Overcoming Wireless Insecurity

author-image
DQChannels Bureau
New Update

In spite of wireless communication getting widely acceptable, concerns related to security in a wireless environment remain. While these concerns may be genuine, resellers need to convince customers that with adequate measures a wireless network can be made as secure as their wired network.

Advertisment

Think wireless and the first thought that comes to mind is insecurity. What
if someone taps into your communications as easily as by putting up an antenna?
But then there’s other side of the coin as well. Breaking through the wireless
security isn’t a child-play as it is often thought to be. Had it been so,
wireless wouldn’t be the key mode of communication for some of the most
critical operations. To illustrate this further, for military, wireless is the
only viable means of communication, and you know how finicky the military people
are about security. Remember the Germans and the Allies trying to decipher each
other’s communications during World War II.

INSECURITY
IS IN THE MIND

Well, wireless communications have come a long way since then. With 128-bit,
then 256-bit, and even higher level encryptions to come, intruders will require
tomorrow’s supercomputers to decode today’s encrypted messages. Plus a whole
lot of luck.

What remain are the misconceptions about wireless technology security. Not
only the IT manager, but even Governments have their fears and hence have
hesitated in opening up the wireless spectrum for the common man.

Advertisment

This article focuses on security issues concerning Wireless LAN (WLAN),
because that is what has recently been liberalized by the Government. And also
the fact that WLAN is going to make the biggest impact on the way communications
happen in the near future.

Though WLAN broadly falls under wireless category, it is still different.
WLAN technology is neither for local area nor for wide area networks. WLAN is
for in-building or campus area coverage of mobile computing users, and not for
cellular phones, cordless phones or pagers. WLAN can also offer point-to-point
communication between LANs separated by a few miles. WLAN primarily aims at
customers owning the equipment, and is not aimed towards usage charges.

More than the real shortcomings of WLAN, it is the wired
inertia of the mind towards wireless technology that acts as a barrier. Did you
think about that when using a mobile or a cordless phone? Even mobile to mobile
communication at some point of time passes over wires. Similarly, WLAN is to be
viewed as an extension of the wired network.

Advertisment

WLAN IS UNESCAPEABLE

WLAN is very simple to install. By attaching access point to any Ethernet
port of the network, a user can create a wireless network. In a way, once you
have a wired LAN, someone else can convert it into a WLAN within minutes and
without giving rise to any suspicion. In fact, according to a Gartner report
published way back in 2001, "Rogue" WLANs do exist in about 20% of the
enterprises worldwide.

In short, now you are left with not much choice of whether or
not to use WLAN. Somebody may be already using it or planning to use it on your
wired LAN. So the smart way is to plan for WLAN and take required measures at
brisk pace, else some day you may come across a big surprise. Planning for a
WLAN helps to have a fresh look at the wired LAN, and thus identify and plug
security holes in your existing wired network.

WLAN CHALLENGES

In today’s world, for lot of communication activity, Internet has become
the default medium. Over Internet, data packets pass through many unknown
networks beyond our control. In a way it is similar to wireless signal traveling
without your control.

Advertisment

Obviously, today when you are accessing Internet, your
network is exposed to many threats and by no means wired networks are as secured
as we think.

WLAN shortcomings are similar to hub-based Ethernet network
that existed a decade ago. The way security over Ethernet has evolved over a
period, wireless is also evolving.

Over a period of time, people have attempted to make network
secure by deploying firewalls. Most of the networks and firewall locations today
are not designed for incorporating WLAN. To make things worse, wireless access
points are mostly deployed behind the corporate firewall. So now one either
re-designs the network altogether or gives special treatment to the wireless
users.

Advertisment

Within 2.4 GHz band there are 11 prefixed channels. These
channels help increase effective bandwidth. But as these are prefixed as
standards, they can be detected by using any simple utility. So this does not
provide much security.

Does that mean wireless today has no security at all?
Certainly not.

DESIGNING SECURE SOLUTIONS

Users must follow strict discipline while using WLAN. One should take extra
precaution towards the wireless connectivity devices. Wireless USB adapter and
wireless PC Card would become as valuable as the office-door key! Here are some
key guidelines.

Some vendors ship out products with WEP control disabled.
Verify that this control is available in each access point you buy.

Advertisment

Disable open broadcast of SSID/BSSID from the access points.

128/256-bit encryption provides high level of security. One
should insist on minimum 256-bit encryption.

You are advised to change your Internet password every 15
days. Similarly it is advisable to change the WEP encryption key regularly.

There is a MAC address table in each access point. Typically
64 MAC addresses can be stored. Access by other MAC address can be denied. Thus
packets from unauthorized user holding different MAC address will be dropped by
the access point itself.

Advertisment

Now, some users may not find these security measures adequate
enough. There are two very logical solutions. One is to build more and more
security before signal gets into the wired network. This means building more
complex security algorithms. But this reduces effective bandwidth which is very
limited as compared to wired network. This also demands more processing power at
every PC connecting device and on the access point. This leads to an increase in
cost, which is many folds higher than the 100 Mbps wired network.

The second approach is to build more security at the entry
point into the wired network. This is prudent because in this case, he network
becomes independent of devices and different wireless standards (802.11a,
802.11b, 802.11g, 802.1x, etc.).

The golden rule is to secure the interface between the
wireless and wired network.

Having followed the golden rule you can go on enhancing
security measures further. If you have authentication process set on your wired
network, you need a controlling device which can make traffic from all access
points follow the authentication without choice. Thus entire resources behind
the access point get all the security existing on the wired LAN and that is the
ultimate security that is achievable.

STEPS TO ULTIMATE SECURITY

The device should communicate with internal policy server before allowing
the usage of any resource on the network.

Create server access control and activity logs in the server
for all users.

Check the password on the security server. Store the
passwords on the security server. Let this server support any authentication
processes set by the wired network.

Make sure the solution is totally independent of wireless
technology/protocol used.

Milind Kamat
is Country Manager, India & SAARC Region, SMC Networks.