      Yasir Zahur      T. Andrew Yang

     University of Houston – Clear Lake

       17th CCSC Southeastern Conference
    Georgia Perimeter College - Dunwoody, GA

 Introduction
 Standards & Specifications
 Vulnerabilities
 Alternate Security Solutions
 Laboratory Setup

Where Does WLAN Fit ?

      (Nov. 6, 2003)

Growth of WLAN

Infrastructure Mode of WLAN

Typical WLAN Architecture

                IEEE 802.11 Standards
Standard                              Description                                               Current Status
IEEE 802.11    Standard for WLAN operations at data rates up to 2 Mbps in the                   Approved in July 1997
                                  2.4-GHz ISM band

IEEE 802.11a   Standard for WLAN operations at data rates up to 54 Mbps in the     Approved in Sept 1999. End-user products began
                                   5-GHz UNII band                                              hipping in early 2002

IEEE 802.11b   Standard for WLAN operations at data rates up to 11 Mbps in the     Sept 1999. End-user products began shipping in
                                   2.4-GHz ISM band                                                 early 2000

IEEE 802.11g             High-rate extension to 802.11b allowing for                     Draft standard adopted Nov 2001.
                          data rates up to 54 Mbps in the 2.4-GHz                        Full ratification expected late 2002
                                          ISM band                                                   or early 2003

IEEE 802.11e     Enhance the 802.11 MAC to improve and manage Quality of           Still in development, i.e., in the task group (TG)
                 Service, provide classes of service, and enhanced security and                          stage
               authentication mechanisms. These enhancements should provide
                the quality required for services such as IP telephony and video

IEEE 802.11f      Develop recommended practices for an Inter- access Point         Still in development, i.e., in the task group (TG)
                 Protocol (IAPP) which provides the necessary capabilities to                            stage
               achieve multi-vendor AP interoperability across a DS supporting
                             IEEE P802.11 Wireless LAN Links

IEEE 802.11i   Enhance the 802.11 Medium Access Control (MAC) to enhance           Still in development, i.e., in the task group (TG)
                          security and authentication mechanisms                                         stage

   Interferences (802.11b)

Cordless                                        Some other
 Phone                                        wireless network


            IEEE 802.11b Specifications
                         (a brief overview)

 Transmission of approximately 11 Mbps of data
 Half Duplex protocol
 Use of CSMA/CA (collision avoidance) instead of CSMA/CD (collision
 Total of 14 frequency channels. FCC allows channels 1 through 11
  within the U.S in 2.4 GHz ISM band
 Only channels 1, 6 and 11 can be used without causing interference
  between access points
 Wired Equivalent Privacy (WEP) based on Symmetric RC4 Encryption
 Use of Service Set Identifier (SSID) as network identifier

    General WLAN Vulnerabilities
•   Eavesdropping
•   Invasion and Resource Stealing
•   Traffic Redirection
•   Denial Of Service Attack
•   Rogue Access Point
•   No per packet authentication
•   No central authentication, authorization, and
    accounting (AAA) support

            802.11b Vulnerabilities

•       MAC address based authentication
•       One-Way authentication
•       SSID
•       Static WEP Keys
•       WEP key vulnerabilities
    o     Manual Key Management
    o     Key Size
    o     Initialization Vector
    o     Decryption Dictionaries

WEP Encryption

                         IEEE 802.1x
 IEEE 802.1x is a port based authentication protocol.
 It forms the basis for IEEE 802.11i standard.
 There are three different types of entities in a typical 802.1x network
  including a supplicant, an authenticator, and an authentication server.
 In an un-authorized state, the port allows only DHCP and EAP
  (Extensible Authentication Protocol) traffic to pass through.

EAPOL Exchange

        IEEE 802.1x – Pros / Cons

   Dynamic Session Key Management
   Open Standards Based
   Centralized User Administration
   User Based Identification
   Absence Of Mutual Authentication
   Lack of clear communication between 802.11 and 802.11i
    state machines and message authenticity

      Absence Of Mutual Authentication

 Supplicant always trusts the Authenticator but not vice versa
 This opens the door for “MAN IN THE MIDDLE ATTACK”

          Session Hijack Attack

802.11 State Machine                 802.11i State Machine

Session Hijack Attack (…cont)

            Alternate Solutions

 Virtual Private Networks (VPN)
     User Authentication
     Encryption
 Cisco LEAP
     Mutual Authentication
     Per Session based Keys
 Secure Socket Layer (SSL)
     Encryption
     Digital Certificates

WEP Attack

Man In The Middle &
Session Hijack Attacks

               Cisco LEAP Setup

LEAP Enabled          LEAP Enabled    AAA Server
   Client              Access Point

             VPN Setup

VPN Client     Pass Through   VPN Server
               Access Point

             SSL Setup

SSL Client     Pass Through   SSL Server
               Access Point

         A Specialized Computer Security
        NSF CCLI A&I grant: 2003-2005
        Two Focuses:
    a)     DCSL: Distributed Computer Security Lab
          Between UHCL and UHD
          Possibly extended to other small or medium-sized colleges
          Customizable testbed for various security-related

    b)     Module-based Computer Security Courseware Design
          Looking for collaborators, courseware developers, users, …

      Computer Security Courseware

b)    Module-based Computer Security Courseware Design
     Units: Modules, submodules, artifacts, …

