Two Novel 802.1x Denial of Service Attacks

Abdulrahman Alruban, Emlyn Everitt · 2011

Denial of Service (DoS) attacks are among the most common security issues threatening today's 802.11 networks. In this paper, we have proposed two 802.1x DoS attacks, EAP-NAK and EAP-Notification flooding attacks. These effectively disrupt the authentication process between the legitimate wireless supplicants and the network authentication server. The evaluation of these attacks against EAP is performed using well-suited metrics which highlight their impact on the targeted network in practice. Furthermore, we discuss possible techniques to detect these attacks, such as configuring the WIDS to create a performance baseline of the wireless network. Lastly, several techniques and solutions were discussed which can be applied to the 802.11i standard in order to enhance the security of the 802.1x for dealing with DoS attacks, such as the use of a process delay time technique.

Read the paper · More papers on PaperTik