How to improve the security of Wi-Fi

Source: Internet
Author: User

15 years ago, Wi-Fi began its long and steady development, from the home to the office, and eventually replaced Ethernet as a number of enterprises preferred network access mode.


Now, with the 802.11AC Drive, enterprise Wi-Fi deployment is further developed, 2014, 802.11AC accounted for the global 176 million access point (AP) shipments of 18%. Wi-Fi will not only change the way employees connect, but will also change the way they protect communications. Wi-Fi security is no longer an add-on; it must be an important part of security policy implementation. In this article, we will explore how enterprises should face this kind of network security transformation.

Security practices

Years ago, the security practices of Wi-Fi deployments were primarily link layer encryption: First, Wired Equivalent Privacy (WEP), followed by Wi-Fi Protection Access (WPA) and temporary Key Integrity Protocol (TKIP). Then the WPA 2 and Advanced Encryption Standard (AES). For nearly a decade, all Wi-Fi certified products support WPA 2 with preshared key (PSK) or 802.11X access control. At the same time, it turns out that wireless attackers are blocked by Wi-Fi sniffers and manual on-site investigations, and now fully automated wireless intrusion detection and defense (wids/wips) has become mainstream, with each enterprise-Class wireless LAN (WLAN) product included in the technology.

While these technologies are primarily for wireless networks, they are now the basis for building a network. For example, 802.11X provides the basis for controlling access to local area networks (wireless and Wired). WIPs containment is usually triggered to block suspicious attackers at a network connection point, whether it is a wireless connection or a wired connection. Now security policy is no longer about how devices are connected, but who is connecting, what they are doing, and where they are.

Wi-Fi deployment and policy execution

Ozer Dondurmacioglu, senior director of product and solution marketing at Aruba Networks, says many large enterprises are trying to create and implement a single security policy to solve all problems.

"When my doctor is in the cafeteria, he may just have to connect to the Internet--nothing more; when he's in the office, he may also have access to patient data; and when he works at other high-risk locations, he may need to take additional protective measures," Dondurmacioglu said. There should be a way to encapsulate all of this in a single policy, and then use tools to implement policy. ”

Organizations can leverage existing tools to help them implement this unified security policy, including identity management Services, network and application firewalls, mobile devices and application managers, secure wired switch ports and access points, location-based services, guest access services, and more. However, it is best for companies to consider the work of implementing such a single policy as a phased process, starting with the target policy, using the tools available to perform the basic work, and gradually adding new tools to enhance policy, threat and user productivity.

For a preliminary deployer, identity management can drive security policy, and should bundle access rights and requirements to individuals and roles, rather than devices or network connection points, for example, in which physicians can be granted different access rights based on policy-driven criteria throughout the workday.

Second, firewalls, switches, and APS can monitor and deploy these access rights. Extensive network fragmentation can be deployed through VLANs and SSID, performed by switches and APS. Network traffic can also be filtered through these edge devices, such as determining whether doctors can access the Internet or patient data. However, based on today's increasingly complex mobile applications and associated risks, application firewalls can help to implement more granular policies to reduce risk, prevent malware, and prevent data disclosure.

Third, policies may need to consider device types, ownership, and trust levels, primarily through the use of mobile devices and application managers. For example, a doctor may carry a smartphone and a tablet computer and use it simultaneously in his or her work. The same policy may set different access rights for tablets and BYOD smartphones issued by companies, or it may require that security containers be installed on each device as a condition for accessing patient data.

In addition, policies have begun to use location-based services, using techniques such as geo-fencing, to restrict access to specific sites and authorized areas. Location-based services are evolving, for example, companies can use new devices such as Apple's ibeacon to improve accuracy (especially indoors), which can be run alone or integrated into the network infrastructure. In our case, a doctor's tablet can identify its location (hospital or café) and change its behavior accordingly, although its device is connected through Wi-Fi in both locations.

Finally, the visitor access service plays an increasingly important role in the implementation of security policy, not only for visitors, but also for employees using BYOD or other devices. Specifically, the network infrastructure can be used to manually or automatically redirect new equipment to the device registration portal, allowing employees to register devices, agree terms of service, accept equipment certificates, and configure them to secure Wi-Fi access. After connecting to a secure network, additional steps are required to achieve security mobility, such as deploying a security container or application to a mobile device that is now licensed and certified by a physician.

Now build Future Extensions

The network technologies described above that enable flexible mobile security policies have been around for years: some are relatively new. All of these technologies can help strengthen the network to enforce security policies, uncover the inherent risks of Wi-Fi deployments, and address these risks at the overall level (i.e., focusing on users and meeting their computing needs). As wireless becomes more common, businesses should use this approach to enforce and enforce secure mobility.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.