Home > Security Tips > Threat Monitor > Lessons learned from TJX: Best practices for enterprise wireless encryption
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

THREAT MONITOR

Lessons learned from TJX: Best practices for enterprise wireless encryption


Mike Chapple
12.19.2007
Rating: -2.92- (out of 5)


Threat Monitor
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Listen to Mike's tip

Download Mike Chapple's enterprise wireless encryption advice to your PC or favorite mobile device.
Between July 2005 and January 2007, TJX Companies Inc. suffered one of the largest data security breaches in the history of information security. Court documents uncovered by The Boston Globe revealed that the intruders systematically mined TJX's computer systems and made off with more than 94 million credit card numbers used by customers at the chain's stores, which include the TJ Maxx and Marshall's clothing retailers.

What was the cause of this breach? At the time of the initial intrusion, TJX relied upon a wireless network using the Wired Equivalent Privacy security model. As early as 2001, security professionals around the world have panned WEP, citing inherent weaknesses that make it possible to determine a network's wireless encryption key. In fact, a recent study demonstrated that it is possible to break a 104-bit WEP key in less than 60 seconds.

The TJX breach revealed all too well that organizations need to protect their wireless networks. Here are some best practices that will minimize exposure:

  • Abandon WEP encryption immediately. It cannot be stated more clearly: WEP is almost completely useless. The only advantage it provides is a thin veil of protection against a casual attacker. The real danger of WEP is that it provides a false sense of security to users and business leaders alike. The fact that Windows calls WEP-encrypted networks "security-enabled" is an extremely dangerous mislabeling. Enterprises using WEP today should immediately begin planning to replace it with the more secure Wi-Fi Protected Access (WPA/WPA2) model.


  • Educate your users. Remember: mobile users travel and use wireless networks outside of the IT department's control. Be sure that they understand the risks inherent in wireless networking and know that connecting to a "secure" external network isn't really providing much protection. Employees must also use another encryption technology to protect sensitive information. VPN and SSL connections fill this role nicely.


  • For more information:

    Learn more about how the TJX hackers attacked security holes in the retail giant's wireless system.

    Joel Dubin takes a closer look at TJX Companies' 10-K filing.

    The TJX data breach has some questioning the effectiveness of PCI DSS, but others say there is a more specific problem.
  • Use RADIUS authentication. All but the smallest businesses should opt for the security provided by WPA-Enterprise, which integrates RADIUS authentication into an organization's infrastructure. RADIUS provides granular access control and can immediately de-provision wireless access for terminated employees. The alternative, WPA-Personal, uses a pre-shared key common to all computers.

    Looking for a rule of thumb on which version of WPA to choose? When an employee leaves, a pre-shared key will need to be changed. If the number of wireless devices in your organization prevents you from easily doing this, then RADIUS authentication is the right choice.

  • Remember to secure access points. If an intruder is able to gain access to one of your wireless access points, that person might be able to reconfigure it to defeat other security controls. Be sure to implement configuration standards -- such as those available from the Center for Internet Security or device manufacturers -- to protect against a network-based intrusion. Additionally, strong physical security controls are needed to prevent an attacker from physically accessing key devices and performing a factory default reset or simply replacing an access point with a rogue device.


  • Firewall off your wireless network. Wired networks are inherently more secure than wireless networks; that's just a fact of life. Physical access to network ports/cables limit access to wired networks. Wireless networks travel through walls and windows, providing outsiders with an opportunity to knock on your network's door. For this reason, it's generally a good idea to firewall off wireless networks in a separate security zone.


  • Wireless networking is here to stay. Mobile users depend upon it for productivity in the office, at home and on the road. It also enables a multitude of new business functions, ranging from handheld point-of-sale devices to distributed sensor networks. There's no reason to let the wireless networking security risks scare you away from leveraging it as part of your organization's technology arsenal. Follow these best practices, and you'll be well on the road to enabling productive, secure wireless computing.

    By the way, did I mention that if you're using WEP in your organization, you need to get rid of it immediately? Start right now!

    About the author:
    Mike Chapple, CISA, CISSP, is an IT security professional with the University of Notre Dame. He previously served as an information security researcher with the National Security Agency and the U.S. Air Force. Mike is a frequent contributor to SearchSecurity, a technical editor for Information Security magazine and the author of several information security titles, including the CISSP Prep Guide and Information Security Illuminated. He also answers your questions on network security.

    Rate this Tip
    To rate tips, you must be a member of SearchSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    BROWSE BY TAG
    Threat Monitor,   Wireless Network Security: Setup and Tools,   Wireless Network Protocols and Standards,   Enterprise Network Security,   Enterprise Data Protection,   Identity Theft and Data Security Breaches,   Wireless LAN Design and Setup,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Threat Monitor
    Server Message Block Version 2 security in question: Disable or patch?
    Preparing for future security threats, evolving malware
    Best practices for (small) botnets
    Cut down on calls to help desk with cybersecurity awareness training
    How to detect software tampering
    How to prevent phishing attacks with social engineering tests
    An enterprise strategy for Web application security threats
    How SSL-encrypted Web connections are intercepted
    How a corporate Twitter policy can combat social network threats
    Cyberwarfare and the enterprise: Is the threat real?

    Wireless Network Protocols and Standards
    GSM cell phone encryption crack may force operators to upgrade
    Wireless network guidelines for PCI DSS compliance
    Best Wireless Security Products
    MMS messaging spoof hack could have global ramifications
    PCI group releases wireless security guide
    802.1X Port Access Control: Which version is best for you?
    Wireless Security Lunchtime Learning
    An introduction to wireless security
    Lesson 1: How to counter wireless threats and vulnerabilities
    Risky Business: Understanding WiFi threats

    Identity Theft and Data Security Breaches
    MA 201 CMR 17 enforcement less likely with prompt reporting, cooperation
    No major PCI DSS revision expected in 2010
    Data breach costs continue to rise in 2009, Ponemon study finds
    Chinese hacker attacks target Google Gmail accounts, top tech firms
    Facebook, McAfee partner to fix social network security issues
    Hacker pleads guilty to orchestrating Heartland credit card heist
    MasterCard reverses PCI compliance requirement
    Verizon report goes deep inside data breach investigations
    Health Net healthcare data breach affects1.5 million
    Massive T-Mobile UK security breach involves insiders

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Wired Equivalent Privacy  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Research Solutions for Network Security, Access Control and Security Threats
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts