliver the unified communications products to remote users working at home, in branch offices or on the road. Aruba said the cost involved in joint Aruba-Polycom remote access points can be as low as USD 99 per site. Aruba noted that its Virtual Intranet Client can deliver remote access points for virtually no cost to PC users while delivering security service economically to branches.




I believe, that the Aruba-Polycom technology definitely much better than Cisco-Tandberg partnership solutions. The International Islamic University Malaysia (IIUM) will be first end user in Asia Pacific to attain the advantage from this collaboration. IIUM has deployed its campus wide wireless infrastructure based on Aruba Network technology since 2008, which centrally managed all together 6 branch campuses. Early of this year, they have engaged with Polycom video conferencing solution as part of their digital education infrastructure.

According to IIUM technical expert; Mr. Jaiz Anuar and Mr. Hairulnizam (from IT Division), IIUM now aiming to provide a future infrastructure for virtual lecture which can be accessed by students via wireless network cloud. Both of them agreed that, the teaching methodology have to change parallel with the technology advancement. Since the Aruba-Polycom partnership focused on proliferating new collaborative communications solutions, it will help the university to realize its intention in establishing mobility campus by providing holistic ICT services for the achievement and continuation of excellence in IIUM. The experts say, many new initiative can be done in the future on Video over WLAN.

Mobile Education is the Future. In other words, the whole ecosystem of learning and communication will undergo a rather serious upheaval — much the same way campuses did when laptop computing became the standard. This will present challenges both in terms of infrastructure and pedagogy, but it will also provide rich opportunities for reinventing the academy and for rediscovering learning.

Communication preferences will also continue to evolve. Just as we have moved from letter writing to e-mail to texting, we will move next into video chat and voice texting. The Pew Foundation’s most recent study shows that “Almost a fifth of American adults – 19% – have tried video calling either online or via their cell phones. These figures translate into 23% of internet users and 7% of cell phone owners who have participated in video calls, chats, or teleconferences. Video calling has become increasingly available as camcorders have spread through the online environment, cameras have been built into smart phones, and as video-chat services like Skype, Google Talk, and Apple iChat have become a feature of the online and smart phone environment. Teleconferencing is also becoming more embedded in the business environment.”

In addition, we will see a fairly rapid evolution of software solutions for both tablets and smart phones that makes it unnecessary to have a large-form computer for all essentially learning tasks. This include better productivity apps and improved multitasking. We will also see a proliferation of integrated and add-on input peripheral devices. More important, cloud-based services like Google Docs will eliminate most of the need for standard productivity software downloaded to devices.

October 25, 2010

Aruba Networks offers the best solution for Video over WLAN

Last week I got a chance to test and review the implementation of Video over WLAN. The test gear is Aruba AP 125, medium range of Aruba Controller and Axis Web Cam. The main medium is over wireless LAN. The overall test is enhanced with Azalea Video Technology (AVT). The result is really superb ! The video run smoothly.


Video transmission over WLAN with AVT is really sharp and smooth. The test then been extended by using Sony CCTV. The remote zooming features from SONY works very well. The video quality has been improved by AVT and the reliable transmission over WLAN enhanced by QoS inside the Aruba technology. The merging of Aruba Networks and Azalea Technology promising a better quality for future deployment of video transmission over WLAN. It offers high reliability, flexibility and mobility. Future education infrastructure will be depending on video broadcasting and Aruba will be the best solution for it.

August 20, 2009

Review: Aruba Virtual Branch Network (VBN) RAPs

Highly-distributed businesses have long faced a choice of evils: ship skilled staff out to install pricey enterprise APs or let small branch and home office workers install their own consumer plug-n-play APs. For organizations with hundreds of storefronts or thousands of teleworkers, the former is prohibitively expensive. But for secure multimedia WLANs, the latter is unthinkable.

According to Aruba Networks, Virtual Branch Networks (VBNs) are a more palatable solution. Interop LV09 judges were impressed, awarding Best of Show in the Wireless/Mobile category to VBN. During our own test drive, we found VBN extremely promising—but we spotted a few rough edges that could use bit more honing.


Virtualizing remote WLANs

Aruba's VBN is an architecture that enables centralized control over a large number of small remote office WLANs, up to 100 clients apiece. In the VBN architecture, every Remote Access Point (RAP) operates as a remotely-managed VPN gateway, enforcing role-based access policies and tunneling only permitted traffic back to the corporate network.

Sure, branch office VPNs can be built using many enterprise wireless routers. What differentiates Aruba's VBNis entry-level gear with "zero-touch" provisioning. Aruba can drop-ship factory-default $99 RAPs to hundreds of destinations on your behalf. On first power-up, each RAP tunnels over the Internet to a user-designated Aruba controller. When the controller hears from a whitelisted RAP, it installs and activates IT-defined firmware and policies over a secure boot-strap tunnel. The end result: a business-grade WLAN, provisioned in less than ten minutes, with almost no end-user or IT assistance.

Eliminating advance or on-site IT provisioning from an otherwise lengthy, error-prone process speeds new site activation and reduces per-site investment. And, because RAPs are managed over that tunnel throughout their life, IT can remotely assert relatively sophisticated, dynamic role-based access controls. While RAPs are ultimately constrained by inexpensive hardware, the policies they can enforce are far from consumer-grade.
RAP2WG.jpg

Putting VBN into action

This architecture can be implemented using any combination of the following new VBN RAPs.

  • The RAP-2WG is a fist-sized single-radio 802.11b/g AP with two 10/100 Ethernet ports, targeted for use by "fixed telecommuters" and home offices with up to five users. (Pictured above.)

  • The RAP-5WN is a desktop/wall-mount dual-band 802.11a/b/g/n AP with five 10/100 Ethernet ports, slated for small branch offices with up to 256 users. (Picture below.)

  • The RAP-5 is a wired-only RAP-5WN, to incorporate small branches that require authenticated, secure Ethernet, but not wireless VBN access.

RAP5WN.jpg

Older (non-VBN) Aruba RAPs can be added to the same network manually—for example, the dual-radio AP-125 for a branch requiring simultaneous dual-band operation. However, the zero-touch feature that appealed to us is only available in new VBN RAPs. To road-test VBN, we therefore installed an RAP-2WG and an RAP-5WN in over a dozen home and small office networks.


June 5, 2009

Review on Aruba RAP-2WG Remote Access Poin


Photo of Remote Access Point RAP-2

The Aruba RAP-2WG is a single radio 802.11b/g, enterprise-class indoor remote access point, capable of supporting multiple functions including wired and wireless access and air monitoring/wireless intrusion detection and prevention across the 2.4-2.5 GHz spectrum.

The RAP-2WG remote access point delivers secure user-centric network services and applications in remote branch offices as well as for home office workers and telecommuters. Centrally managed from an Aruba Controller, the RAP-2WG provides the network administrator with unparalleled control over services and security. The RAP-2WG supports authenticated wired and wireless access, as well as policy based forwarding mechanisms to allow access to centralized and local resources.


The latest product Aruba's Virtual Branch Network (VBN) solution dramatically simplifies the complexity and cost of deploying a remote solution at branches with one to many users. Complex configuration, management, software updates authentication, intrusion detection, and remote site connectivity tasks are handled by powerful data center-based Aruba controllers running new Aruba software. Centralizing these services in the controllers enables the branch office equipment to be greatly simplified and cost reduced. The virtualized functions are transport-independent, so any wide-area network - including 3G cellular and DSL - can be used to connect the branches offices.

I think this a great product for educational institution that always have a meeting a way from their campus escially when researcher need to conduct a research collabaration meeting with other research group and they also need to have their own local network for linking back to the local server at the university.

With this kind of features, remote office can be enable anywhere at anytime in the world.


December 17, 2008

Aruba Networks and Force 10 Networks Offers Reliable Real Time High Speed WLAN for Campus


Aruba

Seamless Converged Mobility Solution

Force10 Networks® and Aruba Networks® have partnered to deliver an interoperable solution for seamless converged mobility with unmatched security services by combining best-of-breed switching and routing with WLAN infrastructure.
The inherent reliability of the Force10 C300 resilient switch guarantees predictable and constant access for all users, wired and wireless. Aruba’s customer focused approach to secure mobility extends network connectivity and enterprise security anywhere as a user roams, allowing the largest networks to be centrally managed.
Together, this innovative solution allows customers to provide a high performance wireless and wired network in education, healthcare, finance and enterprises large and small. By building a unified network fabric that extends pervasive reliability, network control and scalability, enterprises are ensured a network that is a strategic asset.


Solution Key Features

  • Non-blocking architecture supports up to 384 line-rate Gigabit Ethernet ports
  • Embedded security features guarantee a secure connection
  • Intelligent power management system prioritizes power to distributed access points

Suitable Campus Solution

  • In-house Campus Broadcasting Services via wireless network
  • In-house free IP-Telephony VoIP or VoWiFi for campus sommunity

Aruba offers quite secure WEP authentication

Even though we know that WEP is already broken, but still better than deploying wireless without encryption at all. Deploying an Aruba network significantly reduces an attacker’s ability to crack WEP. 

Cuurently, the WEP cracking tools such as (Airsnort, WEPcrack) rely on packets with weak initialization vectors (IVs) in order to conduct analysis. Aruba controllers will not generate packets with weak IVs – thus all downstream packets will be unusable for cracking purposes

Some other cases, clients will still generate weak IVs – small percentage of client traffic will contain packets with weak IVs. A determined attacker will eventually crack the WEP key – though it may take weeks using client traffic alone. - Wireless Zone

For more secure authentication, you have an option to use 802.1x type of authentication and enhance with WPA2 encryption offered by Aruba Controller.

November 20, 2008

Motorola vs Aruba - Patent infringement

Last year somewhere in August 2007, Motorola and his subsidiaries Symbol and Wireless Valley sues Aruba Networks for alleged patent infringement. Then last two months somewhere in September 2008, Aruba files patent infringement countersuit against Motorola, Symbol, and Wireless Valley. The battle still not ended yet. For me, as an end-users who have experience with Motorola-Symbol technology and Aruba technology... a secured wireless technology always synonym to Aruba enterprise solution. Even if we compare to another wireless leader in the market such as Cisco, they have to admit that Aruba technology offers a total solution for secure wireless environment. they offer wireless firewall, VPN etc in one box.


I consider, it is a weird story to hear Motorola also has the capability to offer better wireless solution. As far as I’m concern, the most well known wireless leader being debated among the wireless administrator is between Cisco and Aruba. I don’t agree if someone said that, Motorola-Symbol is another competitor in the wireless market share. Solution from Trapeze, 3Com, Meru or Orinoco which I can considered much better compared to Motorola-Symbol solution. For me, it is a wired story when Motorola sues Aruba for alleged patent infringement. My favorite wireless products rank is listed as below according to its best features offered to the end-users.

1. Aruba
2. Cisco
3. Trapeze/3Com
4. Meru
5. Orinoco
6. Motorola
7. Belkin
8. Colubris
9. Linksys

November 5, 2008

The importance of WLAN in Malaysian Higher Education

Today, Universities and colleges are among the most aggressive adopters of WiFi technology in Malaysia. The trend toward more collaborative and open learning environments, fueled by the explosive adoption of mobile devices like laptops, PDAs and Netbooks among students, makes higher education campuses fertile ground for Wireless LAN.

International Islamic University (IIUM) also doesn't want to be left in deploying Wireless Campus environment. In fact, IIUM can claimed that they are the first institution in Malaysia introducing heterogeneous wireless infrastructure for campus wide environment. A few institution has visited IIUM campus for getting some experience and knowledge sharing in term of designing and managing wireless for campus environment. By using Aruba Wireless as a backbone of wireless network infrastructure, IIUM has put their wireless service on the top in term of security, reliability and scalability features. Together with new research on the effective MIMO on the for wireless backbone, the service will be able to be further enhanced in their diversity and additional security.


With the core value ” access to education” , the IIUM wireless service will not only cater for internet browsing, rather IIUM students, Kulliyyahs, researchers and staff have the flexibility to access online resources from anywhere on campus. They are freed from working in a traditional computer labs environment thanks to some hundrends of wireless access points (APs) that permit linking to the university’s resources via laptop computers, PDAs and cell phones equipped for data connectivity. Meanwhile, Information Technology Division (ITD) has put their effort in designing such a very informative IIUM portal which become a “house of information” for staff and student as well.

In addition, the future development of SIP service and IP Telephony service provide sophisticated voice connectivity and allow IIUM community to deploy Voice over IP and voice over WLAN at its own pace across campus.

As International Islamic University expand its wireless network, the lines between indoor and outdoor communications will vanish. Students, faculty and administrators alike will enjoy seamless connections from one side of the campus to the other. The institution will continue to attract the best students with innovative applications of its wireless-enabled campus.

IIUM is also working towards Multimedia Communication Service for new e-tutorial, “faculty on demand” service, Media Archive Service and Virtual class and pursuing deployment of VoWLAN (VoFi) for increased operational efficiencies and campus security applications. With its converged wireless infrastructure in place, IIUM is sure to continue building upon its heritage of academic excellence and innovation.

October 17, 2008

Trial run of Aruba Wireless Controller and InfoExpress NAC

IT Division of IIUM has run a prove of concept in implementing Aruba wireless and InfoExpress Network Access Control (NAC). The simulation test was done in their mini test lab known as Communication Testing Lab.

The setup are as follows




Cyber Gatekeeper




Aruba AP, Aruba Controller (white box), Cisco C500


Features that ITD wants to test

  1. To verify, users have Anti Virus or not

  2. To check the Anti Virus version

  3. To identify bridging activies


We also test other features offered by InfoExpress.



So far, there haven yet publish the final finding about the integration of Aruba Controller and InfoExpress NAC. I'm still waiting their final release about the result of their testing.

NAC on Heterogeneous Wireless Network: Campus Network


Tested products: Consentry, Infoexpress, Aruba ECS, Bradford, Juniper
schematic wireless network diagram

The most critical feature which can be considered compulsory to the tested NAC that it must be able to detect the network bridging activities running by the users: bridging via UTP cable, Bluetooth, GPRS, Edge, 3G, HSDPA and other possible method of bridging such as via firewire, USB, PCMCIA etc. It must also able to quarantine or disconnect or isolate the users from the wireless network once they activate the bridging processes. In fact, most of the bridging activities is able to create a back door to our secure network. That’s why this feature is really really important to us.
Since we are having heterogeneous network, this NAC must able to support multiple protocol such 802.1x and non 802.1x including all OS platform: e.g Windows, MAC OS and Linux Clients.
We will announce later which product is the most suitable to be deployed to protect our campus wide wireless network.


[more]

March 4, 2008

ARUBA CENTRALIZED WLAN SYSTEM RECEIVES WPA2 CERTIFICATION.

Aruba Wireless Networks (Aruba) is the first centralized wireless LAN (WLAN) systems supplier to obtain 802.11i (Wi-Fi Protected Access 2) certification from the Wi-Fi Alliance.

With this certification, the Aruba WLAN system offers corporate and government customers the highest level of wireless security available today. The Aruba system delivers security services through its unique wireless grid architecture -- a structured, high-performance approach to deploying mission-critical WLANs.

WPA2 is based on the Institute for Electrical and Electronics Engineers' (IEEE) 802.11i amendment to the 802.11 standard, which was ratified on July 29, 2004. WPA2 uses a more advanced encryption technique called the Advanced Encryption Standard (AES) and is backwards compatible with WPA, ensuring that organizations that have already implemented WPA can easily migrate to the new 802.11i standard.

"Aruba is commended for receiving WPA2 certification for its centralized WLAN switching system. This level of commitment to interoperability and security is a clear commitment to the evolving needs of their customers," commented Frank Hanzlik, managing director of the Wi-Fi Alliance.

"Enterprises continue to view security as a key roadblock to the pervasive deployment of Wi-Fi," said Merwyn Andrade, chief technology officer for Aruba. "The WPA2 standard and Aruba's certification are major milestones for enterprises and government organizations planning to deploy wireless. By integrating WPA2 into a centralized WLAN switching system, enterprises can now confidently enable mobile access to their existing data-center applications without sacrificing security or performance."

Centralized WPA2 Security Delivers Device-To-Datacenter Encryption

Aruba's WLAN systems uniquely centralize all 802.11i security functions, including wireless encryption, authentication and user access controls to deliver the highest levels of security for enterprise deployments. Unlike other WLAN approaches, Aruba's WLAN system performs AES encryption inside the WLAN switch rather than in access points (APs). This approach ensures that encrypted wireless traffic is carried over the wired network and immune to security threats.

"WPA2 is a great leap forward in securing the air," said Keerti Melkote, vice president of Product Management and Marketing for Aruba. "However, terminating WPA2 encryption in the access point effectively limits the benefits of WPA2 to airborne traffic alone. It is well known that the internal wired network is insecure and exposed to misuse. By terminating encryption in a centralized WLAN switch instead of the edge access point, Aruba is delivering the industry's only device-to-datacenter encryption solution based on WPA2 and protects wireless traffic from the threats in the air and in the wired network."

Centralized Encryption Enables Low-Cost Workspace Deployment of Access Points

Since all encryption is performed directly within each Aruba WLAN system, encryption keys remain completely secure thereby avoiding the latencies and insecurities associated with distributing encryption keys to each AP. In addition, centralized encryption enables enterprises to safely deploy APs in user workspace rather than in the ceiling. This can dramatically lower installation costs and improve wireless performance through the dense deployment of APs.

Because encryption is performed through a hardware-based cryptographic engine, Aruba's modular WLAN system delivers industry leading WPA2 performance. A single Aruba 5100 can process up to 3.6 Gbps of encrypted user traffic -- a key metric in determining WLAN system performance and scalability.

Pre-Authentication and Key Reuse Enables Faster Roaming

802.11i delivers strong link layer security using digital encryption keys that are generated when a client authenticates with the network. However 802.11i must be adapted to meet the stringent mobility needs of real-time communications such as voice and video.

When a user roams from one AP to another, fresh encryption keys must be renegotiated according to the 802.11i specification. This renegotiation often proves fatal for voice and other real-time communications -- taking hundreds of milliseconds, or even seconds. This results in high latencies, scalability problems and multiple points of failure.

Aruba's centralized encryption breaks new ground for 802.11i deployments by integrating all necessary components for seamless and secure mobility directly within the WLAN system. Key benefits include:

-- Improved WLAN scalability from not having to distribute and synchronize encryption keys to access points when a station roams,

-- Improved RADIUS scalability by offloading authentication for every client roaming event, and

-- Faster secure roaming via centralized key management for 802.11i

With Aruba's centralized encryption model, user encryption keys are stored in a centralized wireless system and do not get propagated to the APs. Faster handoffs and greater scalability are a natural result. In addition, since the pair-wise master key (PMK) is stored centrally and never gets propagated out of the switch, its integrity is assured for much longer periods providing better mobile security.

Distributed or hybrid approaches, where encryption is performed at the AP, must anticipate user mobility by proactively pushing encryption keys to different APs. Aruba eliminates this problem and its associated inefficiencies by centralizing the encryption, mobility state and traffic policies for each user directly within the WLAN system.

Aruba products Wi-Fi CERTIFIED for WPA2 are available immediately.

About Aruba

Aruba Wireless Networks develops and markets centralized systems that enable corporations to secure their networks from the dual threats of Wi-Fi and mobility. Aruba's solution consists of a full range of programmable security platforms designed to securely connect mobile users and mobile devices to corporate applications. Aruba is privately-held and has operations in the United States, Europe, Asia Pacific and India and employs staff around the world. Aruba has received over $59 million in three rounds of venture funding from top-tier venture firms - Matrix Partners, Sequoia Capital, Trinity Ventures and WK Technology Fund.

Aruba Wireless Networks can be found on the World Wide Web at http://www.arubanetworks.com/.

For more information, call 408/504-5487

January 8, 2008

Aruba Technology: The Move to User-Centric Networking

Our increasingly mobile society is forcing many industries to develop ways to make their services accessible whenever and wherever customers require them. In the not too distant past, one could conduct banking transactions only at a bank branch and only during business hours. As mobile customers demanded more convenient access to banking services, banks moved away from an institution-centric model of business to a user-centric model in which banking applications were brought to the customer. The bank branch gave way to the ATM and ultimately to the smart card.
Illustration of Aruba Technology

The Shift from Institution-Centric to User-Centric Products and Services

Increased mobility for the customer, however, resulted in reduced control and security for banks. Unauthorized card duplication, phishing, and ATM substitution all skyrocketed as banking products and services moved closer to the user. The demand for mobility fostered innovations which, in turn, undermined security.

The networking industry is undergoing a similar transformation, and facing the same issues, as the banking industry. Enterprises want to enable users to work wherever and whenever it is most convenient, economical, and expeditious for them to do so - in the office, at home, in hotels, or on the road. The issue is that traditional, port-centric networks use perimeter-based security that was designed and optimized for fixed, non-mobile users. For traditional network suppliers mobility breaks security, and security precludes mobility.

Fortunately, enterprises have a new option that delivers both mobility and security - user-centric networks from Aruba. Aruba's user-centric networks integrate adaptive WLANs, identity-based security, and application continuity services into a cohesive, high-performance system that securely delivers the enterprise network wherever users work or roam. User-centric networks significantly expand the reach of traditional port-centric networks, preserving and extending investments in existing network infrastructure. Additionally, the high performance and robustness of Aruba's solutions provide the first viable alternative to wired networks, making the all-wireless office a reality.

Adaptive WLANs deliver high-performance, follow-me connectivity so users are always within reach of mission-critical information. Identity-based security associates access policies with users, not ports, enabling follow-me security that is enforced regardless of where and how the networked is accessed. Application continuity services enable follow-me applications that continue running even as the user moves between wireless LANs, wired LANs, and cellular networks.


The Components of User-Centric Networks

Aruba's user-centric networks deliver both mobility and security without compromise. The cost, convenience, and security benefits of user-centric networks are fundamentally changing how and where we work.

Aruba Solution

Aruba has integrated all of the elements required to deliver enterprise mobility - security, application, network and radio frequency (RF) management services - into a unified solution. The components of this solution include an award-winning portfolio of wireless LAN, security, diagnostic, network management, and integration products backed by a worldwide support and training organization. Components include:
  • ArubaOS operating system for delivering user-centric enterprise mobility
  • ArubaOS software modules for value-added security and mobility features including mesh networking, wireless intrusion detection, and remote access
  • Aruba Endpoint Compliance System for Network Access Control
  • Aruba Mobility Management System for centralized management
  • Aruba Mobility Controllers for flexible, high-performance support of the ArubaOS operating system and software modules
  • Aruba Access Points and Access Concentrators that provide wireless and wireline access to Aruba Mobility Controllers

Typical Applications

User-centric networks are applicable across a wide range of uses in enterprise, education, finance, government, healthcare, hospitality, and retail applications. To learn more about how Aruba's solutions are being used to enable various applications and industries, please follow the links below.

October 18, 2007

Researchers crafting intelligent, scaleable WLAN defense

By John Cox

Protecting enterprise wireless networks from increasingly sophisticated attacks is the focus of a research project from the Dept. of Homeland Security Advanced Research Projects Agency (HSARPA), a pilot of which is just wrapping up at Dartmouth College.

Researchers from Dartmouth and Aruba Networks are developing a battery of algorithms and a software architecture running over radio frequency sensors to measure and analyze traffic and then react to wireless LAN (WLAN) attacks, especially to the spoofing and evasion that are ever more common today.

There are commercial wireless intrusion-detection systems (IDS) today from AirDefense, AirTight Networks, Network Chemistry, and Aruba itself. But Project MAP -- the acronym stands for measure, analyze and protect -- has two ambitious, distinguishing goals. First, it is an IDS that's far more intelligent in what and how it measures and analyzes wireless traffic. Second, it is an IDS that can handle not only the traffic from thousands of access points and clients, but also the flood of measurement data that its own RF sensors, or sniffers, will create.

Smarter is better
Smarter software is needed because attacks are becoming smarter and sneakier.

"The IDS [today] may not see certain frames, or the attacker may be doing radio frequency jamming, causing the attack to be invisible," says Josh Wright, senior security researcher with Aruba. "Attackers are using evasion techniques, and these are not being addressed by today's [IDS] products."

Scalability is essential to the project's design because the RF sensors will continuously track, collect, and combine a lot of real-time data about a site's entire radio environment.

Launched in summer of 2005, Project MAP is funded by the Department of Homeland Security through DARPA. The researchers are starting to analyze the results of a test MAP deployment at one building on the Dartmouth campus. Those results will guide changes, tweaks, and refinements to the software through the first half of 2007. By the end of 2007, researcher plan to have deployed a full-production MAP system over a major part of Dartmouth's sprawling wireless network.

The pilot consists of off-the-shelf Aruba RF sniffers, which basically are 802.11a/b/g access points that listen only for radio signals. The MAP software listens to the traffic on all channels, measuring a range of statistics, aggregates that information to create an accurate picture of what's happening in the air, and then scans for evidence of attacks, says David Kotz, a Dartmouth professor of computer science and one of the lead MAP researchers.

Lots of RF sniffers
Instead of trying to minimize the number of sniffers, MAP will do the opposite, deploying lots of them to provide effective coverage of all the access points, authorized clients, and attacking clients. "All three devices are involved in an attack," Kotz says. "An attacker may present itself as an access point and tell an authorized client to disassociate [from a legitimate access point]. You may need more than one sniffer to collect the needed data from all three of these parties, which may be separated by some considerable distance."

"We're trying to get as high a resolution 'snapshot' of the net as we can with lots of sniffers and data aggregation," Kotz says.

MAP is intended to be resilient enough to work successfully in the face of the numerous variables and glitches that exist in WLANs. "Sniffers might not be able to collect all the needed packets because of things like packet collisions, RF reflections, or misaligned antennas," says Tristan Henderson, assistant professor of computer science and a MAP researcher. "So we're building algorithms on the assumption that we won't be able to collect everything."

Higher-level stats, and accuracy
Some commercial IDS systems require that every single frame be checked to see if it matches known attack signatures, Henderson says. By contrast, MAP analyzes higher-level statistics. "We can look at statistics about the proportion of control traffic to data traffic in various type of attacks," he says, revealing a pattern that may signal malicious activity. "We can be more certain about an attack than other techniques that rely on capturing every frame."

MAP will also monitor aggressively all 802.11 channels for activity. "Most other products configure their sniffers to listen to only one channel all the time, or to rotate through all the channels, spending the same amount of time listening to each one," Kotz says. MAP adds intelligence; it cycles through all the channels, but spends more time on the busiest ones. In addition, the MAP sensors can be refocused quickly on a channel with suspicious activity. "The software says 'this client appears to be under attack' and it tells the MAP measurement system to get more information," Kotz says. "The measurement system [software] refocuses and spends more time listening to that client."

MAP is intended to be effective against denial-of-service attacks, as well as against a new category of attacks called "reduction of quality (RoQ)." An RoQ attack doesn't deny service completely. Instead, it degrades the quality of the connection or the available bandwidth, either to disrupt communications for others or to get better service for the attacker. A wireless VoIP call, for example, might stay connected but be so plagued with dropped packets or other problems as to be useless.

"It's hard to detect who's doing it, or even whether it's being done at all," Henderson says. "You need much more sophisticated techniques to detect these attacks."

Countering evasive tactics
A higher level of sophistication also is needed to counter the evasive techniques that attackers are starting to exploit, Aruba's Wright says. For example, an access point legitimately can direct a client to deauthenticate in certain cases, so deauthentication traffic is normal on a WLAN. The problem, Wright says, is that an attacker also can use deauthentication traffic to enable, and mask, a denial-of-service attack. More recently, he says, it's being used to trigger software flaws in WLAN driver code.

As part of developing this greater sophistication, MAP researchers are working to improve the accuracy of attack identification, thereby eliminating false alarms (false positives) as well as false negatives -- real attacks that the IDS doesn't recognize.

If successful, MAP could create the foundation of a dynamic WLAN security system that can monitor continuously for, and adapt to, constantly changing attacks.

Aruba Networks Named Rising Star In Deloitte’s Technology Fast 50 Program for Silicon Valley

Award Acknowledges Fast-Growth and Technological Innovation of Aruba’s Wireless LAN and Secure Mobility Business

Aruba Networks, Inc. a global leader in user-centric networks and secure mobility solutions, today announced that it has been named a “Rising Star” in Deloitte & Touche USA LLP’s Technology Fast 50 program for Silicon Valley. The Rising Star award is a special designation for fast-growth companies that have been in business at least three years, but less than five, and is part of the Silicon Valley Technology Fast 50 program, which ranks the 50 fastest growing technology, media, telecommunications, and life sciences companies headquartered in Silicon Valley. Rankings are based on percentage revenue growth between 2004 and 2006. This year’s Silicon Valley Technology Fast 50 program is co-sponsored by Deloitte & Touche USA LLP and Silicon Valley Bank, Cooley Godward Kronish LLP, Korn/Ferry International, and Woodruff-Sawyer & Co.

“The Deloitte Silicon Valley Technology Fast 50 Rising Star companies have shown the strength, vision and tenacity to succeed despite a very challenging technology environment,” said Mark Jensen, partner and national director, Venture Capital Services, Deloitte & Touche LLP. “We applaud the successes of Aruba Networks and acknowledge its place as one of the few to accomplish such a fast growth rate over the past three years.”

To qualify for the Technology Fast 50 Rising Star program, companies must be incorporated a minimum of three years, have operating revenues of at least $50,000 in 2004 and $5,000,000 in 2006, be headquartered within the San Francisco Bay Area (subsidiaries or divisions are typically not eligible), and either devote a significant proportion of revenues to the research and development of technology or own proprietary intellectual property that contributes to a significant portion of the company's operating revenues. The use of another company’s technology or intellectual property in a unique way does not qualify for consideration.

"We are honored to be recognized by Deloitte for our strong growth, which is driven by our innovative, high performance wireless LAN products and unique user-centric architecture,” said Dominic Orr, president and chief executive officer of Aruba Networks. “Our ability to securely deliver enterprise networks to users wherever they work or roam is both a technological innovation and a clear competitive differentiator in a fast growing market. To capitalize on the demand for our products and services, we continue to invest in our industry-leading wireless LANs and network security technology, strengthen our strategic partnerships, and expand the sales and distribution channels for our products.”

Rising Star companies are automatically entered in Deloitte’s Technology Fast 500 Rising Star category. Deloitte’s Technology Fast 500 program ranks North America’s top 500 fastest growing technology, media, telecommunications, and life sciences companies based on percentage revenue growth from 2002 to 2006. Its Rising Star ranking is based on percentage revenue growth over the period from 2004 to 2006.

March 21, 2007

Wireless Access Point

Aruba provides a comprehensive suite of applications for monitoring, planning, fault management, reporting, RF Coverage and location visualization for mobile edge of enterprise networks.
free counters
RP | CU | PH | RR | TCU | MFB | BM | BM | TAW | RM | SM | MLW | QL | QTS | SR | TR | TCR | HR I2U | PH | TAW | ID | AAB | FSB | AG |