Skip Links

Network World

  • Social Web 
  • Email 
  • Close

How we tested

By Joel Snyder and Rodney Thayer , Network World , 10/04/2004

We set up two test beds at Lab Alliance partner Opus One's labs in Tucson, one for stations (clients running wireless network interface cards) and one for access points and wireless LAN switches.  Both sets of tests were monitored using Dell laptop computers running Red Hat Linux 9 and a modified version of AirSnort, the open source Wired Equivalent Privacy (WEP) key recovery tool.  We also made heavy use of our AirMagnet Handheld to diagnose minor interoperability issues between different wireless devices.

AirSnort is designed to recover the WEP keys of any network it sees, as quickly as possible.  It does this by collecting all packets from all stations and all access points.  We modified our version of this open source tool to only look at the packets sent from the device being tested.  This change enabled us to identify whether it was the station or the access point that was vulnerable to AirSnort key recovery.  We also modified AirSnort to print out the "weak" initialization vectors that it was using to guess the WEP key.


Cracking the wireless security code
Security picks
What we tested
WEP: Stick a fork in it
802.1X: A stepping stone
WPA - An accident waiting to happen
802.11i: The next big thing
Security standards aside, lock down your boxes, boys!
Wireless Access Point: Wire-side security testing (PDF)
How to do it: Securing your wireless LAN
Tools, not standards, that help tie down wireless nets
Glossary of wireless security terms
Explaining TKIP
Archive of Network World reviews
Subscribe to the Product Review newsletter


We used an IBM Thinkpad laptop with a 1.2 GHz processor and 512M-byte RAM running a clean installation of Windows 2000 SP4 to test each wireless PCMCIA card, connecting the station to a Cisco Aironet 350 access point.  To test access points, we used the same laptop with a Cisco Aironet 350 card to generate traffic.

For each test, we used the Unix "ping" command with the flood option to generate a high rate of bidirectional traffic over the airwaves.  We let the AirSnort laptop listen to the traffic for a minimum of 50 million packets, usually about 12 hours at the very high traffic rate we were generating. 

We wanted to be sure that AirSnort saw every possible initialization vector (IV), therefore giving it the best chance of recovering the WEP key.  Since there are 16 million IVs, we had to generate sufficient packets to guarantee that every IV was seen at least once (it doesn't do AirSnort any good to see the same IV twice).

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

File Integrity Monitoring: Secure Your Virtual and Physical IT Environments

Discover the capabilities your file integrity monitoring solution should have to effectively secure...

Realizing the Potential of User-Generated and Social Networking

Can communication service providers (CSPs) leverage Web 2.0 services and create new service...

Digital Asset Management Strategy

The reality of Dramatically changing media landscape, has created awareness within the media and...

Webcasts

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Intelligent Mobility: BlackBerry Technical Seminar 2008

The virtual BlackBerry Technical Seminar keeps growing in popularity every year, and we want to...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Special Reports

Ethernet Services: WAN options mature

WAN Ethernet services are reliable, cost-efficient offerings that are widely available and in a...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.