Wi-Fi Standards, Bluetooth, Securing WAPs, Using Captive Portals, Wireless Attacks
6 slides · 5 min read · Domain 4
Wi-Fi Standards, Bluetooth, Securing WAPs, Using Captive Portals, Wireless Attacks
Wi-Fl Standards
Wireless network communications are governed by the IEEE 802.11 standard. Evolution of the standard is published through amendments, which document updated versions of the original standard. Each version or amendment to the 802.11 standard offered improved maximum data rates. 802.11x is often used to indicate all of the specific implementations as a collective whole, but that is not preferred over a general reference to 802.11.
Do not confuse 802.11x with 802.1x - the first is a Wi-Fi standard and the second is an authentication technology not related to wireless.
Authentication of wireless devices is often done with protocols such as EAP, PEAP, and a lighter-weight version of PEAP called (predictably enough) LEAP.
Bluetooth
Although Bluetooth does not actually provide a wireless Ethernet network standard, the technology does support wireless transmissions point to point over a short distance. In general use, the maximum effective distance is about 30 feet. However, there are industrial or advanced versions of Bluetooth that can reach 300 feet. Many types of endpoint devices support Bluetooth, such as mobile phones, laptops, printers, radios, digital personal assistants, along with an increasing number of other loT devices.
The benefits of Bluetooth are that it does not require base stations as it is a direct connection between devices. It also requires very little power, which is good for use with the battery-operated end devices that typically feature Bluetooth. There are also a few downsides. The transmission speed is slower than the 802.11b wireless standard. It conflicts and interferes with existing 802.11b and 802.11g networks as it uses the 2.4 CHz broadcasting spectrum, causing problems for endpoint devices relying on the transmissions.
Another significant downside is Bluetooth's inherent weakness due to its lack of encryption. Using Bluetooth to create a personal area network (PAN) carries security implications, too, since a PAN most likely has vulnerabilities, but those vulnerabilities are not easily identified by corporate sweeps. The reason is that a PAN is a non-routable section or extension of an existing LAN or WAN, making it not easily assessed.
Securing Wireless Access Points (WAPs)
Wireless access points are a type of wired-to-wireless router, which brokers the connection of wireless devices to the wired network infrastructure. Depending upon the type of access point and its configuration, this usually requires the access point to authenticate devices prior to allowing them to connect. DHCP plays a role in this, as do other Wi-Fi Standards firewall features built into the Wi-Fi access point. Based on access control and required frequency values, these access points permit devices to connect.
Even with access controls and frequency settings, a security issue can result from a wireless access point that has a broadcast beacon that is set too powerfully and sends its beacon far beyond the necessary range. Whether broadcasting the beacon far away is seen as an advantage, say to roaming users, is a decision left to the company.
This allows an unwanted wireless device the ability to connect even if the end user is prohibited from accessing the physical area where the wireless access point is installed. In short, securing the wireless access point requires attention to proper placement of the device, shielding it, and limiting noise transmission while satisfying customer need to connect.
Using Captive Portals Captive portals are authentication safeguards for many wireless networks implemented for public use, such as at hotels, restaurants, bars, airports, libraries, and so on. They are a common practice on wired networks, too.
The process is to force a newly connected device to a starting page to establish authorized access. The portal may require input of credentials, payment, or an access code. It is also a good location to publish or provide a link to privacy policies and acceptable use terms and conditions.
If end user consent for tracking and information collection is required, the captive portal allows for that as well. Once the end user satisfies the conditions required by the starting page, only then can they communicate across the network.
Wireless Attacks
In spite of increasing attention and capability for securing wireless networks, they are attractive targets for attackers. The types of attacks continue to grow, and many attacks are effective on wired networks as well as wireless ones. Attacks such as packet sniffing, MITM, and password theft are common to both wireless and wired networks. A few types of attacks focus on wireless networks alone, like signal jamming attacks and a special collection of wireless attacks called war driving.
Countermeasures to wireless attacks include physical, administrative, and technical, and should also consider including:
- Periodic radio frequency (RF) site surveys to search for possible rogue
access points attempting to lure legitimate devices to attach to them
- Analysis of WAP logs
- Using captive portals and other approaches to validate device health (including the update and patch levels of all software and the integrity of organizational data on the device, if any) prior to allowing connection to proceed
- Administrative policies regarding physical areas in which guest Wi-Fi devices can and cannot be used
- Rule-based control of WAPS to prevent their illicit use outside of normal work hours
For further reading on the matter of Wi-Fi security, please see this article: https://www.howtogeek.com/204697/wifi-security-should-you-use-wpa2-aes-wpa2tkip-or-both/amp/
