DocumentCode :
3178923
Title :
A policy-based approach to wireless LAN security management
Author :
Lapiotis, George ; Kim, Byungsuk ; Das, Subir ; Anjum, Farooq
Author_Institution :
Telcordia Technol., Inc., Piscataway, NJ, USA
fYear :
2005
fDate :
5-9 Sept. 2005
Firstpage :
181
Lastpage :
189
Abstract :
Wireless Ethernet (or Wi-Fi) security management is a challenging area of increased interest due to the widespread deployment of Wireless LANs (WLANs) and their well-known vulnerabilities to various types of attacks, as well as stringent scalability requirements in the dynamic wireless domain. Until the adoption of the latest security standards is complete, users and network assets on deployed WLANs, such as 802.11a/b/g networks, need to be protected from existing security threats without depending on the latest features. In addition, while new standards can protect the unauthorized use of network resource for outsiders, they do not deal with the misuse or misbehaviors by insiders. In this paper we present a hierarchically distributed policy-based system architecture and prototype implementation for WLAN security management. The architecture includes a central policy engine that validates policies and computes new configuration settings for network elements when access policies are violated, distributed wireless domain policy managers with consistent local policy autonomy that coordinate dedicated local monitors so as to monitor and control multi-vendor WLAN access points (APs). The local monitors include wireless intrusion detection modules and wireless AP interface adaptors. Although in this paper we focus on wireless security aspects, the overall architecture can be applied to end-to-end security management of wireline and wireless networks.
Keywords :
telecommunication security; wireless LAN; Wireless Ethernet; wireless LAN security management; wireline networks; Communication system security; Computer architecture; Computer networks; Distributed computing; Engines; Ethernet networks; Protection; Prototypes; Scalability; Wireless LAN;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security and Privacy for Emerging Areas in Communication Networks, 2005. Workshop of the 1st International Conference on
Print_ISBN :
0-7803-9468-2
Type :
conf
DOI :
10.1109/SECCMW.2005.1588312
Filename :
1588312
Link To Document :
بازگشت