节点文献

IEEE802.1x网络访问认证技术的攻击应对策略

Countermeasures of Attacks for IEEE8021x Network Access Authentication Techniques

【作者】 周辉

【导师】 谢冬青;

【作者基本信息】 湖南大学 , 计算机软件与理论, 2007, 硕士

【摘要】 目前,无线局域网大部分是基于IEEE802.11标准的,但是许多研究表明IEEE802.11标准存在诸如缺乏双向认证、存在弱密钥等安全问题。IEEE802.1x针对当前无线局域网出现的安全问题,采用了基于端口的访问控制协议来增强访问控制和认证的强度。但是,它的认证机制在设计上仍然是单向的,容易受到中间人攻击、会话接管攻击及拒绝服务攻击。因此,对IEEE802.1x协议认证方法进行改进,提供更为强大的安全保障体系,对于无线局域网的发展和应用有着深远的意义。首先,本文通过介绍无线局域网的基本协议802.11,分析了IEEE802.11所使用的安全服务、认证弱点及加密缺点。然后作者陈述了IEEE802.1x协议中存在的几个问题(缺乏双向认证、扩展认证协议封装格式不完整、认证机制设计缺陷及Authenticator中状态机耦合松散),重点讨论了中间人攻击、会话接管攻击和拒绝服务攻击等常见攻击方式。通过模拟实验证实:攻击者采用恰当的攻击工具和攻击方法,可以对采用802.1x认证协议的无线网络成功地实施以上几种攻击。其次,针对上述三种攻击方式分别提出了相应的改进方案:①使用中央管理器辅助认证服务器以实现减少拒绝服务攻击的目标;②通过修改响应消息的格式可降低中间人攻击的频率;③在认证未断开的情况下丢弃所有MAC断开连接的消息帧可减少会话接管攻击。最后,文章对改进方案的分析结果表明:针对拒绝服务攻击的改进方案能让资源分配更加合理,资源消耗可以控制在最小范围;针对中间人攻击的改进方案能在一定程度上阻止中间人接入;通过对状态机转移的进一步约束和EAPOL帧格式的完善,能够防范现有的接管会话攻击方式。改进方案弥补了IEEE802.1x缺乏双向认证的缺点,设计了中央管理器和修改了EAPOL帧格式等,提供了较好的安全。

【Abstract】 Nowadays, WLAN mostly based on the standard of the IEEE802.11, however, numerous works indicated that there are some security issues such as lack of mutual authentication and weak key. In view of the current security issues on the WLAN, IEEE802.1x introduce access-control-protocols based on ports to enhance access control and the strength of authentication. But its authentication mechanism is also one-way, and it’s easy to suffer Man-In-The-Middle (MITM) Attack, Session Hijacking and denial of service. So it’s meaningful to the improvement and application of the WLAN, by develop the authentication method of the IEEE802.1x and offer more powerful security system.Firstly, by introducing the protocol of IEEE802.11, this article analyzed the secure service, weakness of authentication and the flaw of encryption. Then the author presented many problems in IEEE802.1x (Absence of mutual authentication, lack of field of the extended authenticate protocol, the flaw of the authenticate mechanism and the authenticator state machine loose coupling), and discussed MITM Attack, Session Hijacking and denial of service. It is tested that above of attacks can be performed by simulated attack tests.Secondly, to cope with the three kinds of attacks, three solutions are proposed, which include:①Reduce the denial of service by the center manager assisting authenticator server;②Decrease the frequency of MITM Attack by modifying format of response message;③reduce Session Hijacking by rejecting all MAC message for disconnection when the authentication is association.Finally, the results show: the way that copes with denial of service can distribute the resource more reasonable and control the resource consumption in the smallest range; the way that copes with MITM Attack can prevent MITM connection; the way that copes with Session Hijacking can avoid existing Session Hijacking by restricting state machine transfer and perfecting format of the EAPOL frame.The improving solutions remedy the flaw of absence of mutual authentication in IEEE802.1x, design central manager and modify format of the EAPOL frame, etc, and provide a sufficient level of security.

  • 【网络出版投稿人】 湖南大学
  • 【网络出版年期】2007年 05期
  • 【分类号】TP393.08
  • 【下载频次】186
节点文献中: 

本文链接的文献网络图示:

本文的引文网络