1. 中国科学技术大学计算机科学与技术系,合肥,230027
2. 网络与交换技术国家重点实验室,北京,100876
3. 安徽省计算与通讯软件重点实验室,合肥,230027
网络首发:2010-04-10,
纸质出版:2010
移动端阅览
朱加伟 1, 周颢 1, 3, 等. 基于状态机的802.1X协议攻击检测方法[J]. 西安交通大学学报, 2010,44(4):52-56.
Detection Methods for 802.1X Protocol Attacks Using State Machine[J]. 2010, 44(4): 52-56.
针对802.1X协议存在一定漏洞且易受重放、拒绝服务等攻击
结合802.1X协议的认证过程
抽象出802.1X协议认证的状态转移过程
同时针对802.1X协议的功能性攻击
构造出一套攻击状态转移机制:分析802.11报文和基于局域网的扩展认证协议(EAPOL)/扩展认证协议(EAP)报文的结构; 剔除出重传的报文
逐个字段解析出关键字并存入链表中; 将根据EAPOL/EAP报文格式取得检测所需的EAP报文存入缓存.据此
设计出基于状态机的802.1X的攻击检测方法.实验结果表明
在实际组网环境下的重放/DoS等802.1X功能性攻击能够得到准确的检测
并具有有效、统一的检测结果.
There are some loopholes in 802.1X protocol such as replay attacks
DoS(Denial of Service)attacks and so on. The paper presents an state transition process for certification of 802.1X
and designs an attack state transfer mechanism for functional attacks. The architecture of 802.11 frames
EAPOL frames and EAP frames are analyzed. The replay frames are deleted and keywords are abstracted and saved from the list of remaining frames one by one. Then the EAP frames which are required for detection are saved in the cache. The security detection method of 802.1X is designed based on the state transition mechanism. Experimental results show that functional attacks of 802.1X such as replay/DoS attacks can be detected accurately in real network environments
and the detection is effective and consistent.
BRAWN S K, KOA R M, CAYE K. Secure in an insecure world: 802.1X secure wireless computer connectivity for students, faculty, and staff to the camp-us network [C]∥Proceedings of the 32nd Annual ACM SIGUCCS Conference on User Services. New York, USA: ACM, 2004:273-277.
CROW B P, WIDJAJA I, KIM J G, et al. IEEE 802.11 wireless local area networks[J]. IEEE Communications Magazine, 1997, 35(9):116-126.
JEFFREE T, CONGDON P, SALA D, et al. P802.1X/D11-2001 IEEE standard for local and metropolitan area networks: standard for portbase network access control[S]. Piscataway, NJ, USA: IEEE, 2001.
ABOBA B, BLUNK L, VOLLBRECHT J, et al. RFC 3748-2004 Extensible authentication protocol(EAP)[S]. Piscataway, NJ, USA: IETF, 2004.
MISHRA A, ARBAUGH W A. An initial security analysis of the IEEE 802.1X standard [R]. Maryland, USA: University of Maryland. Department of Computer Science, 2002.
HWANG H, GYEOK J, SOHN K, et al. A study on MITM(man in the middle)vulnerability in wireless network using 802.1X and EAP[C]∥Proceedings of the 2008 International Conference on Information Science and Security. Los Alamitos, CA, USA: IEEE Computer Society, 2008:164-170.
MCFALL R, DERSHEM H L. Finite state machine simulation in an introductory lab[C]∥25th SIGCSE Technical Symposium on Computer Science Education. New York: USA: ACM, 1994:126-130.
Microsoft Corporation. Protected extensible authentication protocol(PEAP)specifi-cation [EB/OL]. [2009-07-27]. http:∥msdn.microsoft.com/en-us/library/cc238354(PROT.13).aspx
DING P, HOLLIDAY J, CELIK A. Improving the security of wireless LANs by managing 802.1X disassociation[C]∥Proceedings of the IEEE Consumer Communications and Networking Conference. Piscataway, NJ, USA: IEEE, 2004:53-58.
PACK S, CHOI Y H. Pre-authenticated fast handoff in a public wireless LAN based on IEEE 802.1X model[C]∥Proceedings of the IFIP TC6/WG6.8 Working Conference on Personal Wireless Communications. Deventer, Netherlands: Kluwer, 2002:175-182.
0
浏览量
4
下载量
1
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621