Slashdot Mirror


Ethernet Wiring Through Hostile Territory?

GoogleDidntFindIt asks: "I need to connect a terminal to a server which contains very sensitive information. Unfortunately, the terminal is about 200 feet away from the server. The server (which even includes a 'self destruct' device) and terminal are both in highly secure areas of the building, but the wiring will be in uncontrolled areas. What should I do to keep people from tapping or monitoring the wire?" Is there any way a conduit can be wired with an alarm which goes off when it's integrity has been violated?

"Heres a basic description of my situation:

  • A new wire/fiber/cable/whatever will be run and I can use any sort of conduit I want.
  • A potential attacker may have several days of undetected access to parts of the wire/conduit and may have sophisticated fiber-optic tapping equipment (which can tap a fiber without cutting it).
  • I can physically inspect the conduit/cable/wire once a month.
  • Ideally, the system would also notify me of a majority of successful attacks (or, even better, disconnect the line).
I'm aware of IPSEC and other encryption systems, but they aren't suitable for this project - I'm looking for systems which address physical security and protect against traffic analysis."

2 of 65 comments (clear)

  1. How do we know that he's the good guy here? by unitron · · Score: 4, Interesting

    What if he's the one trying to break in to an already existing setup and is just looking for ideas on what kinds of defenses he might encounter?

    --

    I see even classic Slashdot is now pretty much unusable on dial up anymore.

  2. duh. easy. by Zurk · · Score: 4, Interesting

    ignore all the comments about high pressure and other crap. pressure systems need to be maintained continously and are prone to failure.
    Try this :
    put a bunch of fibre optic strands into a steel pipe (large). make sure the fibre is all loose strands of single mode fibre (glass) and not encased in a protective coating. then fill the pipe completely with concrete and let it dry. attach the fibre to the terminal and the server and run something to monitor the connection 24/7. if the bad guys blowtorch thru the steel pipe they need to use a hammer to get thru the concrete. cracking the concrete cracks the fibre along with it destroying your connection (even if it is temporary and they rig something up to restore the connection your software monitoring the connection can sound the alarm). since single mode fibre is essentially very thin glass strands you will loose a few strands while pouring the concrete but at least one will work. you can use the one that works.
    its messy but reliable. epoxy and other nasty stuff in layers with the concrete is also useful.