
46
V 2.2 Copyright SystemExperts 2001,2002,2003
91
Future 802.11 Security Enhancements
n Standard 128-bit WEP encryption (WEP2)
n Already implemented by all of the major vendors but
has not been standardized yet
n Advanced Encryption Standard (AES) for
WEP
n Standard key exchange and distribution
n EAP & LEAP seem to be the wave of the future
n Improved data integrity via keyed message
authentication
n Better message integrity checking
V 2.2 Copyright SystemExperts 2001,2002,2003
92
Observations
n This is relatively new territory, so watch for
significant changes
n WEP can be a legitimate tool in the security arsenal
n View 802.11 networks as an insecure MAC layer, over which
you run secure IP protocols
n Use WEP/EAP/802.1x to protect against casual snoopers,
local DoS attacks, and bandwidth theft
n WEP won’t help with stolen equipment and
ex-employees
n It appears that ESN/802.1X has more momentum
than anything else
(i.e., Cisco and Lucent support it)
Kommentare zu diesen Handbüchern