• DocumentCode
    1946690
  • Title

    An anti-DoS attack architecture for wireless IT Infrastructure

  • Author

    K´Ondiwa, N.O. ; Ochola, E.O.

  • Author_Institution
    Telkom Orange (K), Bus. Market R&D, Nairobi, Kenya
  • fYear
    2013
  • fDate
    13-17 July 2013
  • Firstpage
    98
  • Lastpage
    103
  • Abstract
    Widespread deployment of wireless solutions in corporate and government computing infrastructure implies that lots of sensitive information and data is carried over the air. The threats of intrusion and denial of service is real since wireless networks have broadcasted traffic. IEEE 802.11 defines WEP, WPA and WPA2 security protocols as possible countermeasures. The most recent model defined by IEEE, the WPA2 emphasizes data confidentiality, integrity and authentication but pays little attention to availability issues. Management and control frames in WPA2 are still sent in clear making the model vulnerable to DoS attacks. The failure recovery processes require re-authentication and re-association a fact which makes the model easily exploited by various DoS attacks that includes authentication and association frames flooding. In this paper, we propose a drop policy for DoS authentication and Association flooding. We assume deployment of the current IEEE 802.11i provides enough confidentiality, integrity and authentication schemes. We use simulation in OPNET to show that our security model performs better to provide improved security in terms of availability under Denial of service attack.
  • Keywords
    IEEE standards; computer network security; data integrity; message authentication; wireless LAN; DoS authentication; IEEE 802.11i; OPNET; anti-DoS attack architecture; association flooding; confidentiality scheme; denial of service; drop policy; integrity scheme; wireless IT Infrastructure; Authentication; Computational modeling; Computer crime; Floods; Throughput; Wireless LAN; 802.11i; 802.11w security; attacks; availability; denial of service; threats;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Science, Computing and Telecommunications (PACT), 2013 Pan African International Conference on
  • Conference_Location
    Lusaka
  • Type

    conf

  • DOI
    10.1109/SCAT.2013.7055096
  • Filename
    7055096