Save your wireless networks from hackers

How to protect your networks from the wireless hackers.

Written by James Middleton

Security managers need to be aware of the inherent weaknesses in wireless technology, which although similar to those in wired networking, add a few more headaches.

According to security professionals, the IEEE wireless protocol 802.11 not only shares unlicensed frequencies with other devices, including consumer-based Bluetooth devices, cordless phones, and baby monitors - which can, and do, interfere with each other - it also has weaknesses in its encryption structure.

Although wireless networks will use the so-called Wired Equivalent Privacy protocol (WEP), base stations are typically issued with either no password or the same password; so if the default password is left on, chances are it can be guessed.

If it is changed, that still means every user logging on to the base station needs to know the password, giving you more potential for leaks. The same password would need to apply to all stations in the network too, otherwise users would need to log on to every different station as they move about.

The single-password system also means that a brute-force attack on a base station may well yield you passwords for the entire network.

WEP also suffers from known problems with "keystream cipher" encryption. The RC4 encryption protocol it uses can either be captured and modified, so the data is altered, or capturing two encrypted messages would give a hacker the ability to splice the encryption key from the actual messages themselves.

Of course, an intruder could also introduce another base station to the network, even from outside the building, and capture user info and passwords.

Wireless interceptors are on the market for various vendor makes of kit, and with a little tweaking can be modified to grab data. Rather than grabbing data from the network, it is incredibly easy to bombard the wireless Lan with garbage signals, effectively denial-of-servicing it, an attack far easier to carry out wirelessly than on a wired network.

Consistently hammering a base station with access requests, whether successful or not, will eventually exhaust its power supply and knock it out of the network too.

As there is no definitive method of fully securing a base station, Kenneth De Spiegeleire, consulting manager at security group ISS, recommends keeping the two networks apart by putting a firewall between your intranet and the wireless network. Distributing personal firewalls to lock down the client machines is also recommended.

"Companies will have to invest time and money," said Spiegeleire, "access points cannot be trusted. They are external access devices, not internal, so securing the base station is crucial."

He said that regular network discoveries should be carried out to find any rogue base stations or clients, and there should be investment in more firewalls and IDS systems (intrusion detection) to either prevent rogue data getting in, or spotting it when it does.

However, as with a wired network, policies are most crucial, said Spiegeleire. He believes that policy, procedures and best practices should include wireless networking as part of an overall security management architecture to determine what is and is not allowed with wireless technology.

"The same rules apply," he said, "and when wireless standards are decided and the technology becomes commonplace, wireless hacking has the potential to go the same way as internet hacking is today."

A White Paper on wireless Lan security is available ISS here.

Tags:

Further reading

Hacking

2001: A Hacker's Odyssey   More...

Wireless networks: a hackers' playground

The cost-effectiveness and convenience offered by wireless networks makes them a tempting consideration, but a lack of inherent security will turn them into a hacker's playground, security experts have warned.Simply driving through a city centre armed with a wireless detection tool would flag up dozens of networks, and the chances are that most of them won't be watertight.   More...

Experts crack 802.11 protocol

University team expose 802.11 as 'totally insecure'.   More...

Bug Watch: new wireless networks, new dangers

The wireless silver lining contains an ominous dark cloud.   More...

Related articles

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement