Home > Ask the Networking Experts > Wireless networking Questions & Answers > Monitoring your network to detect rogue access points (APs)
Ask The Networking Expert: Questions & Answers
EMAIL THIS

Monitoring your network to detect rogue access points (APs)

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Network security news, advice and technical information
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 15 April 2009
What are the best methods for handling rogue access points (APs)? Can you suggest a small-scale business network solution for dealing with rogue access points?

>
Any unknown access point (AP) operating in or close to your facility is a potential rogue -- but few turn out to be real threats. The trick is to reliably tell the difference -- and fast.

In urban areas, most unknown APs will end up belonging to neighboring businesses, hotels, stores, or metro-area wireless local area networks (WLANs). These neighboring APs are not connected to your wired network, but still pose risk if employees connect to them (accidentally or intentionally), bypassing your network's security. Thus, you may want to monitor your wireless clients to detect employee associations to unknown-but-unconnected APs. This can be done by using a network wireless intrusion prevention system (WIPS) to watch the air or by using a host-resident WIPS to monitor client activity. Large enterprises should deploy network WIPS solutions for full-time air surveillance. Smaller businesses on more limited budgets may prefer to install stand-alone host WIPS programs like Sana Security Primary Response Air Cover. Note that AP discovery tools, like NetStumbler, cannot provide client surveillance.

Of course, some unknown APs in or near your office may be physically connected to your wired network. These "true rogues" pose immediate business threat because they create an unsecured backdoor into your network, accessible to anyone within wireless range. The vast majority of unknown-but-connected APs are installed by naïve employees for the sake of convenience, usually without Wi-Fi authentication or encryption. However, you never know whether one might turn out to be a malicious AP installed by a criminal. For example, a bank in Haifa Israel was robbed by criminals who planted a rogue AP inside the building so that they could connect to the bank network from outside to initiate fraudulent money transfers.

Wireless security school
For more information, view these wireless security learning lessons from Wi-Fi instructor Lisa Phifer.
Here again, large enterprises should really mitigate "true rogues" by deploying sophisticated network WIPS solutions that can not only spot those APs, but trace their network connectivity, estimate their physical location, and examine visible Wi-Fi parameters to focus attention and automated response on real threats. For example, a WIPS may send a command to an upstream switch to disable the Ethernet port connected to a rogue AP, thereby cutting off communication with your network. WIPS-estimated location and a portable tool like a WLAN analyzer can then be used to find the AP, determine who installed it, and decide how it should be dealt with.

Small businesses may prefer to use less sophisticated alternatives for continuous rogue AP detection. For example, many Small Office Home Office (SOHO) or Server Message Block (SMB) APs can scan the airwaves periodically, looking for nearby APs they don't recognize. These APs can be configured with MAC lists of authorized and neighbor APs so that only unknown APs end up triggering rogue alerts. Traditional diagnostic tools like traceroute can then be used to manually assess whether each potential rogue is connected to your network -- but keep in mind that rogues can hide behind NAT and other parts of your network that traceroute won't reach. Rogues can also spoof MAC addresses used by legitimate APs or try to mimic your own WLAN's SSID. In short, reliable rogue AP classification is difficult and time-consuming -- but a periodic scan and manual investigation may find employee-installed rogues that are not really trying to evade detection.

However, many small businesses today rely upon scheduled rogue AP surveys, where admins walk the premises using an ordinary wireless client, WLAN discovery tool, or WLAN analyzer, looking for potential rogues. This methodology is arguably the most labor-intensive and least reliable. For example, a visitor could easily install a rogue AP, use it for a week, and then leave before your next survey. However, scheduled rogue surveys can be useful as a complement to continuous rogue detection -- for example, to check a radio band not scannable by your own APs.

Finally, businesses that are too risk-averse for background AP scans and manual rogue mitigation, but not rich enough for (or ready to invest in) enterprise WIPS, should consider managed WIPS services. Many small and medium-sized businesses (SMBs) already pay providers to install and operate a wired network firewall/IPS on their behalf; some providers now offer WIPS as a managed service. For example, see AirTight SpectraGuard Online.

This question was also answered by our network security expert, Michael Gregg. Read his response to the question: What are the best methods for handling rogue access points?


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
WLAN Security
Where can I find a wire driver that unblocks recognized passwords?
Will using a VPN protect me against fake wireless hotspots?
Fluke gets WLAN design, management, security cred with AirMagnet
Is WPA2 secure enough for a commercial business wireless network?
Health center cut cost securing wireless network edge with Aerohive
Wi-Fi RTLS for WLAN management, location-based security, asset tracking
Wireless LAN performance management and security standards beefed up
How can I hide my WLAN's SSID in an Aruba AP-61?
Wireless LAN security: SonicWall joins crowded WLAN market
Stolen laptop recovery using remote access and wireless network SSIDs

Wireless networking
APs drop connection in WLAN configured as a wireless mesh network
How does Wi-Fi ad-hoc mode react when 802.11n and legacy peers are present?
Can wireless adapters operate as client access points to make SoftAPs?
Will using a VPN protect me against fake wireless hotspots?
WLAN QoS and SLA monitoring with 7/24 Wireless Quality Assurance costs
How can I hide my WLAN's SSID in an Aruba AP-61?
How radio frequency (RF) of microwaves alter wireless signal strength
Stolen laptop recovery using remote access and wireless network SSIDs
How is wireless access point (AP) coverage affected by frequency?
Wireless AP SSID and channel configuration for a distribution network

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts