Weigh and mitigate wireless risks: there need be no security trade-off

December 2003 Infrastructure

Wireless is a smart bet that is gaining corporate momentum, but the security concerns have put corporate spend in a holding pattern. “Security is certainly a big issue but standards are rapidly being ratified and the picture is becoming clear,” says Mark Lilje, MD at RangeGate. “There are several layers of security that can be implemented to safeguard sensitive data. It just takes some common sense.

Mark Lilje
Mark Lilje

"We have been in this market for 14 years, and we know of hundreds of wireless networks running in South Africa, many of them in the warehousing and distribution arenas - and we have implemented many of them. The focus is now shifting to the office environment, but companies wary of adoption are losing the opportunity to invest in architecture that could be of enormous benefit. The solution is to implement with caution, remaining aware of, and mitigating security risks according to the sensitivity of data with the technologies at hand.

"In three years' time we will have seamless roaming between WLANs and cellular networks and, according to researchers, in 15 years there will be more data travelling over WLANs than over cell networks. Locally, the wireless infrastructure market is expected to be worth R1 billion in revenues by 2005. and this excludes access and client device revenues," says Dave Scruse, account manager: wireless networking at RangeGate

"It is easy to get tangled up. Wireless security offers a maze of choices and the slow pace of security standards ratification has given rise to a number of interim solutions," says Lilje. "But do not get caught up in the hype.

"Yes, people can eavesdrop on your wireless communications and hack in through your wireless network if you do not put the right levels of authentication and encryption in place, but the security solutions are here. The latest 802.11i standard is ready to be ratified early next year. Upgrade paths are also being built into new products and alternatives (such as a switch which replaces the access point, with all the advantages of greater intelligence and component upgradeability) are being developed, cutting the cost associated with traditional wireless rip and replace strategies."

Just as important is to lock down the rest of the wireless value chain. Client device asset management, network management, and the physical security of your wireless infrastructure also play a role. Wireless LAN solutions are no longer islands of specialised functionality; they have to be integrated into the rest of the network infrastructure and applications.

"The risk and costs associated with wireless solutions need to be carefully weighed and mitigated - there need be no trade-off on security. It is essential that users and enterprise architects understand the issues, however - connectivity and setup are critical."

A quick glance through the wireless security standards developments paints the background against which companies must develop their security architectures.

The choices

"There is the tried and true IP Security (IPSec) that can be used in a virtual private network but it is limited to IP traffic, with all the complications of wired IPSec, such as configuration complexity and the requirement of client-side code," explains Scruse.

"Then there is the 802.11 Wired Equivalent Privacy (WEP) protocol. WEP's short and static encryption keys do not offer much in the way of security but proprietary and other solutions are attempting to make up for this. Companies such as Symbol have developed an enhanced key rotation technology, for example, that varies the security keys used in WEP at user-specified intervals, making it more difficult for an eavesdropper to obtain enough information to crack WEP keys. Vendors such as Cisco have also developed proprietary solutions that are built into their products. The problem here is that the user is limited to using one vendor's products.

"One up on this is Wi-Fi Protected Access (WPA), which the Wi-Fi Alliance vendor group announced last October. The first WPA-certified products are expected to become available this year based on the first WPA-certified chipsets. Of course South Africa is usually about six months behind on adoption and implementation of these products," says Scruse.

WPA offers stronger encryption with a firmware upgrade that overwrites WEP, and adds authentication protocol 802.1X.

The other choice is the IEEE's 802.11i. It is the WPA standard with stronger encryption and is expected to be completed early next year. Products that claim full or partial 802.11i compliance might begin to ship before 802.11i's ratification. Fully compliant products may only begin to appear in the second quarter of 2004."

The real issues

"The real issues are upgrade paths, migration, integration and compatibility. Of encryption and authentication, the latter is currently the weakest link. Authentication depends on the IETF and there are five incompatible variants of extensible authentication protocol (EAP) that can be used with 802.1X, including proprietary versions from vendors such as Cisco," explains Scruse. "The client and access points have to use the same version for proper authentication. Meanwhile, the EAPs are all at different stages of development or maturity and have different levels of compatibility.

"Replacement also currently means 'rip', which in turn can destroy the solution's estimated ROI because it negates the depreciation period of the equipment. ROI is thus not something many want to bet on.

"A blended or dual access point environment is one solution, while other users are placing their bets with a single vendor, relying on their speed and security upgrade paths. The alternative is to go with IPSec VPNs until the 802.11 standards have matured and de facto EAP winners emerge."

Conclusion

"The value proposition of wireless technologies has been proven; it is now a matter of deciding where and how you want to gear for inclusion of wireless solutions into your existing enterprise architecture," says Lilje. "The single biggest success factor is understanding the strengths and weaknesses of the wireless strategy you choose and ensuring that suitable measures are in place to gain the business advantage without the risk."

For more information contact Mark Lilje, RangeGate, 011 723 9300, mark.lilje@za.rangegate.com





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Five signs your storage is holding you back
Infrastructure Surveillance
In the drive for business growth, organisations across South Africa are investing heavily in talent, applications, and strategy. Yet the foundational technology that underpins every digital interaction - data storage - is often overlooked.

Read more...
Service robot technology for residential complexes
Suprema AI & Data Analytics Infrastructure Residential Estate (Industry)
Suprema has signed a three-party memorandum of understanding (MOU) with Hyundai Motor Group Robotics LAB and Hyundai Engineering & Construction (Hyundai E&C) to collaborate on advancing residential complexes through service robot technology.

Read more...
Genetec launches Cloudlink 2210
Genetec Infrastructure Surveillance
New cloud-managed appliance addresses the practical challenges when adopting a cloud-managed model at scale, including storage costs, support for devices that do not enable direct-to-cloud connectivity, and the need to maintain local operation during connectivity disruptions

Read more...
Proactive estate security in Cape Town
neaMetrics OneSpace Technologies Technews Publishing SMART Security Solutions Fang Fences & Guards ATG Digital Editor's Choice News & Events Integrated Solutions Infrastructure Residential Estate (Industry)
SMART Security Solutions started the year with our annual SMART Estate Security Conference in Cape Town on 26 February 2026. Held at Anna Beulah Farm, the conference saw a number of delegates enjoying the farm’s excellent cuisine, while listening to outstanding presenters.

Read more...
AI projects are failing at alarming rates
AI & Data Analytics Infrastructure
As organisations around the world accelerate their investments in artificial intelligence, digital transformation and data analytics, a growing number of industry experts are warning that many companies are still approaching these initiatives in fundamentally flawed ways.

Read more...
Understanding the Shared Responsibility Model
Infrastructure Security Services & Risk Management
While the cloud can certainly be a growth enabler in many ways, it can also introduce new security risks. Companies want to have a clear understanding of where their security duties end and where their cloud service provider’s begin.

Read more...
Cloud security in visitor management and access control
SA Technologies Access Control & Identity Management Infrastructure Residential Estate (Industry) Commercial (Industry)
Cloud has become the default platform for modern security operations, from visitor management portals and remote access control to incident logging, reporting, analytics, and integrations. But “in the cloud” does not mean “someone else is securing it for us”.

Read more...
New commercial and technical appointments at Veeam
News & Events Infrastructure
Veeam Software has announced two senior appointments in its South African business as it continues to invest in local market growth and partner and customer engagement.

Read more...
Access as a Service is inevitable
Technews Publishing SMART Security Solutions ATG Digital Access Control & Identity Management Infrastructure
When it comes to Access Control as a Service (ACaaS), most organisations (roughly 90% internationally) plan to move, or are in the process of moving to the cloud, but the majority of existing infrastructure (about 70%) remains on-premises for now.

Read more...
Privacy by design or by accident
Security Services & Risk Management Infrastructure
Africa’s data future depends on getting it right at the start. If privacy controls do not withstand real-world conditions, such as unstable power, fragile last-mile connectivity, shared devices, and decentralised branch environments, then privacy exists only on paper.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.