首页> 外文会议> >A policy-based approach to wireless LAN security management
【24h】

A policy-based approach to wireless LAN security management

机译:基于策略的无线局域网安全管理方法

获取原文
获取外文期刊封面目录资料

摘要

Wireless Ethernet (or Wi-Fi) security management is a challenging area of increased interest due to the widespread deployment of Wireless LANs (WLANs) and their well-known vulnerabilities to various types of attacks, as well as stringent scalability requirements in the dynamic wireless domain. Until the adoption of the latest security standards is complete, users and network assets on deployed WLANs, such as 802.11a/b/g networks, need to be protected from existing security threats without depending on the latest features. In addition, while new standards can protect the unauthorized use of network resource for outsiders, they do not deal with the misuse or misbehaviors by insiders. In this paper we present a hierarchically distributed policy-based system architecture and prototype implementation for WLAN security management. The architecture includes a central policy engine that validates policies and computes new configuration settings for network elements when access policies are violated, distributed wireless domain policy managers with consistent local policy autonomy that coordinate dedicated local monitors so as to monitor and control multi-vendor WLAN access points (APs). The local monitors include wireless intrusion detection modules and wireless AP interface adaptors. Although in this paper we focus on wireless security aspects, the overall architecture can be applied to end-to-end security management of wireline and wireless networks.
机译:由于无线局域网(WLAN)的广泛部署以及它们对各种类型攻击的众所周知的漏洞,以及动态无线网络中的严格可伸缩性要求,无线以太网(或Wi-Fi)安全管理是一个日益引起人们关注的挑战性领域领域。在最新安全标准通过之前,需要保护部署的WLAN(例如802.11a / b / g网络)上的用户和网络资产不受现有安全威胁的影响,而不必依赖最新功能。此外,尽管新标准可以保护外部人员未经授权使用网络资源,但它们不能处理内部人员的滥用或不当行为。在本文中,我们提出了用于WLAN安全管理的基于分层策略的分布式系统体系结构和原型实现。该体系结构包括一个中央策略引擎,该策略引擎可在访问策略被违反时验证策略并为网络元素计算新的配置设置;分布式无线域策略管理器具有一致的本地策略自治能力,可协调专用本地监视器,从而监视和控制多厂商WLAN访问点(AP)。本地监视器包括无线入侵检测模块和无线AP接口适配器。尽管在本文中,我们专注于无线安全性方面,但是总体体系结构可以应用于有线和无线网络的端到端安全性管理。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号