joanie_wexler
Writer

Do we really need rogue AP detection?

Opinion
Nov 17, 20043 mins

* Many ways to keep intruders off your WLAN

Theoretically, if enterprises properly implement current wireless LAN security standards, rogue (unauthorized) access points shouldn’t allow intruders to sneak onto a network. Right?

I mean, by definition, with 802.1x authentication in place, outsiders shouldn’t be able to gain network authentication. Thus, they shouldn’t be able to access any (or hardly any) network resources, depending on how the enterprise has set up its policies.

So why do we need to monitor the air for rogue APs?

The key words in this discussion, of course, are “theoretically,” “should” and “depending.” The success of authentication and access control is dependent upon implementation level and proper configuration.

In practicality, many older forms of WLAN security that don’t use 802.1x are still in use. In many of those cases, unblessed APs could plug right into an Ethernet port and unauthorized users attached to that AP could start accessing network resources, if no other credential-checking systems have been set up.

That’s one reason we need and will continue to need rogue AP detection. And it’s why some WLAN monitoring specialists are strengthening the degree of automation in their rogue intrusion detection/prevention systems.

AirMagnet, for example, recently upgraded the centralized flavor of its WLAN monitoring system, now called AirMagnet Enterprise. The latest version, 5.0, not only discovers if a wireless rogue device has found its way onto the WLAN; it will instruct the wired Ethernet switch to block the port to which that AP is connected. That way, the system automatically shuts down anyone accessing the wired network through the unauthorized AP (someone in the parking lot, for example).

Likewise, according to the company, the system can now automatically block rogue communications over the airwaves. You can set a policy ahead of time that says, for instance, “In our financial building, if you see a rogue AP, disable it entirely, e-mail me and page me,” says vice president of marketing Rich Mironov.

The company has also added triangulation software capabilities so that once that pesky AP has been blocked, you can locate it quickly and take appropriate action.

By way of background, the AirMagnet Enterprise architecture uses distributed “smart” sensors that perform all traffic analysis locally and forward only the result to a centralized server appliance. This way, they don’t forward all the event data over the WAN and consume multiple megabits of WAN bandwidth.  AirMagnet’s Mironov claims that the company uses just “2% of the WAN bandwidth of alternate solutions” – by which he means, primarily, AirMagnet’s main competitor, AirDefense.

Speaking of AirDefense, aside from its recently reported integration efforts with Cisco, the company has also upgraded its own software, and some start-ups have also joined the WLAN intrusion-detection crowd. More on those developments in a future newsletter.

joanie_wexler
Writer

Joanie Wexler is an independent writer and editor who has spent 20+ years writing about computer networking technologies, their business potential, and implementation considerations. She serves clients at technology companies and industry publications writing educational materials on all aspects of IT.

More from this author