Dynamic assignment of eduroam users to separate virtual lans

Marko Dolničar · 2013

The aim of the diploma thesis was to thoroughly study the eduroam network, which is, with its authentication and authorisation mechanisms, considered a secure service. However, the network lacks mechanisms to protect the logged-in users from malicious users on the same network. Security vulnerability as a result of insecure protocols of eduroam may result in any malicious user being able to access other users' confidential information. After having set up a test network identical to eduroam, we successfully tested it with some attacks on the Data Link layer. Finally, we provide a solution to enhance security, by separating the users into individual sub networks using VLANs and consequently preventing the attacks on Data Link layer.

Read the paper · More papers on PaperTik