首页> 外文OA文献 >A robust scheme to defend against disassociation and deauthentication DoS attacks in WLAN networks
【2h】

A robust scheme to defend against disassociation and deauthentication DoS attacks in WLAN networks

机译:一种可靠的方案,可防止WLAN网络中的解除关联和取消验证DoS攻击

摘要

Wireless 802.11 (also known as WLAN) has many flaws that expose the medium to numerous types of attacks. WLAN control frame consists of three major parts; data, management and control frames. Data frame is whereby data carried on, in the meantime, management and control frames are both responsible for maintaining the communication between the clients and the access point. The absence of encryption at both of these two frames exposes the medium to inevitable various types of DoS attacks at Data Link Layer. The attacker might spoof the unencrypted Deauthentication/Disassociation message together with the MAC address of the targeted access point and keep retransmitting it to all clients causing a continuous disconnection in WLAN networks. Wireless 802.11w standards has succeeded mitigating the flaw by encrypting the frames, yet only when WPA2 encryption is enforced. In this paper, we developed an enhanced proposed WLAN scheme to mitigate Deauthentication and Disassociation DoS attacks on WLAN networks. The proposed scheme is based on modifying the last twenty bits of the management frame in 802.11n standard using an enhanced version of Linear Congruential Algorithm called MAX algorithm. This is to provide a layer of authentication with no need to enforce WPA2 encryption. The proposed scheme is evaluated using CommeView Simulator and showed to be robust by slowing the attacks in an average of 3551 second on both encrypted and unencrypted networks.
机译:无线802.11(也称为WLAN)具有许多缺陷,使媒体容易受到多种攻击。 WLAN控制框架包括三个主要部分;数据,管理和控制框架。数据帧是管理和控制帧同时进行的数据,负责维持客户端和接入点之间的通信。这两个帧都没有加密,这使媒体在数据链路层容易受到各种DoS攻击。攻击者可能会欺骗未加密的取消身份验证/取消关联消息以及目标接入点的MAC地址,并不断将其重新发送给所有客户端,从而导致WLAN网络中的持续断开连接。无线802.11w标准通过加密帧成功地缓解了该缺陷,但仅在强制执行WPA2加密时才有效。在本文中,我们开发了一种增强的建议WLAN方案,以减轻WLAN网络上的身份验证和解除关联DoS攻击。所提出的方案基于使用称为MAX算法的增强型线性同余算法修改802.11n标准中管理帧的最后20位。这是为了提供身份验证层,而无需强制执行WPA2加密。该提议的方案使用CommeView Simulator进行了评估,通过在加密和未加密的网络上平均平均降低3551秒的攻击速度而显示出强大的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号