Wireless network security shows cracks

By Rupert Goodwins, ZDNet
Tuesday, February 19, 2002 09:32 AM
LONDON--U.S. researchers say a new set of security measures aimed at making 802.11-type wireless LANs safe from hackers is fundamentally flawed.

In a paper published last week, University of Maryland's William Arbaugh and Arunesh Mishra said the new 802.1X security system has two basic problems--one where a hacker can hijack an existing connection, and another where they can interpose themselves during authentication and steal access information as it's being set up.

In the first case, a hacker monitors the transmissions and when a session is established between a client and an access point, he sends a fake packet to the client purporting to be from the access point saying "Session closed". The client just reconnects with a new session while the legitimate access point thinks the old session is still open and is exposed.

The other way-- a "man in the middle" attack--again involves a hacker "pretending" to be an access point, this time relaying messages between the client and the real access point while monitoring their contents, having "...completely bypassed any higher-layer authentication and render(ing) the authentication mechanism ineffective," according to Arbaugh and Mishra.

The paper, An Initial Security Analysis of the IEEE 802.1X Standard, said the standard needs to be modified to include symmetric authentication--where the client and the access point both prove to be legitimate--and better handling of access point authentication. Without this, 802.1X and 802.11 cannot provide sufficient levels of security.

The 802.1X standard itself--and its associated standard, Extensible Authentication Protocol--is already in use for wireless networking in Cisco 802.11b products, for example. 802.1X has already been under investigation for its vulnerability to a number of different potential attacks, including several potential denial-of-service flaws.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Save changes to all open Word documents at one time

Microsoft Office Suite

If your Word sessions often wind up with a lot of open documents, this obscure command can streamline the process of closing them and saving your changes.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. 3g
  2. 3g third generation
  3. apple inc.
  4. apple iphone
  5. broadband
  6. cellular phones
  7. google inc.
  8. handset
  9. internet
  10. mobile
  11. mobile platforms / communications
  12. mobile / wireless
  13. network
  14. phone
  15. revenue
  16. smart phone
  17. smart phones
  18. software
  19. u.s.
  20. web