Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

5/25/2007
05:55 AM
Connect Directly
Facebook
Twitter
RSS
E-Mail
50%
50%

Wireless: Fix, Not Flaw

New applications help WiFi shed its image as enterprises' biggest network vulnerability

LAS VEGAS -- Interop -- Here's a welcome changeup for security pros: Instead of wireless technology being a major security threat, it's getting reworked by vendors like Aruba, Meru, and Shibon Systems to improve enterprise security.

No, what follows is not a paean to WPA 2.0 and the many wonders of broadband wireless in 802.11n (or just "n" as it's referred to in the aisles and briefing rooms here). Rather, wireless apps are getting reinvented in ways that handle access; track assets and personnel; and incorporate policy networking, giving end users different rights, depending on who and where they are.

"This is the year for wireless to emerge as a solution, instead of a vulnerability, for sure," says Chris Silva, analyst, enterprise wireless for Forrester.

In that vein, Meru trotted out its EzRF location manager suite, which uses WiFi-enabled tags to track users and pinpoint rogue access points (APs), managed APs, individual clients, VOIP handsets, and PDAs. In short, the system uses architectural drawings as a grid on which to plot and manage wireless assets. The vendor touted its "single channel virtual cell architecture" as a contrast to other vendors that use multiple WiFi channels (1, 6, 11, e.g.) in a cell as a way that makes EzRF more accurate, to within five to 15 feet.

Meru also said it has partnered with AeroScout and Ekahau for their wireless location policy and engine technologies.

A 500-AP license for EzRF will cost $14,000 and will be available in June. Paul Curto, senior technical marketing manager for Meru, said the vendor's also working on tying together quality of service with extended service set identifiers (ESSIDs), which permit WiFi devices to communicate on a particular WLAN. The QOS/ESSID combo would bolster the policy networking aspects of the system and give enterprises more control over how bandwidth gets allocated, and by whom.

Aruba took location-based technology a bit further with new software called Mobility Access Point that contains role-based user access control, stateful firewalling, and split tunneling for Aruba APs. Aruba bills the product as "follow-me security," which associates security and access policies with individual users, as opposed to specific network ports. MAP is expected to ease secure connectivity challenges for road warriors and mobile workers connecting from hotel rooms or public WiFi hotspots.

Shimon Systems also introduced a hybrid wireless security product this week that combines biometrics with WiFi access. Its fingerprint-based Bio-NetGuard authenticates users for specific AP access. Bio-NetGuard uses fingerprint readers that are built into laptops or USB and PCMCIA card sensors and can block users from logging into wireless networks that aren't equipped with WPA or WPA 2.0, says Baldev Krishan, president and CEO of Shimon.

The device is available in a fingerprint-only version, as well as a two-factor model that uses fingerprints and passwords. Bio-NetGuard works with APs from Bountiful, Cisco, D-Link, Linksys, and NetGear, with others to follow once interoperability certifications have been completed. Pricing is based on the number of users and starts at $495 for a 10-user license and the hardware.

— Terry Sweeney, Editor In Chief, Dark Reading

  • Aruba Wireless Networks
  • Meru Networks Inc.
  • Shimon Systems
  • AeroScout
  • Ekahau Inc.
  • Bountiful WiFi
  • Cisco Systems Inc. (Nasdaq: CSCO)
  • D-Link Systems Inc.
  • Linksys
  • Netgear Inc. (Nasdaq: NTGR)
  • Forrester Research Inc. Terry Sweeney is a Los Angeles-based writer and editor who has covered technology, networking, and security for more than 20 years. He was part of the team that started Dark Reading and has been a contributor to The Washington Post, Crain's New York Business, Red Herring, ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Oldest First  |  Newest First  |  Threaded View
    HackerOne Drops Mobile Voting App Vendor Voatz
    Dark Reading Staff 3/30/2020
    Limited-Time Free Offers to Secure the Enterprise Amid COVID-19
    Curtis Franklin Jr., Senior Editor at Dark Reading,  3/31/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Current Issue
    6 Emerging Cyber Threats That Enterprises Face in 2020
    This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
    Flash Poll
    State of Cybersecurity Incident Response
    State of Cybersecurity Incident Response
    Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2020-11527
    PUBLISHED: 2020-04-04
    In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
    CVE-2020-11528
    PUBLISHED: 2020-04-04
    bit2spr 1992-06-07 has a stack-based buffer overflow (129-byte write) in conv_bitmap in bit2spr.c via a long line in a bitmap file.
    CVE-2020-11518
    PUBLISHED: 2020-04-04
    Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.
    CVE-2020-5347
    PUBLISHED: 2020-04-04
    Dell EMC Isilon OneFS versions 8.2.2 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses.
    CVE-2020-5348
    PUBLISHED: 2020-04-04
    Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in system management mode.