Not Far From It Now

Sunday, December 7, 2008

 

Securing Wireless Networks Internally

WEP, WPA/WPA2, and the associated authentication methods are designed to keep invaders out. However, it has become increasingly easier to crack WEP encrypted networks and cracking WPA/WPA2 networks is difficult, but feasible. These methods help keep external users from being able to access sensitive data, but what about internal, authenticated users?

Internal wireless security is important when utilizing networks of hundreds of users. Say I have a WPA2 AES encrypted network. A normal user will connect to the network and be granted access to the internal wireless network. Unlike wired networks, wireless networks do not have switches to direct traffic to the right ports (users), therefore, every authenticated user can see everybody else's traffic. Now, with a network of hundreds of users, this can pose a problem. Once somebody is authenticated, they are free to sniff traffic, perform man-in-the-middle attacks, etc. It doesn't matter what encryption method (WEP, WPA/WPA2) was used because each authenticated user is using the same key as everyone else to encrypt their data.

For example, many universities are now creating wireless networks around campus which hundreds of students may be connected to simultaneously. What is preventing one student from logging onto the wireless and sniffing all traffic from the gateway until he gets some passwords? Information like that can be used to access someone's email account and once your email account is compromised, you're hosed (hint, "Forgot Password?")

The standard solution to this problem is VPN tunnels. Here's an example, a user joins an open access point provided by the company. When he opens his browser, he is redirected to a page where he needs to download and install the VPN client. After installation, the user will login and the VPN client sets up an encrypted, independent tunnel. Now, he is safe from both external and internal hackers because every bit of his data goes through this tunnel and is encrypted. You could do a man-in-the-middle attack, but all you'll get is encrypted packets.

However, the implementation may not be an option for universities or companies who give 2 cents about user friendliness. Establishing a VPN tunnel requires a client program. That's one more program users need to install on their computers; one more program that users DO NOT want to install. Not only that, the VPN client is yet another product the IT department must support and it also creates an additional level of failure. Some product's installation procedures are less than stellar and can cause more headaches than smiles. You also have to look at how easy it will be to implement over the existing system, support options, delivery of the client, and finally, compatibility. With Windows Vista and it's dreaded UAC, installation of a VPN client has become even more of a hassle that some vendors are trying to overcome for the sake of user friendliness.

A simple solution would be to issue different, unique keys to each user. This encrypts their data with different keys and would act like a VPN tunnel. You could "MacGuyver" it and create an access point with a different key for each user, but that relies on IT "manual labor" and is vastly inefficient. However, if each user got a different key, there would be no client program (a plus for user friendliness) and no additional hardware needed if the software lies on the access point or controller.

Visit http://www.IsYouGeekedUp.com for more details

In this image released by Showtime, actress Mia Kirshner, who plays Jenny Schecter on Showtime's 'The L Word,'  is shown. The program returns for its sixth and final season on January 18. (AP Photo/Showtime, Don Flood)AP - Dead is the word when "The L Word" returns.


Comments: Post a Comment



<< Home

Archives

Jul 8, 2008   Jul 9, 2008   Jul 12, 2008   Jul 13, 2008   Jul 15, 2008   Jul 16, 2008   Jul 19, 2008   Jul 22, 2008   Jul 26, 2008   Jul 29, 2008   Jul 30, 2008   Jul 31, 2008   Aug 1, 2008   Aug 4, 2008   Aug 6, 2008   Aug 9, 2008   Aug 13, 2008   Aug 14, 2008   Aug 15, 2008   Aug 17, 2008   Aug 19, 2008   Aug 22, 2008   Aug 24, 2008   Aug 26, 2008   Aug 31, 2008   Sep 2, 2008   Sep 4, 2008   Sep 5, 2008   Sep 6, 2008   Sep 7, 2008   Sep 8, 2008   Sep 9, 2008   Sep 13, 2008   Sep 14, 2008   Sep 19, 2008   Sep 21, 2008   Sep 22, 2008   Sep 23, 2008   Oct 2, 2008   Oct 3, 2008   Oct 6, 2008   Oct 7, 2008   Oct 8, 2008   Oct 9, 2008   Oct 10, 2008   Oct 11, 2008   Oct 12, 2008   Oct 13, 2008   Oct 14, 2008   Oct 15, 2008   Oct 16, 2008   Oct 17, 2008   Oct 18, 2008   Oct 19, 2008   Oct 20, 2008   Oct 21, 2008   Oct 22, 2008   Oct 23, 2008   Oct 24, 2008   Oct 25, 2008   Oct 26, 2008   Oct 27, 2008   Oct 28, 2008   Oct 29, 2008   Oct 30, 2008   Oct 31, 2008   Nov 1, 2008   Nov 2, 2008   Nov 3, 2008   Nov 4, 2008   Nov 5, 2008   Nov 6, 2008   Nov 7, 2008   Nov 8, 2008   Nov 9, 2008   Nov 10, 2008   Nov 11, 2008   Nov 12, 2008   Nov 13, 2008   Nov 16, 2008   Nov 17, 2008   Nov 18, 2008   Nov 19, 2008   Nov 20, 2008   Nov 21, 2008   Nov 22, 2008   Nov 23, 2008   Nov 24, 2008   Nov 25, 2008   Nov 26, 2008   Nov 27, 2008   Nov 28, 2008   Nov 29, 2008   Nov 30, 2008   Dec 1, 2008   Dec 2, 2008   Dec 3, 2008   Dec 4, 2008   Dec 5, 2008   Dec 6, 2008   Dec 7, 2008   Dec 8, 2008   Dec 9, 2008   Dec 10, 2008   Dec 11, 2008   Dec 12, 2008   Dec 13, 2008   Dec 14, 2008   Dec 15, 2008   Dec 16, 2008   Dec 17, 2008   Dec 18, 2008   Dec 19, 2008   Dec 20, 2008   Dec 21, 2008   Dec 22, 2008   Dec 23, 2008   Dec 24, 2008   Dec 25, 2008   Dec 26, 2008   Dec 27, 2008   Dec 28, 2008   Dec 29, 2008   Dec 30, 2008   Dec 31, 2008   Jan 1, 2009   Jan 2, 2009   Jan 3, 2009   Jan 4, 2009   Jan 5, 2009   Jan 6, 2009   Jan 7, 2009  

This page is powered by Blogger. Isn't yours?