Home > Networking News > Wireless security push fueled by paranoia
Networking News:
EMAIL THIS

Wireless security push fueled by paranoia

By Andrew R. Hickey, News Writer
17 Aug 2006 | SearchNetworking.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Tim Stowell calls it "paranoia."

He doesn't want rogue access points or any other potential security hazards making their way into his wireless network.

"My biggest concerns are rogue access points -- people who install their own access points because they want to be able to walk around wirelessly," said Stowell, corporate network manager for Intermagnetics, a Latham, N.Y.-based manufacturer of large magnets for MRI machines and other medical equipment. "I don't worry too much about people sitting in our parking lot."

To ward off potential intrusions and rogues, Stowell deployed dual-mode access points from Aruba Networks. The dual mode allows them not only to act as access points but to monitor the spectrum for interference, rogues or other troubles.

One thing that wasn't anticipated, however, was how the dual mode would affect connectivity.

"When put into monitoring mode, it bit into performance," Stowell said, adding that users reported slower traffic.

When Stowell switched the monitoring capability off, connectivity came back.

"I turned off monitoring, and the users said, 'Hey, what did you do?'" he said.

Performance was back, but now there was nothing monitoring. Stowell said he came upon RFProtect from Network Chemistry, a wireless monitoring and threat prevention system. RFProtect was installed in the Latham headquarters and also tested out in Intermagnetics' office in Orlando, Fla. Stowell deployed RFProtect to supplement Aruba. Using a separate tool for monitoring allows the Aruba access points to stick solely to transmitting, so monitoring doesn't bite into performance.

In Orlando, they hit a small roadblock, Stowell said, because RFProtect automatically grabs the DHCP address and configures. But that problem was averted within a few minutes with manual configuration. In Latham, the deployment went smoothly.

"I didn't really find too much here in Latham that I didn't anticipate," he said. No rogue access points or other problems. In Orlando, there was one rogue access point, but it was very easy to find, he said, because RFProtect is laptop based and can be carried to the location of a trouble signal. "We saw it immediately," he said. The access point was added by an employee who wanted wireless connectivity without having to sign on to the network.

Stowell also made one other interesting find when a team of Sarbanes-Oxley auditors visited the office. He noticed that the auditors had an ad hoc network running among their laptops. Stowell said he thought it might have been a test -- the auditors quizzing him to see whether he would uncover the problem. It wasn't. And he brought it to the auditors' attention.

For more on wireless security
Check out more on network security in Network Defenders

Find out why Blue Cross of Idaho has a 'no wireless' policy
"Only one knew the ad hoc network was set up," he said.

For Stowell, it's all about peace of mind. At first, he wasn't crazy about the idea of going wireless, he said. He was concerned about security.

"I fought it for a while," he said, until convincing arguments were made for wireless, and his team found a wireless monitoring system. "But I acquiesced."

After giving in to wireless, Stowell plans on going full bore, especially now that he has a view of the wireless network and knows it's secure. He said he wants to install RFProtect in the other Intermagnetics offices in California and Wisconsin.

"It's mainly a level of paranoia to make sure there aren't things that aren't supposed to be there," he said. "There are two philosophies in security: Use an all-in-one product or a specialized product. I like kind of a hybrid of that."

Tags: WLAN SecurityTroubleshooting Wireless NetworksWireless Network SecurityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
WLAN Security
Wireless LAN security: SonicWall joins crowded WLAN market
Stolen laptop recovery using remote access and wireless network SSIDs
Enterprise wireless LAN security: 802.11 and seamless wireless roaming
Monitoring your network to detect rogue access points (APs)
Persistent, secure connections for roaming WiMAX, 3G and 802.11x
802.11n's impact on WLAN security
Set up secure wireless networks with 802.11x, access points and bridges
How wireless network encryption affects signal strength, connectivity
New PCI compliance rules ban WEP, tighten wireless LAN security
How to avoid the WPA wireless security standard attack

Troubleshooting Wireless Networks
How radio frequency (RF) of microwaves alter wireless signal strength
Distributed antenna systems and WLAN: A network management burden
Wireless LAN management platforms key differentiator for WLAN vendors
How is wireless access point (AP) coverage affected by frequency?
From Cisco to Meru to Aruba, school finally finds right WLAN
How to find an SSID and identify neighboring WLANs
How to stop channel interference on 802.11x wireless access points
Troubleshooting networks: Can vendor software self-install firewalls?
How to use Netsh WLAN to configure Windows Server 2008 and Windows Vista wireless connections from the CLI
Free consumer Wi-Fi hot spots: Retail fad or enterprise business tool?
Troubleshooting Wireless Networks Research

Wireless Network Security
Rogue access points: Preventing, detecting and handling best practices
Securing embedded 802.11n devices
How wireless network encryption affects signal strength, connectivity
New PCI compliance rules ban WEP, tighten wireless LAN security
Best practices for securing your wireless LAN
IEEE 802.11w protects wireless LAN management frames
How can I be sure no one is hijacking or hacking my WAP?
Securing Wireless Systems -- 'Build Your Own Security Lab: A Field Guide for Network Testing,' Chapter 9
Why wireless network cards show activity when no one uses the computer
What are recent security developments for MIPv6?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
802.11a  (SearchNetworking.com)
home agent  (SearchNetworking.com)
iDEN  (SearchNetworking.com)
radio frequency  (SearchNetworking.com)
repeater  (SearchNetworking.com)
spectrum analyzer  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Comprehensive network management resources, expert solutions, and professional research informing your technology decisions
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts