SAFE: Wireless LAN Security in DepthVersion 2
The "SAFE: Wireless LAN Security in DepthVersion 2" white paper discusses wireless LAN (WLAN) implementations, with a focus on the overall security of the design. Among the best practices this white paper recommends is to consider network design elements, such as mobility and quality of service (QoS). This white paper describes the following design objectives, listed in order of priority:
- Security and attack mitigation based on policy
- Authentication and authorization of users to wired network resources
- Wireless data confidentiality
- User differentiation
- Access point management
- Authentication of users to network resources
- Options for high availability (large enterprise only)
This document begins with an overview of the architecture and then details four wireless network designs. These designs are for large, medium-sized, small, and remote-user WLANs. This white paper also introduces six new axioms into SAFE:
- Wireless networks are targets.
- Wireless networks are weapons.
- 802.11 is insecure.
- Security extensions are required.
- Network availability impacts wireless.
- User differentiation occurs in wireless LANs.