* Considerations in Wi-Fi IDS/IPS
Human nature being what it is, you pretty much have to run wireless monitoring for intrusion detection and prevention even if you have a “no-Wi-Fi” policy. You need to make sure that no one has plugged an unauthorized access point into your wired LAN, through which attackers could conduct misdeeds.
Wireless LAN monitoring systems allow you to continually scan the 802.11 airwaves for security and performance purposes. Because this product area is getting quite competitive, vendors are working aggressively to stay a step ahead of one another – so the systems are growing pretty sophisticated at detecting intrusions and taking automated action to prevent them.
These systems come in various shapes and sizes from companies such as AirDefense, AirMagnet, AirTight, BlueSocket, Network Chemistry, Newbury Networks and several of the Wi-Fi systems vendors. Here are a few points to think about when considering a Wi-Fi monitoring solution for your network:
* Do you prefer an overlay Wi-Fi monitoring network or one in which the Wi-Fi access points you use for traffic forwarding can double as monitoring sensors?
* Where does the processing of security events take place – in sensors at the distributed sites, in a centralized server, in some combination of these locations, or elsewhere? There are possible bandwidth limitations associated with sending all distributed information back to a central location for processing. But there are also potential event-correlation drawbacks to having all processing conducted in the remote sites. Have potential suppliers talk you through these issues.
* Can the system automatically disable rogue devices that are connected to your network? Can it do so both using location tracking and wired switch-port tracing and shutdown?
* In what format do you receive reports about wireless conditions and activity? Are the reports usable and digestible to you – or do you need a degree in physics to read them?
* There are vendor wars going on about how many alerts each system can support. Determine whether the sheer number of available alerts, or the number of alerts balanced with the level of automated preventive activity supported by the system, is more important.




