Saturday July 4, 2009 6:08 PM AEST
 
Latest Comments
"nothing"
by UMAIR | Jul 4, 2009 5:54 PM
 
"Thank you "
by Dr. Holub | Jul 4, 2009 11:17 AM
 
"Agree that wireless hotspots are an easy way for hackers to gather information from connected ..."
by Patrick Hooper | Jul 3, 2009 4:06 AM
 
"Katarzyna what has this got to do with Symantec?? "
by PaulC | Jul 2, 2009 12:55 PM
 
"Hi Nadim, I'm the chief marketing officer at Ounce Labs, and I disagree with your statement. ..."
by Jennifer Sullivan | Jun 30, 2009 11:56 PM

Securing Wi-Fi must be priority

  • Email a Friend
  • Print Page
By Dan Kaplan
Apr 30, 2008 2:19 PM
Tags: From | Interop | Securing | Wi-Fi | must | be | priority
As the use of Wi-Fi by businesses becomes more pervasive, IT departments must rethink their wireless security strategy to combat threats, a panel said Tuesday at the Interop conference in Las Vegas.
As the use of Wi-Fi by businesses becomes more pervasive, IT departments must rethink their security strategy, a panel said Tuesday at the Interop conference in Las Vegas.

“Wireless is a different medium and presents different challenges that we faced with wired,” said David King, chairman and chief executive officer of AirTight Networks, makers of wireless intrusion prevention systems. “All the borders and boundaries that used to exist at the physical level are gone. The perimeter has to be redefined.”

Panel moderator Lisa Phifer, vice president of Core Competence, a network security consultancy, said businesses must take note of the growing popularity of WiFi, especially as the technology moves to mission-critical devices uses for manufacturing and inventory control.

But many companies face a slew of common wireless vulnerabilities that, if exploited, could lead to the next large-scale data breach, such as TJX, he said.

Flaws include rogue and misconfigured access points (APs), unauthorized clients, client misassociations – authorised clients that errantly connect to a neighboring network – and ad-hoc connections – a two-way connection that does not go through proper security checks.

Meanwhile, threats include denial-of-service attacks and honeypot APs, which falsely advertise themselves as a free, available wireless network, King said. End-users often fall for the bait.

“They want to attach and, to any extent possible, they want to get it for free,” King said.

More threats are on the horizon, especially as wireless-enabled portable devices, such as iPhone, become more prominent in the workplace, King said.

Increased risks are also sure to come from the wireless networking standard 802.11n, a proposed amendment that will allow wireless signals to travel further than ever before, which will permit wireless devices to become more visible to more people, he said. Meanwhile, voice over Wi-Fi (VoWiFi), a wireless-based VoIP service, may open to door to emerging threats.

Applying the latest WPA2 encryption standard and a holistic technology offering, which includes vulnerability management capabilities, can help, King said.

Greg Murphy, chief operating officer of AirWave Wireless, provider of wireless network management software, said defining access control rights and creating centralised policy is paramount to protecting a company's wireless infrastructure.

Murphy also recommended keeping up with vendor patches for devices, maintaining accurate infrastructure inventory and to track and locate lost and stolen devices on one's network.

John Steiner, LAN (local area network) coordinator for the Fargo, N.D. public school district and one of about 200 audience members, said the panel made him think about some of risks his end-users may encounter.

Particularly, he said he needs to investigate some of the trouble that could result from wireless devices connecting to potentially malicious access points.

“That's something that hadn't occurred to me,” Steiner told SCMagazineUS.com afterward. “I don't know…what they might bring back when they connect again [to our network.] Our users are generally naïve when it comes to security issues, as most end-users are.”

David Cohen, director of product marketing for Trapeze Networks, also participated in the panel.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Exclusive Data Centre - Sponsored Content by Microsoft
 
Mobile Whitepapers