While wireless networks are exposed to many of the same risks as wired networks, they are vulnerable to additional risks as well. Wireless networks transmit data through radio frequencies, and are open to intruders unless protected. Intruders have exploited this openness to access systems, destroy or steal data, and launch attacks that tie up network bandwidth and deny service to authorized users. Another risk is the theft of the small and portable devices themselves.
NIST Guidance on Security of Wireless Networks and Devices
security issues associated with wireless local area networks (WLANs) that are based on Institute of Electrical and Electronics Engineers (IEEE) standards 802.11;
security issues related to wireless personal area networks based on the Bluetooth specifications, which were developed by an industry consortium; and
security of wireless handheld devices.
Before establishing wireless networks and using handheld devices, organizations should use risk management processes to assess the risks involved, to take steps to reduce the risks to an acceptable level, and to maintain that acceptable level of risk. Using risk management processes, managers can protect systems and information in a cost-effective manner by balancing the operational and economic costs of needed protective measures with the gains in mission capability to be achieved through the application of new technology.
Two standards for wireless technologies are discussed in NIST SP 800-48. One is the IEEE 802.11 group of standards for WLANs, which were developed by a voluntary industry standards committee. The IEEE 802.11 standards provide specifications for high-speed networks that support most of today’s applications. The Bluetooth standard, which was developed by a computer and communications industry consortium, specifies how mobile phones, computers, and PDAs interconnect with each other, with home and business phones, and with computers using short-range wireless connections.
As wireless technology evolves, new devices are being developed to provide more features, functions, portability and ease of use. Mobile phones can provide multiple services including voice, email, text messaging, paging, web access, and voice recognition services. Newer mobile phones incorporate PDA, wireless Internet, email, and global positioning system (GPS) capabilities.
The trends in use of information technology point to increased implementation of wireless communications networks and use of wireless devices. Each new development will present new security risks, which must be addressed to ensure that critical assets remain protected. Actions that organizations should take to protect the confidentiality, integrity, and availability of all systems and information include:
Assess risks, test and evaluate system security controls for wireless networks more frequently than for other networks and systems. Maintaining secure wireless networks is an ongoing process that requires greater effort than that required for other networks and systems.
Steps that can be taken to improve the management of wireless networks include:
Maintain a full understanding of the topology of the wireless network.
Label and keep inventories of the fielded wireless and handheld devices.
Create backups of data frequently.
Perform periodic security testing and assessment of the wireless network.
Perform ongoing, randomly timed security audits to monitor and track wireless and handheld devices.
Apply patches and security enhancements.
Monitor the wireless industry for changes to standards that enhance security features and for the release of new products.
Monitor wireless technology for new threats and vulnerabilities.
Perform a risk assessment, develop a security policy, and determine security requirements before purchasing wireless technologies.
The risks associated with the use of wireless technologies are considerable, and many products provide inadequate protection. Organizations should plan to protect their essential operations before they adopt wireless technologies. Common administration problems include installing equipment with “factory default” settings, failing to control or inventory access points, not implementing the security capabilities provided, and not developing or installing security architectures that are suitable to the wireless environment. The use of firewalls between wired and wireless systems should be considered. Other good practices are to block unneeded services and ports, and to use strong cryptography. Often the risks can be addressed, but the tradeoffs between technical solutions and costs must be considered as well. Organizations may want to postpone the installation of wireless networks until more robust, open, and secure products are available.
Organizations should perform security assessments prior to implementation of wireless technologies to determine the specific threats and vulnerabilities that wireless networks will introduce in their environments. In performing the assessment, they should consider existing security policies, known threats and vulnerabilities, legislation and regulations, safety, reliability, system performance, the life-cycle costs of security measures, and technical requirements. Once the risk assessment is complete, the organization can begin planning and implementing the measures that it will put in place to safeguard its systems and lower its security risks to a manageable level. The organization should periodically reassess the policies and measures that it puts in place because computer technologies and malicious threats are continually changing.
Apply security management practices and controls to maintain and operate secure wireless networks.
Organizations should identify their information system assets, and develop, document and implement policies, standards, procedures, and guidelines to ensure confidentiality, integrity, and availability of information system resources. NIST recommends the following steps:
The information system security policy should directly address the use of 802.11, Bluetooth, and other wireless technologies.
Configuration/change control and management practices should ensure that all equipment has the latest software release, including security feature enhancements and patches for discovered vulnerabilities.
Standardized configurations should be employed to reflect the security policy, and to ensure change of default values and consistency of operations.
Security training is essential to raise awareness about the threats and vulnerabilities inherent in the use of wireless technologies.
Robust cryptography is essential to protect data transmitted over the radio channel, and theft of equipment is a major concern.
No comments:
Post a Comment