<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>End node problem</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/End_node_problem"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-End_node_problem rootpage-End_node_problem skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">End node problem</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr"><style data-mw-deduplicate="TemplateStyles:r1236090951">
/* start https://en.wikipedia.org/ */
.mw-parser-output .hatnote{font-style:italic}.mw-parser-output div.hatnote{padding-left:1.6em;margin-bottom:0.5em}.mw-parser-output .hatnote i{font-style:normal}.mw-parser-output .hatnote+link+.hatnote{margin-top:-0.5em}@media print{body.ns-0 .mw-parser-output .hatnote{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><div role="note" class="hatnote navigation-not-searchable">For other uses, see <a href="Node_(disambiguation)" class="mw-redirect mw-disambig" title="Node (disambiguation)">Node</a>.</div>
<p>The <b>end node problem</b> arises when individual computers are used for sensitive work and/or temporarily become part of a trusted, well-managed network/cloud and then are used for more risky activities and/or join untrusted networks. (Individual computers on the periphery of networks/clouds are called end nodes.) End nodes often are not managed to the trusted network‘s high <a href="Computer_security" title="Computer security">computer security</a> standards.<sup id="cite_ref-Tim_Fisher_1-0" class="reference"><a href="#cite_note-Tim_Fisher-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> End nodes often have weak/outdated software, weak security tools, excessive permissions, mis-configurations, questionable content and apps, and covert exploitations.<sup id="cite_ref-Natalia_Chrzanowska_2-0" class="reference"><a href="#cite_note-Natalia_Chrzanowska-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> Cross contamination and unauthorized release of data from within a computer system becomes the problem.
</p><p>Within the vast cyber-ecosystem, these end nodes often attach transiently to one or more clouds/networks, some trustworthy and others not. A few examples: a corporate desktop browsing the Internet, a corporate laptop checking company webmail via a coffee shop's open <a href="Wi-Fi" title="Wi-Fi">Wi-Fi</a> access point, a personal computer used to telecommute during the day and gaming at night, or app within a smartphone/tablet (or any of the previous use/device combinations). Even if fully updated and tightly locked down, these nodes may ferry malware from one network (e.g. a corrupted webpage or an infected email message) into another, sensitive network. Likewise, the end nodes may exfiltrate sensitive data (e.g. <a href="Keystroke_logging" title="Keystroke logging">log keystrokes</a> or <a href="Screenshot" title="Screenshot">screen-capture</a>). Assuming the device is fully trustworthy, the end node must provide the means to properly <a href="Authenticate" class="mw-redirect" title="Authenticate">authenticate</a> the user. Other nodes may impersonate trusted computers, thus requiring <a href="Trusted_Platform_Module" title="Trusted Platform Module">device authentication</a>. The device and user may be trusted but within an untrustworthy environment (as determined by inboard sensors' feedback). Collectively, these risks are called the end node problem. There are several remedies but all require instilling trust in the end node and conveying that trust to the network/cloud.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="The_cloud’s_weakest_link">The cloud’s weakest link</h2></div>
<p><a href="Cloud_computing" title="Cloud computing">Cloud computing</a> may be characterized as a vast, seemingly endless, array of processing and storage that one can rent from his or her computer. Recent media attention has focused on the security within the cloud.<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> Many believe the real risk does not lie within a well monitored, 24-7-365 managed, full redundancy cloud host but in the many questionable computers that access the cloud.<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> Many such clouds are <a href="FISMA" class="mw-redirect" title="FISMA">FISMA</a>-certified whereas the end nodes connecting to them rarely are configured to any standard.
</p>
<div class="mw-heading mw-heading2"><h2 id="Ever_growing_risk">Ever growing risk</h2></div>
<p>From 2005 to 2009, the greatest and growing threats to personal and corporate data derived from exploits of users' personal computers. Organized cyber-criminals have found it more profitable to internally exploit the many weak personal and work computers than to attack through heavily fortified perimeters.<sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> One common example is stealing small business's online banking account access.<sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Solutions">Solutions</h2></div>
<p>To eliminate the end node problem, only allow authenticated users on trusted remote computers in safe environments to connect to your network/cloud. There are many ways to accomplish this with existing technology, each with different levels of trust.
</p><p>Many companies issue typical laptops and only allow those specific computers to remotely connect. For example, the US Department of Defense only allows its remote computers to connect via <a href="VPN" class="mw-redirect" title="VPN">VPN</a> to its network (no direct Internet browsing) and uses <a href="Two-factor_authentication" class="mw-redirect" title="Two-factor authentication">two-factor authentication</a>.<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> Some organizations use server-side tools to scan and/or validate the end node's computer, such as communicating with the node's <a href="Trusted_Platform_Module" title="Trusted Platform Module">Trusted Platform Module</a> (TPM).
</p><p>A far higher level of trust can be obtained by issuing an <a rel="nofollow" class="external text" href="http://spi.dod.mil/docs/SEN_SKG_DS_20081024.doc">immutable, tamper-resistant client</a> with no local storage, allowing it to connect only after device and user authentication, remotely providing the OS and software (via <a href="Preboot_Execution_Environment" title="Preboot Execution Environment">PXE</a> or <a href="Etherboot" class="mw-redirect" title="Etherboot">Etherboot</a>), and then only providing remote desktop or browser access to sensitive data.
</p><p>A less expensive approach is to trust any hardware (corporate, government, personal, or public) but provide a known <a href="Kernel_(operating_system)" title="Kernel (operating system)">kernel</a> and software and require strong authentication of the user. For example, the <a href="United_States_Department_of_Defense" title="United States Department of Defense">DoD</a>’s Software Protection Initiative<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> offers <a href="Lightweight_Portable_Security" title="Lightweight Portable Security">Lightweight Portable Security</a>, a <a href="LiveCD" class="mw-redirect" title="LiveCD">LiveCD</a> that boots only in RAM creating a pristine, non-persistent, end node while using <a href="Common_Access_Card" title="Common Access Card">Common Access Card</a> software for authentication into DoD networks.
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="Host_(network)" title="Host (network)">Host (network)</a></li>
<li><a href="Node_(networking)" title="Node (networking)">Node (networking)</a></li>
<li><a href="Secure_end_node" title="Secure end node">Secure end node</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap"><ol class="references">
<li id="cite_note-Tim_Fisher-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-Tim_Fisher_1-0">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><cite id="CITEREFTim_Fisher2018" class="citation web cs1">Tim Fisher (12 December 2018). <a rel="nofollow" class="external text" href="https://www.lifewire.com/what-is-a-node-4155598">"What Is a Node in a Computer Network: Your computer and printer are both network nodes"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">24 December</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-Natalia_Chrzanowska-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-Natalia_Chrzanowska_2-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFNatalia_Chrzanowska2017" class="citation web cs1">Natalia Chrzanowska (23 March 2017). <a rel="nofollow" class="external text" href="https://www.netguru.co/blog/pros-cons-use-node.js-backend">"Why to Use Node.js: Pros and Cons of Choosing Node.js for Back-end Development"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">24 December</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.technologyreview.com/computing/23951/">"How Secure Is Cloud Computing?"</a>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20210813140541/http://www.nets-find.net/Meetings/S09Meeting/Talks/clark.ppt">"Architecture from the top down"</a>. Archived from <a rel="nofollow" class="external text" href="http://www.nets-find.net/Meetings/S09Meeting/Talks/clark.ppt">the original</a> on 2021-08-13<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-01-07</span></span>.</cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20090511131913/http://www.builderau.com.au/strategy/businessmanagement/soa/VPN-users-The-weak-link-in-network-security-/0,339028271,320266862,00.htm">"VPN users: The weak link in network security?"</a>. Archived from <a rel="nofollow" class="external text" href="http://www.builderau.com.au/strategy/businessmanagement/soa/VPN-users-The-weak-link-in-network-security-/0,339028271,320266862,00.htm">the original</a> on 2009-05-11<span class="reference-accessdate">. Retrieved <span class="nowrap">2010-02-06</span></span>.</cite></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-6">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.verizonbusiness.com/resources/security/databreachreport.pdf">"Business Insights and Resources"</a> <span class="cs1-format">(PDF)</span>.</cite></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-7">^</a></b></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="http://content.usatoday.com/communities/technologylive/post/2010/03/cyberthieves-stealing--from-large-percentage-of-small-businesses/1">"Cyberthieves stealing from large percentage of small businesses"</a>. <i>USA Today</i>. 9 March 2010.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://sill-www.army.mil/dhr/Admin_Svcs_Div/FS_Pubs/Regs/25-71.htm">"Fort Sill Virtual Private Network (VPN) Policy"</a>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20110617013457/http://sill-www.army.mil/dhr/Admin_Svcs_Div/FS_Pubs/Regs/25-71.htm">Archived</a> from the original on 2011-06-17<span class="reference-accessdate">. Retrieved <span class="nowrap">2010-02-06</span></span>.</cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="http://spi.dod.mil">DoD Software Protection Initiative</a> <a rel="nofollow" class="external text" href="https://web.archive.org/web/20100513172649/http://spi.dod.mil/">Archived</a> 2010-05-13 at the <a href="Wayback_Machine" title="Wayback Machine">Wayback Machine</a></span>
</li>
</ol></div></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-04-14" href="https://en.wikipedia.org/wiki/?title=End_node_problem&oldid=1285524632">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>