Home > Networking Tips > Wireless Networks > Wireless LAN intrusion detection
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WIRELESS NETWORKS

Wireless LAN intrusion detection


Mike Chapple, CISSP
11.18.2003
Rating: -3.50- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Most security administrators are familiar with the capabilities of modern intrusion-detection systems and the benefits of incorporating this technology into their network security infrastructure. The proliferation of wireless networking introduces new challenges in intrusion detection.

Hackers have taken the old practice of war dialing to the next level with the use of war driving attacks. These simple attacks are passive in nature. The perpetrator simply drives up and down city streets with a wireless-enabled laptop looking for active network signals. This can be done with tools like NetStumbler (which is even available in a PocketPC edition) or with the built-in capability of Windows XP to search out Wireless Access Points (WAPs).

What's an intrusion-detection conscious network administrator to do? Actually, the best starting point is to implement a solid base of traditional intrusion-detection systems designed to detect malicious activity on your network. Chances are that hackers sneaking in through your wireless network will attempt to perform the same malicious activities that they would when sneaking in through a wired network. Once you have that in place, you may wish to consider implementing special measures to deal with two common concerns: unauthorized wireless clients and unauthorized wireless access points.

The issue of detecting unauthorized clients can be somewhat tricky. If you have a finite number of authorized clients, you can simply monitor the wireless network for unfamiliar users. However, networks that provide public access present a thornier issue. Your best bet is to rely upon traditional IDS technology to seek out patterns of malicious activity that require investigation. Additionally, you should watch your networks for the familiar signatures of wireless LAN discovery tools. Joshua Wright has written an excellent white paper on this topic.

Unauthorized access points are a common issue in organizations. All too often, overly ambitious employees decide to plug in a WAP without seeking permission from the MIS organization and unwittingly open up significant security vulnerabilities on the network network perimeter. Fortunately, these rouge WAPs are relatively easy to detect, provided that you're willing to expend a little bit of effort. If your organization uses a single small facility, you can probably simply run a tool like NetStumbler on a single system sitting on your desk and watch for unauthorized access points to appear in your vicinity. Larger facilities and distributed campuses may require a number of sensors strategically placed throughout the organization to provide comprehensive coverage.

Of course, intrusion detection is only one component of a solid security posture. If you're looking for proactive ways to keep intruders off your wireless network, consider implementing the security-conscious 802.11X protocol.

About the author
Mike Chapple, CISSP, currently serves as Chief Information Officer of the Brand Institute, a Miami-based marketing consultancy. He previously worked as an information security researcher for the U.S. National Security Agency. His publishing credits include the TICSA Training Guide from Que Publishing, the CISSP Study Guide from Sybex and the upcoming SANS GSEC Prep Guide from John Wiley. He's also the About.com Guide to Databases.


Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Network Security
Application-specific network intrusion detection systems emerge
Anomaly-based intrusion protection configuration and installation
Preventing hacker attacks with network behavior analysis IPS
Rogue access points: Preventing, detecting and handling best practices
The TPM chip: An unexploited resource for network security
Shifting defenses and dynamic perimeters challenge network security
Compliance in a virtualized world: Server virtualization and NAC security
Securing the new network architecture: Security for distributed, dynamic networks
How to configure Windows Server 2008 advanced firewall MMC snap-in
USB storage devices: Two ways to stop the threat to network security

Wireless LAN Implementation
802.11n wireless APs bring IP video to sprawling Illinois high school
No data cable? Wireless mesh networking the answer for Wi-Fi backhaul
Integrated wireless and wired LAN: Brocade-Motorola deal ups the ante
802.11n WLAN architecture strategies: The 2.4 vs. 5 GHz band debate
802.11n upgrade: College ditches legacy network for new vendor
802.11n ratification will drive down wireless LAN prices
How does Wi-Fi ad-hoc mode react when 802.11n and legacy peers are present?
How to plan for 802.11n wireless LAN upgrades
Wireless LAN supply chain shortages: Vendors struggle to deliver
Can wireless adapters operate as client access points to make SoftAPs?

Wireless Networks
How to plan for 802.11n wireless LAN upgrades
Deploying 802.11n access points: Best practices
Rogue access points: Preventing, detecting and handling best practices
Persistent, secure connections for roaming WiMAX, 3G and 802.11x
Securing embedded 802.11n devices
802.11n's impact on WLAN security
Set up secure wireless networks with 802.11x, access points and bridges
How to use Netsh WLAN to configure Windows Server 2008 and Windows Vista wireless connections from the CLI
How to avoid the WPA wireless security standard attack
IEEE 802.11w protects wireless LAN management frames

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
802.11a  (SearchNetworking.com)
Asynchronous Pulsed Radiated Incident Light  (SearchNetworking.com)
beamforming  (SearchNetworking.com)
cognitive radio  (SearchNetworking.com)
direct sequence spread spectrum  (SearchNetworking.com)
frequency-hopping spread spectrum  (SearchNetworking.com)
phase-locked loop  (SearchNetworking.com)
radio frequency  (SearchNetworking.com)
wireless mesh network  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business

Alcatel-Lucent Network Business Communications Solutions

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts