The ubiquitous and transient nature of wireless technology presents a constantly moving target. Wireless access points let authorized and unauthorized users gain the same level of access through the same access point. Standard network operations center tools are reactive in detecting unauthorized devices. Ping-sweeps and auto-discoveries can identify devices after they have accessed the network by comparing their results against the network map stored in a network management system database. Analyzing a new device’s management information base data to determine that it is a rogue access point is subject to misinterpretation. In addition, such network scans require time and bandwidth to complete, presenting excessive NMS traffic load and leaving a window of access open between scans. Increasing the interval of scanning only magnifies the problem. Random or spot scans of the network are ineffective, as they rely on the “luck of the draw.”
The other side by Marvin Chartoff
Debate the issue with Chartoff and Boyland.
Multiple-level security is the best defense against unauthorized access. Wireless LAN (WLAN) technology complicates the issue because of open access to the airwaves and inability to control the radiation of radio frequency signal. Therefore, in a wireless scenario, only authenticated users should be allowed to use network-attached resources.
It is possible to perform radio frequency scanning on the premises. But success is subject to timing – you need to catch the device in operation, which requires continuous frequency monitoring that can be labor- and capital-intensive. Furthermore, radio frequency scanners are limited in range and accuracy. Stray radio frequency from a variety of legitimate sources, such as other WLANs and cordless phones, can generate false signals to a common scanner. It also is important to note that radio frequency scanning can only detect the presence of a device, but does not correlate it with access to your network. Multi-tenant buildings and densely packed zones can present a challenge. There are products available that discriminate true 802.11 from other radio frequency, but they are still subject to timing, neighboring WLANs and inaccuracies in NMS databases.
Regardless of the technique for identifying the presence of an unauthorized wireless access point, the weak point is timing. The results of the scan must be compared against a reference base of legitimate access points to identify the intruder. Reliance on the accuracy and currency of the database implies tight control on the management process. User authentication for all network access is still essential to providing a truly secured network.
The only effective means of securing corporate assets remains multiple levels of security, including securing the destination. An employee with a wireless router still can expose a company to attack without endpoint security. Although it is a good idea to continue to develop and deploy perimeter security, neither the technologies nor the techniques are mature. Proper domain control and security of the endpoint are still essential. It is a mistake to rely on any one scheme.
Boyland is the Americas Network Engineering practice leader at Cap Gemini Ernst & Young. He can be reached at brian.boyland@cgey.com.




