Welcome Guest. | Log In | Register | Membership Benefits

Fluke Rolls Out New Threat Signatures Released To Protect Against Wireless Attacks

New signatures protect against four attacks that can exploit wireless LANs

Jan 24, 2012 | 04:19 PM | 


EVERETT, Wash., Jan. 24, 2012 -- Fluke Networks today released new threat signatures for its AirMagnet Enterprise 9.0 wireless intrusion detection and prevention system (WIDS/WIPS), including a signature for the recently discovered Wi-Fi Protected Setup (WPS) PIN Brute Force attack. The update also includes threat signatures to protect against Domain Name Server (DNS) and Internet Control Message Protocol (ICMP) Tunneled Traffic, and 802.11 Fuzzing attacks.

The new signatures protect against four attacks that can exploit wireless LANs (WLANs):

• Wi-Fi Protected Setup PIN Brute Force Attack – Wi-Fi Protected Setup (WPS) is a simplified method for configuring security settings that is supported on certain access points and clients. On Dec. 27, 2011, a serious vulnerability was reported in the WPS mechanism that allows an attacker to derive the PIN and therefore gain unauthorized connection to the access point (AP). There are currently two known attack tools that exploit this vulnerability.

• DNS Tunneled Traffic Detection – Domain Name Server (DNS) tunneling is the practice of encapsulating TCP traffic inside DNS packets. This technique can be used to bypass payment and gain unauthorized connectivity through Wi-Fi Hotspots or other protected guest access portals.

• ICMP Tunneled Traffic Detection – Similar to the DNS Tunneling Traffic Detection, Internet Control Message Protocol (ICMP) tunneling is the practice of encapsulating Transmission Control Protocol (TCP) traffic inside ICMP packets. This technique can also be used to bypass payment and gain unauthorized connectivity through Wi-Fi Hotspots or other protected guest access portals.

• 802.11 Fuzzing Attack – 802.11 Fuzzing is the process of introducing invalid, unexpected or random data into 802.11 frames and then replaying those modified frames into the air. This can cause unexpected damage to the destination device including driver crashes, operating system crashes and stack-based overflows that would allow execution of arbitrary code on the affected system, including APs.

AirMagnet Enterprise is the only WLAN security system that can immediately generate signature updates for immediate protection against new threats and automatically push them to customers without requiring scheduled downtime or additional IT resources. For a complete list of signature updates released by Fluke Networks, including Karmetasploit, AirDrop, AirPWN, Device Broadcasting XSS SSID, Ad-hoc Station Broadcasting Free Public Wi-Fi SSID and more, please visit the AirWISE Community. For more information about AirMagnet Enterprise 9.0, please visit Fluke Networks.

About Fluke Networks

Fluke Networks is the world-leading provider of network test and monitoring solutions to speed the deployment and improve the performance of networks and applications. Leading enterprises and service providers trust Fluke Networks' products and expertise to help solve today's toughest issues and emerging challenges in WLAN security, mobility, unified communications and data centers. Based in Everett, Wash., the company distributes products in more than 50 countries. For more information, visit www.FlukeNetworks.com or call +1 (425) 446-4519.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Mobile Security Reports

report Stop Mobile Device-Borne Malware
iPhones, iPads and Android devices are making their way into your company--like it or not. These devices are opening a new gateway for malware that old security tools and procedures can't completely close. Security professionals must combine education, policy development, and the use of existing tools and new mobile device management systems to effectively balance mobile device risk with productivity rewards.

report The Security Pro's Guide to Tablet PCs
As businesses rely increasingly on tablets for the productivity benefits they provide, IT must address the security challenges the devices present. Here's a look at how to build a comprehensive tablet security strategy.




Featured Webcasts
Featured Whitepapers
Featured Reports