The Habit: or There and Back Again to the NISTy Mountains

Opinion
Feb 17, 20093 mins

* Into the NIST documents: Securing wireless systems

Like Bilbo Baggins of Bag End, Hobbiton, whose story “There and Back Again” I have read and reread with pleasure over five decades, I find myself returning many times to favorite haunts such as the NIST list of Special Publications to see how my old friends are doing with their books of wisdom and dragon-slaying lore.

Like Bilbo Baggins of Bag End, Hobbiton, whose story “There and Back Again” Book of Westmarch I have read and reread with pleasure over five decades, I find myself returning many times to favorite haunts such as the National Institute of Standards and Technologies (NIST) list of Special Publications (SP) to see how my old friends are doing with their books of wisdom and dragon-slaying lore.

The 800-series of SPs are focused on computer security. The simple three-part flier called “Roadmap to NIST Information Security Documents” provides a simple list to help beginners identify which document fits specific needs. The“Guide to NIST Information Security Documents” provides a more detailed overview of the publications.

36-page

Today I’ll begin an extensive series looking at a number of recently released SPs and revisions of established SPs dealing with security of a wide range of devices and practices.

The first topic is securing wireless systems.

Distinguished NIST computer scientist Karen Scarfone and coauthors Derrick T. Dicoi, Matthew Sexton and Cyrus Tibbs have updated Special Publication 800-48 for Revision 1, published in July 2008: “Guide to Securing Legacy IEEE 802.11 Wireless Networks: Recommendations of the National Institute of Standards and Technology.” The original version was published in November 2002 and was called “Wireless Network Security: 802.11, Bluetooth, and Handheld Devices.”

The authors explain that the older IEEE 802.11a, b and g standards are fundamentally weak technologies that have been superseded by the 802.11i standard introduced in 2004 and by the upcoming 802.11n standard begun in 2006 and expected to be completed in 2009. “Legacy” wireless standards, in this context, are defined as “those that are not capable of using the IEEE 802.11i security standard.”

SP800-48r1 serves as a primer on legacy wireless technologies, their weaknesses, and practical guidelines for securing such systems until users can convert to the more secure IEEE 802.11i/n standards. The authors write explain each of the following recommendations in detail:

• Organizations should be aware of the technical and security implications of legacy WLAN technologies.

• Organizations should create a wireless networking security policy that addresses legacy IEEE 802.11 WLAN security.

• Organizations should be aware that physical security controls are especially important in a wireless environment.

• Organizations needing to protect the confidentiality and integrity of their legacy WLAN communications should implement additional security controls.

• Organizations should configure their legacy IEEE 802.11 APs to support the WLAN’s security.

• Organizations should properly secure their legacy IEEE 802.11 client devices to enhance the WLAN’s security posture.

The 50-page manual is a good use of our tax dollars. Download this free document and use it as the basis for some serious discussions among your technical crew.

Don’t let Smaug eat your wireless network.

In the next column, we’ll look at NIST guidance on securing wireless networks using IEEE 802.11i technology.