Re: Security level of wireless network



Sebastian Gottschalk wrote:
Marek Elsner wrote:

Hi,

I am writing some kind of work about security and I would like to ask you what do you think.

Consider that you went wardriving and in a random point in town you start searching for available / visible wireless networks. Of course in passive way you can get plenty of information, such as:

- SSID of network
- WEP / WPA
- avarage number of packets
- signal strength
- number of all networks
...

I would like to grade security level of this point in town.
It can be graded in three level scale, or in 0-100 points scale, or in any other way....it does not matter.

What do you think can be the algorithm to grade the security level of this research point..?

Got any ideas or suggestions, what parameters more should be included...?

Oh, you can simply add up points:

SSID hidden: 0
MAC filter: 0
WEP: 0
WPA: 10
WPA+secure key: 90

It the total for one is zero, then the total score for a collection is
zero.

Going to have to disagree with you on that one.

Using your scheme....

WPA+secure key + MAC Filter = 0. Why?

Additionally, how would the OP tell the diference between WPA and WPA+secure key without actually cracking (or attempting to crack) the WPA key?

How does WPA without a secure key attract a weighting of 10?

Other than that, I'd have to agree with you on the numbers!

Bogwitch.
.



Relevant Pages

  • Security level of wireless network
    ... I am writing some kind of work about security and I would like to ask you what do you think. ... Consider that you went wardriving and in a random point in town you start searching for available / visible wireless networks. ... I would like to grade security level of this point in town. ... It can be graded in three level scale, or in 0-100 points scale, or in any other way....it does not matter. ...
    (comp.security.misc)
  • RE: [Full-Disclosure] RE: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!
    ... Subject: RE: MS SQL WORM IS DESTROYING INTERNET ... Perhaps some of the .edu admins need to ... >basic network design concepts and security. ... But the admins whose networks got hit *still* didn't ...
    (Full-Disclosure)
  • Re: << SBS News this week 7/25/2004>>
    ... > Homeland security has become a key issue in the US. ... > the Virginia Cyber-Crime Strike Force. ... > Fifteen employees at Los Alamos National Laboratory ... > networks is urgently required but agreed to work ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: << SBS News this week 7/25/2004>>
    ... > Homeland security has become a key issue in the US. ... > the Virginia Cyber-Crime Strike Force. ... > Fifteen employees at Los Alamos National Laboratory ... > networks is urgently required but agreed to work ...
    (microsoft.public.windows.server.sbs)
  • Re: [Full-disclosure] A Botted Fortune 500 a Day
    ... I believe security of an organisation is orthogonal to the number of ... >> Fortune 500 companies have more employees than some ISPs have customers. ... > compromises on their internal networks. ...
    (Bugtraq)