1. 中国科学技术大学计算机科学与技术系,合肥,230027
2. 网络与交换技术国家重点实验室,北京,100876
3. 安徽省计算与通讯软件重点实验室,合肥,230027
网络首发:2009-10-10,
纸质出版:2009
移动端阅览
薛雨杨 1, 周颢 1, 3, 等. 无线局域网802.1X协议安全性分析与检测[J]. 西安交通大学学报, 2009,43(10):52-55.
The Security Analysis and Detection of 802.1X Wireless Local Area Network[J]. 2009, 43(10): 52-55.
针对无线局域网(WLAN)802.1X协议易受重放、拒绝服务等攻击的问题
采用非形式化方法
根据攻击者的能力
从攻击者扮演的协议角色
即模仿正常的协议行为和破坏正常的通信出发
分析了802.1X协议的安全性
并对攻击行为进行了分类
据此提出了一种基于攻击的无线局域网主动测试方法.通过构造协议报文序列、模拟攻击者的攻击行为对协议运行主体进行攻击
从而判断协议是否存在安全漏洞.测试结果表明
所提方法有效地结合了攻击者和测试者的特点
在一定程度上覆盖了针对802.1X协议的已知安全漏洞
并具有发现潜在问题的能力.
Aimed at the problem that the vulnerable wireless local area network(WLAN)802.1X protocol is not susceptible to replay and DoS(denial of service)attacks
etc
an informal method is introduced to analyze the security properties of 802.1X protocol. The method classifies attack behaviors according to the ability of attackers
and from the aspect of the role which attackers can play in the protocols(i.e.
imitating normal protocol behavior or breaking normal communication). Then a new method
WLAN active testing
is proposed. Attacks to the protocol running mainbody are implemented by simulating the actions of the attacker which can be used to make up protocol messages. The results are used to determine whether the protocol security vulnerabilities exist or not. Testing results show that the method combines characteristics of both the attacker and the tester to cover some known protocol security vulnerabilities
and has the ability to reveal some potential problems.
Institute of Electrical and Electronic Engineers. ANSI/IEEE 802.1X-2001 Standard for local and metropolitan area networks port-based network access control [S].Piscataway, NJ, USA: IEEE, 2001.
ABOBA B. IEEE 802.1X network port authentication [EB/OL]. [2008-12-20]. http:∥www. drizzle. com/~ aboba/IEEE/.
ABOBA B, BLUNK L, VOLLBRECHT J, et al. RFC3748 Extensible authentication protocol(EAP)[S]. Reston, VA, USA: Internet Society, 2004.
WILLIAM M, ARBAUGH A. An initial security analysis of the IEEE 802.1X standard [EB/OL]. [2008-12-10]. http:∥www.cs. umd. edu/~waa/.x.pdf.
DOLEV D, YAO A. On the security of public key protocols [J]. IEEE Trans on Information Theory, 1983, 29(2):198-208.
0
浏览量
4
下载量
2
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621