A Solution to WLAN Authentication and Association DoS Attacks

A Solution to WLAN Authentication and Association DoS Attacks
复制标题

WLAN认证和关联DoS攻击的解决方案

DOI:
--
复制
发表时间:
2007
期刊:
影响因子:
--
通讯作者:
James T. Yu
James T. Yu
中科院分区:
--
文献类型:
--
作者:
Chibiao Liu;James T. Yu

文献摘要

被引文献

相似文献

基于802.11的无线局域网(WLAN)的日益普及也增加了其安全攻击的风险。新的WLAN安全标准802.11i解决了用户身份验证和数据加密方面的大多数问题;但是,它不能保护WLAN免受拒绝服务(DoS)攻击。本文提出了一种检测和解决认证请求洪泛(AuthRF)和关联请求洪泛(AssRF)的解决方案。我们开发了一个实验框架来演示和量化针对TCP和无线IP语音(WVoIP)通信的AuthRF和AssRF攻击。我们的研究表明,这种攻击很容易发动,并导致服务中断。然后,我们实现了一个基于流量模式分析和过滤的解决方案,以解决和防止AuthRF和AssRF攻击。该方案得到了经验数据的验证。
The growing popularity of the 802.11-based Wireless LAN (WLAN) also increases its risk of security attacks. The new WLAN security standard, 802.11i, addresses most issues on user authentication and data encryption; however, it does not protect WLANs against Denial of Service (DoS) attacks. This paper presents a solution to detect and resolve authentication request flooding (AuthRF) and association request flooding (AssRF). We developed an experimental framework to demonstrate and quantify AuthRF and AssRF attacks against TCP and wireless Voice over IP (WVoIP) communications. Our study shows that such attacks can be easily launched, and cause service disruption. We then implement a solution based on traffic pattern analysis and filtering to resolve and prevent AuthRF and AssRF attacks. This solution is validated by empirical data.