Who is on my network?

Most of us have no idea who is on the network, and if they are on my network they must be legitimate right? Well no not necessarily. If you have a decent firewall between you and the internet, (a function usually incorporated into your broadband router) then computers generally cannot get into your network from the internet. There are exceptions of course such as remote access through the firewall which needs to be configured by someone.

I have spent much of the past month decorating and installing a new office, and reviewing my network(s)…. Yes I have more than one.

Sharing your network

At home I used to share my network with the family. That is to say in the conventional sense, we were all connected together behind the same router. So the router, with its built in firewall function provided protection from intruders from the internet.

However my son tends to cruise the internet and visit all sorts of websites of dubious content. He is way past the age of trying to apply any parental controls. If he happened to click on something (I stress if, there is no evidence it ever happened) he might install a local virus on his computer, which will open access through the firewall to a remote server. He also does a lot of gaming, and I did not want that getting in the way either.

Solution

I have several layers of network, an inner network which is tightly controlled, and an outer network which uses both wired and wireless systems in the conventional sense. Guests and anyone else that need general access can join the outer network and access email, the web and anything else they need. The wireless runs over 5GHz and 2.4GHz and uses WPA2 and PSK for encryption with complex passwords.

Inner network

While the outer network is protected from the internet using a router, there is a second router which connects the outer network to an inner network. The inner network has wired and wireless connections too at 2.4GHz and 5GHz, in this case a special configuration is used where only one SSID (Wifi Name) is used, and the router figures out which band to put them on based on the performance. It is all automatic and works quite well. But I also use another feature built into routers and WiFi which you may not be aware of.

Access Control Lists

There used to be a view when all networks were wired before WiFi came on the scene that if your premises were secure then nobody could get on to your network without your knowledge. That was because you had to be physically in the building in order to plug a cable into the network.

When WiFi came along you no longer needed to be in the building to join the network, you just needed to be within range. I once sat outside a block of flats in my car waiting for someone, out of curiosity and because I was bored I got out my iPhone and looked around to see what WiFi networks were around. I found one very near, I could establish which router it was (Netgear), found the default user name and password, and managed to log in! This was only possible because the owner never read the instructions and changed the default password. But it demonstrates it can happen. From here I could have done all sorts of things, but obviously did not.

WiFi routers have something called ACL’s or Access Control Lists. These allow you to enter the MAC (Media Access Control) Address into the router for each WiFi device on your network. Each networking device has a MAC Address, this is a sequence of hexadecimal characters usually written like this: 08:0E:05:21:DF:41 the first three sets of characters can be used to identify the manufacturer of the controller chip used in the device. They are usually but not always hardwired into a device. They are generally unique too. As in most things there are exceptions to this rule.

You set up your WiFi router to allow specific networking devices to connect to your WiFi providing their MAC address is in the list. If it is not in the list it cannot connect to the network even if the WiFi password and SSID is known. So in other words, you control who can access your network and resources on your network. A third party knowing the WiFi network and the password cannot connect to your network. It reports the password is wrong, even though it is isn’t.

Returning to who is on my network

There are tools you can use to discover who or what is on your network. These tools are well known in the Linux world if you play with computers a lot or come from a networking background. There are some programs out there that you can use to scan your network and list what is in the network.

Checkout the following if you have an iPhone: https://techet.net/netanalyzer written by Jiri Techet. If you are curious about your network and its performance, this is an incredibly useful tool. Plus it is portable, you can test any network with it.

The way it works is you connect your iPhone to the network you wish to scan, then run it. It will go through all of the IP addresses on the network to see if there are devices present. IP addresses are generally set by the router, it allows data to be sent to and from devices on your network, these are the equivalent to a postal address for a house.

For the £3 the application cost, it is brilliant and shows a list of everything that is connected. In my case on my inner network before I turned on ACL I found 12 devices ranging from TV’s, internet radio, printer, Ikea lighting controller, iPad, iPhones and other devices. But, it only shows you the MAC address of each device, you need to find out what it is.

I quickly established what most of them were, but then was stuck on the last one. It was eventually resolved to a BT Set Top Box attached to a TV.

The important point being that I now know precisely what is connected to my inner network, where it is located, and what it is doing. I can now add all of those MAC addresses into an Access Control List, and only those devices can connect to my network.

Going Deeper

It is also possible on the App to check on which ports are open on each device. If you imagine a device on your network is like a house, and the network is like the street your house is on, the ports are like doors into and out of your device. These can give you a clue about what it is and what it is doing. It may indicate something is communicating with something outside of your network. If that is the case it is important to know what it is.

WiFi Performance Test

The application can also check the performance from the smart phone over WiFi to a server on the internet to check the data performance. So you can check if there are dead spots anywhere, or areas where there are reduced performance. At my location from most areas in the house I can achieve over 60Mb/s download and 16Mb/s upload, so the WiFi performance is as good as my broadband performance. I am using advanced routers to do this that use 802.11ac WiFi.

Paranoia Prevails

So is this additional security worth the effort? I think it is, it provides some control over what can get into the inner network.

Is it foolproof?

If you are really paranoid, then it is conceivable in theory that an external monitor can monitor the network, and will over time figure out the password, even using WPA2 there are WiFi password cracking programs out there. Just do a search on Kali and WiFi, and you will find one. So this means no WPA2 network is really totally secure. If you have access to the MAC address in a hacking device, you can pretend you are a device in the Access Control List, so it is possible to get through these measures if you really know what you are doing.

However hackers generally look for soft targets and will go for those that are easier. So all I have achieved is mine is quite a bit more difficult to get into. There are other layers of security which are used to access and protect resources on the network such as passwords and accounts. Other monitoring will also quickly figure out if a duplicate MAC address or IP address is in use, which will also flag up a problem to the user.

If you are interested in looking at this further for your network get in touch in normal way.

Wingrove-Services
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

You can adjust all of your cookie settings by navigating the tabs on the left hand side.

My privacy policy can be located here: Wingrove Media Privacy Policy (opens in a new window)

My Cookies Policy can be found here: Wingrove Media Cookies Policy (opens in a new window)