The security risks and ways to decrease vulnerabilities in a 802.11b wireless environment

>statistic in 2001 by Gartner said that, “at least
This document explains topics relating to wireless20 percent of enterprises already have rouge
networks. The main topics discussed include, whataccess points.” Another type of attack would
type of vulnerabilities exist today in 802.11be if, someone from outside the organization,
networks and ways that you can help prevententers into the workplace and adds an Access
these vulnerabilities from happening. WirelessPoint by means of Social Engineering.
networks have not been around for many years.Insecure Network Configurations- Many
Federal Express has been using a type of wirelesscompanies think that if they are using a firewall or
networks, common to the 802.11 networks useda technology such as VPN, they are automatically
today, but the general public has recently justsecure. This is not necessarily true because all
started to use wireless networking technology.security holes, big and small, can be exploited. Also
Because of weak security that exists in wirelessif devices and technologies, such as VPNs,
networks, companies such as Best Buy havefirewalls or routers, are mis-configured, the
decided to postpone the roll-out of wirelessnetwork can be compromised.
technology. The United States Government hasAccidental Associations — This can happen
done likewise and is suspending the use ofif a wireless network is setup using the same
wireless until a more universal, secure solution isSSID as your network and within range of your
available.wireless device. You may accidentally associate
Backgroundwith their network without your knowledge.
What is Wireless?Connecting to another wireless LAN can divulge
Wireless LANs or Wi-Fi is a technology used topasswords or sensitive document to anyone on
connect computers and devices together.the neighboring network. Wireless LAN Security
Wireless LANs give persons more mobility and— What Hackers Know That You Don't
flexibility by allowing workers to stay connectedCopyright 2002
to the Internet and to the network as they roamSocial Engineering — Social Engineering is
from one coverage area to another. Thisone of the most effective and scariest types of
increases efficiency by allowing data to beattacks that can be done. This type of attack
entered and accessed on site.really scares me and can be done for many other
Besides being very simple to install, WLANs arepurposes besides compromising security in
easy to understand and use. With few exceptions,wireless networks. A scenario: Someone dressed
everything to do with wired LANs applies toup as a support person from Cisco enters the
wireless LANs. They function like, and areworkplace. The secretary sees his fake
commonly connected to, wired Ethernetcredentials and lets him get pass the front desk.
networks.The impersonator walks from cubicle to cubicle,
The Wireless Ethernet Compatibility Alliancecollecting user names and passwords as he/she
[WECA] is the industry organization that certifiesgoes. After finding a hidden corner, which seems
802.11 products that are deemed to meet a baseto be lightly traveled, he plugs an insecure Access
standard of interoperability. The first family ofPoint into the network. At the same time he
products to be certified by WECA is that basedconfigures the Access Point to not broadcast its
on the 802.11b standard. This set of products isSSID and modifies a few other settings to make
what we will be studying. Also more standardsit hard for the IT department to find this Rouge
exist such as 802.11a and 802.11g.Access Point. He then leaves without ever being
The original 802.11 standard was published in 1999questioned by anyone because it looks like he just
and provides for data rates at up to 2 Mbps atfits in. Now, all he has to do is be within 300 feet
2.4 GHz, using either FHSS or DSSS. Since thatfrom the access point, (more if he added an
time many task groups have been formed toantenna), and now has access to all kinds of
create supplements and enhancements to thesecure documents and data. This can be a
original 802.11 standard.devastating blow to any corporation and could
The 802.11b TG created a supplement to theeventually lead to bankruptcy if the secrets of
original 802.11 standard, called 802.11b, which hasthe company were revealed to competitors.
become the industry standard for WLANs. It usesBruce Schneier came to my classroom and said
DSSS and provides data rates up to 11 Mbps atthe following about Social Engineering,
2.4 Ghz. 802.11b will eventually be replaced by“Someone is just trying to do their job, and be
standards which have better QoS features, andnice. Someone takes advantage of that by
better security.targeting this human nature. Social Engineering is
Network Topologyunsolvable.”
There are two main topologies in wirelessSecuring Wireless Networks
networks which can be configured:According to Bruce Schneier and others such as
Peer-to-peer (ad hoc mode) — ThisKevin Mitnick, you can never have a totally secure
configuration is identical to its wired counterpart,computing environment. What is often suggested
except without the wires. Two or more devicesis to try and control the damage which can be
can talk to each other without an AP.done if security is breached. One can try many
Client/Server (infrastructure networking) —different tools on the market which can help
This configuration is identical to its wiredprevent security breaches.
counterpart, except without the wires. This is theWEP — WEP supports both 64 and 128-bit
most common wireless network used today, andkeys. Both are vulnerable, however, because the
what most of the concepts in this paper apply to.initialization vector is only 24-bits long in each case.
Benefits of Wireless LANsIts RC4 algorithm, which is used securely in other
WLANs can be used to replace wired LANs, or asimplementations, such as SSL, is quite vulnerable in
an extension of a wired infrastructure. It costsWEP. Wireless Insecurities By Dale Gardner.
far less to deploy a wireless LAN than to deploy aDifferent tools exist to break WEP keys, including
wired one. A major cost of installing and modifyingAirSnort, which can be found at Although this
a wired network is the expense to run networkmethod is not a secure solution, it can be used to
and power cables, all in accordance with localhelp slowdown an attacker if other means are not
building codes. Example of additional applicationspossible financially or otherwise.
where the decision to deploy WLANs include:VPN and IPSec- IPSec VPNs let companies
Additions or moves of computers.connect remote offices or wireless connections
Installation of temporary networksusing the public Internet rather than expensive
Installation of hard-to-wire locationsleased lines or a managed data service. Encryption
Wireless LANs give you more mobility andand authentication systems protect the data as it
flexibility by allowing you to stay connected to thecrosses the public network, so companies don't
Internet and to the network as you roam.have to sacrifice data privacy and integrity for
Cons of Wireless LANslower costs. A lot of VPN's exist on the market
Wireless LANs are a relatively new technologytoday. An important note about VPNs is,
which has only been around since 1999. With anyinteroperability does not really exist, and whatever
new technology, standards are always improving,you use for your server has to be the same
but in the beginning are unreliable and insecure.brand as your clients most of the time. Some
Wired networks send traffic over a dedicated lineVPNs include:
that is physically private; WLANs send their trafficBorderware
over shared space, airwaves. This introducesBroadConnex Networks
interference from other traffic and the need forCheckPoint
additional security. Besides interference fromCisco
other wireless LAN devices, the 2.4 GHz is alsoComputer Associates
used by cordless phones and microwaves.DMZ — Adding this to your network
Security Issues of WLANsenables you to put your wireless network on an
War-drivinguntrusted segment of your network.
War-driving is a process in which an individual usesFirewalls — Firewalls are all over the place.
a wireless device such as a laptop or PDA toFirewalls range from hardware to software
drive around looking for wireless networks. Someversions. By adding a firewall between the
people do this as a hobby and map out differentwireless network and wired network helps
wireless networks which they find. Other people,prevent hackers from accessing your wired
who can be considered hackers, will look fornetwork. This paper doesn't go into specifics
wireless networks and then break into theabout different firewalls and how to set them up,
networks. If a wireless is not secure, it can bebut there are many. Some of the firewalls include:
fairly easy to break into the network and obtain- ZoneAlarm (an inexpensive based software
confidential information. Even with security,firewall) - Symantec has many different firewalls
hackers can break the security and hack. One ofdepending what you require.
the most prevalent tools used on PDAs andPKI - Public-key infrastructure (PKI) is the
Microsoft windows devices is, Network Stumbler,combination of software, encryption technologies,
which can be downloaded at Equipped with theand services that enables enterprises to protect
software and device, a person can map outthe security of their communications and business
wireless access points if a GPS unit is attached.transactions on the Internet. What is PKI?
Adding an antenna to the wireless card increasesSite Surveys — Site Surveys involve using
the capabilities of Wi-Fi. More information can bea software package and a wireless device to
found at: and to name a few.probe your network for Access Points and
War-chalkingsecurity risks.
War-chalking is a method of marking wirelessProactive Approaches
networks by using chalk most commonly.Since wireless technology is insecure, companies
War-driving is usually the method used to searchor anyone can take a proactive approach to try
for networks, and then the person will mark theand identify hackers trying to gain access via
network with chalk that gives information aboutwireless networks.
the network. Some of the information wouldHoneypots — are fake networks setup to
include, what the network name is, whether thetry and lure in hackers. This enables administrators
network has security, and possibly the contactto find out more about what type of techniques
information of who owns the network. If yourhackers are using to gain access. One product is
wireless network is War-chalked and you don'tMantrap created by Symantec.
realize it, your network can be used and/or“ManTrap has the unique ability to detect both
broken into faster, because of information shownhost- and network-based attacks, providing hybrid
about your network.detection in a single solution. No matter how an
Eavesdropping & Espionageinternal or external attacker tries to compromise
Because wireless communication is broadcastthe system, Symantec ManTrap's decoy sensors
over radio waves, eavesdroppers who just listenwill deliver holistic detection and response and
over the airwaves can easily pick up unencryptedprovide detailed information through its system of
messages. These intruders put businesses at riskdata collection modules.”
of exposing sensitive information to corporateIntrusion Detection — Intrusion Detection is
espionage. Wireless LAN Security — Whatsoftware that monitors traffic on the network. It
Hackers Know That You Don't Copyright 2002sounds out a warning if a hacker it trying to
Internal Vulnerabilitiesaccess the network. One such free product is
Within an organization network security can beSnort.
compromised by ways such as, Rouge WLANs“Before we proceed, there are a few basic
(or Rouge Aps), Insecure Network Configuration,concepts you should understand about Snort.
and Accidental Associations to name a few.There are three main modes in which Snort can
Rouge Access Points — An employee ofbe configured: sniffer, packet logger, and network
an organization might hook up an access pointintrusion detection system. Sniffer mode simply
without the permission or even knowledge of IT.reads the packets off of the network and
This is simple to do, all a person has to do is plugdisplays them for you in a continuous stream on
an Access point or wireless router into an existingthe console. Packet logger mode logs the packets
live LAN jack and they are on the network. Oneto the disk.