Jason Crawford has learned that if you want to break into secure Wi-Fi networks, you don't need to buy equipment from the black market. Instead, you can buy it from Toys "R" Us, he says.
Crawford, who works as a principal investigator for R&D projects at Lockheed Martin's newly opened wireless-security laboratory, says he has figured out how to crack the seemingly secure wireless networks that consumers and corporations use -- with nothing more than a cluster of eight PlayStation 3s. Crawford won't go into the details of just how he used the PS 3s to hack Wi-Fi networks, but he says that you don't have to be a top-level hacker to figure it out.
"The PS 3s use a processor called the Cell Broadband Engine, and it's so insanely fast that it didn't take long for us to crack [Wi-Fi Protected Access] networks once we started writing some software for it," Crawford says. "I set up a cluster of about eight PS 3s. . . . Getting them together wasn't all that expensive," he says.
Crawford's PlayStation hack is just one of many projects that Lockheed Martin researchers are working on to head off the dangers of technological surprise. In other words, the brains at the company are in a race to discover the loopholes and faults in wireless security before terrorists and cyber criminals do. Needless to say, this requires a tremendous amount of outside-the-box thinking, says John Morrison, chief of the company's Wireless Cyber Security Lab.
"The 9/11 Commission said that one of the biggest reasons that the government failed to prevent the 9/11 attack was a failure of imagination," Morrison says. "We're trying to ensure that something similar doesn't happen in the realm of wireless communications," he says.
Defining the problem
So, just what are the biggest emerging threats in wireless security? Perri Nijeb, CTO for Lockheed Martin Information Systems, says her biggest concern has been the gradual migration of the office to the home. In other words, as workers increasingly connect to company data through corporate VPNs from their homes, companies have less and less control over where their employees can gain access to sensitive information.
"The lines between our 'work' environment and our 'home' environment are becoming increasingly blurred as wireless routers, phones and aircards rapidly extend the traditional office enterprise further and further to the 'edge,'" Nijeb says. "The network now moves with the individual to their living room, hotel room, car and coffee shop. . . . This is both exciting and challenging for us."
To that end, Lockheed Martin has been running tests on many types of consumer technology that have been migrating to enterprise networks, including Wi-Fi, WiMAX, Bluetooth, and cell phones. The abundance of Wi-Fi hot spots is one of the lab's most pressing concerns because Wi-Fi increasingly has become ubiquitous in urban areas and oftentimes users can connect to unsecured networks and not even realize that they're at risk. The major issues with Wi-Fi include "connection hijacking, deliberate or inadvertent denial of service, the creation of security holes in corporate or government networks, and difficulty in attributing network actions to specific IP addresses, due to the ease of hijacking," Nijeb says. Morrison says all these issues, particularly connection hijacking, have the potential to cause massive headaches for corporate IT departments if they don't educate their users about security issues.
"When I was working in New York City as the IT director for a financial services company, we had a problem with drug dealers using others' unprotected Wi-Fi networks to do their deals," Morrison says. "And then when the authorities would trace their IP address, it would go back to the home of one of our unsuspecting employees."
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Taking On Demand CRM Integration to the Next Level
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Making the Business Case for IT Consolidation
Controlling storage costs with Oracle database 11g
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Delivering the Power of Choice with Microsoft Dynamics CRM
Email Archiving Implementation: Five Costly Mistakes to Avoid
Gaining Competitive Advantage Through Enterprise Planning
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Virtual magic: HR specialist throws out 40 servers, adds 8TB SAN and saves $100,000 for disaster recovery 2008-12-01 15:28:00+11
Sybiz adds up for SMEs in downturn 2008-12-01 14:27:00+11
EXCOM scores back-to-back award trifecta 2008-12-01 10:46:00+11
Citect extends SCADA networks with mobility solutions 2008-12-01 09:48:00+11
Citect extends SCADA networks with mobility solutions 2008-12-01 09:48:00+11
The state of Middleware
Middleware delivers unprecedented visibility and control over your business by making timely information available to decision makers. Organisations are using Middleware to leverage their existing IT investments, while optimizing their IT and business operations, securing their infrastructure and driving compliance. Read on to discover how Middleware can help you increase your businesses profitability.











