A risk analysis and risk management methodology for mitigating wireless local area networks (WLANs) intrusion security risks
Abstract (Summary)
Every environment is susceptible to risks and Wireless Local Area Networks (WLANs)
based on the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard are
no exception. The most apparent risk of WLANs is the ease with which itinerant intruders
obtain illicit entry into these networks. These intrusion security risks must therefore be
addressed which means that information security risk analysis and risk management need
to be considered as integral elements of the organisation’s business plan.
A well-established qualitative risk analysis and risk management methodology, the
Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) is selected for
conducting the WLAN intrusion security risk analysis and risk management process.
However, the OCTAVE risk analysis methodology is beset with a number of problems that
could hamper a successful WLAN intrusion security risk analysis. The ultimate deliverable
of this qualitative risk analysis methodology is the creation of an organisation-wide
protection strategy and risk mitigation plan. Achieving this end using the OCTAVE risk
analysis methodology requires an inordinate amount of time, ranging from months to
years. Since WLANs are persistently under attack, there is a dire need for an expeditious
risk analysis methodology. Furthermore, the OCTAVE risk analysis methodology stipulates
the identification of assets and corresponding threat scenarios via a brainstorming session,
which may be beyond the scope of a person who is not proficient in information security
issues.
This research was therefore inspired by the pivotal need for a risk analysis and risk
management methodology to address WLAN intrusion attacks and the resulting risks they
pose to the confidentiality, integrity and availability of information processed by these
networks.
Bibliographical Information:
Advisor:
School:University of Pretoria/Universiteit van Pretoria
School Location:South Africa
Source Type:Master's Thesis
Keywords:risk assessment wireless lans computer networks
ISBN:
Date of Publication: