Site Survey Methodology for Security Engineers
Site surveys are usually framed as a coverage and capacity exercise, but for security engineers they're also the moment to baseline the RF environment: what legitimate infrastructure exists, what unauthorized devices are already present, and where physical exposure lets an attacker get RF line-of-sight to your network from outside your controlled space. This article covers a practical methodology — predictive planning, the AP-on-a-stick validation survey, and the security-specific checks that a pure coverage survey typically skips.
Predictive survey (design phase)
Before any hardware goes up, a predictive survey uses floor plans, building material attenuation data, and modeling software to estimate AP placement, expected coverage, and channel/power planning. From a security standpoint, this phase is where you decide how far you want RF to bleed past your physical perimeter — high-gain omnidirectional placement near exterior walls maximizes convenience but also maximizes the range at which an attacker in a parking lot or adjacent building can associate with, or at minimum passively observe, your network.
Predictive planning should also account for 5 GHz DFS channel usage. DFS channels (the block spanning roughly 5260–5720 MHz, covering UNII-2 and UNII-2 Extended) require radar detection and a Channel Availability Check before the AP can transmit — practically 60 seconds in most regions, though some regions require substantially longer checks on channels adjacent to Terminal Doppler Weather Radar (TDWR) installations. If an AP detects radar during operation it must vacate the channel and re-run the check elsewhere, which causes a brief service interruption. Factor this into placement and channel planning for any AP near an airport or weather radar installation, and don't rely on DFS channels alone for links where that interruption is unacceptable.
AP-on-a-stick validation survey
After initial deployment (or before, for validation of a design), an AP-on-a-stick survey involves physically walking the space with a temporary AP and survey software (Ekahau, iBwave, or similar) measuring actual signal strength, SNR, channel utilization and co-channel interference at each point, rather than relying on predictive modeling alone. This validates that predicted coverage matches reality — building materials, furniture density, and RF reflectors are notoriously hard to model precisely.
For security purposes, walk the survey past your intended coverage boundary deliberately — into the parking lot, the floor above and below, and any adjacent tenant space — to measure how far a usable signal actually extends. This tells you where an attacker could realistically operate from, not just where your intended coverage is strong.
Baselining the RF environment for rogue detection
A security-focused survey should also produce a baseline inventory of every SSID and BSSID visible from the site — your own infrastructure, neighboring networks, and anything unexplained. This baseline becomes the reference your WIDS/WIPS tooling (or manual periodic re-scans, if you don't have dedicated WIDS) compares against later: a new, unexplained BSSID broadcasting one of your corporate SSIDs after the baseline was taken is a strong evil-twin indicator, and an unexplained AP wired into your internal subnets during a follow-up scan is a rogue-on-wire candidate.
Capture this baseline with a spectrum-aware tool (Kismet, a commercial survey tool with spectrum analysis, or your WIPS infrastructure itself) rather than a simple SSID scan, since some rogue and attack tooling (deauth injection, certain jamming behavior) shows up as RF noise or non-802.11 interference rather than as a discoverable network.
Coverage vs. attack surface tradeoffs
Every decision that improves coverage or capacity has a corresponding attack-surface tradeoff worth documenting explicitly during the survey rather than leaving implicit:
- •Higher transmit power extends coverage but also extends the range from which an attacker can associate or capture traffic — tune power to actual coverage needs rather than maximum output.
- •Directional/sectorized antennas near exterior walls can hold coverage inside the building while reducing bleed outward, at the cost of more careful placement and planning.
- •Wider channels (80/160 MHz in 5/6 GHz) increase throughput but reduce the number of non-overlapping channels available, which can push more APs onto DFS channels and increase exposure to radar-triggered channel changes in radar-dense regions.
- •Guest/open network placement should be surveyed separately from the corporate SSID footprint — a guest AP with strong signal reaching a public-adjacent area is expected; the same bleed on a corporate-authenticated SSID is a finding worth remediating.
Documentation and handoff
The survey output should give both networking and security teams what they need going forward: a heatmap and AP placement record for operations, and for security specifically — the RF baseline inventory (SSIDs/BSSIDs seen), measured perimeter bleed distances, DFS-channel APs flagged for CAC-interruption awareness, and any physical exposure findings (e.g., ground-floor APs near glass exterior walls, or coverage reaching an unsecured stairwell or lobby).
Re-run an abbreviated validation survey after any significant change — new construction, added APs, power/channel replanning — since even modest physical changes to a space can shift the coverage boundary in ways that matter for RF exposure even when they don't affect capacity planning.
Practical checklist
- •Model and then physically validate coverage boundaries, walking deliberately past intended perimeter into adjacent/public space.
- •Capture a full SSID/BSSID RF baseline as an artifact of the survey, not just a coverage heatmap.
- •Flag every AP operating on a DFS channel and document CAC behavior expectations for that region.
- •Document guest vs. corporate SSID bleed separately — different risk tolerance applies to each.
- •Re-survey after material physical changes to the space, not on a fixed calendar alone.
References
Primary sources for the material above. Standards are cited by identifier so they stay findable as publishers reorganise their sites.
- IEEE 802.11-2020 — Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) Specifications
- NIST SP 800-153 — Guidelines for Securing WLANs
- FCC Part 15.407 — Radio Frequency Devices, UNII Band Operation