Intrusion Prevention

The Wireless Intrusion Protection System (WIPS) provides continuous protection against wireless threats and acts as an additional layer of security complementing VPNs and encryption and authentication policies. WIPS is supported through the use of dedicated sensor devices (access point radios) designed to detect and locate unauthorized devices. After detection, unauthorized devices are blocked by manual termination or air lockdown.

Unauthorized APs are untrusted access points connected to a LAN that accept client associations. They can be deployed for illegal wireless access to a corporate network, implanted with malicious intent by an attacker, or could just be misconfigured access points that do not adhere to corporate policies. An attacker can install an unauthorized AP with the same ESSID as the authorized WLAN, causing a nearby client to associate to it. The unauthorized AP can then steal user credentials from the client, launch a man-in-the middle attack or take control of wireless clients to launch denial-of-service attacks.

WiNG managed controllers, service platforms and access points support unauthorized AP detection, location and containment natively. A WIPS server can alternatively be deployed as a dedicated solution within a separate enclosure. A WIPS deployment provides the following enterprise class security management features and functionality: