Development of device identity using WiFi layer 2 management frames for combating Rogue APs

Development of device identity using WiFi layer 2 management frames for combating Rogue APs
复制标题

使用 WiFi 第 2 层管理帧开发设备身份以打击恶意 AP

DOI:
--
复制
发表时间:
2013
期刊:
International Conference on Security and Cryptography
影响因子:
--
通讯作者:
A. Marshall
A. Marshall
中科院分区:
--
文献类型:
--
作者:
J. Milliken;Valerio Selis;K. Yap;A. Marshall

文献摘要

被引文献

相似文献

WiFi网络对流氓接入点攻击的敏感性源于802.11设备缺乏身份。在目前的研究中,检测这些攻击的最常见方法是通过跟踪未经授权和可能恶意的AP的凭据或位置。在本文中,作者概述了一种方法来区分WiFi接入点使用802.11 MAC层管理帧流量配置文件。该系统不需要位置估计或证书跟踪技术,如在当前的研究技术中使用的,这是已知的是不准确的。这些特性管理流量配置文件显示为每个设备是唯一的,相当于一个MAC身份。该技术的应用,以解决流氓AP攻击的约束下,一个开放的访问,公共WiFi环境进行了讨论的结论是,身份实际上是很难伪造。
The susceptibility of WiFi networks to Rogue Access Point attacks derives from the lack of identity for 802.11 devices. The most common means of detecting these attacks in current research is through tracking the credentials or the location of unauthorised and possibly malicious APs. In this paper, the authors outline a method of distinguishing WiFi Access Points using 802.11 MAC layer management frame traffic profiles. This system does not require location estimation or credential tracking techniques as used in current research techniques, which are known to be inaccurate. These characteristic management traffic profiles are shown to be unique for each device, tantamount to a MAC identity. The application of this technique to solving Rogue AP attacks under the constraints of an open access, public WiFi environment is discussed with the conclusion that the identity is practically very difficult to forge.