Lost Password? No account yet? Sign up! Why bother?
  • Narrow screen resolution
  • Wide screen resolution
  • Auto width resolution
  • Increase font size
  • Decrease font size
  • Default font size

SmallNetBuilder - Small Network Help

  
Home arrow Wireless arrow Wireless How To arrow How To: Sniffing the Air
How To: Sniffing the Air Print E-mail
Derek Boiko-Weyrauch   
September 28, 2005

Introduction

Wireless security - two words generally spoken in the same tone as "jumbo shrimp" and "government organization". Because of the nature of the technology, and the easily-broken encryption solutions that are currently out there, it becomes a question of not if, but when an attack will occur. Small- and home-office users are especially vulnerable, as they generally have more important things to worry about than securing their wireless assets and lack the resources of larger companies to devote to a security contact or team.

But all is not lost, as there are ways to verify the security of a wireless network despite the oxymoron that wireless security generally conjures to mind. Intrusion Detection Systems (IDS for short) provide a way to detect these attacks even before they happen, while the intruder is still casing the place. They are not the be-all-end-all to security, but when combined with firewalls and other security tools they can be very powerful. It is helpful to think of IDS as similar to burglar alarms: they will tell you that a break-in has happened, but leave it up to other systems to handle the break-in itself.

The namesake of the Snort IDS

Figure 1: The namesake of the Snort IDS

Snort is an open source IDS that can be custom-tailored to fit your wireless network. Calling itself "the de facto standard for intrusion detection", Snort is flexible, fast, and most importantly, free. All it takes is a little bit of elbow grease to get it up and sniffing away at wireless traffic.

Snort and other IDS can be especially effective when dealing with wireless attacks. In a previous series, Humphrey Cheung talked about how the Wired Equivalent Privacy (WEP) encryption scheme can be easily cracked. In addition to this, even more advanced encryption methods can be cracked and wireless authentication schemes broken by a determined attacker. This makes Snort a vital tool in detecting these kinds of attacks and stopping them before they begin.

There is a version of Snort available that is tailored specifically towards the wireless user. Appropriately titled Snort Wireless, this version contains rules that are suited to detecting some of the most common attacks against a wireless access point, and can also be custom-tailored to the specific needs of a wireless network. This article will give you a basic outline of Snort's operation and how it can be applied to your wireless network, leaving the specifics of deploying it up to you.



Tags: How To, security, sniff, Snort, WiFi,

Related Articles:

Snort vulnerability found
Nmap getting SNORTed
SmoothWall Express 2.0
How To Crack WEP - Part 3: Securing your WLAN
Auditor Security Collection CD reviewed
 

Most Read

 
 

Over At The Forums

Any Drobo Review Coming?
Tim last time ( in May?? ) you said you were in queue for Drobo Review unit, Have you have any response from them yet?

Qnap 209 Pro II, very slow transfer, advice welcome
Hello I have a Qnap 209 Pro II, I get a very slow file transfer rate. I think (hope) I have something wrong with either my...

For sale brand new original unlocked BlackBerry Storm 9500 $300
Welcome to Phonesstockcity Ltd in United State, We deal with All Electronics Product it is All Brand New with the complete accessories and come with...

Brand New Unlocked Apple Iphone 3G 16GB For Sale at just $350USD
We offer 10% discount for any series of Nokia samsung apple iphone you purchase with Free Shipping.and we are in promo now if buy three...

breaking the magic 100MB/s
Hi, Been following your articles on really fast NAS, and sorry, I think I may of just done it :) I have two p5w64's linked via a...

Slideshows

Western Digital ShareSpace QNAP TS-509 Pro D-Link DNS-343 4-Bay Network Storage Enclosure Thecus N3200 RAID 5 NAS D-Link DIR-628 RangeBooster N Dual Band Router Adtran NetVanta 3120 More

Win This!

Enter to Win!

You could win a Promise NetStor NS2300N NAS.

Learn How!

 

Ldr:0.00175881385803, Rct:0.00593185424805, Sky:0.00773286819458, Tlink:0.0890848636627, TopPG:0.0891649723053, GQV:0.08931183815 seconds to load.