Home > Mobile Computing Tips > Mobile Security > Wireless security and privacy: Best practices and design techniques
Mobile Computing Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

MOBILE SECURITY

Wireless security and privacy: Best practices and design techniques


Ed Tittel
03.10.2004
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


The title of this week's tip is actually the title of an excellent book by Tara M. Swaminatha and Charles R. Elden (Addison-Wesley, 2002, ISBN: 0201760347). Although it's a bit dated because it omits coverage of 802.11g and 802.11x security issues (more on those topics in tips to come), it's nevertheless a worthwhile addition to anybody's wireless library because it deals with 802.11b (still the most common type of wireless networking technology in use) and because of its simple, straightforward coverage of key topics in wireless security and in designing more secure wireless networks. The book also covers BlueTooth and the Wireless Application Protocol (WAP) in some detail.

The book begins with an overview of these key wireless technologies, then goes on to explore typical wireless networking setups. These include so-called personal area networks (PANs, usually deployed in small-scale home settings), local area networks (usually abbreviated as WLANs, for wireless LANs, to distinguish them from wired networks), and wide area networks (WANs). Next, the book moves on to examine a series of four case studies with a primary emphasis on WLANs, including scenarios in a home, an office complex, a university campus and a hospital.

In explaining and exploring wireless security, the authors stress security as an ongoing process that must start with system design, and carry through pilot test, deployment, maintenance (and ultimately, migration to some successor). They also do a great job of covering key security principles to provide readers with the vocabulary and techniques necessary to assess risk and establish proper security implementations. Along the way, they provide cogent and succinct coverage of key security topics that include AAA (authentication, authorization, and accounting/auditing), access controls, confidentiality, integrity, privacy, and non-repudiation.

They also delve into wireless networking devices and configurations, cryptography, and privacy topics. The book concludes with a series of four chapters on what the authors call the I-ADD security analysis process:

  • Identify targets and roles
  • Analyze known attacks, vulnerabilities, and potential attacks to avoid or protect yourself from them
  • Define a security strategy, establishing trade-offs among security, functionality, and management as your risk analysis requires
  • Design security into your systems from the get-go

For those seeking to understand wireless security concepts and principles, this is a terrific book. But it is not a product guide or a step-by-step deployment manual. For those purposes, other tools make more sense (and will be covered in future tips).


Ed Tittel is a full-time writer, trainer, and consultant. He's written widely on security topics, including security policy tips for SearchSecurity.com, certification prep books for TICSA, CISSP, and Security+, and as a contributing editor for Certification Magazine. E-mail Ed at etittel@techtarget.com.


Rate this Tip
To rate tips, you must be a member of SearchMobileComputing.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Security
Wireless security
RIM announces overhauled Enterprise Server
New products, standards help boost wireless security
Safe computing in public hot spots
Don't be fooled by the Java sandbox
Nonpareils of mobile security info: Intel's Wireless Security Resource Center
Symbol upgrades to meet new Visa security standards
Centralized PDA virus protection released
WEP vulnerabilities -- wired equivalent privacy?
Duo forges new creed for mobile data backup

Mobile Security
Mobile security threats
Two-factor authentication: Mobile security at your fingertips
Securing your Windows Mobile devices
In-the-cloud defenses for mobile malware
On-device defenses for mobile malware
Is malware coming to a smartphone near you?
Protecting data on your BlackBerry
Defining your mobile security policy
Government regulations and mobile security policies
Symbian: Protect your data, not just your device

Mobile Device Security
Fingerprint recognition and mobile security
Traditional security threats coming soon to mobile device near you
Securing your Windows Mobile devices
Mobile security: Protecting your data, not just your devices
Prevent mobile malware: Learn how to protect your enterprise and devices
Podcast: The truth about network security and mobile device access
Protecting data on your BlackBerry
Going green: Recycling and energy saving tips for mobile devices -- podcast
New challenges in mobile device discovery
Quiz: Mobile Device Security -- Who else can hear me now?
Mobile Device Security Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
mobile VPN  (SearchMobileComputing.com)
real-time location system (RTLS)  (SearchMobileComputing.com)
screaming cell phone  (SearchMobileComputing.com)
SMiShing  (SearchMobileComputing.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Mobile Computing Security - Device Security, Mobile Authentication, Mobile Threats

Notebook Deals at Notebook Review

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts