Integrity Check for Disassociate/Associate/Re-associate March 2002 Integrity Check for Disassociate/Associate/Re-associate Tim Moore Microsoft Tim Moore, Microsoft
Problem Disassociate, etc messages are not integrity checked March 2002 Problem Disassociate, etc messages are not integrity checked Denial of service attacks Tim Moore, Microsoft
Solutions Integrity check the disassociate, etc. message March 2002 Solutions Integrity check the disassociate, etc. message Disallow disassociate message when in 802.1X authenticated state Do not allow assoicate/reassoicate messages to affect DS Tim Moore, Microsoft
Integrity check Use data framing for disassociate, etc message March 2002 Integrity check Use data framing for disassociate, etc message Not encrypted when no keys Needed because disassociate is used before authenticate Encrypted when keys available Tim Moore, Microsoft
802.1X With changes requested of 802.1X yesterday March 2002 802.1X With changes requested of 802.1X yesterday EAP-Logoff is authenticated Require stations send an EAP-Logoff before disassociating Tim Moore, Microsoft