Improving the security of SNMP in wireless networks

被引:0
作者
Otrok, H [1 ]
Mourad, A [1 ]
Debbabi, A [1 ]
Assi, C [1 ]
机构
[1] Concordia Univ, Concordia Inst Informat Syst Engn, Comp Secur Lab, Montreal, PQ, Canada
来源
2005 International Conference on Wireless Networks, Communications and Mobile Computing, Vols 1 and 2 | 2005年
关键词
SNMPV3; Diffie-Hellman; certification authority;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Simple network management protocol (SNMP) is widely used for monitoring and managing computers and network devices on wired and wireless network. SNMPv1 and v2 do not provide security when managing agents. Three very important security features (authentication, encryption, access control) are added to SNMPv3 under the User-based Security Model (USM). Symmetric cryptography is used for encryption and one-way cryptography is used for authentication. The two keys used for encryption and authentication are derived from the shared password between the manager and agent. In this paper, we are addressing (1) the problem of one way authentication that leads to the man-in-the-middle attack and (2) the vulnerability pertaining to the password update method of SNMPv3. We propose to use certification authority for two-way authentication and Diffie-Hellman algorithm for key exchange to mitigate the impacts of these problems.
引用
收藏
页码:198 / 202
页数:5
相关论文
共 10 条
[1]  
[Anonymous], 2002, 3414 RFC
[2]  
BORISOV N, 2001, 7 ANN C MOB COMP NET
[3]  
Case J., 1999, 2570 RFC
[4]  
CHATZIMISIOS P, SECURITY ISSUES VULN
[5]  
*IETF WORK GROUP, 1999, 2631 IETF RFC WORK G
[6]  
MAXIM M, WIRELESS SECURITY BO
[7]  
Menezes AJ., 1997, HDB APPL CRYPTOGRAPH
[8]  
MISHRA A, 2002, 802IX IEEE U MAR
[9]  
SONG R, 2003, SECURITY COMMUNICATI
[10]  
STALLINGS W, 1999, SNMP SNMPV2 SNMPV3 R