Top 10 tips for Wireless Home Security

A wireless home network brings many benefitsare within range, and what their names are.
– all the family can access the InternetIt’s the first step to connecting to a wi-fi
simultaneously, you can use a laptop anywherenetwork. This feature is not necessary in a home
within the radius of the wireless network, freeingnetwork, however, and is undesirable since it
you from physical constraints, you don’t haveallows external entities to discover your
to string Cat-5 cabling throughout your house (nonetwork’s SSID. It is strongly advised that
holes in the wall either!) – but a wi-fi networkhome network users disable this feature in order
also brings it’s own set of security problems.to improve the security of your wi-fi network.
The following recommendations itemise the steps6. Enable MAC Address filtering
which should be taken to improve your wi-fiThe functionality known as Media Access Control
network’s security.(MAC) address filtering uses a computer's physical
1. Put the access point in a central positionhardware. Each computer has its own unique MAC
Wi-Fi signals radiate from the router or accessaddress. MAC address filtering allows the network
point, so positioning the access device as centrallyadministrator to enter a list of MAC addresses
as possible achieves two objectives. Firstly itthat are allowed to communicate on the network.
ensures that the wi-fi signal will reach all areas inIt also allows the network administrator to deny
your house, and secondly it will minimize theaccess to any MAC address not specifically
amount of signal leakage beyond your property.allowed onto the network. This method is very
This is important to minimize the chance ofsecure, but if you buy a new computer or if
drive-by access to your system. If your signalvisitors to your home want to use your network,
can be accessed by someone in the street, ityou'll need to add the new machine’s MAC
may be detected and exploited by unscrupulousaddress to the list of approved addresses.
people, and if your network security is not7. Assign Static IP Addresses to Devices
sufficient, they may even be able to access yourStatic IP address assignment (sometimes also
confidential information.called fixed addressing) is an alternative to
2. Enable an Encryption Scheme for devices ondynamic addressing (called DHCP) on Internet
your networkProtocol networks. Dynamic Host Configuration
All Wi-Fi equipment supports some form ofProtocol (DHCP) is an Internet protocol for
encryption which makes messages sent over aautomating the configuration of computers that
wireless network less likely to be read by anuse TCP/IP. DHCP can be used to automatically
external entity. Available encryption schemesassign IP addresses to devices connected to your
vary, with WEP being the weakest (and oldest)wi-fi network.. Dynamic addressing is convenient.
and WPA -  and now WPA2 -  being strongerIt also allows mobile computers to more easily
and better. You can’t mix and match, though,move between different networks. Unfortunately,
as all wi-fi devices on your network must use thethis can work to the advantage of hackers, who
same encryption scheme. WEP may be not ascan get valid IP addresses from your
good as the WPA settings, but remember thatnetwork’s DHCP pool. To avoid this possibility,
it’s far better than no encryption at all.turn off DHCP on your access point or router and
3. Choose new default Usernames andassign a fixed IP address to each device on the
Administrator Passwordsnetwork.
An Access Point or Router is the heart of a8. Enable hardware and software Firewalls on your
home wi-fi network. These come from thenetwork
factory with default administrator usernames andMost routers these days contain built-in hardware
passwords. Manufacturers set both the accountfirewall capabilities, but it’s also recommended
username and password at the factory. Thethat each computer (PC or laptop) connected to
admin account allows a user to enter networkyour wi-fi network should have its own personal
addresses and account information. The usernamesoftware firewall installed. A software firewall will
is often simply the word admin or administrator.protect your computer from intrusion by scanning
The password is typically blank or consists of theincoming messages and blocking suspicious traffic
words "admin", "public" or "password". Hackers arefrom entering your system. It will also prevent
well aware of these defaults and if you don’tunauthorized outgoing messages which may
change them, there is a grave danger of leavingprevent Trojans on your system from sending
your network open to access by a baddie. Asyour valuable information to a hacker.
soon as you set up your access point or router,9. Disable automatic connection to open Wi-Fi
change the admin username and password andnetworks
it’s a good idea to change them on a regularIf your wi-fi enabled device detects an open (i.e.
basis, say every 30 to 60 days.unsecured) wi-fi network, such as a free wireless
4. Change the default SSID namehotspot or even a neighbors unsecured network,
Manufacturers of wi-fi access points and routersit may connect automatically without informing
normally ship their products with a defaultyou. For example, on Windows XP computers
network name (the SSID). SSID stands forhaving Wi-Fi connections managed by the
Service Set Identifier, which is a 32-characteroperating system, the setting is called
sequence that uniquely identifies a wireless LAN. In"Automatically connect to non-preferred
other words, the SSID is the name of thenetworks." Once connected, you could be
wireless network. In order for a wireless deviceexposing your system to a security risk. Disable
to connect to a wireless network it must knowall automatic connections, or at least only allow
the SSID of the wireless network in question. Ifconnection once you have been informed and
you plug your wireless router or access point inhave approved the connection.
and leave the default SSID, it won't take long for10. Shut down your network when you’re not
an attacker to determine what the SSID is. Asusing it
soon as you configure your access point orIf your wi-fi network isn’t turned on, hackers
router, change the SSID to a unique name thatcan’t get to it. This is possibly the very best
will be difficult to guess.way to avoid security problems. Of course, if
5. Disable SSID Broadcastingit’s turned off, you can’t use it either…
SSID broadcasting by your access point or routerHowever, consider turning off your wireless
occurs every few seconds and is intended tosystem during periods of non-use, such as
allow users to find, identify and connect to wi-fivacations, if you are away from home on
networks. If you have a wireless device, thisbusiness, or any other periods when you know
feature allows you to discover which networksyou won’t be using it.