★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/documentation_article-6585.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Documentation 1/22/2003 9:44

Detecting Wireless LAN MAC Address Spoofing

Published By: Joshua Wright
Posted By: Eric Lubow
1/22/2003

An attacker wishing to disrupt a wireless network has a wide arsenal available to them. Many of these tools rely on using a faked MAC address, masquerading as the network access point or as an authorized client. Using these tools, an attacker can launch denial of service attacks, bypass access control mechanisms, or falsely advertise services to wireless clients.

This paper describes some of the techniques attackers utilize to disrupt wireless networks through MAC address spoofing, demonstrated with captured traffic that was generated by the AirJack, FakeAP and Wellenreiter tools. Through the analysis of these traces, the author identifies techniques that can be employed to detect applications that are using spoofed MAC addresses. With this information, wireless equipment manufacturers can implement anomaly-based intrusion detection systems capable of identifying MAC address spoofing to alert administrators of ongoing attacks against their networks.


Click here to go to this article.

Linux Security Newsletters - Subscribe Today!
Feb 1

Cyclone: A Safe Dialect of C
Feb 1

Should Microsoft pay your security patch costs?
Jan 31

Bush Approves Cybersecurity Strategy
Jan 31

DNS Cache Poisoning - The Next Generation
Jan 31

SEAS Aids U.S. Security Efforts
Jan 31

DOD Looking Ahead On Security
Jan 31

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000