Archive

Posts Tagged ‘unwired’

Ugly, Bad and Good of Wireless Rogue Access Point Detection

September 20th, 2009

One critical requirement from wireless intrusion prevention system (WIPS) is that it should offer robust protection against rogue wireless access points. The protection should entail instant detection followed by automatic blocking (prevention). Rogue AP detection should be free from false alarms – both on positive and negative sides.

Rogue AP means unauthorized AP wired to (connected to) monitored enterprise network. In other words, rogue AP satisfies two conditions: i) It is not on the authorized AP list, AND ii) it is wired to the monitored enterprise network.

Classification

The first of the above two conditions is easy to test, just compare BSSID of detected AP with your managed AP BSSID list. The second condition is where things start to become interesting. Accurately and reliably detecting if every AP seen in air is wired or not wired to the monitored enterprise network requires technological sophistication. Based on the level of sophistication, three types of rogue AP detection workflows are prevalent in wireless intrusion prevention system (WIPS) solutions available in the market. Read more…

Post to Twitter Post to Yahoo Buzz Post to Delicious Post to Digg Post to Ping.fm Post to Reddit Post to StumbleUpon

Hemant Chaskar Wireless scanning, Wireless security , , , , , , ,

Twitter links powered by Tweet This v1.8.2, a WordPress plugin for Twitter.