design

 
Find IT training and SDLC training by State
 

click the map, enter a zip,
or course keyword to find
our current public sessions
    About ASPE Technology  |   Get Credit  |   Contact Us  |   Testimonials  |   Client List

For real-time information or assistance with classes,
call us toll-free at 877-800-5221 or email us at customerservice@aspetech.com


Course HomeCourse DatesCourse DetailsCourse OutlineCourse FacultyCourse Procing
 

COURSE 1200 | 2-DAY SESSION
Hands-On Wireless Network Defense
Course Outline

Hands-On Labs and In-Class Demonstrations
you must bring your laptop to participate in the hands-on labs during this course.

1) Hands-on—Network Discovery: Wireless Devices, Access Points and Packet Capture
2) Hands-on—Discovery of Closed Networks using Probe Requests and Probe Responses

3) Demo—Wired-Side Network Discovery using SNScan

4) Demo—Network Discovery with a Spectrum Analyzer

5) Hands-on—Capture and Decode Packets using Ethereal

6) Hands-on—Use AirSnort to Crack Web Encryption

7) Demo—Set-up Soft Access Points to Decoy and Masquerade

8) Hands-on—Counterfeit Packet Injection and Replay Attack

9) Demo—Mock Denial of Service Attack Using Signal Bombing

10) Hands-on—MAC Spoofing to Circumvent MAC Access Lists

11) Demo—Security Capabilities for Consumer to Enterprise Grade Access Points

12) Hands-on—Setup and Run Fake AP to Simulate War Drivers

13) Demo—Demonstrate the Configuration and Operation of a Wireless Intrusion Detect System


Section 1: Reconnaissance — Wireless Network Discovery
In this section, we will explore both active and passive scanning techniques for detecting and locating wireless networks. You will learn to use the freeware products most commonly used by hackers to detect wireless networks. You'll learn about the communications that normally occur between a Wireless Access Point and a Wireless Client device, and how that information can be used to detect even supposedly "closed" networks. We'll also take a look at several commercial wireless detection products.

  • What does the WiFi Finder tell us?
  • Passive scanning with PocketPC
    1. MiniStumbler
    2. PrismStumbler
    3. MAC address
    4. Service Set Identifier (SSID)
    5. Using Signal Strength for AP location
  • Beacon Frames
  • Active scanning with Windows Laptop
    1. Wireless Client Utility
    2. NetStumbler
  • Probe Request & Probe Response
  • Rogue Access Point detection
    1. Friendly vs. Hostile Rogue Access Points
  • Active scanning with Linux Laptop
    1. Kismet
    2. Wellenreiter
    3. WiFiScanner
    4. WlanProbe
    5. AirTraf
  • Site Survey
    1. Mapping Authorized Access Points
    2. Wireless Perimeter Definition
    3. Directional Antennas
    4. Periodic Security Scan
  • WarChalking

Section 2: Intelligence - Packet Capture & Analysis
In this section you will learn to use a variety of freeware and commercial tools to capture and decode wireless network traffic. You'll see firsthand the vulnerability of unencrypted traffic. You'll learn to capture and decode logins and passwords for email, FTP and other applications.

  • Windows-based capture and analysis tools
    1. Ethereal and WinPCap
    2. AiroPeek
    3. AirMagnet
  • Linux-based capture and analysis tools
    1. Wellenreiter
    2. WiFiScanner
    3. AirTraf
  • 802.11 MAC Frame Format
  • Wired Equivalent Privacy (WEP) Encryption

Section 3: Threat Models
In this section you will learn to use a wide variety of tools and methods commonly used by hackers to attack your network. You'll learn to use AirSnort to crack a WEP key. You'll set up a Man-in-the-Middle attack. You'll learn how to combine RF Jamming with a Decoy Access Point. You'll see MAC Spoofing used to circumvent a MAC Access List.

  • Confidentiality
  • Cracking WEP encryption
    • AirSnort
    • WEPcrack
    • WEPWedgie
  • Man in the Middle
    • Wired
    • Wireless
  • Decoy Access Points
    • SoftAP
    • Integrity
  • Man in the Middle
  • Packet Injection
    • AirJack
  • Replay Attack
  • Access
  • Denial of Service (DoS)
    • RF Jamming
    • Disassociate Signal Bombing
    • War Spamming
  • ARP Attacks
  • MAC Spoofing
  • SMAC

Section 4: Countermeasures
Now that you have a good understanding of the potential vulnerabilities of Wireless LANs, and the attack methods designed to exploit them, we turn our attention to countering those attacks. You'll learn who and where the threat comes from, and how to configure any and all parameter settings to minimize your risk. What are the new security-related standards all about, and what can they do to defend your network?

  • Who is the Hacker?
    • Insider
    • Outsider
    • Social Engineering
  • Access Point Configuration Guidelines
    • Password
    • SSID
    • DHCP
    • MAC Access List
    • SNMP
    • DMZ
  • Authentication
  • WiFi Protected Access (WPA)
  • Extensible Authentication Protocol (EAP)
    • Lightweight EAP
    • Protected EAP
    • 802.1x
    • RADIUS
    • Virtual Private Network (VPN)
  • Encryption
  • Enhanced WEP (802.11i)
  • Temporal Key Integrity Protocol
  • Message Integrity Check
  • Advanced Encryption Standard
  • Counterattacks
    • Wireless Honeypots
      • Honeyd
      • FakeAP

Section 5: Multi-Layer Security
This section is a comprehensive review of configuration options and security policies. You'll learn to implement a multi-layered defense strategy. This strategy is intended to minimize wireless network vulnerabilities and significantly increase the time and effort required to penetrate your network.

  • Access Filters
  • Server-based Authentication
  • Authorization
  • Encryption
  • Wireless Security Policy Addendum

Section 6: Intrusion Detection Systems
In this section you'll learn about wireless Intrusion Detection Systems (IDSs). These systems attempt to identify network intrusions and misuse by gathering and analyzing data. You'll explore how wireless IDSs monitor and analyze user and system activities, recognize patterns of known attacks, identify abnormal network activity, and detect policy violations for WLANs. You will learn how wireless IDSs gather local wireless transmissions and generate alerts based either on predefined signatures or on anomalies in the traffic.

  • Wireless Intrusion Detection Architecture
  • Threat Detection
  • Threat Response
  • Commercial Products
    1. Airdefense RogueWatch and Airdefense Guard
    2. Internet Security Systems Realsecure Server
    3. AirMagnet Distributed
    4. Neutrino Wireless Intrusion Detection System
  • Linux & Shareware Solutions
    1. Snort-Wireless
    2. WIDZ
    3. AirSnare






ASPE logo