Radio/WiFi Analysis

Service Overview

The Radio and WiFi Security Analysis service assesses the security of business wireless infrastructure and radio protocols used in operational contexts—enterprise WiFi networks, guest networks, wireless IoT networks and industry-specific radio protocols (Zigbee, Z-Wave, BLE, DECT, LoRaWAN, PMR networks). Wireless networks are a perimeter that by nature extends the attack surface beyond the physical walls of the organization, accessible from parking spaces, common spaces and, in some cases, from hundreds of meters away with specialized hardware.

Radio/WiFi Analysis

Radio

Areas of Analysis

For WiFi networks, testing covers: verification of authentication protocols implemented (WPA2/WPA3-Enterprise with 802.1X vs WPA2-Personal), analysis of RADIUS configuration, deaution attack resistance test and Evil Twin (rogue access point), verification of segmentation between corporate and guest networks, analysis of PMKID mechanisms and handshake to assess the resistance to offline cracking, and unauthorized internal reporting.

For specific radio protocols, we perform sniffing and traffic analysis with SDR hardware (Software Defined Radio), verification of the presence of encryption and authentication of messages, identification of replay attack, and analysis of the specific protocol attack surface in use in the customer's operating context.

Deliverable

Reports with wireless coverage map, technical findings for each identified vulnerability, severity and real operational impact, and remediation with specific configuration techniques for enterprise platforms in use (Cisco, Aruba, Ruckus, Ubiquiti).

EnglishenEnglishEnglish