无线入侵防御技术的实验评估

Amit Vartak, Sohail Ahmad, K. Gopinath
{"title":"无线入侵防御技术的实验评估","authors":"Amit Vartak, Sohail Ahmad, K. Gopinath","doi":"10.1109/COMSWA.2007.382464","DOIUrl":null,"url":null,"abstract":"Wireless Local Area Networks (WLANs) can open certain security backdoors which cannot be mitigated by conventional security mechanisms such as firewalls. This has lead to the development and quick adoption of a new suite of products that specialize in securing a network from the WLAN based security threats. Such products, known as Wireless Intrusion Prevention System (WIPS), not only detect wireless intrusions, but can also prevent them. One of the popular methods used in a WIPS for intrusion prevention is Over-The-Air (OTA) prevention which involves the transmission of specially crafted Medium Access Control (MAC) level packets over the wireless medium. Although OTA prevention is generally based on known MAC level denial-of-service techniques, there is little information available on the strengths and limitations of such techniques in mitigating unauthorized communication. In this paper, we first provide a test-bed based experimental evaluation of several (four) OTA prevention techniques in mitigating unauthorized wireless communication. Experimental results demonstrate that: (i) none of the considered OTA techniques may individually be able to prevent all the wireless threat scenarios reliably, (ii) certain techniques can fail against devices from certain vendors, and, (iii) OTA techniques require continual transmission of MAC level packets for effective blockage. Finally, we discuss the implications of the experimental results on the design of a WIPS.","PeriodicalId":191295,"journal":{"name":"2007 2nd International Conference on Communication Systems Software and Middleware","volume":"80 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-07-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":"{\"title\":\"An Experimental Evaluation of Over-The-Air (OTA) Wireless Intrusion Prevention Techniques\",\"authors\":\"Amit Vartak, Sohail Ahmad, K. Gopinath\",\"doi\":\"10.1109/COMSWA.2007.382464\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Wireless Local Area Networks (WLANs) can open certain security backdoors which cannot be mitigated by conventional security mechanisms such as firewalls. This has lead to the development and quick adoption of a new suite of products that specialize in securing a network from the WLAN based security threats. Such products, known as Wireless Intrusion Prevention System (WIPS), not only detect wireless intrusions, but can also prevent them. One of the popular methods used in a WIPS for intrusion prevention is Over-The-Air (OTA) prevention which involves the transmission of specially crafted Medium Access Control (MAC) level packets over the wireless medium. Although OTA prevention is generally based on known MAC level denial-of-service techniques, there is little information available on the strengths and limitations of such techniques in mitigating unauthorized communication. In this paper, we first provide a test-bed based experimental evaluation of several (four) OTA prevention techniques in mitigating unauthorized wireless communication. Experimental results demonstrate that: (i) none of the considered OTA techniques may individually be able to prevent all the wireless threat scenarios reliably, (ii) certain techniques can fail against devices from certain vendors, and, (iii) OTA techniques require continual transmission of MAC level packets for effective blockage. Finally, we discuss the implications of the experimental results on the design of a WIPS.\",\"PeriodicalId\":191295,\"journal\":{\"name\":\"2007 2nd International Conference on Communication Systems Software and Middleware\",\"volume\":\"80 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2007-07-09\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"9\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2007 2nd International Conference on Communication Systems Software and Middleware\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/COMSWA.2007.382464\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 2nd International Conference on Communication Systems Software and Middleware","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/COMSWA.2007.382464","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

摘要

无线局域网(wlan)可以打开某些传统安全机制(如防火墙)无法缓解的安全后门。这导致了一套专门保护网络免受基于WLAN的安全威胁的新产品的开发和快速采用。这类产品被称为无线入侵防御系统(Wireless Intrusion Prevention System, WIPS),它不仅能检测到无线入侵,还能阻止无线入侵。在WIPS中用于入侵防御的流行方法之一是空中(OTA)防御,它涉及在无线媒体上传输特制的介质访问控制(MAC)级数据包。尽管OTA预防通常基于已知的MAC级拒绝服务技术,但关于此类技术在减轻未经授权通信方面的优势和局限性的信息很少。在本文中,我们首先提供了一个基于试验台的实验评估,用于减轻未经授权的无线通信的几种(四种)OTA预防技术。实验结果表明:(i)所考虑的OTA技术可能无法单独可靠地防止所有无线威胁场景,(ii)某些技术可能对来自某些供应商的设备失败,以及(iii) OTA技术需要连续传输MAC级数据包才能有效阻塞。最后,我们讨论了实验结果对wps设计的启示。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
An Experimental Evaluation of Over-The-Air (OTA) Wireless Intrusion Prevention Techniques
Wireless Local Area Networks (WLANs) can open certain security backdoors which cannot be mitigated by conventional security mechanisms such as firewalls. This has lead to the development and quick adoption of a new suite of products that specialize in securing a network from the WLAN based security threats. Such products, known as Wireless Intrusion Prevention System (WIPS), not only detect wireless intrusions, but can also prevent them. One of the popular methods used in a WIPS for intrusion prevention is Over-The-Air (OTA) prevention which involves the transmission of specially crafted Medium Access Control (MAC) level packets over the wireless medium. Although OTA prevention is generally based on known MAC level denial-of-service techniques, there is little information available on the strengths and limitations of such techniques in mitigating unauthorized communication. In this paper, we first provide a test-bed based experimental evaluation of several (four) OTA prevention techniques in mitigating unauthorized wireless communication. Experimental results demonstrate that: (i) none of the considered OTA techniques may individually be able to prevent all the wireless threat scenarios reliably, (ii) certain techniques can fail against devices from certain vendors, and, (iii) OTA techniques require continual transmission of MAC level packets for effective blockage. Finally, we discuss the implications of the experimental results on the design of a WIPS.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
A Fast and Efficient Authentication Protocol for a Seamless Handover between a WLAN and WiBro On Utilizing Directional Antenna in 802.11 Networks: Deafness Study An Architecture and a Programming Interface for Application-Aware Data Dissemination Using Overlay Networks An Efficient Management Method of Access Policies for Hierarchical Virtual Private Networks Real-time End-to-end Network Monitoring in Large Distributed Systems
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1