This article explains topics connecting to wireless networks. The main topics discussed include, what type of vulnerabilities exist today in 802. 11 networks and ways that you can help avoid these vulnerabilities from happening. Wireless networks have not been about for many years. National Definite has been using a type of wireless networks, conventional to the 802. 11 networks used today, but the broad-spectrum communal has in recent times just in progress to use wireless networking technology. As of weak guarantee that exists in wireless networks, companies such as Best Buy have certain to postpone the roll-out of wireless technology. The United States Authority has done similarly and is suspending the use of wireless until a more universal, confident blend is available.


What is Wireless?

Wireless LANs or Wi-Fi is a know-how used to attach computers and diplomacy together. Wireless LANs give people more mobility and flexibility by allowing employees to stay coupled to the Internet and to the complex as they roam from one coverage area to another. This increases efficiency by allowing data to be entered and accessed on site.

Besides being very down-to-earth to install, WLANs are easy to appreciate and use. With few exceptions, all to do with wired LANs applies to wireless LANs. They do like, and are frequently attached to, wired Ethernet networks.

The Wireless Ethernet Compatibility Alliance [WECA] is the commerce business that certifies 802. 11 food that are deemed to meet a base average of interoperability. The first ancestors of crop to be practiced by WECA is that based on the 802. 11b standard. This set of foodstuffs is what we will be studying. Also more principles exist such as 802. 11a and 802. 11g.

The fundamental 802. 11 banner was available in 1999 and provides for data rates at up to 2 Mbps at 2. 4 GHz, using both FHSS or DSSS. Since that time many task groups have been bent to conceive supplements and enhancements to the creative 802. 11 standard.

The 802. 11b TG fashioned a supplement to the creative 802. 11 standard, called 802. 11b, which has develop into the activity accepted for WLANs. It uses DSSS and provides data rates up to 11 Mbps at 2. 4 Ghz. 802. 11b will in the long run be replaced by values which have beat QoS features, and develop security.

Network Topology

There are two main topologies in wireless networks which can be configured:

Peer-to-peer (ad hoc mode) - This configuration is alike to its wired counterpart, bar devoid of the wires. Two or more campaign can talk to each other exclusive of an AP.

Client/Server (infrastructure networking) - This configuration is duplicate to its wired counterpart, bar lacking the wires. This is the most conventional wireless exchange ideas used today, and what most of the concepts in this paper apply to.

Benefits of Wireless LANs

  • WLANs can be used to exchange wired LANs, or as an additional room of a wired infrastructure. It costs far less to position a wireless LAN than to position a wired one. A major cost of installing and modifying a wired association is the cost to run association and power cables, all in accordance with local edifice codes. Illustration of added applications where the certitude to install WLANs include:

  • Additions or moves of computers.

  • Installation of impermanent networks

  • Installation of hard-to-wire locations

Wireless LANs give you more mobility and flexibility by allowing you to stay attached to the Internet and to the association as you roam.

Cons of Wireless LANs

Wireless LANs are a comparatively new expertise which has only been about since 1999. With any new technology, principles are all the time improving, but in the activation are unreliable and insecure. Wired networks send travel over a enthusiastic line that is physically private; WLANs send their passage over common space, airwaves. This introduces interference from other passage and the need for further security. As well interference from other wireless LAN devices, the 2. 4 GHz is also used by freestyle phones and microwaves.

Security Issues of WLANs

  • War-driving

    War-driving is a course in which an character uses a wireless apparatus such as a notebook or PDA to drive about looking for wireless networks. Some ancestors do this as a hobby and map out altered wireless networks which they find. Other people, who can be measured hackers, will look for wireless networks and then break into the networks. If a wireless is not secure, it can be equitably easy to break into the arrangement and achieve confidential information. Even with security, hackers can break the defense and hack. One of the most prevalent tools used on PDAs and Microsoft windows campaign is, Complex Stumbler, which can be downloaded at http://www. netstumbler. com. Equipped with the software and device, a being can map out wireless admittance points if a GPS unit is attached. Accumulation an mast to the wireless card increases the capabilities of Wi-Fi. More in a row can be found at: http://www. wardriving. info and http://www. wardriving. com to name a few.

  • War-chalking

    War-chalking is a approach of marking wireless networks by using chalk most commonly. War-driving is customarily the fashion used to hunt for networks, and then the anyone will mark the exchange ideas with chalk that gives in sequence about the network. Some of the in sequence would include, what the exchange ideas name is, whether the arrangement has security, and probably the acquaintance in order of who owns the network. If your wireless exchange ideas is War-chalked and you don't accomplish it, your association can be used and/or broken down into faster, for the reason that of in sequence shown about your network.

Eavesdropping & Espionage

Because wireless contact is announcement over radio waves, eavesdroppers who just snoop over the airwaves can certainly pick up unencrypted messages. These intruders put businesses at risk of exposing delicate in a row to corporate espionage. Wireless LAN Collateral - What Hackers Know That You Don't www. airdefense. net Copyright 2002

Internal Vulnerabilities

Within an company arrangement collateral can be compromised by ways such as, Rouge WLANs (or Rouge Aps), Insecure Arrangement Configuration, and Chance Associations to name a few.

Rouge Admission Points - An member of staff of an association might hook up an admission point exclusive of the authorization or even comprehension of IT. This is austere to do, all a character has to do is plug an Contact point or wireless router into an free live LAN jack and they are on the network. One guide in 2001 by Gartner said that, "at least 20 percent of enterprises previously have rouge admittance points. " A further type of argue with would be if, a big cheese from beyond the organization, enters into the agency and adds an Contact Point by means of Common Engineering.

Insecure Complex Configurations- Many companies think that if they are using a firewall or a knowledge such as VPN, they are by design secure. This is not of necessity true since all defense holes, big and small, can be exploited. Also if campaign and technologies, such as VPNs, firewalls or routers, are mis-configured, the arrangement can be compromised.

Accidental Associations - This can ensue if a wireless arrangement is setup using the same SSID as your association and contained by range of your wireless device. You may by accident ally with their association not including your knowledge. Concerning to a further wireless LAN can give away passwords or easily upset authenticate to any person on the adjacent network. Wireless LAN Defense - What Hackers Know That You Don't www. airdefense. net Copyright 2002

Social Commerce - Community Commerce is one of the most effectual and scariest types of attacks that can be done. This type of argue with exceedingly scares me and can be done for many other purposes above and beyond compromising collateral in wireless networks. A scenario: A celebrity dressed up as a aid being from Cisco enters the workplace. The escritoire sees his fake id and lets him get pass the front desk. The imitator walks from stall to cubicle, collecting user names and passwords as he/she goes. After decision a covert corner, which seems to be lightly traveled, he plugs an insecure Contact Point into the network. At the same time he configures the Admittance Point to not announce its SSID and modifies a few other settings to make it hard for the IT administrative area to find this Rouge Contact Point. He then trees devoid of ever being questioned by a person as it looks like he just fits in. Now, all he has to do is be contained by 300 feet from the approach point, (more if he added an antenna), and now has admittance to all kinds of assure credentials and data. This can be a devastating blow to any corporation and could in the long run lead to insolvency if the secrets of the ballet company were discovered to competitors.

Bruce Schneier came to my classroom and said the subsequent about Collective Engineering, "Someone is just annoying to do their job, and be nice. A big shot takes gain of that by targeting this human nature. Collective Manufacturing is unsolvable. "

Securing Wireless Networks

According to Bruce Schneier and others such as Kevin Mitnick, you can never have a completely assured computing environment. What is often recommended is to try and charge the break which can be done if confidence is breached. One can try many altered tools on the bazaar which can help foil defense breaches.

WEP - WEP ropes both 64 and 128-bit keys. Both are vulnerable, however, for the reason that the initialization vector is only 24-bits long in each case. Its RC4 algorithm, which is used strongly in other implementations, such as SSL, is quite vulnerable in WEP. Http://www. infosecuritymag. com/2002/jan/cover. shtml Wireless Insecurities By Dale Gardner. Atypical tools exist to break WEP keys, together with AirSnort, which can be found at www. airsnort. net. Even though this fashion is not a acquire solution, it can be used to help brake an foe if other means are not likely financially or otherwise.

VPN and IPSec- IPSec VPNs let companies bond cool offices or wireless acquaintances using the communal Internet fairly than classy leased lines or a managed data service. Encryption and endorsement systems guard the data as it crosses the community network, so companies don't have to sacrifice data privacy and integrity for lower costs. A lot of VPN's exist on the marketplace today. An central note about VPNs is, interoperability does not certainly exist, and anything you use for your ma?tre d' has to be the same brand as your clients most of the time. Some VPNs include:

  • Borderware

  • BroadConnex Networks

  • CheckPoint

  • Cisco

  • Computer Associates

DMZ - Accumulation this to your arrangement enables you to put your wireless arrangement on an untrusted segment of your network.

Firewalls - Firewalls are all over the place. Firewalls range from hardware to software versions. By adding up a firewall concerning the wireless association and wired complex helps avert hackers from accessing your wired network. This paper doesn't go into essentials about another firewalls and how to set them up, but there are many. Some of the firewalls include:

  • ZoneAlarm (an easy on the pocket based software firewall) Zonelabs. com

  • Symantec has many altered firewalls depending what you require.

PKI - Public-key infrastructure (PKI) is the arrangement of software, encryption technologies, and military that enables enterprises to defend the confidence of their connections and big business transactions on the Internet. What is PKI? http://verisign. netscape. com/security/pki/understanding. html

Site Surveys - Site Surveys be relevant to using a software box up and a wireless contraption to probe your exchange ideas for Approach Points and defense risks.

Proactive Approaches

Since wireless expertise is insecure, companies or a person can take a practical advance to try and ascertain hackers frustrating to gain approach via wireless networks.

Honeypots - are fake networks setup to try and lure in hackers. This enables administrators to find out more about what type of techniques hackers are using to gain access. One effect is Mantrap bent by Symantec.

"ManTrap has the inimitable capability to discover both host- and network-based attacks, on condition that amalgam detection in a lone solution. No be relevant how an home or outdoor enemy tries to bargain the system, Symantec ManTrap's decoy sensors will consign holistic detection and answer and endow with exhaustive in rank because of its classification of data album modules. "

http://enterprisesecurity. symantec. com/products/products. cfm?ProductID=157

Intrusion Detection - Infringement Detection is software that monitors travel on the network. It sounds out a advice if a hacker it difficult to contact the network. One such free artifact is Snort.

"Before we proceed, there are a few basic concepts you must absorb about Snort. There are three main modes in which Snort can be configured: sniffer, envelope logger, and exchange ideas disturbance detection system. Sniffer mode easily reads the packets off of the arrangement and displays them for you in a permanent course on the console. Container logger mode logs the packets to the disk. Complex disturbance detection mode is the most composite and configurable configuration, allowing Snort to dissect complex passage for matches adjacent to a user distinct rule set and achieve quite a few dealings based upon what it sees. " http://www. snort. org/docs/writing_rules/chap1. html#tth_chAp1

Network Monitoring- Exchange ideas Monitoring would be foodstuffs such as snort that check the flow of travel over the network.

Quick tips and tricks

  • When backdrop up wireless networks and admission points there are a few quick steps that can be taken to directly acquire the network, even although it does not make it secure. Some of these ways include:

  • Change your evade SSID: each router or admittance point comes with a evade SSID. By altering this it can take longer for an assailant to know what type of badge he is annoying to hack.

  • Change the evade password - generic evasion passwords are assigned to admission points and routers. Every now and then the password is admin. By varying this password, the enemy cannot adapt settings on your router as easily.

  • Disable giving out SSID: By defaulting AP's announcement their SSIDs, if you shutoff this background it is harder for outsiders to find your AP.

  • Enable MAC filtering: WARNING: this can only work in less significant environments where a central contact list does not need to be maintained. You can permit only certain wireless cards to contact the AP by only enabling those MAC addresses.

  • Turn off shares: If guarantee is important, scanning for shares and spinning off the shares on the arrangement can help. Also encrypting aware data can check hackers from accessing the data.

  • Put your wireless admission points in a hard to find and reach spot.

  • Keep your drivers on all wireless paraphernalia updated. This helps patch offered guarantee vulnerabilities.

  • Read in progress press releases about emerging wireless news.

About The Author

Richard J Johnson

Network+ Certified

RJ CPU Consulting

http://rjcomputerconsulting. com

Richard@johnsorichard. com


