Designs of a Secure Wireless LAN Access Technique and an Intrusion Detection System for Home Network
Taesub Kim, Yikang Kim, Byungbog Lee, Seungwan Ryu, Choong-Ho Cho · InTech eBooks · 2011
Home network service has been integrated with various communication technologies to help people have a more convenient life.It is expected that wireless LAN (WLAN), B l u e t o o t h , u l t r a w i d e b a n d ( U W B ) , a n d Z i g b e e w i l l b e u s e d i n h o m e n e t w o r k s a s wireless access technologies to provide various home network services.WLAN study among them is actively making progress.But WLAN communication technologies have a problem in that access points (APs) cannot control the transmission range.This property allows the neighbor or person in the next house to receive the traffic and a malicious intruder to subvert the privacy.Therefore, authentication mechanisms have to be considered so that only an eligible user is authenticated to use the resources of a home network.IEEE 802.11 working group (WG) specifies an authentication procedure but it provide the only basic mechanism which can't protect the WLAN communications from the ineligible approach.The IEEE 802.11i standardization group is working on an access control based on IEEE 802.1x and air traffic encryption to strengthen WLAN security techniques.In a conventional method, the nonprofessional user finds it very difficult to setup security information inside WLAN stations and APs.However, there are the various user levels of computer knowledge in a home network.Because of this reason the way to setup authentication information should be prepared so it is easy for users who are not computer professionals.In this research, we propose access control mechanism considering the convenience of users, secure authentication protocol, and the intrusion detection system to support access control mechanism.Section II presents related literatures.In Section III, we propose authentication mechanism and the intrusion detection system for home network.The performance analysis of the proposed security mechanisms is presented in Section IV.Finally Section V concludes the research. www.intechopen.comIntrusion Detection Systems 218 2. Related literatures EAP (Extensible Authentication Protocol)Extensible Authentication Protocol (EAP) is a mechanism that defines a standard message exchange between devices using an agreed upon authentication protocol.EAP is used as one of the base technologies to allow both wired and wireless clients to authentication to network devices.Because the EAP protocol does not require the IP protocol to communicate (it uses the link layer), it can transport messages between devices without the EAP clients requiring an IP Address.EAP is effective in networks that rely on DHCP for their IP addresses -as the client will not be able to retrieve an IP address from the DHCP server until they are authenticated to the network and given a network connection.EAP by itself cannot be used as an authentication protocol -as it is merely a standard by which to exchange authentication messages between a client and an authentication server.EAP supports a number of authentication protocols to provide security during the authentication process.The security features and encryption strength vary with each EAP authentication protocol allowing companies to choose which EAP authentication protocol makes the most sense for their 802.1Xapplication.EAP is a method of conducting an authentication conversation between a Client/supplicant, Authenticator and an authentication server.* Client/Supplicant: The client, or supplicant, is the device that needs to be authenticated.The client supplies the authentication credentials (such as certificate or username and password information) to the authenticator and requests access to the network.The client uses EAP Over LAN (EAPOL) to talk to the authenticator.Examples of clients include workstations (both wired and wireless), PDA's, and wireless Voice Over IP phones.* Authenticator: The authenticator is the device performing the 802.1X port-level security and it controls access to the network.The authenticator receives the user credentials from the client, passes it onto the authentication server, and performs the necessary block or permit action based on the results from the authentication server.Depending on the EAP authentication protocol negotiated between the client and authentication server, the authenticator relays the necessary messages between the client and authentication server to facilitate the authentication request.The authenticator can operate in two different modes: it can perform the EAP messaging functions locally and communicate with the authentication server using the RADIUS protocol or it can operate as an EAP pass-through device to allow the authentication server to perform the necessary EAP protocol messaging functions.Examples of authenticators include network switches and routers (wired network application) and wireless access points or wireless gateway switches.Authentication Server: The authentication server validates the user's credential information from the client and specifies whether or not access is granted.The authentication server also specifies the EAP authentication protocol to be used between the client and itself and may specify optional parameters once access is granted.Optional p a r a m e t e r s m a y b e u s e d t o a u t h o r i z e a c c e s s t o s p e c i f i c a r e a s o f t h e n e t w o r k u s i n g dynamic VLAN or user policies.Examples of authentication servers include RADIUS and Active Directory servers.It is also an authentication protocol for general purpose.The authentication methods in EAP include message digest 5(MD5), transport layer security (TLS), tunneled TLS (TTLS) and so on.These method protocols have features as follows. www.intechopen.com How to referenceIn order to correctly reference this scholarly work, feel free to copy and paste the following: Taesub Kim, Yikang Kim, Byungbog Lee, Seungwan Ryu and Choongho Cho (2011).Designs of a Secure Wireless LAN Access Technique and an Intrusion Detection System for Home Network, Intrusion Detection Systems, Dr. Pawel Skrobanek (Ed.), ISBN: 978-953-307-167-1, InTech, Available from: http://www.intechopen.com/books/intrusion-detection-systems/designs-of