Auditing Wireless Networks: Who Is Listening to My Network Traffic?

In today's business environment, the installation of wireless networks has taken a center-stage position. Wireless permits an organization to use networked devices in locations where Cat 5 cable is not available.

The Institute of Electrical and Electronics Engineers (IEEE, www.ieee.org) has taken a lead position in the creation and development of wireless networking protocols. In 1990, IEEE established the 802.11 working group. One of their goals was the creation of a wireless local area network (WLAN) standard. The standard specified an operating frequency in the 2.4 GHz band that had been specified for industrial, scientific, and medical use. Seven years later, in 1997, the IEEE adopted the first WLAN standard with data rates of 1 Mbps and 2 Mbps. In 1999, the working group approved two extensions to the 802.11 protocol. The first, 802.11a, operates in the Unlicensed National Information Infrastructure band of 5 GHz with a transfer rate of 54 Mbps. This standard protocol only allowed clients within 40 to 50 feet, due to power restrictions enforced by the Federal Communications Commission (FCC). The second adopted standard is one of the more popular WLAN protocols, 802.11b. This protocol operates on the 2.4 GHz band with operating distances sometimes exceeding 1000 feet and has speeds near 11 Mbps. It is the 802.11b standard known popularly as "Wi-Fi," Wireless Fidelity.

Basic Wi-Fi Architecture

One basic workstation to other compatible client is known as the independent basic service. It provides peer-to-peer communication links between two or more wireless devices with the use of an Access Point, AP, device. In other words, the devices connected via the wireless links are known as "cells" and generally do not have any outside connections other than their connections to each other. This connection structure is known as "Ad hoc." For example, three laptops are connected via their 802.11b wireless network interface cards. In this fashion, they may transact their business through this rudimentary peer-to-peer wireless network.


Experience Note

Peer-to-peer wireless networking is the default setting for most wireless network cards.

The most common WLAN infrastructure is known as the "basic service set" where an access point (AP) and at least one wireless client are required. The AP is a device that acts as a router connecting networks, and the wireless client acts in a similar fashion to a Network Interface Card for the client device. APs are relatively small hardware devices that require very little technical knowledge and time to install. In most cases, APs can be purchased for less than $200. Wireless clients are easily installed in desktops and laptops and frequently cost less than $100. In most WLAN architectures, the AP is the connection point between the LAN and the Internet or other open-ended network, while the wireless clients are installed in workstations and mobile systems.

Connections between the AP and its clients are initiated with the proper Service Set Identifier, SSID. Basically, the SSID is the name the owner gives the WLAN network. It is supposed to provide a logical separation between the AP and its clients. In theory, clients must have been configured with the same SSID as the AP in order to connect. It is important to remember that APs act in very similar fashion to routers, and the wireless clients act in similar fashion to NIC cards.


Experience Note

It is possible for wireless clients to be placed in a promiscuous mode by placing the word "any" or leaving the configuration blank in the client's SSID configuration. In essence, this configuration will sniff the air for WLANs and possibly connect if the network does not have any other security features. Some APs are configured to broadcast their SSIDs to any receiving wireless clients. In this fashion, the wireless client connects to the sending AP without being required to know the SSID beforehand.

Most WLANs have the ability to be configured for Wired Equivalence Protection, WEP. This is an encryption method between the AP and clients. Due to flaws in WEP, it is possible for attackers to record a significant amount of the encrypted traffic between AP and clients, deduce the encryption, and decipher the traffic. This attack requires a significant amount of recorded traffic and specialized software. Regardless, successfully attacking a wireless network, featuring WEP, can be done by tenacious persons. It is simply a matter of patience and skill.


Experience Note

Any traffic that is encrypted is better than clear text traffic. If a wireless network is passing traffic of a sensitive nature, the traffic should be passed over a Virtual Privacy Network, VPN, ensuring privacy and authentication. Many manufacturers are offering APs supporting VPN technology at inexpensive prices.

802.11b Information Packet Types

Beacon packets are typically transmitted continually by APs. These packets contain the SSID, maximum transfer rate, and MAC address of the AP. Generally, APs send from six to ten beacon packets every second. Probe packets are sent by clients to APs while attempting to join a network. Probe packets request the SSID of the network it wishes to join. If an AP permits the client to associate with the target network, the AP responds with a response containing the SSID. Data packets are simply TCP/IP encapsulations of the data being exchanged between the client and the AP. Ad hoc packets are similar to beacon packets, except they are exchanged client card to client card instead of through an AP.

Wi-Fi Network Detection

Active detection is the condition where the client transmits probe packet requests and listens for responses to them. This is the process followed by Netstumbler (www.netstumbler.com). Active detection requires the wireless client to be located within the radio frequency range of the AP to exchange traffic with the target network.

Passive detection is the process where the client merely listens to all detectable traffic in the air and extracts pertinent information from the intercepted packets. The client needs to be within the useable range of the AP to detect the packets. Passive detection cannot locate an AP that is not broadcasting. The wireless sniffer application, Airsnort, available at airsnort.shmoo.com, uses this listening detection method. If an attacker uses the passive detection method, it is virtually impossible to detect an attacker monitoring the target network.

802.11b Headers

Wireless network headers contain the most basic packet information: the MAC of the transmitting source, destination, SSID, WEP information, supported transfer rates, the channel, and the direction of the communication. It is important for auditors to note that WEP only encrypts the data packets. Packets in the link-layer such as beaconing, probes, etc., are not encrypted. They are exchanged in clear text.

WEP

WEP effectiveness is determined by its key-length, the number of flawed systems generating packet traffic, and the traffic levels on the network. If there are no systems generating data traffic, then attackers are not going to have the opportunity to capture weak keys. WEP has the flaw of being a shared secret key encryption method. Once the system's key is compromised, all systems must be updated with a new WEP key. The new key must be of a greater length or the newly generated and shared key will have the same weaknesses as the compromised key. Compromised keys may result from attackers, former employees, or lost systems.

Cloaking SSIDs

Currently, there are many manufacturers that have the feature of blanking the SSID from the beacon packets. Unless the client knows the correct SSID, it cannot associate with the AP and join the network. However, this protection is possibly transparent as a client joining the network, the AP sends its SSID to the client in the clear. This becomes important in that every time a client exchanges traffic with an AP, the SSID is broadcast in clear text. Legitimate users actually facilitate the AP sending the SSID. Attackers can force an AP to disclose its SSID by attacking it with jamming transmissions and as the clients attempt to rejoin the network, there is an exchange of the SSID in cleartext. Jamming consists of any strong 2.4 GHz transmitter.

Some manufacturers attempt to protect APs by disabling their beaconing ability. This is not a panacea either, such as cloaking the SSID is disclosed as users join the network. Auditors should remember that APs not transmitting the SSID and having their beaconing disabled are merely steps toward system security. Like WEP, they are not the only steps.

Wi-Fi Audit Program Features

Signal strength is one of the features of WLANs that permits attackers to gain a foothold in your system. Walls, doors, glass, and other types of building construction will not provide sufficient containment of the wireless signal. The AP placed inside a typical office can transmit a signal anywhere up to 1000+ feet. In many settings, a signal broadcast in any direction will place it in a neighboring office, road, or parking lot. Vertical signal reception must also be considered in that offices located above and beneath should be factors when selecting a location for the AP. Attackers have been known to engage in a practice known as "war driving," in which they spend their time driving from location to location equipped with a laptop, wireless client, and specialized software in search of unsecured Wi-Fi networks. Some attackers have gone as far as integrating their war-driving network interceptions with GPS and have created maps where wireless networks and their corresponding SSIDs are listed. Several Internet Web sites are dedicated to showing the location and SSIDs of unsecured networks. Of particular interest to attackers are those unprotected wireless networks located in business conference rooms. Software designed to locate unprotected wireless networks is available from www.netstumbler.com.

Many wireless network administrators feel that configuring their networks to recognize specific Network Interface Cards in the form of their individual MAC, Media Access Control, addresses is a measure that goes a long way to securing their networks from unauthorized intruders. MACs are individually significant digital addresses assigned to NICs. MACs identify the specific component and theoretically belong only to that component and none other in the world.

So, if an administrator configures her system to accept only specific MACs, then all others should not be permitted access. In this fashion, MAC filtering provides a significant degree of wireless network security. It is important to remember that there are software utilities that allow attackers to spoof their MAC addresses, however considering the large number of possible digital MAC combinations, there are a hundred million combinations, and the probability of guessing a MAC address is practically impossible. So if an intruder successfully spoofed an authorized MAC address, the intruder has had access to an authorized piece of equipment or has successfully intercepted an authorized MAC that was broadcast in the clear without being encrypted such as a VPN. Having an accurate inventory of equipment and accompanying identifying numbers, such as the MAC, can provide some avenue as to how the MAC was compromised.

Features associated with Wired Equivalent Privacy (WEP) have given wireless administrators and senior managers a false sense of security. In short, it is possible to break WEP contingent on the tenacity, and luck, of the attacker. Even when WEP is properly deployed on a wireless network, it is possible to break the encryption and gain access to the AP. It is important to know that WEP encryption keys are static and configured manually.

WEP protocol requires the same secret key to be shared by all wireless clients within the cell. The flaws are highlighted in the manner that WEP uses Initialization Vectors, IV, in establishing the encrypted link between the AP and the authorized clients. If a determined attacker intercepts a sufficient amount of wireless traffic, he can penetrate the wireless network's WEP and gain access using available software. [12]

Beyond the idea of restricted MACs and WEP deployment, the only viable solution of private and authorized system traffic is the deployment of a Virtual Privacy Network, VPN. This is not without its issues, but it is a means of allowing only authorized clients to use the system's facilities and provides an encrypted tunnel between clients and other system components. The following factors determine whether it is worth the trouble to deploy a VPN system:

  • What is the sensitivity of the traffic this system is going to be seeing?

  • What is the importance of privacy?

  • Is it important for my wireless network to eliminate unauthorized users?

  • Is my wireless network connected to other sensitive system components? What are the risks if an attacker gained access, through the wireless network, to other network elements?


Experience Note

Recently, an auditor saw a financial processing sub-network that was separated from the organization's other internal network by a firewall. None of the workstations in the financial unit was allowed Internet access as an added precaution due to the perceived sensitivity of the unit's work. Many employees complained they were being treated poorly, so their organization established a wireless network with separate Internet workstations on each employee's desk allowing them to use the Internet for official purposes. This wireless network was not connected to any internal network and only serviced the employee's Internet needs.

Wireless Denial-of-Service Attacks

Wi-Fi networks can become victims to denial-of-service attacks in the same fashion as wired networks. They have some of their own issues distinct from conventionally wired systems.

  • Users with malicious intent can configure a wireless client to transmit thousands of connection requests to an AP eventually leading to a complete shutdown of the AP. This makes a strong auditor argument for system logging and having the MACs assigned to specific machines with accurate inventories.

  • Extraneous radio frequency (RF) generation can result in Wi-Fi jamming from sources such as an arc-welder. Having an AP that cannot receive the transmissions of its assigned clients due to powerful RF jamming from a nearby construction project or body and fender repair shop will not receive intended traffic.

  • In wireless systems, it is possible to reach a saturation of RF devices. This is true in 802.11b, 802.11a, 802.11g, and Bluetooth systems. In essence, there are more users than the system can handle.

Auditor Considerations for Wireless Networks

Wireless networks have a different set of system security countermeasures than hardwire systems do. These are some audit program features that may be worth incorporating:

  • APs should have the correct antenna configuration.

  • If the system has the ability to attenuate the signal strength, has the broadcast signal strength been reduced sufficiently to cover the intended area and no more?

  • Turn off the SSID broadcasting at the AP. If this is not possible, consider using another vendor if restricting unauthorized users is a primary consideration.

  • What SSID naming convention was used? SSIDs should not disclose any useful information about the wireless system, for example: Finanzoffice, HRMail, or BWINET.

  • What is the level of security dependence on the client's MAC as an access authenticator? Wireless systems must not solely depend on MAC layer filters as their only security measure. This is one of those steps that should be part of the whole system authentication process. Remember that MACs can be spoofed.

  • Does the target system have an Intrusion Detection System, IDS, configured to alert administrators in the event an excessive amount of ARP, Address Resolution Protocol, replies are detected on the system? Remember that ARP associates MAC with IP addresses.

  • Is the system configured with software tools that will provide notification when IP to MAC bindings change. One such tool is called Arpwatch and is available at www.nrg.ee.lbl.gov.

  • Has a VPN solution been effectively implemented between the target system and the clients? Use a third party VPN solution to connect the clients to a single AP with each use being routed to the appropriate VPN endpoint in the organization's network.

  • Are there multiple APs to access different segments of the system, each with a unique SSID?

  • Does the organization's current policy prohibit the installation of APs and other hardware/software without prior written approval of the information security officer?

  • Are all APs logically located outside the organization's perimeter firewall?

  • Are all unused internal switch ports disabled?

  • Is there a systemwide mechanism to monitor any new MAC addresses on the organization's internal system? How effective is this monitoring?

Firewall Auditing: First We Build an Impregnable Barrier, then We Punch Holes in It

If administrators were to name the hardware/software device that is the most critical for system security, they would most likely name the firewall. Of course, firewall architects will swear their equipment and software will stop all illicit intruding traffic and possibly rampaging elephants.

Barbarians at the Wall

In the firewall assessment process, it has to be determined exactly what it is the organization is expecting of its firewalls and that the firewalls are performing at that level of expectation. Assessing the firewall is done with a copy of the organization's policies in hand before verifying the firewall's rulebase. Basically, auditing a firewall consists of two steps. The first step consists of testing the firewall itself and ensuring it is secure. The second step is testing the firewall's rulebase ensuring that only authorized traffic is permitted to pass through it. After all, the firewall's purpose is to deny entry to all traffic, except traffic that is specifically enumerated as being permitted to pass in the rulebase.

These are steps that should be included in the firewall audit program:

  • Demonstrate that the firewall is physically secure having very restrictive access. No one should have access without a very specific reason to the machine where the firewall is located. In other words, is the firewall secure from everyone except those having a need-to-know?

  • Is remote access permitted to the firewall? Is there a very serious need for remote administration? If not, is the firewall accessible from terminals outside its physical location, and why? Is the firewall accessible only from the physically attacked console?

  • Is the operating system used to support the firewall fully armored? Have all unnecessary hardware and software features not needed to support the firewall's operation been removed? Does the firewall reside on a machine used for other functions other than the firewall? It is strongly recommended that all firewalls, regardless of their type and configuration, reside on dedicated machines, devoid of other applications.

There are many checklists available for locking down operating systems. The platform supporting the firewall should be a barebones installation with only the features and ports required to support the firewall opened and enabled.


Experience Note

An auditor was engaged in a firewall audit and asked to review the system supporting the network firewall. The administrator admitted the auditor to the secure firewall room and showed her to the computer supporting a proxy service. The auditor noticed a pair of speakers attached to the computer and asked why these were present. The administrator stated she used the computer to listen to music while working in the room. After a closer inspection, the auditor noted the installation of a sound card, supporting sound software, MP-3 software, a media player, and a CD-RW in addition to the already installed CD-ROM. Her audit report reflected her findings.

Auditors may want to scan the firewall ports from internal and external views looking for UDP and TCP open ports. On most correctly configured firewalls, auditors should find few open ports, and auditors should not be able to "ping" the firewall and receive a response.


Experience Note

Auditors should employ a number of scans, other than the Ping, in their firewall assessment.

Auditors should be aware that many firewalls have open ports as a matter of default installations. For example, in some firewall installations, ports 256 and 258 are open for administration of the firewall by default. All ICMP ports should be closed thereby thwarting an attacker's ability to map the internal system. If administrative ports are required, then a formal policy should reflect which specific ports are to be open and that only specific IP addresses are allowed to connect to them. Obviously, the idea behind the firewall's configuration is to deny all connections except those specifically allowed.

Firewall Rulebase

The goal behind examining the rulebase is to ensure that the firewall is enforcing what is expected of it, any exceptions should be considered a performance gap and finding. Examining the actual firewall policy can be done by assessing the processes allowed to pass denying all others. This can be accomplished by placing a laptop, with a scanning program such as Nmap installed, on the outside of the firewall and attempt to scan a system located on the inside of the firewall. Placing a workstation on the inside of the firewall with and TCPdump, or Windump, installed will allow the auditor to examine all passing traffic and determine if the written firewall policy is reflected in the passing traffic.

Because firewalls may be used to partition segments of a network, it is prudent to scan network segments. For example, if a firewall is connected to the outside open-ended network such as the Internet, a scanning computer should be connected to this outside connection. The scanner should scan the firewall looking for the protected DMZ network segment and test the permitted traffic rulebase. From this point, other network segments can be scanned from the scanning machine's perspective. It is a wise step for an auditor to validate the DMZ rulebase and attempt to penetrate the internal network. This basically determines the probability of an attacker compromising the DMZ, containing such services as DNS and Web services, and gaining access to the protected internal network. It is important for auditors to note that if they have the organization's policy in one hand and their scan results are different, then they have an item requiring quick resolution. If the auditor discovers open doors in firewalls, this is cause for immediate and positive action before attackers can launch against these potential exploits.

Before merely listing the open ports and unnecessary services, auditors should assess the degree of risk they pose to the organization. By doing this, the auditor extends her view beyond the firewall and begins to gain visibility into the internal network.


Experience Note

Ranking vulnerabilities according to their risk is part of professional due diligence and good procedure. It is the auditor's goal to identify the existence of system vulnerabilities. The system should not be limited to the firewall's function; rather it should extend beyond.

Exhibit 1 is a sample of a typical firewall policy for Web service on port 80.

Direction
Source Address Destination Address Protocol Source Port Destination Port Notes
In External Internal TCP >1023 80 Request external client to internal server
Out Internal External TCP 80 >1023 Response internal server to external client
Out Internal External TCP >1023 80 Request internal client to external server
In External Internal TCP 80 >1023 Response external server to internal client
Exhibit 1: Firewall Policy Sample

For each of the firewall's permitted protocols, the firewall should have a policy statement similar to the one above where allowed traffic is scheduled with all others being denied passage. There should not be any services for which there are not rules. Exceptions are considered deviations and should be identified as audit report findings.

Look at Logging

After assessing the permeability of the firewalls, take a serious look at firewall logs:

  • Did the firewall detect all the earlier scans and were expected alerts made to the appropriate employees?

  • What was the extent of the firewall's logging?

  • If the firewall did not log all the scans, why did not it?

  • How extensive is the logging? Is the logging capability remotely accessible?

  • Is the media holding the logs erasable?

  • Are firewall logs stored within the interior protected network?

  • Has the machine holding the logs been fortified against attacks?

Auditing Remote System Administration


Generally, administrating a network consists of updating user accounts, examining logs, establishing and maintaining standard configurations, and installing and updating software. Administrators perform these tasks from either the location of the workstation or server or from a remote location. For the administration team who has several hundred servers and several thousand workstations, handling these tasks remotely is the most effective and efficient way of doing business.

Here are a few considerations that should be part of the auditor's program in systems with remote configuration capability:

  • Ensure that the system accepts administration commands from only an authenticated administrator. Client systems must use strong authentication and traffic encryption mechanisms. Under no circumstances should the administrator send her password in clear text to the system on which she is going to work. The only logical exception for transmitting the user password in clear text is the use of one-time passwords transmitted from the administrator and accepted by the target system.

  • Auditors must ensure that the system permits administration to take place from the authenticated host only. It is important that the system receiving the administrator's attention authenticates her identity through means distinct from IP addresses or DNS names, as attackers can easily spoof (falsify) such information. In the case of UNIX, using an authentication tool such as secure shell, SSH, is recommended. In other cases, establishing a VPN, Virtual Privacy Network, where the identity of the administrator is assured and the computer traffic is encrypted through a tunnel, is also highly recommended.

  • Auditors must ensure that all administration tasks are operating at the minimum privilege necessary. Administrator tasks should only be performed at minimum privilege levels and not higher. It is a wise consideration to review the separation of duties among administrators so privilege levels are restricted to just a few employees. Of course, the size of the operation will generally dictate the number of privileged individuals. This procedure eliminates risks in having a single point of failure with one administrator.

  • Auditors must ensure that administrator information cannot be intercepted, modified, or read by attackers. Mechanisms such as encrypted traffic or VPNs will go a long way ensuring that traffic travels between the administrator's system and the system being serviced in a private and unaltered fashion. If the administrators' communication packets can be read by unauthorized persons, not only does this pose a serious risk to the target system, but this information could be used to attack other systems.

  • Auditors should determine if administrators have created checksums of critical system files before placing the system in a production environment. This will permit administrators to know if important files have been altered, deleted, or created by attackers hoping to corrupt the target system.

Popular Posts