AirMagnet still reigns, but others closing in
In 2004 we tested several wireless LAN protocol analyzers and found two distinct characteristics: Those dedicated and built from the ground up for WLANs, and those that were modest add-ons to what were then labeled classic protocol analyzer products.
Three years later, much has changed, but much has remained the same. The products have grown, some more than others. After subjecting the latest products to several problem identification tests, we found that AirMagnet Laptop is still the one to beat, because it excels at 802.11-specific analysis. Its rapid analysis and accuracy clearly are at the top of the list. But AirMagnet has considerable and highly evolved competition, so it’s going to be difficult for the company to maintain its lead in this area.
We asked for tactical WLAN protocol analyzers, with an emphasis on portability as well as the ability to do spectrum analysis. Three of the four products tested (Fluke’s OptiView III, WildPackets’ OmniPeek Enterprise and AirMagnet Laptop) use the same card, running the WLAN/Wi-Fi spectrum analysis with largely the same application. None of the vendors that submitted this card (a great one from Cognio) did anything special to relate spectrum analysis to their application.
It’s like having a drill and a circular saw in the toolbox; they’re important but unrelated to the core WLAN protocol-analysis applications tested. The fourth product tested, Sniffer Portable from Network General, did not provide spectrum analysis.
All of the products except Fluke’s OptiView III used distributed sensor networks to feed data to a central engine. How the data is reviewed is treated differently among the applications. WildPackets and Network General offer a data view that is round-robin, meaning one sensor at a time, although alarms can be sent, received and reviewed via one console. Otherwise, sensors are treated as separate objects. AirMagnet goes further, treating sensors as objects and offering more empirical object (meaning parental) management of sensors. Fluke’s OptiView III is a stand-alone tool, and is not really designed for distributed sensor use, but rather as a tactical Swiss Army knife-like tool set.
Sensors (when used) come in two categories – a notebook PC (desktops will work for branches and fixed locations as long as they have a wireless card) or a dedicated sensor device, similar to a wireless access point. We reviewed AirMagnet’s and WildPackets’ sensors (www.nwdocfinder.com/8321 and /8322). These sensors send information to a mother-ship engine that in turn serves as a viewing and manipulation/reporting point for captured data.
The differences in these approaches help define the use of the products with distributed sensor capabilities. Two categories emerge – one in which a product serves as a 24/7 monitoring tool, much like an SNMP tool kit that monitors and watches a network; the second category works more like a tactical field-service tool kit. The overlapping features for these categories are defined by the vendors – all but Fluke take an overlapping approach.
Fluke OptiView III
The Fluke system is based on a portable PC running Windows XP with Service Pack 2. The device has a touch-screen, and as a base platform runs wireline, Gigabit Ethernet-speed protocol and SNMP analysis. It has an external battery attachment (which it needs when not connected to AC power) and a heavy-duty carrying case. It’s more durable than a typical tablet PC. While the Gigabit Ethernet, fiber and extensive wireline capabilities weren’t needed for our WLAN needs, we liked them anyway.
In previous tests, OptiView II, based on the same basic hardware platform, wasn’t really up to snuff. It had only remedial tools, and was deficient in terms of overall usability. This was disheartening, because this $20,000 tool had very good, if not legendary, wireline analysis.
The good news is that Fluke has paid a great deal of attention to evolving its WLAN analysis with OptiView III. The OPVS3-GIG/W version we tested comes with WLAN analysis grafted as a separate application. We also tested the AirAnalyzer option, which uses something common to the other products we tried – the aforementioned Cognio spectrum analyzer CardBus adapter.
OptiView III comes ready to go. There are no drivers to hunt down, no hardware-matching needed, which we found very convenient. The device plays two roles specific to WLANs – through the features of the AirAnalyzer application that’s based on the Windows XP SP2 base platform, or those used in conjunction with the spectrum analyzer. There are limited remote distributed-use possibilities, as the WLAN analysis only works with the OptiView III platform.
In testing, OptiView III saw our attacks (see “How we did it,” above), but described them as excessive numbers of unauthorized devices rather than articulating the attack as a flood or even the exact type. While the device could discern multiple media access control (MAC) addresses with the same IP as a problem, it didn’t even come close to articulating the exact nature of the attack, or come even close. The other analysis engines in the other three products tested found increasingly articulate ways to describe the problem.
OptiView III’s WLAN monitoring software generates HTML reports. Alarms can’t be sent or communicated elsewhere, making this a field device rather than a monitoring tool.
WildPackets OmniPeek For Windows 4.1
WildPackets markets several versions of OmniPeek with increasing feature sets, up to the OmniPeek Enterprise version with Enhanced Voice Option. We were sent the OmniPeek Workgroup Pro version to test. OmniPeek runs on engines that can be located in remote locations (think branches), letting OmniPeek peek in on branch operations for diagnostic purposes. It’s a Windows XP SP2-only platform that tracks many protocols, including VoIP.
OmniPeek’s analyzing method has an interesting architecture: Everything is ignored unless it is specifically selected to be watched. A long and rich list of protocols can be actively selected for examination, along with attack-specific filters (such as worm traffic and damaged-packet errors that indicate distributed denial-of-service attacks) and packets associated with specific services (including DNS requests, VoIP and HTTP traffic). Filters can be constructed and turned on, leaving it up to operators to build what they believe will be a sufficient filter list, along with triggers. However, some conditions don’t require a quantity or quality setting; the mere appearance of a condition can be sufficient to trigger an alarm.
As previously mentioned, OmniPeek connects with the Cognio spectrum analyzer card, which lets a notebook user gauge and identify radio-frequency noise using the card’s antenna. Interfering sources can be identified, and it recognizes the interfering signal type often by device, such as a noisy microwave oven or a 2.4GHz wireless phone.
The OmniEngine core sniffing application can be remotely or locally deployed. The engine doesn’t have an easily downloadable installation routine (you need the product CD and appropriate license) for remotes, but we found installation to be reasonable, covering a spread of popular network cards.
Filters for common virus and worm traffic are available from WildPackets’ Web site. These filters can be used to set alarms in monitor mode or for later analysis of specific captures. Packet pattern matching was simple to use with the filters, and we could change them on the fly without having to stop our packet captures. You have to set up the filters to bring OmniPeek to a useful state, but this is helped dramatically with a highly useful visual filter editor.
The WLAN channels (802.11a, b and g) selection capture templates were easy to set up, and contained several selections and combinations that could be saved and progressively tailored as needed. Notes can be added to packets or portions of traces for later review as things get busy during capturing sessions. Instructions on how to set up the filters were explicit and useful, but we found it helpful to understand the types of 802.11 attacks in order to get the best results from the filters.
In testing, our MAC spoof and 802.11 authentication flood (and others) were easily detected, although the authentication flood was slightly misidentified as a multicast storm (which has similar characteristics). We built a filter to then describe how to recognize and then make an alarm from the authentication flood we’d seen. A dictionary attack also was identified in this way. The lesson we learned was to pay attention to multi-cast storms, as they may be one of several kinds of attacks – it’s a catch basin for OmniPeek, and a few custom filters will be needed.
OmniPeek can send alarms as SNMP traps to SNMP management platforms, syslog applications (and those that analyze them) or via e-mail. In this regard – messaging of alarm conditions – OmniPeek excelled over the other products tested.
OmniPeek’s reports were lacking, although this category of product is usually designed for field analysis. Reports lacked formatting or correlation, and were inarticulate compared with the other products tested. The OmniReport service, which ostensibly provides better reporting, wasn’t compatible with the Workgroup Pro version we received, so Enterprise version users may have more luck than we did.
Network General Sniffer Portable 4.90 (Decode Engine 1.06) and Sniffer Portable Field Service
Network General’s Sniffer Portable was a bit difficult to install, but when we conquered the demons (incorrect host-processor speed detection and WLAN network interface-card driver problems), we found that there have been numerous changes to the product.
On the surface, it looked like the same Sniffer GUI that we’ve seen for 20 years, and underneath, the Sniffer filters still included packet filtering for such long-lost protocols as Banyan Vines and Apollo Systems. Added inside, however, are extensive WLAN protocol components that can be identified, and the optional (but not tested) “Application Intelligence Option” can see packets from SAP, Oracle and PeopleSoft.
The Sniffer decode engine lies at the heart of Sniffer Portable, and digests packets whether wireline or WLAN. Optional versions allow for mobile phone decodes and diagnoses, but these weren’t tested as we stuck strictly to WLAN environments. Like WildPackets’ OmniPeek, distributed Sniffers can be used, but also like the OmniPeek version we tested, the data from distributed units isn’t easily amalgamated for examination. What differs is that the reporting done by Sniffer is a couple of steps ahead of OmniPeek (lacking the OmniReports Service), just by adding simple headers to reports annotating what’s on the printout/report and a date.
We subjected Sniffer Portable to our suite of tests (man-in-the-middle and dictionary attack). While the man-in-the-middle attack was detected, the dictionary attack was seen as a critical error but was identified as a Physical Layer Convergence Protocol threshold error – a packet rate problem, rather than the multicasting alarm thrown by OmniPeek. Traffic issues were also shown in the Alarm Log when we ran the dictionary attack. Sniffer Portable has a limit on how alarm conditions are communicated when it’s used as a monitoring device (rather than a field service diagnostic unit) compared with OmniPeek. When it’s in monitoring mode, only e-mail or VB script can be used to deliver alarms.
Sniffer Portable doesn’t include a spectrum-analyzer option, unlike the other three WLAN analyzers we tested. It also has a very traditional (hasn’t changed in decades) user interface that’s difficult to maneuver if you’re a novice or unsure of how protocols relate to each other. Defining filters are more difficult to perform, and has been traditionally. (OmniPeek was much easier to manipulate filters visually). Both products require a working knowledge of TCP/IP and the 802.11 basics, but assembling filters with Sniffer Portable was more difficult, while filled with all the correct options. The user interface is growing long in the tooth, despite the advanced decodes possible with the venerable Sniffer Portable.
The Expert Diagnosis portion of Sniffer Portable divides captured/seen packets into different levels, relating to views of the analyzed data. These views, in turn, can be drilled down into other views relating to statistics associated with, as an example, 802.11 problems, application problems (such as DNS errors, which we simulated), or global network errors (multicasting errors, as an example). By tabbing back and forth, a matrix of conversations between IP/MAC pairs can be seen, as well as a distribution-by-protocol chart, and even a packet decode relating to the observation made by Sniffer Expert. This portion of Sniffer Portable wasn’t quite as good or as rich in detail as OmniPeek.
Overall, Sniffer Portable advanced from the last time we looked at it. WildPackets has made a good attempt at trumping Sniffer Portable by offering a better user interface, and we’d guess that the the company’s advancements are on the backs of deficiencies we found with Sniffer Portable.
AirMagnet Laptop
Like OptiView III and OmniPeek, AirMagnet Laptop came with a Cognio Spectrum Analyzer card. AirMagnet Laptop uses an engine that is accessible by AirMagnet sensors, which can be other notebooks running licensed AirMagnet sensor applications or dedicated AirMagnet sensors (similarly to OmniPeek’s optional sensors).
AirMagnet sensors run in two modes: Enterprise Analyzer Sensor or AirMagnet Enterprise Sensor. The Enterprise Sensor mode sends information to a mother-ship node, while the Analyzer Sensor uses an application console that looks into the sensor. The server is an engine that collects sensor data for correlation in the console that provides an integrated view of the entire grid of sensors.
A Web interface permits a download of the console application (password controlled), and several users can access the engine simultaneously. The console then becomes the business end for this intrusion-detection system (IDS)/intermediate distribution frame/monitoring application.
Finding rogues
AirMagnet found the man-in-the-middle attacker as a rogue access point. The flood attacks were deemed “Suspicious activity,” which was amusingly closer to reality than the description offered by OmniPeek and Sniffer.
In our tests, AirMagnet excelled in two places. First, the user interface allows a great deal of inter-related information to be shown on screen. This big-picture console display let us watch attacks and get detailed information from several perspectives concurrently. Second, AirMagnet’s diagnostic feature is an articulate description of what is being seen. Highly detailed information about alarms and detailed references are shown so that captured alarm information can be understood by the operator. This lets operators assign priorities, knowing how AirMagnet has judged the traffic it is seeing – and more importantly, why it’s alarming. This information is invaluable, as the errors found among WLAN protocol analyzers aren’t often called by the same description. The detective work of determining the seriousness of an error or alarm is more rapidly discerned as a result. The AirMagnet user interface is the antithesis of command-line-interface information.
In monitoring mode, AirMagnet lets you assign different roles to users. Some may have full administrative capabilities, while others can see but not acknowledge alarms that have been found. The AirMagnet console-monitoring application is available as an HTTP download from the main data-collection server so that rapid access to problems that require the use of the console can be accommodated throughout the enterprise.
Alarm conditions can spawn syslog messages, e-mail, SNMP traps, pager, instant messages or Short Message Service messages. The system supports connection to other wireline IDS software, but we didn’t test this. Notification rules can be set on a per-alarm basis.
Analyzing the analyzers
The field has improved since our last test. While AirMagnet Laptop remains on top, WildPackets’ OmniPeek is becoming tough competition. But the trend towards multiple options make price comparisons more difficult and hazy. Network General’s Sniffer Portable is aging, but remains a tool by which others are compared because of its initial prominence in the market. And Fluke’s OptiView III has once again become a good tool – while not really useful as a 24/7 monitor, it begs to be hung around our shoulder as we crawl through rafters in search of WLAN problems – just not attacks.
Henderson is principal researcher and Dvorak is a researcher for ExtremeLabs in Indianapolis. They can be reached at thenderson@extremelabs.com.




