Title :
SWAN: a secure wireless LAN architecture
Author :
Virendra, Mohit ; Upadhyaya, Shambhu
Author_Institution :
Dept. of Comput. Sci. & Eng., State Univ. of New York, USA
Abstract :
Existing wireless LAN (WLAN) security schemes are few and product specific. While there exist some schemes for information integrity related problems, there are few standard solutions for quality of service and network health maintenance related problems in wireless networks. In this paper we propose an architecture model for secure WLAN that is generic in its design, so that it can easily be incorporated into existing systems at low cost, thus making it feasible and easy to implement. Our secure wireless LAN (SWAN) architecture first describes an admission control mechanism and deals with intrusion detection, malicious behavior detection, and maintaining quality of service and network health. We then introduce a novel infrastructure for an ad-hoc migration scheme (IAMS) to deal with denial of service (DOS) attacks on WLAN, and describe a unique traffic distribution protocol (TDP) for routing traffic when an access point is under attack, thus ensuring network survivability in the case of a DOS attack. We simulate the IAMS and the TDP using the network simulator GloMoSim.
Keywords :
authorisation; computer network management; computer network reliability; quality of service; routing protocols; telecommunication security; telecommunication traffic; wireless LAN; DOS attacks; GloMoSim; SWAN; TDP; WLAN security; ad-hoc migration scheme; admission control mechanism; denial of service; generic design; intrusion detection; malicious behavior detection; network health maintenance; network survivability; quality of service; secure wireless LAN architecture; traffic distribution protocol; traffic routing; wireless networks; Admission control; Communication system traffic control; Computer crime; Costs; Information security; Intrusion detection; Quality of service; Traffic control; Wireless LAN; Wireless networks;
Conference_Titel :
Local Computer Networks, 2004. 29th Annual IEEE International Conference on
Print_ISBN :
0-7695-2260-2
DOI :
10.1109/LCN.2004.120