Computer Hardware Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 9 January 2012

Wireless Networking Basic Security

Posted on 00:57 by Unknown

How an end user client with a WLAN NIC accesses a LAN
  1. To allow clients to find the AP easily, the AP periodically broadcasts beacons, announcing its (SSID) Service Set Identifier, data rates, and other WLAN information.
  2. SSID is a naming scheme for WLANs to allow an administrator to group WLAN devices together.
  3. To discover APs, clients will scan all channels and listen for the beacons from the AP(s). By default, the clientwill associate itself with the AP that has the strongest signal.
  4. When the client associates itself with the AP, it sends the SSID, its MAC address, and any other security information that the AP might require based on the authentication method configured on the two devices.
  5. Once connected, the client periodically monitors the signal strength of the AP to which it is connected.
  6. If the signal strength becomes too low, the client will repeat the scanning process to discover an AP with a stronger signal. This process is commonly called roaming.

SSID and MAC Address Filtering

When implementing SSIDs, the AP and client must use the same SSID value to authenticate. By default, the access point broadcasts the SSID value, advertising its presence, basically allowing anyone access to the AP. Originally, to prevent rogue devices from accessing the AP, the administrator would turn off the SSID broadcast function on the AP, commonly called SSID cloaking. To allow a client to learn the SSID value of the AP, the client would send a null string value in the SSID field of the 802.11 frame and the AP would respond; of course, this defeats the security measure since through this query process, a rogue device could repeat the same process and learn the SSID value.
Therefore, the APs were commonly configured to filter traffic based on MAC addresses. The administrator wouldconfigure a list of MAC addresses in a security table on the AP, listing those devices allowed access; however, the problem with this solution is that MAC addresses can be seen in clear-text in the airwaves. A rogue device can easily sniff the airwaves, see the valid MAC addresses, and change its MAC address to match one of the valid ones.
This is called MAC address spoofing.

WEP

WEP (Wired Equivalent Privacy) was first security solutions for WLANs that employed encryption. WEP uses a static 64-bit key, where the key is 40 bits long, and a 24-bit initialization vector (IV) is used. IV is sent in clear-text. Because WEP uses RC4 as an encryption algorithm and the IV is sent in clear-text, WEP can be broken. To alleviate this problem, the key was extended to 104 bits with the IV value. However, either variation can easily be broken in minutes on laptops and computers produced today.

802.1x EAP

The Extensible Authentication Protocol (EAP) is a layer 2 process that allows a wireless client to authenticate to the network. There are two varieties of EAP: one for wireless and one for LAN connections, commonly called EAP over LAN (EAPoL).
One of the concerns in wireless is allowing a WLAN client to communicate to devices behind an AP. Three standards define this process: EAP, 802.1x, and Remote Authentication Dial In User Service (RADIUS). EAP defines a standard way of encapsulating authentication information, such as a username and password or a digital certificate that the AP can use to authenticate the user.802.1x and RADIUS define how to packetize the EAP information to move it across the network.

WPA

Wi-Fi Protected Access (WPA) was designed by the Wi-Fi Alliance as a temporary security solution to provide for the use of 802.1x and enhancements in the use of WEP until the 802.11i standard would be ratified. WPA can operate in two modes: personal and enterprise mode. Personal mode was designed for home or SOHO usage. A pre-shared key is used for authentication, requiring you to configure the same key on the clients and the AP. With this mode, no authentication server is necessary as it is in the official 802.1 x standards. Enterprise mode is meant for large companies, where an authentication server will centralize the authentication credentials of the clients.

WPA2

WPA2 is the IEEE 802.11i implementation from the Wi-Fi Alliance. Instead of using WEP, which uses the weak RC4 encryption algorithm, the much more secure Advanced Encryption Standard (AES)–counter mode CBC-MAC Protocol (CCMP) algorithm is used.
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Structure of IP (Internet Protocol) addresses (IPv4, IPv6).
    Systems that have interfaces to more than one network require a unique IP address for each  network interface . The first part of an  Intern...
  • How To Verify the Installation of ADS and How to Remove ADS
    In our last article we  configured  ADS. In this tutorial I will guide you how to check ads installation. ADS installation can be verify fro...
  • (no title)
  • How to add clients in domain advance method used in Company Environments Server side Configurations
    In our last article we saw how a client can join domain. We used  default   administrator account  for this process.Administrator account ca...
  • Define the function of TCP / UDP (Transmission Control Protocol / User Datagram Protocol) ports.
    On the other hand, a UDP transmission does not make a proper connection and merely broadcasts its data to the specified network address with...
  • XP Tips and Tricks
    From our series of XP tips n tricks in this article we will show  you that  how can you Customize visual effect on XP Optimize Hard disk whe...
  • How to create hardware profile in xp step by
    A hardware profile is  a collection of   configuration  information about the hardware that is  installed on  your computer. Within a profil...
  • Identify factors which affect the range and speed of wireless service
    Infrared Infrared (IR) radiation is electromagnetic radiation of a wavelength longer than that of visible light, but shorter than that of  m...
  • how to configure DNS domain name system in Server 2003
    ADS relies entirely on  Domain Name System  (DNS) to locate resources on a network. Without a reliable DNS infrastructure, domain controller...
  • How to add clients in domain advance method used in company environments client side configurations
    In our pervious article we have completed  server side   configuration  to make clients form  user accounts . In this tutorial I will show y...

Blog Archive

  • ▼  2012 (76)
    • ►  February (4)
    • ▼  January (72)
      • how to diffrenciate between window xp, 2000 profes...
      • Windows Run Line Commands
      • Number of Microsoft Certified Professionals Worldwide
      • A+ Core Hardware
      • Saurabh’s Hardware Notes
      • Best Gaming CPUs For The Money: November 2011
      • Opinion: 10 Technologies That Need to Deliver in 2012
      • Networking interview questions
      • Share Dial Up Internet Connection
      • System administrations User managements
      • System administrations User managements
      • Hide drive from my computer Show icon on my compute
      • windows xp bootable cd Step by Step
      • Remove XP VISTA Window7 Server 2003 Server 2008 Pa...
      • Step by step guide of partitions recovery
      • Install xp from pen drive usb drive
      • Troubleshooting Peer to Peer Workgroup Network
      • How to configure Gmail With Microsoft outlook Expr...
      • Sending a remote assistance request
      • Wireless Network
      • Step by Step guides For wireless configuration
      • Wireless networking Access Modes
      • Wireless Networking Basic Security
      • wireless networking basic Transmission Factors Res...
      • XP Tips and Tricks
      • Sample technical support engineer Desktop support ...
      • Sample hardware Engineer resume Desktop support en...
      • Sample Resume Objectives Resume skills Resume care...
      • Resume skills Hardware Network Resumes skills Samp...
      • Full Form of hardware and networking devices and T...
      • Basic Computer Hardware review
      • Complete interview question with answer
      • How to create hardware profile in xp step by
      • How to configure roaming profile, mandatory profil...
      • How to configure roaming profile, mandatory profil...
      • How to add clients in domain advance method used i...
      • How to add clients in domain advance method used i...
      • No title
      • How to add or remove clients from domain network o...
      • how to configure DNS domain name system in Server ...
      • How To Verify the Installation of ADS and How to R...
      • How to configure ads active directory service step...
      • Replication Between Domain Controllers
      • What is Active Directory Services?
      • Editions of Windows Server 2003
      • Upgrade path MCSE on server 2003 to Server 2008
      • Main features of 802.2 Logical Link Control 802.3 ...
      • Network utility (FOR MY IIJT STUDENTS)
      • Networking Devices
      • 10BaseT 10BaseF 10Base2 5-4-3 rule 10Base5 100Base...
      • TCP IP model tcp ip stack MAC OSI IPX/SPX IPX SPX ...
      • Structure of IP (Internet Protocol) addresses (IPv...
      • Logical or Physical Network Topologies
      • Rj-45 J Rj-11 USB MT-RJ Coaxial BNC LC Local Conne...
      • cable media stp utp SMF MMF Coaxial cable ThickNet...
      • Identify factors which affect the range and speed ...
      • Define the function of TCP / UDP (Transmission Con...
      • Network Security protocols purpose and function
      • Turn Off Window Animation
      • Disable Password Caching
      • Changing Windows' Icons
      • Backup / Restore the Registry
      • Registry Tricks and Tips
      • Delete Autorun.inf Virus Manually using just Winrar
      • Hacking Youtube to find good quality videos
      • Install Windows xp in less than 15 minutes
      • Shutdown Computer With Command Prompt or shortcut ...
      • Recover Windows XP Administrator Password
      • NOKIA SECRET CODES
      • 10 TRICKS TO SPEED UP SYSTEM
      • Trick to Show Your name after time in taskbar...
      • TIP & TRICKS
Powered by Blogger.