Home > Security Tips > Threat Monitor > Lessons learned from TJX: Best practices for enterprise wireless encryption
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

THREAT MONITOR

Lessons learned from TJX: Best practices for enterprise wireless encryption


Mike Chapple
12.19.2007
Rating: -2.92- (out of 5)


Threat Monitor
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Between July 2005 and January 2007, TJX Companies Inc. suffered one of the largest data security breaches in the history of information security. Court documents uncovered by The Boston Globe revealed that the intruders systematically mined TJX's computer systems and made off with more than 94 million credit card numbers used by customers at the chain's stores, which include the TJ Maxx and Marshall's clothing retailers.

What was the cause of this breach? At the time of the initial intrusion, TJX relied upon a wireless network using the Wired Equivalent Privacy security model. As early as 2001, security professionals around the world have panned WEP, citing inherent weaknesses that make it possible to determine a network's wireless encryption key. In fact, a recent study demonstrated that it is possible to break a 104-bit WEP key in less than 60 seconds.

The TJX breach revealed all too well that organizations need to protect their wireless networks. Here are some best practices that will minimize exposure:

  • Abandon WEP encryption immediately. It cannot be stated more clearly: WEP is almost completely useless. The only advantage it provides is a thin veil of protection against a casual attacker. The real danger of WEP is that it provides a false sense of security to users and business leaders alike. The fact that Windows calls WEP-encrypted networks "security-enabled" is an extremely dangerous mislabeling. Enterprises using WEP today should immediately begin planning to replace it with the more secure Wi-Fi Protected Access (WPA/WPA2) model.


  • Educate your users. Remember: mobile users travel and use wireless networks outside of the IT department's control. Be sure that they understand the risks inherent in wireless networking and know that connecting to a "secure" external network isn't really providing much protection. Employees must also use another encryption technology to protect sensitive information.


    VPN and SSL connections fill this role nicely.


  • Use RADIUS authentication. All but the smallest businesses should opt for the security provided by WPA-Enterprise, which integrates RADIUS authentication into an organization's infrastructure. RADIUS provides granular access control and can immediately de-provision wireless access for terminated employees. The alternative, WPA-Personal, uses a pre-shared key common to all computers.

    Looking for a rule of thumb on which version of WPA to choose? When an employee leaves, a pre-shared key will need to be changed. If the number of wireless devices in your organization prevents you from easily doing this, then RADIUS authentication is the right choice.

  • Remember to secure access points. If an intruder is able to gain access to one of your wireless access points, that person might be able to reconfigure it to defeat other security controls. Be sure to implement configuration standards -- such as those available from the Center for Internet Security or device manufacturers -- to protect against a network-based intrusion. Additionally, strong physical security controls are needed to prevent an attacker from physically accessing key devices and performing a factory default reset or simply replacing an access point with a rogue device.


  • Firewall off your wireless network. Wired networks are inherently more secure than wireless networks; that's just a fact of life. Physical access to network ports/cables limit access to wired networks. Wireless networks travel through walls and windows, providing outsiders with an opportunity to knock on your network's door. For this reason, it's generally a good idea to firewall off wireless networks in a separate security zone.


  • Wireless networking is here to stay. Mobile users depend upon it for productivity in the office, at home and on the road. It also enables a multitude of new business functions, ranging from handheld point-of-sale devices to distributed sensor networks. There's no reason to let the wireless networking security risks scare you away from leveraging it as part of your organization's technology arsenal. Follow these best practices, and you'll be well on the road to enabling productive, secure wireless computing.

    By the way, did I mention that if you're using WEP in your organization, you need to get rid of it immediately? Start right now!

    About the author:
    Mike Chapple, CISA, CISSP, is an IT security professional with the University of Notre Dame. He previously served as an information security researcher with the National Security Agency and the U.S. Air Force. Mike is a frequent contributor to SearchSecurity, a technical editor for Information Security magazine and the author of several information security titles, including the CISSP Prep Guide and Information Security Illuminated. He also answers your questions on network security.

    Rate this Tip
    To rate tips, you must be a member of SearchSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    BROWSE BY TAG
    Threat Monitor,   Wireless Network Security: Setup and Tools,   Wireless Network Protocols and Standards,   Enterprise Network Security,   Enterprise Data Protection,   Identity Theft and Data Security Breaches,   Wireless LAN Design and Setup,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    Threat Monitor
    How to defend against rogue DHCP server malware
    When BIOS updates become malware attacks
    Mac OS memory flaws pose challenges for enterprise endpoint protection
    Cybercrime and threat management
    How to find and stop automated SQL injection attacks
    Short-lived Web malware: Fading fad or future trend?
    Security book chapter: The Truth About Identity Theft
    How to use (almost) free tools to find sensitive data
    How to block adult websites from enterprise users by logging content
    Are Windows Vista security features up to par?

    Wireless Network Protocols and Standards
    Wireless Security Lunchtime Learning
    An introduction to wireless security
    A wireless network vulnerability assessment checklist
    Lesson 1: How to counter wireless threats and vulnerabilities
    Lesson 1 quiz: Risky business
    Wireless Security Lunchtime Learning Entrance Exam
    Risky Business: Understanding WiFi threats
    Study reveals lack of financial wireless computer security
    Preparing enterprise Wi-Fi networks for PCI compliance
    Cracks in WPA? How to continue protecting Wi-Fi networks

    Identity Theft and Data Security Breaches
    TJX to pay $9.75 million for data breach investigations
    Man pleads guilty in online banking hacking scam
    White House cybersecurity czar faces major hurdles
    Heartland breach cost $12.6 million, CEO says
    An inside look at security log management forensics investigations
    LexisNexis investigates breach, notifies thousands
    Senators hear call for federal cybersecurity restructuring
    Former Federal Reserve Bank employee arrested
    Attackers cash in on fundamental data handling mistakes, Verizon finds
    Courts turn aside data breach suits

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    bot worm  (SearchSecurity.com)
    CISP-PCI  (SearchFinancialSecurity.com)
    cookie poisoning  (SearchSecurity.com)
    drive-by pharming  (SearchSecurity.com)
    extrusion prevention  (SearchSecurity.com)
    identity theft  (SearchSecurity.com)
    parameter tampering  (SearchSecurity.com)
    pretexting  (SearchCIO.com)
    Rock Phish  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Research Solutions for Network Security, Access Control and Security Threats
    More Security Resources for Resellers, VARs and OEMs
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts