Wireless network security covers the principles and tools used to protect Wi-Fi infrastructure, from site planning and signal management to encryption standards and authentication protocols.
Wireless Security
One thing that we need to be really diligent about is making sure our wireless networks have good security. Otherwise, we are just broadcasting our information out into the world.
When it comes to wireless, the best thing that we can do from a security standpoint is not have wireless at all. The problem is that if you install wireless, then it casts this information out into the world, and anybody that is sitting on the outside here can then see the traffic that is going back and forth. There is no way to stop them from seeing the little ones and zeros that are going across the air. There are ways that we can secure that, but they still see it. So we need to watch out for implementing wireless security.
In a lot of businesses it is probably not realistic to do away with wireless. That is, we are probably going to have to implement some form of wireless in most of our networks. The problem is that it is just so convenient. Imagine everybody comes to a boardroom here, or some sort of conference room, and they have got their laptops. They are either not going to have connectivity, or they are going to have to string cords back and forth in order to gain that connectivity, if they do not have wireless. So really, most businesses are probably going to implement some form of wireless. But how do they do that securely?
It all starts out with a site survey - understanding what your site looks like. What you would do is go through and map out your office building and what it looks like. You are going to map out the walls, not only just what walls they are, but what type of walls they are. Are they hollow, or do they have insulation in them? Are they made of bricks? Are they made of concrete? Are they made of drywall? All that is going to determine how well the signal goes through it. So we are going to make a determination of how well our radio signals are going to be sent throughout this whole office plan here.
We are also going to take a look at things like microwaves. Here is a lunchroom right here, so there is probably some sort of microwave here. We are going to look at interference that is going to interfere with our signal.
We are also going to take into account how many users are going to be in each of the areas. For instance, this is a conference room and can have a lot of users in this area. We have quite a few users that can set up there. On this side, maybe not as much. So we are going to have a different set of users in each one of these rooms, and we have to understand how many users are going to get on in a certain area.
Once we have our site survey, we are going to want to start determining what our heat map looks like. A heat map is going to be where you put your access points and how far out they broadcast. There are certain powers to each one of our access points that we put in there, and we can vary that power depending on how far we want to cast that signal.
If we just had one access point that serviced all of this area, we might have to have a really strong power, in which case it could cast well beyond the walls that we have on this building. What we want to do is gear this up so that we are not casting it too far out. We want to just supply internet access wirelessly through this building, based on what the shape of this building or this area looks like, and also based off of how many users are in each of those areas.
So what we do is we create a heat map. We start analyzing where we should put access points and where each is going to service, and we start manipulating and controlling that so that we have good coverage in this area without casting it out too far. Maybe in this building we just need two access points: one that is going to cast a little bit further out, so it is going to be at a higher power, and one that is going to be at a lower power that is going to cover this other wing here. So we would want to set up two different access points.
There are also a lot of options that we are going to need to figure out, in terms of what it is that we are willing to support. For instance, there are a lot of different wireless protocols, and they encompass different encryptions and different authentication protocols.
One of them is wired equivalent privacy. The idea behind this is that it was supposed to have privacy similar to the wired equivalent, which means that you are plugging it in, which means it is not really casting it out. What it is doing is it is so secure that it is like a wired system. Turns out that this was not that way, that it was hacked very easily and was really problematic.
Shortly after that, they came out with Wi-Fi protected access, or WPA, and then they came out with WPA2 and WPA3. So we have some options here. This is the newest of the ones as of this video, but WPA3 also does not necessarily have full compatibility with all the systems that are out there at this point.
We also have different authentications that we can do, such as personal or enterprise. Personal just means you have a pre-shared key, and you just type in what that key is and then it uses that for the authentication. Or there is enterprise, which is 802.11x, and we can do that with credentials - have the user type in the credentials - or with a certificate.
Each one of these has their different encryptions that they use for encrypting that traffic. They also have, for the session keys, different lengths of session keys, and we are not going to get in depth into that. Just know that this is a level of security, depending on what the session key options are there. They have the authentication protocols that they are going to support with it, or authentication approaches.
Really, WEP and WPA are considered insecure at this point in time. WPA2 is not the best option, but it is better than WEP and WPA, and then WPA3 is the best option here, but not everything supports that.
The enterprise is essentially 802.1x on the back end. So when we select enterprise, we are selecting 802.1x, and then it is set up just like the 802.1x that we have been talking about. Both WPA and WPA2 have several different extensible authentication protocol methods that they will support.
Now, the authentication protocol is to carry on that authentication, but in itself it is not going to secure the traffic. So we also need some sort of cryptographic protocols to help secure that. These are the different wireless protocols and the cryptographic protocols that they use in order to encrypt that traffic.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →