Aimed at the problem that the vulnerable wireless local area network(WLAN)802.1X protocol is not susceptible to replay and DoS(denial of service)attacks
etc
an informal method is introduced to analyze the security properties of 802.1X protocol. The method classifies attack behaviors according to the ability of attackers
and from the aspect of the role which attackers can play in the protocols(i.e.
imitating normal protocol behavior or breaking normal communication). Then a new method
WLAN active testing
is proposed. Attacks to the protocol running mainbody are implemented by simulating the actions of the attacker which can be used to make up protocol messages. The results are used to determine whether the protocol security vulnerabilities exist or not. Testing results show that the method combines characteristics of both the attacker and the tester to cover some known protocol security vulnerabilities
and has the ability to reveal some potential problems.
关键词
Keywords
references
Institute of Electrical and Electronic Engineers. ANSI/IEEE 802.1X-2001 Standard for local and metropolitan area networks port-based network access control [S].Piscataway, NJ, USA: IEEE, 2001.
ABOBA B. IEEE 802.1X network port authentication [EB/OL]. [2008-12-20]. http:∥www. drizzle. com/~ aboba/IEEE/.
ABOBA B, BLUNK L, VOLLBRECHT J, et al. RFC3748 Extensible authentication protocol(EAP)[S]. Reston, VA, USA: Internet Society, 2004.
WILLIAM M, ARBAUGH A. An initial security analysis of the IEEE 802.1X standard [EB/OL]. [2008-12-10]. http:∥www.cs. umd. edu/~waa/.x.pdf.
DOLEV D, YAO A. On the security of public key protocols [J]. IEEE Trans on Information Theory, 1983, 29(2):198-208.