Cisco`s SAFE document on securing wireless networks is upbeat about the 'securability` of the technology, but says the fact that their reach often extends beyond physical boundaries, and with wireless data being airborne, wireless is riskier than wired.
However, Paul Williams, Cisco SA spokesman, says the highly publicised "insecurity" of wireless is by and large a myth. "It is much like a wired network. If you don`t secure it, it is insecure. There are many effective ways to secure WLANs," he says.
"Like a wired network, it must be noted that it can never be absolutely secure, but there`s no reason for the palaver, if you follow best practices such as those outlined in our security advisory, SAFE."
Cisco`s SAFE document explains the risks associated with wireless. "Because WLAN devices ship with all security features disabled, the wide deployment of wireless has attracted the attention of the hacker community. Several Web sites now document all the freely available wireless connections in the US.
"Although most hackers use these connections as a means to get free Internet access or to hide their identity, a smaller group uses it to break into networks that otherwise might have been difficult to attack from the Internet, because unlike a wired network, wireless networks send data over the air and usually extend beyond the physical boundary of an organisation," the paper says.
Anyone within radio frequency range can target wireless devices by interfering with the signal, and it is possible that other devices within the same frequency spectrum can do so too, whether an access point is used, or client devices are set up to work peer-to-peer. Wireless devices can also be used as "weapons", getting users` client devices to associate with rogue access points.
On top of this, Williams says, the 802.11 standard used to transmit data on wireless devices is insecure. "Unfortunately, this standard makes use of Wired Equivalent Privacy/Protocol (WEP), a frame encryption protocol in 40-bit and 128-bit variants. Both can easily be cracked. It does not address automatic key distribution and redistribution, and therefore causes implementation problems, and the initialisation vector can be picked up as plain text."
The Cisco way
Cisco proposes customers deploy elements of three technologies as alternatives to WEP, being IPSec, used on the network instead of WEP (overlaying cleartext WiFi comms), or 802.1x , a mutual authentication-based key distribution method, or some proprietary Cisco enhancements to WEP.
Together with 802.1x, Cisco has developed the Extensible Authentication Protocol (EAP), allowing users access to an AP only after performing a network logon. In such a case, the client device and server perform a mutual authentication, and the server allocates a client-specific WEP key for the duration of the session.
"User passwords and session keys are never transmitted in the clear," the document states.
Additionally, where WEP is used, enhancements such as WEP key hashing and message integrity checks make this safer.
"Organisations should choose to deploy either IPSec or EAP/802.1X, but generally not both. Use IPSec when you have the utmost concern for the sensitivity of transported data, but remember that this is more complex to deploy and manage than EAP. EAP should be used when you want reasonable assurance of confidentiality and a transparent user security experience. The basic WEP enhancements can be used anywhere WEP is implemented. For the vast majority of networks, the security provided by EAP is sufficient," the paper concludes.
The rest of the paper focuses on wireless network design aspects.

