There are some loopholes in 802.1X protocol such as replay attacks
DoS(Denial of Service)attacks and so on. The paper presents an state transition process for certification of 802.1X
and designs an attack state transfer mechanism for functional attacks. The architecture of 802.11 frames
EAPOL frames and EAP frames are analyzed. The replay frames are deleted and keywords are abstracted and saved from the list of remaining frames one by one. Then the EAP frames which are required for detection are saved in the cache. The security detection method of 802.1X is designed based on the state transition mechanism. Experimental results show that functional attacks of 802.1X such as replay/DoS attacks can be detected accurately in real network environments
and the detection is effective and consistent.
关键词
Keywords
references
BRAWN S K, KOA R M, CAYE K. Secure in an insecure world: 802.1X secure wireless computer connectivity for students, faculty, and staff to the camp-us network [C]∥Proceedings of the 32nd Annual ACM SIGUCCS Conference on User Services. New York, USA: ACM, 2004:273-277.
CROW B P, WIDJAJA I, KIM J G, et al. IEEE 802.11 wireless local area networks[J]. IEEE Communications Magazine, 1997, 35(9):116-126.
JEFFREE T, CONGDON P, SALA D, et al. P802.1X/D11-2001 IEEE standard for local and metropolitan area networks: standard for portbase network access control[S]. Piscataway, NJ, USA: IEEE, 2001.
MISHRA A, ARBAUGH W A. An initial security analysis of the IEEE 802.1X standard [R]. Maryland, USA: University of Maryland. Department of Computer Science, 2002.
HWANG H, GYEOK J, SOHN K, et al. A study on MITM(man in the middle)vulnerability in wireless network using 802.1X and EAP[C]∥Proceedings of the 2008 International Conference on Information Science and Security. Los Alamitos, CA, USA: IEEE Computer Society, 2008:164-170.
MCFALL R, DERSHEM H L. Finite state machine simulation in an introductory lab[C]∥25th SIGCSE Technical Symposium on Computer Science Education. New York: USA: ACM, 1994:126-130.
Microsoft Corporation. Protected extensible authentication protocol(PEAP)specifi-cation [EB/OL]. [2009-07-27]. http:∥msdn.microsoft.com/en-us/library/cc238354(PROT.13).aspx
DING P, HOLLIDAY J, CELIK A. Improving the security of wireless LANs by managing 802.1X disassociation[C]∥Proceedings of the IEEE Consumer Communications and Networking Conference. Piscataway, NJ, USA: IEEE, 2004:53-58.
PACK S, CHOI Y H. Pre-authenticated fast handoff in a public wireless LAN based on IEEE 802.1X model[C]∥Proceedings of the IFIP TC6/WG6.8 Working Conference on Personal Wireless Communications. Deventer, Netherlands: Kluwer, 2002:175-182.