Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Networking
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Top 10 Vulnerabilities in Today's Wi-Fi Networks

 

Sign up to receive Networking and Internet Resource Alerts

July 15, 2002 (Computerworld) -- How can you plug the holes in your wireless network? Here are 10 tips:
1. Hackers are looking for easy targets.
Avoid advertising the presence of your wireless LAN: The easier it is to find, the more likely it will be a target. Be sure to change the Service Set Identifier (SSID) so that it's not the factory default, and turn off SSID broadcasting. If possible, adjust access point (AP) antennas and power levels to avoid signal leakage to areas where coverage is neither required nor desirable.
2. It is easy to "convert" a device so that it looks like another device.
Lost or stolen devices are also a severe threat. Media Access Control addresses are, therefore, a poor method of network authentication. Instead, rely on device-independent authentication, such as user names and passwords, with integration with existing network directories or authentication schemes. Wireless LANs are a natural extension to RSA SecurID token deployments.
3. Wireless data requires data encryption.
Built-in wireless LAN encryption (such as Wired Equivalent Privacy) is weak. Instead, use virtual private network technologies such as IPsec with triple DES to protect data. Avoid proprietary schemes in order to assure maximum interoperability.
4. Limit or control where wireless LAN traffic can go.
If the wireless LAN is to be used for a selected purpose, such as to access an enterprise resource planning system, then place specific packet filters on the wireless LAN to allow only that access.
5. Don't place APs on desks or other places that can be easily accessed.
Unscrupulous visitors or careless employees can easily move, replace or reset the APs. Security can't be assured in such insecure locations. Instead, move management and security to the wiring closet.
6. Actively monitor AP configurations.
It's not sufficient to configure an AP correctly; once configured, the AP must stay properly configured. Consider that it is easy for someone to perform a hardware reset on an AP that sits on a desk or ceiling. By actively monitoring the AP configuration, you can ensure that the AP is automatically reconfigured should such an event occur.
7. Be aware that APs are easily installed by employees and intruders and may easily bypass the enterprise's wireless security policies.
Active sniffing for these rogue devices is a critical operational requirement. New tools to ease this task are readily available.
8. Over a wireless LAN, an intruder can attack the wireless clients themselves in a peer-to-peer fashion.
This attack can give the intruder network access by simply using a legitimate client as an accepted entry point. To address this issue, desktop firewalls should be deployed, along with network management tools that actively audit and manage the client before permitting access via the wireless LAN.
9. Prevent denial-of-service attacks by ensuring adequate bandwidth management on the wireless LAN.
The wireless LAN bandwidth is relatively limited and shared by multiple users. Particularly in environments in which different users need to perform different mission-critical tasks, this bandwidth must be policed to provide fair access.
10. Deploy real-time policy management.
As they are deployed, wireless LANs will span entire campuses and incorporate multiple global sites. Security policies (e.g., valid user lists or access rights) will naturally change. These changes must be reflected in real time throughout the wireless LAN to reduce the window of opportunity for intrusion and, more important, provide immediate lockdown of detected security holes.

Singhal is chief technology officer at ReefEdge Inc. in Fort Lee, N.J.

Special Report

The Security Action Plan
Stories in this report:



Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"Some Asian airlines are reporting rising losses to inflight credit card fraud because there is typically no online credit-card authorization..." Read more...
Read more Security posts or See all Blogs
Obama's choice for DHS could flame tech visa battle
BlackBerry Storm sales should be strong, Verizon says
10 great Bluetooth gadgets
More top stories...
Microsoft to launch IE8 in '09; RC due out in Q1
Review: BlackBerry's Storm is awkward and disappointing
Google shutters its Lively virtual world
If you're like our 7,000 survey respondents, your paycheck this year has been flattened and your bonus obliterated. We offer 12 ways to plump up your paycheck.
Microsoft's next OS might more accurately be called Windows 6.5: It's essentially a better version of Vista.
Twitter can be a valuable business tool -- if you know what you're doing. Here's how to juice it for all it's worth.
By helping Intel with loosened 'Vista Capable' requirements, Microsoft 'severely damaged' its credibility, said an HP exec in a newly unsealed Feb. 2006 e-mail.
Get the latest news, reviews and more about Microsoft's newest desktop operating system
Find wage data for 50 IT job titles.
All Zones
Business Continuity Zone
The File Data Management Zone
Security Management Zone
The SAS Zone
Business Intelligence and Analytics Zone
The Enterprise Search Zone
Software as a Service Zone
The Security Zone

Ads by TechWords

See your link here
Advance your BlackBerry(R) solution management know-how this July
Advance your BlackBerry(R) solution management know-how this July
BlackBerry Technical Seminar, register today!
Go to the webcast 
Cut Data Center Energy Costs
Get this white paper now!
(Source: Liebert) Cooling accounts for 35% of data center energy consumption. Discover strategies that can reduce cooling energy costs by as much as 40%, including simple steps you can take to get more from your existing cooling system and emerging technologies that can increase cooling capacity and data center density.
Download this white paper go
Computerworld Executive Briefing: Automating Network Management
Download this Executive Briefing now (a $195.00 value), compliments of ProCurve Networking by HP.
(Source: Computerworld) This briefing looks at the basics of network management, which tend to get lost in the dizzying array of products and processes. It also examines new tools that are on the way to help IT executives deal with management in the new era of automation.Download this Executive Briefing now (a $195.00 value), compliments of ProCurve Networking by HP.
Download this executive briefing download
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
2008 Internet Malware Trends Report
Security Trends Overview: Targeted Phishing Attack
Enterprise Findability Without the Complexity
View more whitepapers 

Keys to Microsoft application acceleration: advances in delivery systems
Simply designing a data center that only deploys more servers, more storage, and more devices significantly increases network complexity and cost. You can now ensure significantly faster access to the Microsoft applications your users depend on.

Download this whitepaper 
Next Gen Load Balancing: 8 Things You Need to Handle Today's Network Traffic
Learn how you can replace your aging load balancer with a true web application delivery appliance that provides 100% availability through full Layer 7 awareness and intelligent traffic management and delivers web apps with the highest performance and security possible.

Download this white paper 
Constellation Brands Case Study
Learn why a $6.5 billion international producer and marketer of alcoholic beverages chose Citrix NetScaler to increase Web app performance and ensure high availability of global intranet and public Web sites.

Download this case study 
Welch's Case Study
Learn why a large US food processor chose Citrix NetScaler to securely deliver a new Oracle ERP solution to external partners and remote users. You'll learn how Welch's was able to add 250 new users without expanding their IT staff or taxing the availability of their network resources.

Download this case study