Wireless security problem is a big time issue for any corporate and almost all of them constantly monitor there wireless connection for an intrusion detection. What are these threats?
- Bandwidth thieves: taking away your wireless bandwidth and get free internet or LAN access causing heavy congestion for other legitimate
- Point of attacks: an attacker can alter the settings of any other machine using your wireless network as a point of attack and may proceed with distribution of illegal or pirated software, music or pornographic content.
- Resource access: can gain access to shared content on the network or on your personal computer and can View, modify, copy or even delete these resources using the wireless network
- Infection: this is the main pain area where on daily basis machines are being compromised with viruses, worms, Trojans, malware and spyware etc.
- DOS attacks: A denial of service attack can be triggered to crash a system or server or service which can cause the ultimate damage, major downtimes can cost major loads of cash to the organization
Wireless security Tips for small companies
- Use static IP addresses as much as you can and avoid DHCP leased IP's on the wireless router. By doing this an un-authorized stranger will not get a local IP to access the resource on the network.
- Put your wireless access points in directions or places where the scope of intrusion is less. Avoid using high ranged antenna's as they could stretch your wireless courage area.
- Turn of WAP if you don't need wireless on daily basis other than assisting a partner or employee or a visitor to connect to internet through your wireless connection.
- Keep changing the default SSID every month and push the new SSID to only computer which are part of domain via group policy only. Also make sure the SSID broadcasting is turned off as avoid displaying your wireless in the list of available networks.
- Enable MAC filtering for those clients who are going to connect via wireless connection. And any new unidentified connection will not pass through wireless router's MAC filter table.
Wireless security Tips for large companies
- Make sure your wireless connection is supported by hardware/software based Firewalls. Always implement your wireless connections in a DMZ, a kind of perimeter network, for the only reason incase the connection get compromised it does not affect your wired LAN. Moreover let the user use a VPN connection after connected to WLAN to get inside the wired network LAN.
- Monitor all your traffic with Intrusion detect systems (IDS) or response sensors on the wireless network. Make full use of NAP (network access protection) to manage and configure your wireless clients to put them through a quarantine state before they could be allowed to enter your network.
Keep testing your wireless connection and find the ways in which it could be compromised to put a fix to such a void. The more you identify the threats, the better you can fix them.
Leave a Comment