Frequently Asked Questions
Q What is the Network Chemistry RFprotect™ System?
A Network Chemistry's RFprotect is a cost effective next-generation distributed Layer 1 and Layer 2 intrusion protection system for enterprise WLANs. It provides the component missing from standard authentication and encryption performed by wireless access points and client software products (including Cisco’s). RFprotect leverages intelligent radio frequency (RF) sensors distributed throughout the network, plus a high-performance, GUI-based analysis engine. RFprotect automatically detects internal policy violations, external attacks, and network performance issues. This highly distributed solution monitors WLAN activity 24 x 7 across 802.11a, b, and g spectrums. Second-by-second real time updates enable immediate response. Wireless traffic capture capability with rich decoding functions allows detailed troubleshooting of the most complex problems. RFprotect’s plug-and-play architecture facilitates installation and operation in a matter of minutes. Plus, the system comes ready for integration with any existing security or performance management system.
Q How is Network Chemistry's RFprotect different from a wired network intrusion detection system (IDS)?
A RFprotect detects intrusions that a wireline IDS simply cannot. Wireline IDSes operate at Layer 3 and above. The layer 1 and layer 2 wireless frames are stripped off and converted by the AP before it’s forwarded to the wired IP network, rendering a wireless IDS useless for wireless-specific threats.
Q How is Network Chemistry's RFprotect different from the security monitoring features provided by some WLAN AP and switch vendors?
A Intrusion protection capabilities are only as effective as they are operable and accurate. First, security experts concur that using the WLAN APs and switches to perform security self-diagnostics and monitoring is perilous since it’s the networking devices themselves that wireless hackers attack. As in the wired world, IDS/IPS is best performed by systems independent of the packet transmission systems. Second, AP and wireless switch vendors simply don't keep up with all of the new vulnerabilities and attacks that plague WLANs. At Network Chemistry, our only focus is RF-specific intrusion protection. We have the background to leverage best-of-breed algorithms that accurately detect wireless-specific weaknesses and attacks. Plus, our expertise enables us to identify new threats and update detection mechanisms rapidly. Moreover, our advanced architecture makes software updates easy with a simple download and installation.
Q I already use authentication and encryption on my WLAN. Why do I need Network Chemistry's RFprotect?
A If you require robust security, you need to use a layered approach. Therefore both wireless VPN and intrusion protection are a must if you want a hack-proof WLAN. Even with a VPN in place, you’re still vulnerable to advanced attacks (i.e., man-in-the-middle, and honey pot attacks) and emerging assaults that prey on VPN standards such as Cisco System’s Light Extensible Authentication Protocol (LEAP). Since hacker software is readily available and constantly evolving, you need a system that detects new and future hacker tools. You also need a system that identifies all kinds of rogue devices, not just the most common, and one that scans for vulnerabilities, weak configurations, and changes to WLAN security parameters – all which are easily overlooked and exploited.
Q How is Network Chemistry's RFprotect different from the security monitoring features provided by some WLAN AP and switch vendors?
A An intrusion protection system is only as effective as it is accurate. Solutions from other vendors do not detect all vulnerabilities and attacks that can plague WLANs. At Network Chemistry, our only focus is RF-specific intrusion protection. Thus, we have the background to leverage best-of-breed algorithms that accurately detect wireless-specific weaknesses and invasions. Plus, our expertise enables us to identify new threats and update detection mechanisms rapidly. Moreover, our advanced architecture makes software updates easy with a simple download and installation.
Q I plan to implement WLAN security and management on my Cisco-based WLAN. Why do I need Network Chemistry's RFprotect?
A When combined, the Cisco Structured Wireless-Aware Network (SWAN), CiscoWorks Wireless LAN Solution Engine (WLSE), and the RFprotect system provide a complete security and performance management solution for Cisco-based WLANs. The Cisco solution provides configuration control and monitoring for Cisco WLAN infrastructure component vulnerabilities. It also provides basic rogue AP and interference detection. RFprotect complements the Cisco solution by providing full-spectrum rogue device detection of all rogues, including non-AP rogues and non-Cisco APs. RFprotect also provides client station vulnerability detection and advanced intrusion detection. In addition, it performs traffic capture and decoding for forensic and problem analysis. Cisco monitors devices, but not wireless traffic like RFprotect. Plus, the Network Chemistry solution works with non-Cisco products.
Q If I have a no-wireless policy, a rogue wireless attack won’t affect me until I deploy a WLAN, right?
A Wrong. Whether it’s wired or wireless, any network is vulnerable to attacks due to rogue wireless devices. An employee can unknowingly deploy a rogue WLAN by installing an AP from home or laptop preconfigured with wireless capability. Hackers can easily set them up. By the time your IT department finds out, it’s too late. The security risks posed by rogue WLANs are extremely high and must be eliminated immediately. You just might have more unauthorized wireless use on your network than you realize.
Q If I use Network Chemistry's RFprotect to enforce my no-wireless policy, can I migrate to a full intrusion detection when I deploy my WLAN?
A Yes. Network Chemistry won’t nickel and dime you when you deploy your WLAN. RFprotect comes preconfigured and ready to perform full intrusion and performance monitoring of your WLAN as soon as you deploy it, at no additional cost.
Q Will most of the Network Chemistry functionality simply get added to APs?
A No. An access point (AP) can't function as an AP and a surveillance sensor at the same time without doing a poor job of either. A surveillance sensor must continuously and rapidly scan all channels on all 802.11 frequencies. An AP must operate on a single channel to send and receive data to associated client stations. If it performs surveillance, an AP loses throughput and processing power needed for serving wireless clients. Finally, how can you rely on an AP to do your security monitoring when the AP itself is a likely target of a hacker attack?
Q Which IT personnel should operate Network Chemistry's RFprotect?
A Although the system was designed for network security personnel, RFprotect provides a broad range of fault and performance management capabilities, making it extremely useful for network operations folks, too. Naturally, the system can be used by employees who perform both functions.
Q How is Network Chemistry's RFprotect different from a handheld testsets?
A Handheld testsets provide isolated snapshots of the network and are best suited for reactive troubleshooting. RFprotect provides real-time monitoring of the entire physical environment 24 x 7 and takes critical proactive measures to stop intruder attacks and performance degradations from causing problems.
Q Can I use my RFprotect Sensors with open source software like Kismet, Snort, and Packetyzer?
A Absolutely. Many of our customers do now. Contact us for details.
Q What is the Neutrino Sensor?
A It’s the previous name for the RFprotect Sensor.
Q How can I contact Network Chemistry product support?
A E-mail us at support@networkchemistry.com or call 650-575-1425
Q Where can I buy Network Chemistry products?
A To start using RFprotect today, you can order an exceptionally-priced pilot package directly from our web site. For prices for other packages, please contact us at sales@networkchemistry.com
|