• DocumentCode
    2185690
  • Title

    A design of egress NAC using an authentication visa checking mechanism to protect against MAC address spoofing attacks

  • Author

    Puangpronpitag, Somnuk ; Suwann, Atthapol

  • fYear
    2011
  • fDate
    17-19 May 2011
  • Firstpage
    300
  • Lastpage
    303
  • Abstract
    An egress Network Access Controller (NAC) is important to authenticate internal users before accessing external networks (such as browsing the Internet). It is generally deployed at most Wi-Fi hotspots. It can be also used to control wired access on any open Ethernet jacks (such as business centers or hotel rooms). However, a MAC address spoofing attack is a very simple but powerful technique to bypass the egress NAC. By spoofing their MAC Address to a legitimate user´s, attackers can easily access network resources under that user´s permission. There have been several previous proposals to solve this problem. However, all of them have been proven to be ineffective. In this paper, we therefore propose a new solution using an authentication visa checking mechanism. From experimental results on a test-bed, our new egress NAC has shown its effectiveness and efficiency in protecting against the MAC address spoofing attack on both wireless and wired network environments.
  • Keywords
    access protocols; wireless LAN; Egress NAC; MAC address spoofing attacks; Wi-Fi hotspots; authentication visa checking mechanism; network access controller; wired network environments; Logic gates; Switches; Egress NAC; MAC Address Spoofing; MAC Address Spoofing Prevention; Network Attacks;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Electrical Engineering/Electronics, Computer, Telecommunications and Information Technology (ECTI-CON), 2011 8th International Conference on
  • Conference_Location
    Khon Kaen
  • Print_ISBN
    978-1-4577-0425-3
  • Type

    conf

  • DOI
    10.1109/ECTICON.2011.5947832
  • Filename
    5947832