Session Hijacking Attacks in Wireless Local Area Networks

Abstract

Wireless Local Area Network (WLAN) technologies are becoming widely used since they provide more flexibility and availability, Unfortunately, it is possible for WLANs to be implemented with security flaws which are not addressed in the original 802.11 specification, IEEE formed a working group (TGi) to provide a complete solution (code named 802.11i standard) to all the security problems of the WLANs, The group proposed using 802.1X as an interim solution to the deficiencies in WLAN authentication and key management, The full 802. 11i standard is expected to be finalized by the end of 2004, Although 802.1X provides a better authentication scheme than the original 802.11 security solution, it is still vulnerable to denial-of-service, session hijacking, and man-in- the-middle attacks, Using an open-source 802.lx test-bed, this thesis evaluates various session hijacking mechanisms through experimentation, The main conclusion is that the risk of session hijacking attack is significantly reduced with the new security standard (802.11i); however, the new standard will not resolve all of the problems, An attempt to launch a session hijacking attack against the new security standard will not succeed, although it will result in a denial-of-service attack against the user,

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Mar 01, 2004
Accession Number
ADA422361

Entities

People

  • Hulusi Onder

Organizations

  • Naval Postgraduate School

Tags

Communities of Interest

  • Energy and Power Technologies

DTIC Thesaurus Topics

  • Authentication
  • Computer Networks
  • Computer Programming
  • Computer Programs
  • Computers
  • Data Links
  • Denial Of Service Attack
  • Electronic Mail
  • Local Area Networks
  • Network Architecture
  • Network Protocols
  • Network Science
  • Operating Systems
  • Security Protocols
  • Test Beds
  • Web Browsers
  • Wireless Networks

Fields of Study

  • Computer science

Readers

  • Aviation Safety and Air Traffic Management
  • Military and Counterinsurgency Studies.
  • Radio communications and signal processing.