Forums: Wireless Intrusion Detection And Response - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Wireless Intrusion Detection And Response

#1 User is offline   RELiC 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 163
  • Joined: 09-August 03

Posted 05 May 2004 - 08:29 AM

Quote

GA Tech: Wireless Intrusion Detection and Response

Abstract
A prototype implementation of a wireless intrusion detection and active response system is described. An off the shelf wireless access point was modified by downloading a new Linux operating system with non-standard wireless access point functionality in order to implement a wireless intrusion detection system that has the ability to actively respond to identified threats. An overview of the characteristics and functionality required in a wireless intrusion detection system is presented along with a review and comparison of existing wireless intrusion detection systems and functionalities. Implemented functionality and capabilities of our prototyped system are presented along with conclusions as to what is necessary to implement a more desirable and capable wireless intrusion detection system.
http://users.ece.gatech.edu/~owen/Research/Conference%20Publications/wireless_IAW2003.pdf
../
../

Attached File(s)


0

#2 Guest_T3cHn0b0y_*

  • Group: Guests

Posted 06 May 2004 - 12:38 PM

Thanks for the file...this will make good reading :)
0

#3 User is offline   billkennedy32 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 53
  • Joined: 09-October 03

Posted 07 May 2004 - 06:56 PM

didnt check out the link but just thinking about IDS for WLAN's, one could simply have his or her own dhcp server with trigger code. Once to many IP's are out on the WLAN pen test's, scanns alarms go off and trace the last node that got the IP.

easy az pie
0

#4 User is offline   packet 

  • Specialist
  • Icon
  • Group: Members
  • Posts: 628
  • Joined: 17-July 03

Posted 08 May 2004 - 09:13 PM

Cool stuff,

other tools I use to make sure unknown APs and other machines get detected on my network is with arpwatch letting me know each new MAC on the network. I use 802.1X or MAC based authentication to actually prevent any new device coming on that hasn't been approved.

So while detecting anything new in the airwaves is cool, I tend to like the old fashioned approach of authenticated VLANs and preventing any unauthorized devices from even touching the network.

--P>G>>
Abusus non tolit usum
The gopher is back!
0

#5 User is offline   Imps2 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 56
  • Joined: 30-July 03

Posted 19 May 2004 - 05:24 AM

Thnx for sharing that's a real nice paper


Greetz Imps2
0

#6 User is offline   Spookie 

  • Staff Sergeant
  • Icon
  • Group: Specialist
  • Posts: 293
  • Joined: 21-December 03

Posted 20 July 2004 - 07:25 AM

Heres something that might be of interest . Simple yet does a pretty fair job.

AirSnare

Should accomplish some of what your looking to do.
Beauty is only a light switch away
0

#7 User is offline   twistedps 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 271
  • Joined: 20-March 04

Posted 12 August 2004 - 09:51 PM

AirDefense is a good product that my company resells. i havent had muchtime to look into it, but ive heard a lot of good things from the engineers here about it.
0

#8 User is offline   Spookie 

  • Staff Sergeant
  • Icon
  • Group: Specialist
  • Posts: 293
  • Joined: 21-December 03

Posted 19 August 2004 - 06:57 AM

I've had the chance to attend a few AirDefense demos and like you I think it's a pretty good product. Pretty pricey if I recall correctly.

Sonicwall also has The SOHO TZW which might be of interest to those that are looking for something within a limited budget.

AirSnare is also pretty neat for the average home user.

Heres another link board members may find of interest concerning wireless
Wireless Intrusion Detection Systems - Talisker

Usually AirDefense is out at the gatherings and have a few or there toys setup. At one of the DefCons they setup shop and kept a tally of various attacks they recorded. AirDefense Discovers New Threats to Wireless LANs at Hacker Conference
Beauty is only a light switch away
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting