top of page

WIPS: Wireless Intrusion Prevention System

Nov 10, 2015
6 min read

Well, it’s about that time again!! Let’s see how many things I find to purchase tonight.

The topic is: What is Wireless Intrusion Prevention System.

I just happened to find a fantastic article on this Website, http://whatis.techtarget.com/definition/WIPS-wireless-intrusion-prevention-system.

The following definition is given:

A wireless intrusion prevention system (WIPS) is a dedicated security device or integrated software application that monitors a wireless LAN network's radio spectrum for rogue access points and other wireless threats.

A WIPS compares the MAC addresses of all wireless access points on a network against the known signatures of pre-authorized, known wireless access points and alerts an administrator when a discrepancy is found. To circumvent MAC address spoofing, some higher-end WIPS are able to analyze the unique radio frequency signatures that wireless devices generate and block unknown radio fingerprints.

The PCI Security Standards Council recommends the use of WIPS to automate wireless network scanning. In addition to providing a layer of security for wireless LANS, WIPS are also useful for monitoring network performance and discovering access points with configuration errors.

There are three basic ways to deploy a WIPS. The first, primarily found at the lower-end of the market, is known as time slicing or time sharing. In this type of deployment, the wireless access point does double duty, providing network traffic with wireless connectivity while periodically scanning for rogue access points.

In the second approach, which is known as integrated WIPS, a sensor that is built into the authorized access point continually scans radio frequencies, looking for unauthorized access points.

In the third approach, which is known as WIPS overlay, sensors are deployed throughout a building to monitor radio frequencies. The sensors forward the data they collect to a centralized server for further analysis, action and log archiving. This approach is more expensive because it requires dedicated hardware, but it is also thought to be most effective.

WIPS overlay hardware resembles a rack server and the associated sensors resemble Wi-Fi access points. Most WIPS overlay systems share the same fundamental components:

Sensors -- monitor the radio spectrum and forward logs back to a central management server.

Management server -- receives information captured by the sensors and take appropriate defense actions based on this information.

Database server –- stores and organizes the information captured by the sensors.

Console -- provides an interface for administrators to set up and manage the WIPS.

While WIPS overlays provide many valuable features and protections, especially to large enterprises who capture customer data, they can be quite costly. With hardware, applications, subscriptions and training all factored in, an enterprise with 250 access points might spend as much as $100,000 on WIPS. Oh, $100,000 is way too much for me.

Well now, here we are going to step into a different article. Same station, different channel. Note my unusual tone of excitement as I read the golden rule of do unto others before they DOS attack unto you. The advantages and disadvantages that I noticed are italicized. Well, they were until I copied this article into the blog page. Some may have gone unnoticed due to the late hour that I am working on this blog.I'm going to bed now... Good night. You may finish reading because this was written hours ago.

“Wireless Intrusion Prevention System (WIPS) Deployment Architectures – Overlay, Integrated & Hybrid." ExcITingIPcom. 14 Jan. 2011. Web. 11 Nov. 2015.

So, as mentioned above, a wireless intrusion prevention system continuously scans for various wireless threats over the air and reports the same, when found. Some of them are automatically configured to take action like initiating a reverse DOS attack on the offending client/AP so that the misbehaving client/AP cannot connect to the network. YA! Take that!

This next part is a little redundant, however, it will cover the advantages and disadvantages more clearly. Still from the same author and article:

The Wireless Intrusion Prevention Systems can be deployed in many ways. We will discuss four popular ones in this article.

Type 1 – Overlay (Dedicated Wireless Sensors from third party for WIPS Scanning):

One popular WIPS deployment architecture is using dedicated wireless sensors (which are like access points, but hardened and purpose built for wireless security scanning only) and a centralized server that does threat analysis. Generally these devices are provided by a specialized manufacturer who is different from the Wireless LAN solution vendor.

The first obvious advantage is that they are dedicated to the task of wireless scanning. So, they can scan all the channels quickly for possible intrusions. Some of them claim that they offer comprehensive regulatory compliance and forensics analysis, though that may be vendor dependent. Some of them can store security event data in the sensors itself, for a limited period of time, and some of them can locally analyze all the packets and send only certain selected events that match threat pattern, to the central server for further processing. This might make distributed deployments of such sensors (over the WAN), easier.

This type of deployment is good for companies having high volume wireless data transfer as the security data is captured and analyzed separately. The cost of such a solution though, might be on the higher side, when compared to others. These dedicated sensors are security hardened and do not divulge information like vendor name, firmware version etc., on casual probing by hackers. These sensors cannot work as normal access points for wireless traffic forwarding. They may not be able to give location information of misbehaving clients/APs.

Encrypted wireless traffic cannot be analyzed by these sensors. So, insider attacks and few application layer attacks are hard to detect. The best a sensor can do to stop an attack is to counter attack through methods like Reverse DOS. But there is a possibility that the misbehaving client can disassociate from the current access point and try attacking the next one.

Type 2 – Overlay (Dedicated Access Points from WLAN vendor for WIPS Scanning):

In this architecture, certain wireless access points from the Wireless LAN vendor are dedicated for WIPS Scanning and monitoring instead of using third party wireless sensors. The obvious advantages would be the common administration interface, bulk purchase (along with wireless access points) and single vendor maintenance.

The traffic from these access points, more often than not, is sent to the centralized controller/ server for security analysis. This increases the strain on the performance of the wireless controller. There is a higher chance that a general purpose access point can be compromised by a hacker, than a specialized wireless sensor. Access Points are generally made to operate in legally allowed channels of a particular country. Hence, if a hacker is using other channels, they might go undetected.

Since these are normal access points, they can be used for traffic forwarding and other wireless LAN functions if need arises (like an event where too many unexpected wireless users accumulate). Location identification services to detect the misbehaving client/AP can be implemented with this solution. Even encrypted traffic can be scanned and misbehaving clients can be cut off from connecting to any of the access points in the network.

Type 3 – Integrated (Time Shared Access Points from WLAN vendor for Wireless Access as well as WIPS Scanning):

Some vendors offer access points that can give wireless access as well as scan for wireless threats, simultaneously on a time-shared basis (The access points forward wireless data traffic for some time and scans the airwaves for security threats at other times). So, as you might have guessed, this solution uses the minimum number of access points (both combined) and is cost effective. This could be implemented in companies with a tight budget and less demanding wireless usage. But for this architecture, the cons outweigh the pros!

The access points in this architecture cannot perform both scanning and traffic forwarding at the same time (simultaneously), and this impacts the performance for both. Especially, when real time applications like voice and video are used over wireless. While the channel in which the access point is forwarding traffic can be scanned for wireless threats, it does not monitor the other channels frequently. An access point in this mode, cannot block an intrusion simultaneously as it is forwarding traffic.

The biggest disadvantage of this architecture is the little time (relatively) spent for WIPS scanning and more often than not, scanning for wireless threats is sacrificed for wireless data traffic forwarding. Moreover, all the channels are not scanned frequently, resulting in increased chances for wireless attacks. Other than these, all the disadvantages of type-2 architecture apply for this one as well.

Type 4 – Hybrid (Mix of Dedicated Wireless Access Points & Time Shared Access Points from WLAN vendor for WIPS Scanning):

Well, this is actually a compromise between type-2 & type-3 architectures. This one is about deploying dedicated access points for wireless threat mitigation as far as possible, but it also advocates the usage of some access points on a time-shared basis at the same time. For example, dedicated WIPS scanning access points can be used at dense wireless deployment scenarios & strategic regions and shared access points at other less demanding places. The advantages and disadvantages are same as the above two types (type-2, type-3) of architectures.

For my third citation, I am forced to use the book just to cover requirements and, well: Bartz, Robert J. CWTS Certified Wireless Technology Specialist Official Study Guide (exam PW0-071). 2nd ed. Hoboken, N.J.: Wiley;, 2012. Print.

  • Advantages are Captures info by 24/7monitoring

  • Detects threats to the wireless infrastructure

  • Notifies you about threats through a variety of mechanisms

  • Supports integrated spectrum analysis

  • Includes elaborate reporting systems

  • Ensures compliance with corporate security policy and legislative compliance

  • Retains data for forensic investigation

  • Uses hardware sensors for monitoring


 
 
 

Comments


Featured Posts
Recent Posts
Archive
WHATEVER THE WEATHER
INSPIRATION
Follow Me

    This is the day the Lord has made;

    let us rejoice and be glad in it.

       -Psalm 118:24     

     

     

    Whatever you do,

    work at it with all your heart,

    as working for the Lord,

    not for men.

    - Colossians 3:23     

     

    • LinkedIn - Black Circle

     

     

    E-mail: 

    anne_shroble@sbcglobal.net

    © 2023 BY FREE LINE CREATIVE STUDIO. PROUDLY MADE BY WIX.COM

    bottom of page