|
Risk Assessment
|
 | Assets to protect |
 | Threats to protect against |
 | Legal Issues |
 | Costs |
 | Basic security measures |
 | Threat analysis |
 | Impact analysis |
|
Threat Analysis & Hacking Methodology
|
 | Target profiling |
 | Physical security |
 | Social engineering |
 | Wireless bridges |
 | Packet analysis |
 | Information theft |
 | Malicious data insertion |
 | Denial of Service (DoS) |
 | Peer-to-peer hacking |
 | Unauthorized control |
Rudimentary Security Measures |
 | SSID |
 | MAC filters |
 | Static WEP |
 | Default configurations |
 | Firmware upgrades |
 | Physical security |
 | Periodic inventory |
Intermediate Security Measures |
 | Rogue equipment |
 | Cell sizing |
 | Protocol filters |
 | SNMP |
 | Discovery protocols |
 | Wireless segment configuration |
 | Remove vulnerabilities |
 | Client security |
 | IP Services |
Advanced Security Measures |
 | Wireless security policy |
 | Authentication & encryption |
 | Wireless DMZ and VLANs |
 | Audits |
 | Traffic pattern analysis |
 | Authenticated DHCP |
Wireless LAN Auditing Tools |
 | Discovery tools |
 | Password crackers |
 | Share enumerators |
 | Network management and control |
 | Wireless protocol analyzers |
 | Manufacturer defaults |
 | Password sniffers |
 | Antennas and WLAN equipment |
 | OS fingerprinting and port scanning |
 | Application sniffers |
 | Networking utilities |
 | Network discovery and management |
 | Hijacking users |
 | RF Jamming and Dataflooding tools |
 | WEP crackers |
Hardware & Software Solutions |
 | RADIUS with AAA Support |
 | RADIUS Details |
 | Kerberos |
 | Static and Dynamic WEP and TKIP |
 | 802.1x |
 | Extensible Authentication Protocol (EAP) |
 | VPNs |
 | Encryption Schemes |
 | Routers |
 | Switch-Routers |
 | Firewalls |
 | MobileIP VPN Solutions |
 | Enterprise Wireless Gateways |
 | Switches, VLANs, & Hubs |
 | SSH2 Tunneling & Port Redirection |
 | Thin Client Solutions |
Prevention & Countermeasures |
 | 802.1x |
 | 802.11i |
 | TKIP |
 | AES |
 | Intrusion detection |
 | US Federal and state laws |
Implementation and Management |
 | Design and implementation |
 | Equipment configuration and placement |
 | Interoperability and layering |
 | Security management |