Home > Security Tips > Network Security Tactics > Part 1: Strategies for securing your wireless LAN
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

Part 1: Strategies for securing your wireless LAN


by Mia Shopis, Assistant Editor
05.11.2004
Rating: -2.94- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


At the recent Spring 2004 Information Security Decisions conference Joel Snyder, senior partner of Opus One, outlined several wireless security strategies. This tip is based on the highlights from his session.

Here's the good news about wireless LANs: They're not as insecure as you have been lead to believe and breaking into a wireless network isn't as fast or easy as it's been portrayed. What's the bad news? You still need to pay close attention to your WLAN security choices, because there are vulnerabilities and weaknesses that can threaten your network security.

However, deciding on a solution really depends on the organization. After all, the term "security" means different things to different people. So, which solution is right for you? Here's the low down on WEP, 802.1X and the promise of 802.11i.

Wired Equivalent Privacy (WEP)
The attraction of using the WEP protocol (specified in the 802.11b standard) is that it's easy to install and compatible, which makes it a popular choice. Unfortunately, WEP is plagued by several well-known vulnerabilities such as static keys, weak initialization vectors and RC4 encryption, one of the weakest encryption algorithms and not designed for wireless security.

However, the biggest problem with WEP, stressed Snyder, is management. WEP keys are difficult to change, so they are often not updated and managed improperly. Since WEP keys are shared by groups of people, Snyder said it's like, "You're giving everyone the same password and they're not allowed to change it."


MORE INFORMATION ON SECURING A WIRELESS LAN:

802.1X
This standard adds a user authentication requirement and can be deployed in a wir



ed or wireless environment. "Before the user is allowed to get onto the LAN, they have to authenticate," said Snyder. And when used with TLS-based authentication, you have per-user/per-session WEP keys, stressed Snyder. 802.1X's short-lived keys means that admins can change them as often as needed -- making communication more secure (in comparison with WEP's static key model).

Some drawbacks of using 802.1X require the use of a client and a RADIUS server.

802.11i/WPA
The 802.11i standard (part of the 802.11 designed specifically for wireless) has not been approved yet, but it is intended to improve security under 802.11. (Wi-Fi Protected Access is an intermediate standard to be replaced by 802.11i when it is finally released.) Improvements to 802.11i include these features: Temporal Key Integrity Protocol (TKIP), which enhances WEP with per-packet re-keying mechanism and adds a Message Integrity Check field to each packet; replaces RC4 encryption with Advanced Encryption Standard (AES); and adds encryption for management frames.

Snyder added that to take full advantage of 802.11i, an organization is going to need to change its hardware and use AES encryption and go for 802.1X authentication. That said, Snyder doesn't recommend running out to buy AES hardware. After all, he continues, if you're happy with RC4 encryption, there's no real need to change to AES.

Deciding on the "right" WLAN solution isn't an easy task. There are pros and cons to each solution, but armed with the right knowledge organizations can decide what's the best one for them.

About the author
Mia Shopis is assistant editor for SearchSecurity.com. You can e-mail her here at mshopis@techtarget.com

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Network Security Tactics,   Wireless Security Issues,   Infrastructure and Network Security,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network Security Tactics
Screencast: Samurai offers pen-testing nirvana
Firewall rule management best practices
Chained Exploits: How to prevent phishing attacks from corporate spies
Rootkit Hunter demo: Detect and remove Linux rootkits
Enterprise UTM security: The best threat management solution?
Making the case for network security configuration management
An inside look at security log management forensics investigations
How to find sensitive information on the endpoint
How to perform Microsoft Baseline Security Analyzer (MBSA) scans
How to spot attacks through Apache Web server log analysis

Wireless Security Issues
Adventures in wireless security: Why home and corporate wireless LANs are insecure
WLAN security tools
Infosec Know IT All Trivia: Wireless security
Wireless LAN intrusion detection
Trend to ponder: Our fragile smart phones
The X Factor: 802.1X keeps intruders off your network
Slowly but surely, Wi-Fi security is improving
10 Common questions (and answers) on WLAN security
Tutorial test: Implementing WLAN security countermeasures
Defending the WLAN

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts