802.1X认证环境下的非法用户接入检测  被引量:5

The Detection of Unauthorized Users′ Access in 802.1X Authentication Environment

在线阅读下载全文

作  者:于丰[1] 刘威[1] 

机构地区:[1]沈阳建筑大学网络中心,辽宁沈阳110168

出  处:《沈阳建筑大学学报(自然科学版)》2009年第6期1193-1197,共5页Journal of Shenyang Jianzhu University:Natural Science

基  金:辽宁省教育厅科学技术研究项目(2008607)

摘  要:目的解决基于802.1X协议认证环境下的用户非法接入问题,使全网认证用户可管理.方法从分析802.1X认证技术特点和非法用户通讯原理出发,利用认证服务器定期向认证用户发送UDP探测报文,根据客户端返回的ACK报文丢失率检测出提供非法服务主机.结果在以校园网为代表的高速以太网环境中,网络不发生大面积拥塞的前提下,实现非法接入用户的实时网络阻断与客户端信息保存,管理者可根据系统保存的用户记录采取相应处罚措施.结论提出的检测方法对802.1X环境下的非法用户检测具有良好的准确性和快捷性,对于实现IntranetAAA系统具有现实意义,充分保障了网络的认证安全与计费安全.In order to forbid the unauthorized users' access in 802.1X authentication environment and make all the users in intranet manageable, this paper offers a method by analyzing the principle of 802.1X technical features and the network communication of unauthorized users. The authentication server sends the clients UDP messages periodically and finds the computers which offer illegal services by calculating the loss rate of ACK messages from the clients. In the high-speed ethernet environment like campus network, under the condition that a serious congestion doesn't occur, this method can cut off the network of unauthorized user in real time and save information of the client. And the network administrator can give punishment according to the records in the system. The method is proved good performance during experiments and achieves the desired results. It also has practical significance to AAA system and ensures the security of network authentication and accounting.

关 键 词:802.1X 客户端 认证服务器 非法接入 

分 类 号:TP393.1[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象