Title :
Security Gateway for Accessing IPv6 WLAN
Author :
Shih, Chih-Mou ; Kao, Shang-Juh
Author_Institution :
Dept. of Comput. Sci., Nat. Chung-Hsing Univ., Taichung
Abstract :
The existing IETF standards specify that the network communications can be protected with IPsec authentication header (AH). However, the current specification didn´t resolve the problem of automatic key management. Even though several solutions have been proposed, such as CGA and ABK, the implementations for IPv6 are still far away from completeness. This paper presents an approach of security gateway to effectively detect the security threats or illegal access attempts to IPv6 WLAN. By taking the advantages of wireless technology for mobility as well as IPv6 features, the security gateway is capable of offering precautionary reports for potential intrusions, attacks, or system vulnerabilities before a global IP being determined. The gateway is composed of traffic collection unit, traffic processing unit, behavior analysis unit, response unit, authentication unit, and policy management unit. With monitoring and analyzing the communication traffic from the managed devices, using the widely available tools from SNMP, ICMP, DHCP, and RADIUS, the security gateway provides an elegant solution to filter most illegal accesses to wireless IPv6 networks
Keywords :
IP networks; internetworking; message authentication; telecommunication security; telecommunication traffic; transport protocols; wireless LAN; DHCP; ICMP; IETF standards; IPsec authentication header; IPv6 WLAN illegal access; RADIUS; SNMP; authentication unit; automatic key management; behavior analysis unit; communication traffic monitoring; policy management unit; response unit; security gateway; traffic collection unit; traffic processing unit; Access protocols; Authentication; Communication standards; Communication system security; Computer science; Information security; National security; Network servers; Routing; Wireless LAN; IPv6; Network Management; Security Gateway; WLAN;
Conference_Titel :
Computer and Information Science, 2006 and 2006 1st IEEE/ACIS International Workshop on Component-Based Software Engineering, Software Architecture and Reuse. ICIS-COMSAR 2006. 5th IEEE/ACIS International Conference on
Conference_Location :
Honolulu, HI
Print_ISBN :
0-7695-2613-6
DOI :
10.1109/ICIS-COMSAR.2006.76