Information Technology News
Who’s on first? Wireless network security with Linux | Who’s on first? Wireless network security with Linux |
|
| by David M Williams | |
| Tuesday, 06 November 2007 | |
|
Page 2 of 3 Ideally, your hardware also supports MAC address filtering. This means you can configure your access point so only wireless cards with specific MAC addresses can connect to it. Practically, in a large organisation, this may be difficult to implement because it requires vigilant maintenance whenever new machines are purchased, and whenever older equipment is decommissioned. Nevertheless, if feasible, this adds another layer of security. It’s possible someone can still spoof a “good” MAC address, but this requires existing knowledge of your network.
Featured Whitepaper
5 Best Practices for Smartphone Support
One of the simplest attacks that can be perpetrated against you is denial of service. It’s important to know if any factors in your environment can affect your wireless signal quality, like microwave ovens, cordless telephones or even competing wireless networks from your neighbours. Apart from these, proactive routine testing of drops in signal strength along with unknown access points and devices with unknown MAC addresses will be possible hints of malicious activity. A DoS attack can be carried out in several ways, but there are three major methods. The first is – like in the wired world – to connect to the network and begin sending relentless packets against important internal machines such as a mail server or DNS server or a router. Alternatively, and this is unique to wireless networks, a hostile person need not even bother connecting to your network; they need not even have a WiFi card. Instead, an object known to cause interference could be physically placed inside the wireless network’s perimeter.
Or, an attacker might configure a new wireless AP with the same SSID as you use, but without this AP being connected anywhere. Computers located close to where this AP is situated would strive to connect to it, and either succeed – with no communication possible – or fail, with the same result.
Not all attackers are necessarily malicious; it’s not uncommon for people to try and leech free Internet access so they can check mail or surf the web or do other things. Unexpected high bandwidth consumption can tip you off this is happening. As before, be sure to review logs; you might discover high usage during the night hours when you know that legitimate users only operate during daylight hours, for example.
|
| < Next story in category | Previous story in the category > |
|---|







