IT managers ready defenses against flaw in wireless LANs
Users could face DoS attacks, but the risks are seen as low
Computerworld - Information technology managers last week said a denial-of-service vulnerability that affects some Wi-Fi wireless LANs could force companies to develop new skills and rethink the way their networks are set up. But, they added, it should be relatively easy to defend WLANs against attacks seeking to exploit the flaw.
For example, an attacker would need to be within the typical 200- to 300-ft. range of a WLAN to shut down data transmissions, according to security researchers and wireless vendors. Corporate WLANs that are well shielded within buildings or fenced-off areas should be safe from attacks, they said.
Companies that operate multiple access points on their WLANs could also switch network traffic to other access points if one or more were attacked, although doing so would require radio frequency management skills and tools.
Defensive Measures
The denial-of-service risks were outlined on May 13 by the Australian Computer Emergency Response Team and amplified by its U.S. counterpart (see story). The problem affects WLANs based on the 802.11b protocol, as well as the original 802.11 protocol and low-speed 802.11g wireless devices operating at rates below 20Mbit/sec., the two groups said.
They added that networks built around 802.11a or high-speed 802.11g technology aren't affected by the vulnerability, which involves an access-control function used by WLANs that support the Direct Sequence Spread Spectrum (DSSS) modulation scheme. No technology fix is available, so users must take other steps to protect their networks from attacks.
Mike Taylor, CIO at Todd Shipyards Corp. in Seattle, said he thinks geography serves as his best defense. Todd Shipyards runs its WLAN over 40 access points spread across its 44-acre shipyard, Taylor said. That means attackers would have to surround the shipyard and then try to take out every one of its widely scattered access points to stop traffic, he added.
Geography also works in FedEx Corp.'s favor, said Ken Pasley, director of wireless business development at the Memphis-based company.
FedEx runs extensive WLANs at its package-delivery hubs to connect wireless bar-code scanners used in package sorting. But the hubs are located within the fenced periphery of airports, which should make it difficult for an attacker to get within range, Pasley said.
FedEx also uses radio frequency scanning tools in an effort to detect potential attacks and protect its wireless networks, Pasley said.
The flaw was discovered by a team of graduate students at Queensland University of Technology in Brisbane, Australia. Mark Looi, a professor there, suggested that one defense against attacks would be to replace all 802.11b access points with802.11a technology, which uses a different form of modulation than DSSS.
But a spokeswoman for United Parcel Service Inc., which operates one of the largest 802.11b networks in the world, said the Atlanta-based company views a move to 802.11a as unacceptable because of the money it has invested in its existing WLAN deployment. She added that UPS is waiting for input from its WLAN vendor, Symbol Technologies Inc., on safeguarding its network.
Read more about Mobile and Wireless in Computerworld's Mobile and Wireless Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Digital Transformation: Creating New Business Models Where Digital Meets Physical
- Individuals and businesses alike are embracing the digital revolution. Social networks and digital devices are being used to engage government, businesses and civil...
- Empowering Your Mobile Worker
- Today's most productive employees are mobile, and your company's IT strategy must be ready to support them with 24/7 access to the business...
- An Interactive Guide: Bring Your Own Device
- BYOD presents significant security and management challenges to IT departments who want to take advantage of the trend, but still protect corporate assets....
- Calculating ROI for Mobile Client Acceleration
- As mobile devices continue to expand in business use, ensuring these devices have optimal performance is becoming an IT imperative. This EMA paper...
- Tablet Computing Without Compromise
- This paper provides an overview of how and why that migration-from any old tablet to Windows tablets-came to be. All Mobile and Wireless White Papers
- Live Webcast
North Pole to South Seas: Overcoming the Pitfalls of remote Performance - In today's always-on world, connectivity is a business requirement. You need the tools that allow you to operate as if you were on...
- Supporting Mobile Productivity With A Limited IT Budget
- Join us and hear from Kaseya mobile IT management experts as we discuss core strategies for supporting the mobile revolution on a shoestring...
- North Pole to South Seas: Overcoming the Pitfalls of remote Performance
- In today's always-on world, connectivity is a business requirement. You need the tools that allow you to operate as if you were on...
- Unified Communications 101
- What's the best way to implement a unified communications solution for your organization?
- QNX® and BlackBerry® PlayBook™ Tablet.
- RIM's multi-processor, multi-tasking BlackBerry PlayBook runs a new Tablet OS powered by QNX, a bullet-proof microkernel operating system. This track will take a...
- A Close Look at Tablets
- Learn More All Mobile and Wireless Webcasts