Wireless Risks
Many security professionals fall into the trap of dealing only with the theory and not the practice of defending a network. While it would be great to be protected from all potential attacks that a wireless network may come under, that level of protection may not be practical.
When securing your network, you must consider the risk associated with each attack and address it accordingly. The topic of risk assessment and risk management is one that could fill a book on its own. However, it is important that you understand the basics of risk assessment so you spend your time and money wisely addressing the real issues rather than waste resources on topics that present no risk.
Determining Risk
Figuring out your risk boils down to questions like: “What can happen?”, “How likely is it to happen?”, “What occurs when it happens?”, and “How hard is it to defend against?”. The “What can happen” question has already been answered in this chapter. Determining the likelihood of any particular attack is the next step.
The likelihood of an attack depends on factors such as:
- How easy it is to launch the attack?
An attack that is theoretical today may be widely distributed in “script kiddie” code tomorrow. The problems with WEP started out as a paper that described the theoretical problems with the protocol. Very few people had the ability to take the vulnerability and write code to exploit it. Within a few months, several different exploit programs had been developed and were publicly ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access