Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


July 2003

Tips for Wireless Security

Protect your WLAN from 802.11b's deficiencies
RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Wireless is the hottest new LAN technology going, and with good reason. The ability to roam the workplace while remaining connected to the network and even the Internet can aid productivity. However, wireless LANs (WLANs) have shortcomings, the biggest of which is security. Many organizations allow wireless networks to be implemented at the department level with no security whatsoever. If someone bridges these WLANs into the corporate network, the result can be a Grand Canyon–sized hole in your network's security. To make your 802.11b networks more secure until the next generation of 802.1x wireless devices arrive, implement these 10 tips.

10. Secure your Access Points (APs)—Network security starts with physical security: You can't place your wireless AP on a countertop and expect it to be secure. Treat your APs like hubs—restrict physical access by keeping them locked up and out of sight. In some cases, the ceiling can be a good location for devices that have drop-down antennas. Also, to reduce the possibility that a war driver will intercept your signal, try to put your APs close to the building's core.

9. Implement wireless APs outside the perimeter firewall—Putting your APs outside your firewall gives your network an extra layer of defense by treating all wireless users as untrusted users. If you must deploy your WLAN within the firewall, consider using a demilitarized zone (DMZ), screened subnet, or Virtual LAN (VLAN) to isolate your WLAN traffic.

8. Change the default Service Set Identifier (SSID)—The SSID is essentially a mechanism for naming wireless devices. It's not a strong security measure, but discovering your WLAN's SSID is an intruder's first step toward breaking into your network. To make that step a little more difficult, change the default SSID value and choose an SSID name that isn't easy to guess.

7. Disable the automatic SSID broadcast feature—By default, many APs broadcast the SSID to make connecting easy for wireless devices. However, broadcasting the SSID lets intruders more easily discover your SSID. Most APs support disabling SSID broadcasts, although a firmware update might be necessary for older devices.

6. Use media access control (MAC) address restrictions—Like standard NICs, each wireless card has a unique MAC address. Configuring your AP to allow only devices that have registered MAC addresses to access the network will go a long way toward securing your WLAN.

5. Enable the Wired Equivalent Privacy (WEP) standard—A shocking number of organizations implement wireless networks without security. Although WEP has known flaws that a determined attacker can exploit, it will prevent casual unauthorized users from accessing your WLAN.

4. Change the WEP key from its default value—One common mistake that many organizations make when implementing WEP is using the default vendor-supplied key. WEP security relies on a secret key, and the default WEP keys are well known. Change the WEP key to ensure that it's unique to your implementation.

3. Change the WEP key regularly—Some high-end 802.11 devices can automatically manage the WEP keys used throughout the WLAN, but most devices require manual updating. To reduce key-related vulnerability, set up and adhere to a schedule to regularly update the WEP keys that your organization uses.

2. Regularly sniff out rogue networks—Use a tool such as AirMagnet Laptop or Marius Milner's NetStumbler to monitor your premises for rogue networks. Well-meaning but unsecured departments can set up WLANs and inadvertently undermine your network security.

1. Use VPNs for better security—Although WEP is better than no security at all, several well-known exploits can crack WEP. To get the best possible security with the current crop of 802.11 devices, implement a VPN connection from your wireless devices to your network. A VPN lets you create an encrypted tunnel for your wireless traffic that's highly resistant to intrusion. For instructions about how to set up a wireless VPN, see "Securing 802.11 Wireless Networks," June 2002, http://www.winnetmag.com, InstantDoc ID 24873.

End of Article



Reader Comments
In Top 10: "Tips for Wireless Security" (July 2003, http://www.winnetmag.com, InstantDoc ID 39201), Michael Otey lists the top 10 ways to protect your wireless LAN (WLAN). Number 7 is to disable the Service Set Identifier (SSID) broadcast. Although this tactic might seem to be an obvious measure, I would argue that you're only making connecting to the wireless network more difficult for your users. A determined intruder will find your network and get in without seeing the SSID when browsing; plus, if you follow the nine other steps, knowing the SSID won't help the hacker get in anyway.<P>


Thanks for your comments. Although none of the measures presented in my column will prevent a determined and skilled intruder from gaining access to your WLAN, the idea behind each of them is to make unauthorized access as difficult as possible. Concealing your SSID is just one more step to accomplish this. As you note, this approach does make connecting to the WLAN somewhat more difficult for your authorized users, but you can add the appropriate connection information to your setup instructions for users who configure their own systems.<br>

—Michael Otey

Steven J. Briggs January 15, 2004


I would like to thank the person who put this information up. I am currently working on a project in class concerning wireless networks and taking a more stealthy approach as opposed to a large brick wall seems the best course of action when coming to wireless network security. I like this idea and I will research it in depth if possible.

Anonymous User February 02, 2005 (Article Rating: )


An interesting layer of physical security is the wifi-blocking paint available from http://forcefieldwireless.com/. Also, directional antennas placed at the corners of the building facing inward is another approach to keeping the signal inside the building.

And nothing beats good old encryption. GPG/PGP for mail, SSL for other things- https, ssh, etc. For an intranet, a self-signed (read: free) SSL key can be used to encrypt traffic.

I know this is a Windows site, but a server running Linux with a wireless card and a copy of Kismet (http://www.kismetwireless.net/) can detect intrusion attempts. NetStumbler basically screams that it's scanning; Kismet will detect these probes, as well as other nasty attacks like broadcast disconnect packets (which will make every machine on the network drop connection and reauthenticate- possibly to a spoofed AP being run by an attacker.

If your hardware supports it, WPA is much better than WEP. And running an 802.11a network (rather than B or G) can make things just a little harder for attackers since it is on a different band and 802.11a or dual-band hardware is more expensive. It also is in use by far fewer people and has non-overlapping channels, so the band is much less crowded than 802.11b/g, not to mention not sharing a band with cellphones, cordless phones, and microwaves :)

Anonymous User March 22, 2005 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Accessing Database Data with ADO

...

Two Exchange Server Tools You Should Know About

These free tools can help you troubleshoot performance problems with Exchange 2007 and Exchange 2003, and help you figure out what's going on with your servers from the transactions logs. ...

The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...


Security Whitepapers Anti-Virus Is Dead: The Advent of the Graylist Approach to Computer Protection

Getting the Job Done: Comparing Approaches for Desktop Software Lockdown

Instant Messaging, VoIP, P2P, and games in the workplace: How to take back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Maximize your SharePoint Investment – 8 Cities
Discover best practices and tips for both architecting and administering SharePoint. Early Bird Price of $99 through Sept 15th.

Find a new job now on the all new IT Job Hound!
Search jobs, post your resume, and set up job e-mail alerts!

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Top Tools for Virtualization Disaster Recovery & Replication
View this web seminar on August 14th to learn about two tools that will result in faster backup and restore with P2V disaster recovery.

SharePointConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

VMworld 2008 - Sign Up Today!
Join your peers on September 15-18 at The Venetian Hotel in Las Vegas as VMware hosts VMworld 2008, the leading Virtualization event.



Increase Application Performance
Free White Paper by Editor's Best winner, Texas Memory Systems.

Microsoft® Tech•Ed EMEA 2008 IT Professionals
Advance your thinking with new ideas and practical real-world solutions at Microsoft’s FIVE day technical infrastructure conference 3-7 Nov., 2008. Register before 26 September 2008 to save €300.

Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Are You Really Compliant with Software Regulations?
View this web seminar that will help you with compliance best practices and check out a management solution to assure that you won’t be in jeopardy of an audit.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing