Wi-Fi Security Gets a Boost
802.11i standard will plug security holes, but products may not be available for almost a year.
Stephen Lawson, IDG News Service
The IEEE 802.11i standard will plug all known security holes in IEEE 802.11 wireless LANs, also known as Wi-Fi, but probably won't see final approval or shipping products until about a year from now, according to an Intel network architect involved in the drafting of the standard who spoke at Intel's Spring Developer Forum last week.
However, technical advances already available can make wireless LANs far more secure than they originally were. Also, to give themselves some protection, many companies could start by simply using what came with 802.11 to start with, said a Cisco Systems engineer who spoke at the same session.
WEP, or Wired Equivalent Privacy, the security mechanism initially built into all standard 802.11 products, encrypts data on the wireless network but is flawed because it reuses the same encryption key, said Jesse Walker, a network architect at Intel and the editor of the 802.11i standard now in development under the Institute of Electrical and Electronics Engineers. A would-be hacker can figure out that key from a small amount of traffic, he said. WEP also doesn't stop interlopers from altering data as it crosses the network, he added.
More Secure
Effective wireless LAN security requires several parts, the engineers said. There have to be mechanisms to make sure the data is really coming from its supposed source, that it can't be seen and that it can't be modified.
"It's not enough just to have authentication. You need to have, along with that strong authentication, a strong encryption mechanism, coupled with data integrity," said Sri Sundaralingam, a technical marketing engineer at Cisco, in San Jose.
Among other improvements, 802.11i will include a system for creating fresh keys at the start of each session. It also will provide a way of checking packets to make sure they are part of a current session and not repeated by hackers to fool network users, Walker said. To manage keys, it will use RADIUS (Remote Access Dial-In User Service) to authenticate users and the IEEE 802.1x standard.
In advance of the approval of 802.11i, users should be able to give their wireless LANs a subset of the upcoming security features through a software or firmware upgrade to WPA (Wireless Protected Access), a specification adopted by the Wi-Fi Alliance, the industry group that certifies Wi-Fi products. Beginning in August, all Wi-Fi products will be equipped with WPA, Walker said.
War Driving
Wireless LANs in many companies don't even have basic protection against "war driving," in which interlopers drive by buildings or park outside and intercept wireless LAN traffic, Sundaralingam said. In some companies, managers claim the company has no wireless LANs but employees have set up their own "rogue" access points, he said.
To defend themselves against "war driving," users can simply turn on the WEP encryption that is already built in, and most war drivers will just move on to one of the many wireless LANs that isn't protected, Sundaralingam said. Going to the next step, users can implement user authentication and dynamic WEP, with keys that change, to protect themselves from "script kiddies," teenagers who use packaged hacking tools to infiltrate systems. Those authentication systems could include EAP-TLS (Extensible Authentication Protocol-Transport Level Security), PEAP (Protected EAP), or Cisco's LEAP (Lightweight EAP), which Cisco introduced as part of an effort to boost its own products' security beyond WEP for demanding enterprise customers.
For protection against professional hackers, Sundaralingam recommended going the next step to strong encryption systems such as TKIP (Temporal Key Integrity Protocol), which will be used in WPA and 802.11i, or CKIP (Cisco Key Integrity Protocol), a proprietary implementation of the 802.11i recommendations that Cisco developed as a stop-gap measure.
As stronger industry-standard security mechanisms become available, Cisco will offer them but also continue to support its own protocols for some time to serve customers that want to use them, Sundaralingam said.
"As a company, we're really happy to see [WPA] gain wide momentum, and very soon it's going to be supported by multiple vendors," he said.
Microsoft Office Home and Student 2007
The Best of PC World
Featured APC Accessories
-
APC Back-UPS ES
Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
- APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.
People who read this also read:
Best Prices on Wireless Routers
WRT54G2 Wireless RouterPrice: $21.50
WRT610N Dual-N Band Wireless RouterPrice: $158.99
DI-655 Xtreme N Gigabit RouterPrice: $75.99
Wireless-N Home Wireless RouterPrice: $59.70
WNDR3700 RangeMax Dual Band Wireless RouterPrice: $159.99
Dual-Band Wireless-N Gigabit Wireless RouterPrice: $109.99
- 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
- A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.
Cameras
Camcorders
Cell Phones
Components
Desktops
HDTV
Home Theater
GPS
Laptops
Monitors
MP3 Players
Networking &
Printers
Storage








