Cisco releases WLAN security protocol
It's designed to defeat password dictionary attacks
April 13, 2004 12:00 PM ETComputerworld -
Cisco Systems Inc. announced the availability of a protocol that's designed to defeat brute-force dictionary attacks that capture users' passwords in its wireless LAN products. The company urged end users and systems administrators to download the related patch from its Web site.
Joshua Wright, a systems engineer and deputy director of training at the SANS Institute in Bethesda, Md., developed an automated dictionary-attack tool last year that could be used against Cisco's Lightweight Extensible Authentication Protocol, known as LEAP (see story) while working at Johnson & Wales University in Providence, R.I. Wright released the attack tool last week, according to Cisco. A dictionary attack is a method in which an attacker runs millions of passwords against a database until a match is eventually found.
Chris Bolinger, manager of wireless LAN product marketing at Cisco, said the company's new protocol defeats dictionary attacks by sending credentials through an encrypted tunnel. The patch is relatively easy to install, Bolinger said, and it updates wireless LAN client software on a notebook or laptop computer.
Cisco announced the availability of the protocol, called the Extensible Authentication Protocol-Flexible Authentication via Secure Tunneling (EAP-FAST), and made it available to the Internet Engineering Task Force in February (see story).
Bolinger said he expects other wireless LAN vendors to incorporate EAP-FAST into their security offerings.
Wright said that while he believes EAP-FAST is a better authentication solution than Cisco's proprietary LEAP, "I am not yet convinced it is completely secure." He recommended that users migrate to the Protected Extensible Authentication Protocol, which is also available from Cisco, instead of experimenting with EAP-FAST, since PEAP is a more established protocol.
Wright said the source code and a Windows executable for his dictionary attack tool are available at http://asleap.sourceforge.net.
Mobile/Wireless
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Southern Company
Download Now
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Defending Against the Storm
Download Now
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Ponemon Study: The Business Risk of a Lost Laptop
Download Now
Managing Laptops Outside the Office
Learn how you can reduce costs by tracking mobile computers no matter where they are located.
Airport Insecurity: The Case of Lost Laptops
Download Now
4G Ahead Video Program
Uncover the features and benefits of the two leading 4G technologies for enterprises considering future deployment.
Case Study: Roughing IT
Download Now
Complimentary Webcast: Taking a Strategic Approach to Enterprise Mobility
Download This Webcast Today!
