joanie_wexler
Writer

Virtualization and wireless nets

Opinion
Nov 9, 20103 mins

* Virtualized client devices become the vulnerable link

The virtualization craze is hitting all aspects of IT, and wireless is no exception.  

In the Wi-Fi arena, Meru Networks introduced virtualization years ago with its “virtual cell” technology, which pools access points together such that they appear to be one big resource to the controller. And Aerohive and Bluesocket have VMware-based, virtualized versions of their respective management and controller appliances.

The hottest virtualization products at VMworld

Most recently, virtualization has been moving toward Wi-Fi client devices in the form of so-called “soft APs.”  These are basically Wi-Fi adapters that can simultaneously serve as both a secured client station and an open AP. In other words, they can share an authorized network connection with other Wi-Fi devices.

This embedded function offers the same capabilities as small Novatel MiFi and Sierra Wireless Overdrive hotspot devices offered by the major carriers (except AT&T) for creating a mobile hotspot of your own. 

This trend is a positive one in terms of getting more people and devices affordably connected. Yet it’s also one reason that client devices are becoming a bigger target for hackers and likely another reason to seriously consider wireless intrusion-prevention systems that monitor over-the-air network traffic.

Enterprises tend to focus their security efforts on battening down corporate APs. So attackers have turned to targeting client devices — in part because there are so many to choose from. And those clients’ newfound virtual capabilities turn secured connections into an unmanaged bridge into the corporate network that hackers can use to get inside.

Client vulnerabilities and exploits are trickier to detect than unauthorized (“rogue”) APs. Rogue APs at least remain relatively static and there are far fewer of them to keep track of than clients.

Increasingly, then, clients require stateful monitoring and analysis of the network traffic that is in the air — the way wired intrusion detection/prevention systems statefully monitor and analyze actual traffic on the wired network. Relying on your wired-side IDS/IPS doesn’t work in these cases, because by the time the outsider has gained wired network access, the connection looks legit (it appears to be the authorized client).

It’s a good idea to ask your soft AP supplier — whether that’s Microsoft with its Windows 7 OS, Sprint or Verizon selling you a tiny mobile AP or an embedded soft AP in an Android phone — what the risks are and what security measures they offer. If they begin to hem and haw, you might want to consult with wireless security experts at the likes of AirMagnet/Fluke Networks, Motorola/AirDefense and AirTight Networks.

joanie_wexler
Writer

Joanie Wexler is an independent writer and editor who has spent 20+ years writing about computer networking technologies, their business potential, and implementation considerations. She serves clients at technology companies and industry publications writing educational materials on all aspects of IT.

More from this author