SCAFFISD: A Scalable Framework for Fine-grained Identification and Security Detection of Wireless Routers

SCAFFISD: A Scalable Framework for Fine-grained Identification and Security Detection of Wireless Routers
复制标题

DOI:
10.1109/trustcom50675.2020.00160
复制
发表时间:
2020-12
期刊:
2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)
影响因子:
--
通讯作者:
Fangzhou Zhu;Liang Liu;W. Meng;Ting Lv;Simin Hu;Renjun Ye
Fangzhou Zhu;Liang Liu;W. Meng;Ting Lv;Simin Hu;Renjun Ye
中科院分区:
其他
文献类型:
--
作者:
Fangzhou Zhu;Liang Liu;W. Meng;Ting Lv;Simin Hu;Renjun Ye

文献摘要

被引文献

相似文献

无线网络设备的安全性受到了广泛的关注,但现有的方案大多无法实现细粒度的设备识别。实际上,设备的安全漏洞在很大程度上取决于其型号和固件版本。出于这个问题,我们提出了一个通用的,可扩展的和设备无关的框架称为SCAFFISD,它可以提供细粒度的识别无线路由器。它可以生成访问规则,自动从路由器管理页面提取有效信息,并对已知设备漏洞进行快速扫描。同时,SCAFFISD可以识别流氓接入点(AP)结合现有的检测方法,目的是执行一个全面的无线网络的安全评估。我们实现了SCAFFISD的原型,并通过实际产品的安全扫描验证其有效性。
The security of wireless network devices has received widespread attention, but most existing schemes cannot achieve fine-grained device identification. In practice, the security vulnerabilities of a device are heavily depending on its model and firmware version. Motivated by this issue, we propose a universal, extensible and device-independent framework called SCAFFISD, which can provide fine-grained identification of wireless routers. It can generate access rules to extract effective information from the router admin page automatically and perform quick scans for known device vulnerabilities. Meanwhile, SCAFFISD can identify rogue access points (APs) in combination with existing detection methods, with the purpose of performing a comprehensive security assessment of wireless networks. We implement the prototype of SCAFFISD and verify its effectiveness through security scans of actual products.