Keep pace with WLAN security developments

ANALYSIS
Deploying first-rate wireless security tools is a worthless endeavor if the enterprise is not diligent in keeping them current. Not updating security in access points and other gear can be worse than having no security at all. Some companies are so skittish about WLAN security that they refuse to deploy it -- even if their enterprises are prime candidates for its benefits -- despite the availability of tools that can make their WLAN as secure as a wired network. Some executives just don't want to risk deploying a WLAN. Devin Akin, the CTO of Planet3 Wireless, says, "This is perfectly valid if they do not understand the technology. Most people don't. That's one of the problems. It falls back to educating the user, the installer, and the administrator." To get a better view of the problems with this technology, the ways to combat those problems, and the new security trends, here is a closer look at wireless security from the CIO perspective. Turn on security and use it
The two biggest problems with WLAN security -- outside of the lack of education among users -- are:
  • The security that comes loaded with access points and related gear is not turned on.
  • The current security standard -- the Wired Equivalent Privacy (WEP) -- is thought by many to be insecure. There are, however, workarounds to the most obvious faults of WEP.
An enterprise using WEP should be careful of how it is deployed and administered. To show how many enterprises were not taking adequate precautions with WEP, Brice Clark, worldwide director of strategy and business planning for Hewlett-Packard Company's HP ProCurve Networking Business, referred to research that was done by International Data Corporation (IDC) on WLAN security. IDC commissioned wireless detection flights over San Francisco and San Diego that revealed that a majority of access points run in a default mode that broadcasts service set identifiers (SSIDs). A great majority of organisations were found not to use WEP, and those that did were found to operate it in an inadequate manner. Setting and enforcing a solid wireless security policy, of course, can largely diminish this improper use of WLAN. Set a clear policy
Setting a policy means making security priorities clear to employees. For instance, they must be told in no uncertain terms that it is not okay to stop by Radio Shack or Best Buy and pick up a wireless access point to plug into the Ethernet port at the office. Doing so creates rogue access points that are outside the realm of the enterprise's security infrastructure and can lead to lost data. The bookend to a clear security policy is enforcement. This means having the right tools on hand to test for the presence of rouge access points. "Another important step is strong policy control on the network side," says Sandeep Singhal, CTO of wireless security vendor ReefEdge. Different levels of access must be established for different people using the WLAN. For instance, the CTO should have more wireless access than an account executive. Singhal also recommends security validation testing. This ensures that configurations are set up correctly and are doing their jobs. "As with any network that faces the public, ongoing intrusion detection is important as well," Singhal says. Joel Snyder, a senior partner for Opus One, says that it's important to do something as simple as switching the WEP key periodically. "The least you can do is change it," he says. "That will help." Hope is on the horizon
A new approach to WLAN security is emerging. There are hopes that the wide-scale acceptance of WLANs and the resulting publicity around security issues is making people more aware of the issues and, therefore, less careless. The standard itself is changing as well. In the short term, a new standard -- WiFi Protected Access (WPA) -- will replace WEP. Over the long haul, the standard from which WPA is derived, called 802.11i, will also take over. Clearly, the industry is struggling to gets its ducks in a row even as wireless usage increases radically. For the time being, says Clark, "companies can be relatively safe by using WEP Weak Key Avoidance." This approach, as the name implies, bypasses the compromised elements of WEP. Also, "A key to implementing WLAN security is that it has a clear migration path," says Singhal. This can be in the form of potential software-based upgrades or the inclusion of a middleware level that handles the complexities of standards transitions independently of the security software itself. WPA has encryption and authentication layers. On the encryption layer, a concept called the temporal key integrity protocol (TKIP) is currently working its way through the IEEE's 802.11i standards committee. "TKIP will initially use RC4 encryption, but later it will implement the more secure advanced encryption standard (AES)," says Snyder. WPA authentication is being developed under a framework referred to as 802.1x. Under this framework, many possible authentication protocols or methods -- from legacy approaches to two-factor approaches to certificates -- will be available to vendors and end users.
For a weekly round-up of the enterprise IT news, sign up for the
Enterpise newsletter. Find out what's where in the new Tech Update with our
Guided Tour. Tell us what you think in the
Enterprise Mailroom.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

9 minutes ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

56 minutes ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

3 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

3 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

3 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

4 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

4 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

7 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

8 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

8 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

9 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

10 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

12 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

20 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

1 day ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

1 day ago by k0tcs3 on US indicts Romanian over NASA climate change hack
Random_Error

I think he's referring specifically to Android apps, as Apple do regulate their App Store, but Google seem to let any old crap onto the Android store!

1 day ago by Random_Error on RIM: BlackBerry will keep 'garbage' apps out of store