DO AN THUC TAP

Embed Size (px)

Citation preview

LI CM N

u tin em xin gi li cm n n cc thy c gio trong trng i hc Giao Thng Vn Ti TP. HCM truyn t nhng kin thc, kinh nghim qu bu cho em trong sut thi gian hc tp, gip em c nn tng c s nghin cu thc hin ti ny. c bit em xin c gi li cm n n thy ng Nhn Cch, thy tn tnh gip , trc tip hng dn em trong sut qu trnh lm ti tt nghip. Sau cng em cm n tt c bn b, v gia nh to iu kin vt cht v tinh thn, ng gp nhng kin gip em hon tt ti tt nghip ny. Trong qu trnh thc hin ti do cn hn ch v trnh hiu bit, thiu cc thit b h tr v thi gian thc hin nn khng trnh khi nhng thiu st, sai lm. Em rt mong nhn c cc kin gp ca thy c ti c hon thin, nng cao s hiu bit gp phn vo cng vic sau ny.

Bi Xun Diu Phm K Cng Lp CN07C Khoa Cng Ngh Thng Tin Trng i hc Giao Thng Vn Ti Tp. HCM Tp. HCM, ngy 10 thng 5 nm 2010

Tm hiu mng WLAN v cc phng thc bo mt

LI NHN XT ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ...................................................................................................................................................... ......................................................................................................................................................

MC LC:LI CM N........................................................................................................................1

Page 2

Tm hiu mng WLAN v cc phng thc bo mt

TM TT:.............................................................................................................................8 ti bao gm 9 chng trong :..................................................................................8 - Chng 1: lm r cc khi nim v chun kt ni s dng trong mng WLAN..............8 - Chng 2: a ra cc m hnh s dng v cc thit b h tr u cui.........................8 - Chng 3: gii thiu k thut tri ph............................................................................8 - Chng 4: phn tch an ninh trong mng WLAN, cc l hng v hnh thc tn cng.....8 - Chng 5: cc k thut m ha d liu..........................................................................8 - Chng 6: bin php phng chng tn cng trong mng WLAN v cc gii php bo mt ang c s dng trong thc t..............................................................................8 - Chng 7: tm hiu h thng gim st lu lng mng.................................................8 - Chng 8: cc vn cn lu khi tham gia vo mng WLAN.....................................8 - Chng 9: kt lun v a ra kin pht trin ti....................................................8 M U:..............................................................................................................................8 TNG QUAN:........................................................................................................................9 Chng 1:..........................................................................................................................10 CC VN C BN TRONG MNG WLAN........................................................................10 1.1. Khi nim mng cc b khng dy( WLAN ):...........................................................11 1.1.1. Khi nim WLAN: Wireless Local Area Network.................................................11 1.1.2. Lch s ra i: ...................................................................................................11 1.2. Cc ng dng ca mng WLAN:..............................................................................12 Mng WLAN l k thut thay th cho mng LAN hu tuyn, n cung cp mng cui cng vi khong cch kt ni ti thiu gia mt mng xng sng v mng trong nh hoc ngi dng di ng trong cc c quan. Sau y l cc ng dng ph bin ca WLAN thng qua sc mnh v tnh linh hot ca mng WLAN: Lab 1-1: ng nhp vao router giao din dong lnh .......................................................................................................12 1.3. Cc vn ca mng khng dy, tng quan i vi mng c dy:.......................22 Phm vi ng dng......................................................................................................23 phc tp k thut..................................................................................................23

Page 3

Tm hiu mng WLAN v cc phng thc bo mt

tin cy...................................................................................................................23 Lp t, trin khai......................................................................................................23 Tnh linh hot, kh nng thay i, pht trin..............................................................24 Gi c.........................................................................................................................24 Chng 2:..........................................................................................................................24 CC M HNH V THIT B DNG TRONG MNG WLAN.....................................................24 2.1. Chun 802.11:.........................................................................................................24 2.1.1. Nhm lp vt l PHY:.........................................................................................24 2.1.2. Nhm lp lin kt d liu MAC:..........................................................................26 2.2. Mt s c ch s dng khi trao i thng tin trong mng khng dy:.....................27 2.2.1. C ch CSMA-CA:...............................................................................................27 2.2.2. C ch RTS/CTS:................................................................................................28 2.2.3. C ch ACK:.......................................................................................................28 2.3. Phn bit WLAN v LAN:..........................................................................................28 2.4. M hnh mng WLAN:..............................................................................................30 2.4.1. M hnh Ad-hoc:.................................................................................................30 2.4.2. M hnh kiu c s h tng( Infrastruture):........................................................35 2.5. Cc thit b h tng trong mng:.............................................................................36 2.5.1. Antenna:............................................................................................................36 2.5.2. Wireless Access Point:......................................................................................39 2.6. C ly truyn sng, tc truyn d liu:.................................................................45 Chng 3:..........................................................................................................................46 L THUYT TRI PH.........................................................................................................46 3.3. Cc loi tri ph c s dng:...............................................................................47 Chng 4:..........................................................................................................................53 BO MT MNG KHNG DY.............................................................................................53

Page 4

Tm hiu mng WLAN v cc phng thc bo mt

4.2. Cc loi hnh tn cng trong WLAN:........................................................................54 4.2.1. Tn cng b ng Passive attacks:..................................................................54 4.2.1.1. nh ngha:....................................................................................................54 4.2.1.2. Kiu tn cng b ng c th - Phng thc bt gi tin (Sniffing):.................55 4.2.2. Tn cng ch ng Active attacks:.................................................................57 4.2.2.1. nh ngha:....................................................................................................57 4.2.2.2. Cc kiu tn cng ch ng c th:..............................................................57 4.2.3. Tn cng kiu chn p - Jamming attacks:........................................................63 4.2.4. Tn cng theo kiu thu ht - Man in the middle attacks :..................................64 Chng 5:..........................................................................................................................69 CHNG THC V M HA.................................................................................................69 5.1.Chng thc( Authentication):....................................................................................70 Chng thc c ngha l chng nhn, xc thc s hp php ca mt ngi, mt qu trnh tham gia, s dng no qua cc phng thc, cng c nh m kha, cha kha, ti khon, ch k, vn tay, vv.. Qua c th cho php hoc khng cho php cc hot ng tham gia, s dng. Ngi c quyn tham gia, s dng s c cp mt hay nhiu phng thc chng nhn, xc thc trn.............................................70 M ha d liu( Data Encryption) m bo thng tin truyn i, ngi ta s dng cc phng php m ha (encryption). D liu c bin i t dng nhn thc c sang dng khng nhn thc c theo mt thut ton no (to mt m) v s c bin i ngc li (gii m) trm nhn. Phng tin s dng trong qu trnh m ha gi l mt m................................................................................................71 5.1.1. Chng thc bng a ch MAC MAC Address:...................................................71 Nguyn l thc hin:..................................................................................................71 Nhc im:...............................................................................................................72 Bin php i ph:.....................................................................................................73 5.1.2. Chng thc bng SSID:......................................................................................73 Nguyn l thc hin:..................................................................................................73 Nhc im ca SSID:................................................................................................74

Page 5

Tm hiu mng WLAN v cc phng thc bo mt

Bin php i ph:.....................................................................................................76 5.1.3. Chng thc bng WEP:......................................................................................76 5.2. M ha:....................................................................................................................77 5.3. M ha WEP:(Wired Equivalent Privacy):.................................................................81 WEP khng c an ton, vy ti sao WEP li c chn v a vo chun 802.11? Chun 802.11 a ra cc tiu chun cho mt vn c gi l bo mt, l: - C th xut khu - mnh - Kh nng tng thch - Kh nng c tnh c - Ty chn, khng bt buc WEP hi t cc yu t ny, khi c a vo thc hin, WEP d nh h tr bo mt cho mc ch tin cy, iu khin truy nhp, v ton vn d liu. Ngi ta thy rng WEP khng phi l gii php bo mt y cho WLAN, tuy nhin cc thit b khng dy u c h tr kh nng dng WEP, v iu c bit l h c th b sung cc bin php an ton cho WEP. Mi nh sn xut c th s dng WEP vi cc cch khc nhau. Nh chun Wi-fi ca WECA ch s dng t kha WEP 40 bit, mt vi hng sn xut la chn cch tng cng cho WEP, mt vi hng khc li s dng mt chun mi nh l 802.1X vi EAP hoc VPN...............................................................88

5.3.2. Mt s cch tn cng trong WEP:....................................................................88 Phng thc d m chng thc:................................................................................88 Phng thc d m dng chung Share key trong WEP:...........................................88 Bin php i ph:.....................................................................................................91 5.3.3. Ci tin trong phng php chng thc v m ha WEP:..................................91 Chng 6:..........................................................................................................................95 CC GII PHP BO MT...................................................................................................95 6.1. Nguyn l RADIUS Server:.......................................................................................96 6.2. Giao thc chng thc m rng EAP:........................................................................98 6.2.1. Bn tin EAP:.......................................................................................................99 6.2.2. Cc bn tin yu cu v tr li EAP ( EAP Requests and Responses ):................99 6.2.3. Mt s phng php xc thc EAP:.................................................................100

Page 6

Tm hiu mng WLAN v cc phng thc bo mt

Bc AddRoundKey...................................................................................................103 Bc SubBytes..........................................................................................................103 Bc ShiftRows.........................................................................................................104 Bc MixColumns......................................................................................................104 6.7.1. Lc SSID:.........................................................................................................105

Chng 7:........................................................................................................................107 TM HIU V IDS V IDS TRONG MNG KHNG DY........................................................107 Chng 8:........................................................................................................................117 MT S VN KHC.....................................................................................................117 8.1. Bo mt c bn khi s dng Wlan:........................................................................117 8.2. Mt s phng php tn cng Wlan thc t:.........................................................120 8.2.1. Crack WEP:......................................................................................................120 8.2.2. Crack WPA s dng t in:............................................................................126 8.2.3. Crack WEP trn giao din Windows:................................................................132 Chng 9:........................................................................................................................137 KT LUN V HNG PHT TRIN CA TI...............................................................137 TI LIU THAM KHO.......................................................................................................138

Page 7

Tm hiu mng WLAN v cc phng thc bo mt

TM TT: ti bao gm 9 chng trong : - Chng 1: lm r cc khi nim v chun kt ni s dng trong mng WLAN. - Chng 2: a ra cc m hnh s dng v cc thit b h tr u cui. - Chng 3: gii thiu k thut tri ph. - Chng 4: phn tch an ninh trong mng WLAN, cc l hng v hnh thc tn cng. - Chng 5: cc k thut m ha d liu. - Chng 6: bin php phng chng tn cng trong mng WLAN v cc gii php bo mt ang c s dng trong thc t. - Chng 7: tm hiu h thng gim st lu lng mng. - Chng 8: cc vn cn lu khi tham gia vo mng WLAN. - Chng 9: kt lun v a ra kin pht trin ti. ti hng n vic nghin cu, phn tch v nh gi cc u- khuyt im ca cc phng thc bo mt ang c s dng rng ri trong thc t, v a ra cc gii php tng cng mc bo mt cho ngi s dng. Bn cnh ti cn tm hiu cch thc hot ng ca cc thit b u cui, gip ngi qun tr c th qun l c h thng mng WLAN mt cch hiu qu. Tuy ch dng li qu trnh tm hiu, nghin cu nhng ti em li mt nn tng kin thc v h thng mng cc b khng dy, nhng tin rng nu c u t thm thi gian cng nh cc thit b phn cng h tr th n s em li hiu qu cao, ng gp cho vic bo v an ton h thng mng cc b khng dy hin nay.

M U: u im ca mng my tnh c th hin kh r trong mi lnh vc ca cuc sng. chnh l s trao i, chia s, lu tr v bo v thng tin. Bn cnh nn tng mng my tnh hu tuyn, mng my tnh khng dy ngay t khi ra i th hin nhiu u im ni bt v linh hot, tnh n gin, kh nng tin dng. Trc y, do chi ph cn cao nn mng

Page 8

Tm hiu mng WLAN v cc phng thc bo mt

khng dy cn cha ph bin, ngy nay khi m gi thnh thit b phn cng ngy mt h, kh nng x l ngy cng tng th mng khng dy c trin khai rng ri. Do c im trao i thng tin trong khng gian truyn sng nn kh nng thng tin b r r ra ngoi l hon ton d hiu. Hn na, ngy nay vi s pht trin cao ca cng ngh thng tin, cc hacker c th d dng xm nhp vo mng hn bng nhiu con ng khc nhau. V vy, c th ni im yu c bn nht ca mng my tnh khng dy l kh nng bo mt, an ton thng tin. Thng tin l mt ti sn qu gi, m bo c an ton d liu cho ngi s dng l mt trong nhng yu cu c t ra hng u. Chnh v vy em quyt nh chn ti tm hiu mng WLAN v cc vn bo mt lm ti tt nghip, vi mong mun c th tm hiu nghin cu, ng thi h tr vic lm sau ny.

TNG QUAN: Cng ngh mng khng dy ra i l mt bc tin mnh m trong lnh vc cng ngh thng tin, em li s thun tin cng nh hiu qu cng vic, gim thiu chi ph lp t v s qun l d dng. T khi ra i n nay cc nh sn xut khng ngng nghin cu ci tin thit b v gi thnh thit b ngy mt h, chnh iu lm mng khng dy c trin khai

Page 9

Tm hiu mng WLAN v cc phng thc bo mt

rng ri trn cc lnh vc i sng t bnh vin, trng hc, sn bay, cc trung tm thng mi, cng ty Tuy nhin mt vn lm au u cc nh sn xut, cc nh nghin cu v c ngi s dng l s bo mt, v mng khng dy lm vic trong mi trng truyn sng nn kh nng d liu b r r l rt cao. T khi ra i n nay cc nh sn xut khng ngng ci tin, tng cng cc bin php bo mt nhm em n s an ton tuyt i cho ngi s dng nhng vi s pht trin khng ngng ca lnh vc cng ngh thng tin cc hacker c th xm nhp vo mng khng dy mt cch nhanh chng. Chnh v th ti tp trung vo nghin cu cc l hng, cc li gp phi trong cc giao thc truyn d liu ca mng khng dy, t a cc bin php gii quyt gim s tn cng ca cc hacker v hng dn n s an ton tuyt i.

Chng 1: CC VN C BN TRONG MNG WLAN

Page 10

Tm hiu mng WLAN v cc phng thc bo mt

Mng WLAN l mt h thng thng tin lin lc d liu linh hot c thc hin nh phn m rng, hoc thay th cho mng LAN hu tuyn trong nh hoc trong cc c quan. Mng WLAN truyn v nhn d liu qua khong khng, ti gin nhu cu cho cc kt ni hu tuyn. Nh vy, mng WLAN kt ni d liu vi ngi dng lu ng, v thng qua cu hnh c n gin ha, cho php mng LAN di ng. Cc nm qua, mng WLAN c ph bin mnh m trong nhiu lnh vc, t lnh vc chm sc sc khe, bn l, sn xut, lu kho, n cc trng i hc. Ngnh cng nghip ny kim li t vic s dng cc thit b u cui v cc my tnh notebook truyn thng tin thi gian thc n cc trung tm tp trung x l. Ngy nay, mng WLAN ang c n nhn rng ri nh mt kt ni a nng t cc doanh nghip. Li tc ca th trng mng WLAN ngy cng tng. 1.1. Khi nim mng cc b khng dy( WLAN ): 1.1.1. Khi nim WLAN: Wireless Local Area Network Wlan l mt loi mng my tnh cho php cc thit b kt ni vi nhau thng qua mt giao thc chun m khng cn n cc kt ni vt l ( dy cable). Cc thnh phn trong mng s dng sng in t truyn thng vi nhau. Chun s dng trong Wlan l 802.11. 1.1.2. Lch s ra i: Cng ngh WLAN ln u tin xut hin vo cui nm 1990, khi nhng nh sn xut gii thiu nhng sn phm hot ng trong bng tn 900Mhz. Nhng gii php ny (khng c thng nht gia cc nh sn xut) cung cp tc truyn d liu 1Mbps, thp hn nhiu so vi tc 10Mbps ca hu ht cc mng s dng cp hin thi. Nm 1997, Institute of Electrical and Electronics Engineers(IEEE) ph chun s ra i ca chun 802.11, v cng c bit vi tn gi WIFI (Wireless Fidelity) cho cc mng WLAN. Chun 802.11 h tr ba phng php truyn tn hiu, trong c bao gm phng php truyn tn hiu v tuyn tn s 2.4Ghz. Mng WLAN khng dng cp kt ni, thay vo chng s dng sng radio tng t nh in thoi khng dy. u th ca mng WLAN l kh nng di ng v s t do tin li, ngi

Page 11

Tm hiu mng WLAN v cc phng thc bo mt

dng khng b hn ch v khng gian v v tr kt ni. Nhng u im ca mng WLAN bao gm : . Kh nng di ng v s t do - cho php kt ni t bt k u. . Khng b hn ch v khng gian v v tr kt ni. . D lp t v trin khai . Khng cn mua cp. . Tit kim thi gian lp t cp. . D dng m rng. 1.2. Cc ng dng ca mng WLAN: Mng WLAN l k thut thay th cho mng LAN hu tuyn, n cung cp mng cui cng vi khong cch kt ni ti thiu gia mt mng xng sng v mng trong nh hoc ngi dng di ng trong cc c quan. Sau y l cc ng dng ph bin ca WLAN thng qua sc mnh v tnh linh hot ca mng WLAN: Lab 1-1: ng nhp vao router giao din dong lnh

Lab 1-1: ng nhp vao router giao din dong lnh

Yu cu Bi thc hnh ny gip ngi c lam quen vi ch lnh (CLI-Command

Page 12

Tm hiu mng WLAN v cc phng thc bo mt

Line Interface) va mt s lnh c ban cua h iu hnh CiscoIOS. Hng dn 1. Ni cap am bao an toan thit bi trong khi thc hanh, cn phai tt hoan toan ngun in cac thit bi trong khi ni cap. Dung cap Console (cap Rolled) ni cng COM1 cua may PC (dung Terminal chuyn i t DB-9 sang RJ45) vi cng Console cua Router. Kim tra lai dy am bao a ni chc chn. 2. ng nhp vao router Khi ng Windows, vao HyperTerminal Start - Programs - Accessories - Communications - Hyper Terminal

- Name: - Icon: chon biu tng tuy thich.

Page 13

Tm hiu mng WLAN v cc phng thc bo mt

Connect using : COM1

Thit lp cu hinh nh trong hp thoai sau:

Page 14

Tm hiu mng WLAN v cc phng thc bo mt

Khi ng Router Bt ngun cho Router. Xem cac thng tin v Router c hin thi trn HYPER TERMINAL. System Bootstrap, Version 11.0(10c), SOFTWARE Version cua IOS ang lu trong ROM Copyright (c) 1986-1996 by cisco Systems 2500 processor with 14336 Kbytes of main memory Cho bit loai b x ly Router (2500) va dung lng b nh RAM Notice: NVRAM invalid, possibly due to write erase. F3: 4+573916 at 0x3000060 Restricted Rights Legend Use, duplication, or disclosure by the Government is subject to restrictions as set forth in subparagraph (c) of the Commercial Computer Software Restricted Rights clause at FAR sec. 52.227-19 and subparagraph (c) (1) (ii) of the Rights in Technical Data and Computer Software clause at DFARS sec. 252.227-7013. cisco Systems, Inc. 170 West Tasman Drive

Page 15

Tm hiu mng WLAN v cc phng thc bo mt

San Jose, California 95134-1706 Cisco Internetwork Operating System Software IOS (tm) 2500 Software (C2500-I-L), Version 12.1(3), RELEASE SOFTWARE (fc1) Version cua IOS ang lu trong flash Copyright (c) 1986-2000 by cisco Systems, Inc. Compiled Thu 06-Jul-00 07:33 by cmong Image text-base: 0x0303E710, data-base: 0x00001000 cisco 2509 (68030) processor (revision M) with 14336K/2048K bytes of memory. Processor board ID 07143970, with hardware revision 00000000 Bridging software. X.25 software, Version 3.0.0. 1 Ethernet/IEEE 802.3 interface(s) 2 Serial network interface(s) 8 terminal line(s) 32K bytes of non-volatile configuration memory. 8192K bytes of processor board System flash (Read ONLY) --- System Configuration Dialog --Would you like to enter the initial configuration dialog? [yes/no]: no Would you like to terminate autoinstall? [yes]: Press RETURN to get started! Nhn Enter tip tuc xut hin du nhc i lnh, luc nay ang user mode, vao priviledge mode, dung lnh enable Router>_ Router>enable Router#

Page 16

Tm hiu mng WLAN v cc phng thc bo mt

quay lai user mode bng lnh disable hoc lnh exit Router#disable Router> Dung lnh logout thoat ch dong lnh Router>logout Router con0 is now available Press RETURN to get started. Ban ang ch user mode, nhp ky t ? (chm hoi) xem cac lnh c dung trong ch nay: Router>? Exec commands: access-enable Create a temporary Access-List entry access-profile Apply user-profile to interface clear Reset functions connect Open a terminal connection disable Turn off privileged commands disconnect Disconnect an existing network connection enable Turn on privileged commands exit Exit from the EXEC help Description of the interactive help system lock Lock the terminal login Log in as a particular user logout Exit from the EXEC mrinfo Request neighbor and version information from a multicast router mstat Show statistics after multiple multicast traceroutes mtrace Trace reverse multicast path from destination to source name-connection Name an existing network connection pad Open a X.29 PAD connection ping Send echo messages ppp Start IETF Point-to-Point Protocol (PPP)

Page 17

Tm hiu mng WLAN v cc phng thc bo mt

resume Resume an active network connection --More-Nu s hang thng tin cn hin thi nhiu hn mt trang man hinh (25 hang), cui man hinh hin ch --More-- ban nhn phim ENTER xem hang k tip, hoc phim SPACE xem trang k tip. Nu bn nhn phm ENTER, thng tin s hin th thm tng hng. Nu bn dng SPACE BAR, thng tin s hin th theo trang mn hnh. Lnh giup (?) rt hu dung, ban co th dung trong bt ky ch nao, Router se a ra cac mc chn c phep s dung va y nghia cua lnh o. Vi du ban mun xem tip cac phn cua lnh show, ban go: Router>show ? Hoc ban khng nh tt c nhng lnh bt u bng cc k t te, ban co th go: Router>te? Telnet Terminal Khi , router s lit k tt c cc lnh bt u bng te. H iu hanh trong Router Cisco cho phep go tt. Ban chi cn go s ky t u phn bit cac cu lnh vi nhau la cu lnh c chp nhn, hoc ban nhn phim TAB hin y u cu lnh. Router>tel[TAB] Router>telnet Vao ch global-configuration-mode, dung lnh configuration terminal Router#configuration terminal Enter configuration commands, one per line. End with CNTL/Z. Mt s t hp phim tt: K thi CCNA i hi ngi hc phi s dng thnh tho t hp cc phm tt ny. Ngai ra, mt s chng trnh dng lm terminal c th khng h tr cc t hp phm ny.

Page 18

Tm hiu mng WLAN v cc phng thc bo mt

Ctrl-A Tr v u dong Ctrl-B Mui tn trai Tr v mt ky t Esc-B Tr v mt t Ctrl-E n cui dong Ctrl-F Mui tn phai Ti mt ky t Ctrl-P Mui tn ln n cu lnh a thc hin trc o Ctrl-N Mui tn xung n cu lnh a thc hin sau cu lnh o 3. Xem thng tin v cu hnh cua router Tai ch privileged mode, ban hay thc hin cac lnh sau, va kim tra kt qua cua tng lnh: show version Xem tn files IOS, version cua IOS ang s dung, cu hinh phn cng cua Router, ch BOOT (thanh ghi) show flash: dir flash Xem file IOS ang lu trong flash dir nvram Xem cac file ang lu trong NVRAM show interface [interface]

Page 19

Tm hiu mng WLAN v cc phng thc bo mt

Xem cu hinh cua tt ca cac cng hay cua cng c chi inh show running-config Xem cu hinh chung ang s dung show startup-config show configuration Xem cu hinh chung dung cho khi ng (lu trong NVRAM) show clock Xem ng h show user Xem cac kt ni ang truy cp vao Router show line Xem tt ca cac kt ni (line) cua Router show ip route Xem bang chon ng cua Router show arp Xem bang tng ng (map) t ia chi MAC va ia chi IP show host Xem tn va ia chi cua cac host a bit (a c t tn) Xoa cu hinh c router dng luc khi ng: dung lnh erase startupconfig. Khi a thc hin lnh nay, nu xem lai cu hinh khi ng, ban se nhn thng bao li Router#erase startup-config Erasing the nvram filesystem will remove all files! Continue? [confirm] [OK] Erase of nvram: complete Router#sh start %% Non-volatile configuration memory is not present Router# 4. S dung HYPER TERMINAL S dung trnh tic ch truyn file cua HYPER TERMINAL co th cu hinh nhanh mt Router, ban co th soan thao trc cac cu lnh bng NotePad theo ung trinh t, lu di dang file text, sau o dung Send Text File... (Transfer -> Send Text File...) truyn File:

Page 20

Tm hiu mng WLAN v cc phng thc bo mt

Vi du: ban soan thao file SHOW.TXT nh sau: show version show flash: show running-config show startup-config configuration terminal exit Cach truyn file chi hu dung vi cac lnh cu hinh khng co cac thng s xac nhn (mt dong la cu lnh hoan chinh), khng thc hin c cho cac cu lnh co thng s la chon. Chng han: khng nn dung cho lnh enable (vi co th phai xac nhn mt khu), khng th dung cho lnh lu cu hinh vao NVRAM vi co xac nhn tn file: Router#copy running-config startup-config Destination filename [startup-config]? Building configuration... [OK] Chinh thi gian tr dong lnh co th theo doi kip cac thng bao, ban cai thi gian tr khi truyn tng dong khoang 2000ms - 4000ms (Chon File Properties ASCII Setup ...) Capture thao tac Trong qua trinh lam Lab, ban mun ghi lai cac thao tac, cac thng tin cua Router khi thc hanh, ban s dung Capture cua Hyper -Terminal (Transfer Capture Text ... ) Ban hay nhp tn file vi ng dn y u. Bt u t luc nay, tt ca cac thao tac cua ban va kt qua u c ghi lai. Khi thc hin xong, nh Stop Capture (Transfer -> Capture Text -> Stop) lu file va s dung WordPad xem lai.

Page 21

Tm hiu mng WLAN v cc phng thc bo mt

- Trong cc bnh vin, cc bc s v cc h l trao i thng tin v bnh nhn mt cch tc thi, hiu qu hn nh cc my tnh notebook s dng cng ngh mng WLAN. - Cc i kim ton t vn hoc k ton hoc cc nhm lm vic nh tng nng sut vi kh nng ci t mng nhanh. - Nh qun l mng trong cc mi trng nng ng ti thiu ha tng ph i li, b sung, v thay i vi mng WLAN, do gim bt gi thnh s hu mng LAN. - Cc c s o to ca cc cng ty v cc sinh vin cc trng i hc s dng kt ni khng dy d dng truy cp thng tin, trao i thng tin, v nghin cu. - Cc nh qun l mng nhn thy rng mng WLAN l gii php c s h tng mng li nht lp t cc my tnh ni mng trong cc ta nh c. - Nh qun l ca cc ca hng bn l s dng mng khng dy n gin ha vic ti nh cu hnh mng thng xuyn. - Cc nhn vin vn phng chi nhnh v trin lm thng mi ti gin cc yu cu ci t bng cch thit t mng WLAN c nh cu hnh trc khng cn cc nh qun l mng a phng h tr. - Cc cng nhn ti kho hng s dng mng WLAN trao i thng tin n c s d liu trung tm v tng thm nng sut ca h. - Cc nh qun l mng thc hin mng WLAN cung cp d phng cho cc ng dng trng yu ang hot ng trn cc mng ni dy. - Cc i l dch v cho thu xe v cc nhn vin nh hng cung cp dch v nhanh hn ti khch hng trong thi gian thc. - Cc cn b cp cao trong cc phng hi ngh cho cc quyt nh nhanh hn v h s dng thng tin thi gian thc ngay ti bn hi ngh. 1.3. Cc vn ca mng khng dy, tng quan i vi mng c dy: Khi xy dng mt mng my tnh, a ra gii php k thut v thit b ph hp, ngi ta phi da trn vic phn tch kh nng p ng yu cu theo cc tiu ch ra. thy c nhng vn ca mng khng dy cng nh tng quan nhng vn so vi

Page 22

Tm hiu mng WLAN v cc phng thc bo mt

mng c dy, ti xin a ra mt s tiu ch c bn v so snh gii php ca mng c dy v mng khng dy. Phm vi ng dng Mng c dy Mng khng dy - C th ng dng trong tt c cc m hnh - Ch yu l trong m hnh mng nh v mng nh, trung bnh, ln, rt ln trung bnh, vi nhng m hnh ln phi kt hp vi mng c dy - Gp kh khn nhng ni xa xi, a hnh - C th trin khai nhng ni khng thun phc tp, nhng ni khng n nh, kh ko tin v a hnh, khng n nh, khng trin dy, ng truyn phc tp k thut khai mng c dy c

Mng c dy Mng khng dy - phc tp k thut ty thuc tng loi - phc tp k thut ty thuc tng loi mng c th mng c th - Xu hng to kh nng thit lp cc thng s truyn sng v tuyn ca thit b ngy cng n gin hn tin cy Mng c dy Mng khng dy - Kh nng chu nh hng khch quan bn - B nh hng bi cc yu t bn ngoi nh ngoi nh thi tit, kh hu tt mi trng truyn sng, can nhiu do thi tit - Chu nhiu cuc tn cng a dng, phc - Chu nhiu cuc tn cng a dng, phc tp, nguy him ca nhng k ph hoi v tp, nguy him ca nhng k ph hoi v tnh v c tnh - t nguy c nh hng sc khe Lp t, trin khai Mng c dy Mng khng dy - Lp t, trin khai tn nhiu thi gian v - Lp t, trin khai d dng, n gin, tnh v c tnh, nguy c cao hn mng c dy - Cn ang tip tc phn tch v kh nng nh hng n sc khe

Page 23

Tm hiu mng WLAN v cc phng thc bo mt

chi ph Tnh linh hot, kh nng thay i, pht trin

nhanh chng

Mng c dy Mng khng dy - V l h thng kt ni c nh nn tnh linh - V l h thng kt ni di ng nn rt linh hot km, kh thay i, nng cp, pht trin Gi c hot, d dng thay i, nng cp, pht trin

Mng c dy Mng khng dy - Gi c ty thuc vo tng m hnh mng - Thng th gi thnh thit b cao hn so c th vi ca mng c dy. Nhng xu hng hin nay l cng ngy cng gim s chnh lch v gi

Chng 2: CC M HNH V THIT B DNG TRONG MNG WLAN 2.1. Chun 802.11: 802.11 l mt trong cc chun ca h IEEE 802.x bao gm h cc giao thc truyn tin qua mng khng dy. Chun 802.11 c chia lm hai nhm: nhm lp vt l PHY v nhm lp lin kt d liu MAC. 2.1.1. Nhm lp vt l PHY: - Chun 802.11b: 802.11b l chun p ng cho phn ln cc ng dng ca mng. Vi mt gii php rt hon thin, 802.11b c nhiu c im thun li so vi cc chun khng dy khc. ChunPage 24

Tm hiu mng WLAN v cc phng thc bo mt

802.11b s dng kiu tri ph trc tip DSSS, hot ng di tn 2,4 GHz, tc truyn d liu ti a l 11 Mbps trn mt knh, tc thc t l khong t 4-5 Mbps. Khong cch c th ln n 500 mt trong mi trng m rng. Khi dng chun ny ti a c 32 ngi dng / im truy cp. u im ca 802.11b gi thnh thp nht; phm vi tn hiu tt v khng d b cn tr. Nhc im ca 802.11b tc ti a thp nht; cc ng dng gia nh c th xuyn nhiu( v tn s 2.4GHz, trng vi tn s ca cc thit b trong gia nh nh l viba, in thoi bn khng dy) - Chun 802.11a: Trong khi 802.11b vn ang c pht trin, IEEE to mt m rng th cp cho chun 802.11 c tn gi 802.11a. V 802.11b c s dng rng ri qu nhanh so vi 802.11a, nn mt s ngi cho rng 802.11a c to sau 802.11b. Tuy nhin trong thc t, 802.11a v 802.11b c to mt cch ng thi. Do gi thnh cao hn nn 802.11a ch c s dng trong cc mng doanh nghip cn 802.11b thch hp hn vi th trng mng gia nh. 802.11a h tr bng thng ln n 54 Mbps v s dng tn s v tuyn 5GHz. Tn s ca 802.11a cao hn so vi 802.11b chnh v vy lm cho phm vi ca h thng ny hp hn so vi cc mng 802.11b. Vi tn s ny, cc tn hiu 802.11a cng kh xuyn qua cc vch tng v cc vt cn khc hn. Do 802.11a v 802.11b s dng cc tn s khc nhau, nn hai cng ngh ny khng th tng thch vi nhau. Chnh v vy mt s hng cung cp cc thit b mng hybrid cho 802.11a/b nhng cc sn phm ny ch n thun l b sung thm hai chun ny.

u im ca 802.11a tc cao; tn s 5Ghz trnh c s xuyn nhiu t cc thit b khc. Nhc im ca 802.11a gi thnh t; phm vi hp v d b che khut. 802.11g thc hin s kt hp tt nht gia 802.11a v 802.11b. N h tr bng thng

- Chun 802.11g: ln n 54Mbps v s dng tn s 2.4 Ghz c phm vi rng. 802.11g c kh nng tng

Page 25

Tm hiu mng WLAN v cc phng thc bo mt

thch vi cc chun 802.11b, iu c ngha l cc im truy cp 802.11g s lm vic vi cc adapter mng khng dy 802.11b v ngc li.

u im ca 802.11g tc cao; phm vi tn hiu tt v t b che khut. Nhc im ca 802.11g gi thnh t hn 802.11b; cc thit b c th b xuyn nhiu t nhiu thit b khc s dng cng bng tn.

- Chun 802.11n: Chun mi nht trong danh mc Wi-Fi chnh l 802.11n. y l chun c thit k ci thin cho 802.11g trong tng s bng thng c h tr bng cch tn dng nhiu tn hiu khng dy v cc anten (cng ngh MIMO). Khi chun ny c a ra, cc kt ni 802.11n s h tr tc d liu ln n 100 Mbps. 802.11n cng cung cp phm vi bao ph tt hn so vi cc chun Wi-Fi trc n nh cng tn hiu mnh ca n. Thit b 802.11n s tng thch vi cc thit b 802.11g.

u im ca 802.11n tc nhanh v phm vi tn hiu tt nht; kh nng chu ng tt hn t vic xuyn nhiu t cc ngun bn ngoi. Nhc im ca 802.11n gi thnh t hn 802.11g; s dng nhiu tn hiu c th gy nhiu vi cc mng 802.11b/g gn.

2.1.2. Nhm lp lin kt d liu MAC: - Chun 802.11d: Chun 802.11d b xung mt s tnh nng i vi lp MAC nhm ph bin WLAN trn ton th gii. Mt s nc trn th gii c quy nh rt cht ch v tn s v mc nng lng pht sng v vy 802.11d ra i nhm p ng nhu cu . Tuy nhin, chun 802.11d vn ang trong qu trnh pht trin v cha c chp nhn rng ri nh l chun ca th gii. - Chun 802.11e: y l chun c p dng cho c 802.11 a,b,g. Mc tiu ca chun ny nhm cung cp cc chc nng v cht lng dch v - QoS cho WLAN. V mt k thut, 802.11e cng b xung mt s tnh nng cho lp con MAC. Nh tnh nng ny, WLAN 802.11 trong mt tng li khng xa c th cung cp y cc dch v nh voice, video, cc dch v i hi QoS rt cao. Chun 802.11e hin nay vn ang trong qua trnh pht trin v cha chnh thc p dng trn ton th gii.

Page 26

Tm hiu mng WLAN v cc phng thc bo mt

- Chun 802.11f: y l mt b ti liu khuyn ngh ca cc nh sn xut cc Access Point ca cc nh sn xut khc nhau c th lm vic vi nhau. iu ny l rt quan trng khi quy m mng li t n mc ng k. Khi mi p ng c vic kt ni mng khng dy lin c quan, lin x nghip c nhiu kh nng khng dng cng mt chng loi thit b. - Chun 802.11h: Tiu chun ny b xung mt s tnh nng cho lp con MAC nhm p ng cc quy nh chu u di tn 5GHz. Chu u quy nh rng cc sn phm dng di tn 5 GHz phi c tnh nng kim sot mc nng lng truyn dn TPC - Transmission Power Control v kh nng t ng la chn tn s DFS - Dynamic Frequency Selection. La chn tn s Access Point gip lm gim n mc ti thiu can nhiu n cc h thng radar c bit khc. - Chun 802.11i: y l chun b xung cho 802.11 a, b, g nhm ci thin v mt an ninh cho mng khng dy. An ninh cho mng khng dy l mt giao thc c tn l WEP, 802.11i cung cp nhng phng thc m ha v nhng th tc xc nhn, chng thc mi c tn l 802.1x. Chun ny vn ang trong giai on pht trin. 2.2. Mt s c ch s dng khi trao i thng tin trong mng khng dy: 2.2.1. C ch CSMA-CA: Nguyn tc c bn khi truy cp ca chun 802.11 l s dng c ch CSMA-CA vit tt ca Carrier Sense Multiple Access Collision Avoidance a truy cp s dng sng mang phng trnh xung t. Nguyn tc ny gn ging nh nguyn tc CSMA-CD (Carrier Sense Multiple Access Collision Detect) ca chun 802.3 (cho Ethernet). im khc y l CSMA-CA n s ch truyn d liu khi bn kia sn sng nhn v khng truyn, nhn d liu no khc trong lc , y cn gi l nguyn tc LBT listening before talking nghe trc khi ni. Trc khi gi tin c truyn i, thit b khng dy s kim tra xem c cc thit b no khc ang truyn tin khng, nu ang truyn, n s i n khi no cc thit b kia truyn

Page 27

Tm hiu mng WLAN v cc phng thc bo mt

xong th n mi truyn. kim tra vic cc thit b kia truyn xong cha, trong khi i n s hi thm d u n sau cc khong thi gian nht nh. 2.2.2. C ch RTS/CTS: gim thiu nguy xung t do cc thit b cng truyn trong cng thi im, ngi ta s dng c ch RTS/CTS Request To Send/ Clear To Send. V d nu AP mun truyn d liu n STA, n s gi 1 khung RTS n STA, STA nhn c tin v gi li khung CTS, thng bo sn sng nhn d liu t AP, ng thi khng thc hin truyn d liu vi cc thit b khc cho n khi AP truyn xong cho STA. Lc cc thit b khc nhn c thng bo cng s tm ngng vic truyn thng tin n STA. C ch RTS/CTS m bo tnh sn sng gia 2 im truyn d liu v ngn chn nguy c xung t khi truyn d liu. 2.2.3. C ch ACK: ACK Acknowledging l c ch thng bo li kt qu truyn d liu. Khi bn nhn nhn c d liu, n s gi thng bo ACK n bn gi bo l nhn c bn tin ri. Trong tnh hung khi bn gi khng nhn c ACK n s coi l bn nhn cha nhn c bn tin v n s gi li bn tin . C ch ny nhm gim bt nguy c b mt d liu trong khi truyn gia 2 im. 2.3. Phn bit WLAN v LAN: WLANs cng l mt chun trong h thng 802. Tuy nhin vic truyn d liu trong WLAN s dng sng Radio. Trong mng LAN, d liu c truyn trong dy dn. Tuy nhin i vi ngi dng cui th giao din s dng chng l tng t nhau. C WLAN v Wire LAN u c nh ngha da trn hai tng Physical v Data Link (trong m hnh OSI). Cc giao thc hay cc ng dng u c th s dng trn nn tng LAN v WLAN. V d nh IP, IP Security (IPSec). Hay cc ng dng nh Web, FTP, Mail S khc nhau gia WLAN v LAN: - WLAN s dng sng radio truyn d liu ti tng Physcial. + WLAN s dng CSMA/CA (Carrier Sense Multiple Access with Collision Avoidance) cn LAN s dng cng ngh CSMA/CD (Carrier Sense Multiple Access with Collision Detect). Collision Dectect khng th s dng trong mng WLAN bi thng tin truyn i khng th

Page 28

Tm hiu mng WLAN v cc phng thc bo mt

ly li c do chng khng th c tnh nng Collision Detect c. m bo gi tin truyn khng b xung t mng WLAN s dng cng ngh CSMA/CA. Trc khi truyn gi tn hiu Request To Send (RTS) v Clear To Send (CTS) hn ch xung t xy ra. + WLAN s dng nh dng cho Frame d liu khc vi mng LAN. WLAN bt buc phi thm thng tin Layer 2 Header vo gi tin. - S dng Radio vo vic truyn thng tin s chu mt s vn m khi s dng dy dn khng mc phi: + Vic kt ni s chu nh hng bi khong cch, do phn x sng nn i khi ngun pht tn hiu c th b thay i v c nhiu tn hiu n trc n sau, mt card mng WLAN c th kt ni ti nhiu mng WLAN khc nhau. + Do sng Radio c th tm thy nn vic kt ni v bo mt trn Wireless LAN cng l vn khng nh. - WLAN s dng cho ngi dng thng xuyn phi di chuyn trong cng ty. - WLAN s dng mt gii tn sng Radio nn c th b nhiu nu mt sng Radio khc c cng tn s. Tng t nh c ch truy cp ng truyn CSMA/CD ca mng c dy (IEEE 802.3), Trong mng IEEE 802.11 s dng c ch CSMA/CA. CA c ngha l Collition Avoidance khc vi CD l Collition Detection trong mng c dy. Ni nh vy khng c ngha l CSMA/CD khng c c ch pht hin Collition nh trong mng c dy bi v c th ca thit b khng dy l haft-duplex (Mt khi n ang nhn th khng th truyn v nu ang truyn th khng th nhn). Trong CSMA/CA c 2 khi nim l CSMA/CA v CSMA/CA based on MACA CSMA/CA: my pht s lng nghe trn mi trng truyn, v khi mi trng truyn ri th n s tin hnh gi d liu ra mi trng truyn, cn khng n s s dng gii thut backoff tip tc ch. C ch ny b gii hn bi trng hp hidden node. Gi s, c 3 my A,B,C my B nm trong range ca A v range ca C. Khi A gi cho B th C khng nhn c tn hiu trn mi trng truyn, v nu C cng gi cho B th xy ra Collition.CSMA/CA based on MACA xut hin gii quyt node bng cch trc khi mt my truyn d liu th n s lng nghe ng truyn, v nu ng truyn ri th n s gi frame RTS (request to send), trong trng hp ny, my nhn s p li bng frame CTS (Clear to send), nhng my cn li nu nhn c 1 trong 2 frame trn th s t ng to ra NAV

Page 29

Tm hiu mng WLAN v cc phng thc bo mt

(Network allocation vector) ngn cn vic truyn d liu. C ch CSMA/CA cn c gi chung l DCF (Distribute Coordination Function) l tiu ch bt buc ca chun 802.11, cn c 1 c ch khc t thng dng hn l PCF (Point Coordination Function), hin nay c rt t thit b h tr c ch ny (Ch p dng cho m hnh infrastructure). PCF lm vic tng t nh c ch truy cp ng truyn ca mng Tokenring. Theo c ch ny, PC ( Point Controller) tch hp trong Access Point lm nhim v polling cho cc station theo 1 schedule v ch c station no c poll th mi c php truyn. C ch ny thch hp cho cc ng dng i hi tnh thi gian thc cao bi v n s lm cho cc station tham gia vo mng u c c hi s dng mi trng truyn nh nhau. 2.4. M hnh mng WLAN: 2.4.1. M hnh Ad-hoc: tng ca mng Ad-hoc (theo ting Anh c ngha l "v mc ch") l xy dng 1 mng kt ni gia cc thit b u cui m khng cn phi dng cc trm thu pht gc (BS). Cc thit b u cui s t ng bt lin lc vi nhau hnh thnh nn 1 mng kt ni tm thi dng cho mc ch truyn tin gia cc nt mng. Ad-hoc u tin c pht trin cho mc ch qun s, nhng do u im v gi thnh v s linh ng, ngy nay, mi ngi u c th c s dng n.

Page 30

Tm hiu mng WLAN v cc phng thc bo mt

V cc mng ad-hoc ny c th thc hin nhanh v d dng nn chng thng c thit lp m khng cn mt cng c hay k nng c bit no v vy n rt thch hp s dng trong cc hi ngh thng mi hoc trong cc nhm lm vic tm thi. Tuy nhin chng c th c nhng nhc im v vng ph sng b gii hn, mi ngi s dng u phi nghe c ln nhau.

-Sau y l m hnh Ad-hoc kt hp cung cp dch v chia s Internet:

Page 31

Tm hiu mng WLAN v cc phng thc bo mt

-Thit lp cu hnh my trong m hnh Ad-hoc: t cu hnh cho my ch:

- u tin bn hy b ht nhng im truy cp khng dy (WAP) m my tnh ca bn ang lin kt m bo n ch lm vic duy nht vi mng Ad-hoc m chng ta ang thit lp. - Tip theo, kch vo tab "Advanced", chn "Computer to computer (ad hoc) networks only" v xa la chn "Automatically connect to non-preferred networks" - Kch li vo tab "Wireless Networks". Di phn "Preferred Networks", kch "Add". Trong phn hp thoi "Wireless Network Properties", t tn mng Adhoc ca mnh vo "Network name (SSID)". Nh nh du chn "computer-to-computer network".

Page 32

Tm hiu mng WLAN v cc phng thc bo mt

- Thit lp "Wireless Equivalency Protocol (WEP)" cha cn phi lm ngay bc ny v ta nn lp mng Ad-hoc chy trn tru trc khi m ha d liu. Sau ny, quyt nh c dng m ha d liu hay khng ph thuc vo mi trng. Trong a s trng hp, nn dng tnh nng ny.

Page 33

Tm hiu mng WLAN v cc phng thc bo mt

- n du x bn cnh tn mng. Khi c 1 my khc trong vng ph sng v lin kt vi my ch ny, du x s mt i. t cu hnh cho my khch:

- Khi nm trong phm vi ph sng ca my ch, trn my khch s xut hin tn ca mng Ad-hoc m my ch va to ra. Chn tn ny, kch "Configure". V cha thit lp WEP nn kch tip vo "OK". Chia s kt ni Sau khi thit lp c 1 kt ni gia my ch v my khch, ta s thit lp cu hnh chia s kt ni Internet. - M "Network Connections" trn my ch, (chn Start>Control Panel>Switch to classic view>Network Connections). - Chn kt ni internet chia s, chn "Allow other network users to connect through this computer's Internet connection" trong tab "Advanced". - Nu cha c firewall, bn nn thit lp "Internet Connection Firewall (ICF)" ti bc ny. - C th ty chn cho nhng ngi dng khc kim sat hay thay i kt ni ny. Sau khi kt thc vic thit lp cu hnh cho ICS, ca s "Network Connection" s xut hin trn my ch vi trng thi "shared" v "Enable". Trn ca s "Network Connection" ca my khch, kt ni ny s hin th l "Internet Gateway".

Page 34

Tm hiu mng WLAN v cc phng thc bo mt

- My khch s nhn c 1 a ch ip ni b dng 192.168.0.* t DHCP ca my ch v c thng ra Internet. t cu hnh cho WEP: Sau khi thit lp thnh cng mng Ad-hoc, tr li "Network Properties" thit lp cho WEP. - Trn my ch, m "Wireless Network Properties", chn "Data encryption (WEP enabled)".

Nh vy bn hon tt qu trnh thit lp v chia s kt ni internet bng chc nng thit lp mng Ad-hoc ca Windows XP. 2.4.2. M hnh kiu c s h tng( Infrastruture): y la kiu kt ni cac may client thng qua Access Point

Page 35

Tm hiu mng WLAN v cc phng thc bo mt

Trong mng WLAN c s h tng, nhiu im truy cp lin kt mng WLAN vi mng ni dy v cho php cc ngi dng chia s cc ti nguyn mng mt cch hiu qu. Cc im truy cp khng cc cung cp cc truyn thng vi mng ni dy m cn chuyn tip lu thng mng khng dy trong khu ln cn mt cch tc thi. Nhiu im truy cp cung cp phm vi khng dy cho ton b ta nh hoc khu vc c quan.

2.5. Cc thit b h tng trong mng: Mt mng wireless gm cc thnh phn sau : - Antenna - Wireless Access Point - Wireless End-user device (Wireless Adapter Card) 2.5.1. Antenna: Antenna chnh l thit b thu pht sng in t, kch thc vt l ca anten (chng hn nh chiu di ca anten) lin quan trc tip n tn s hot ng ca anten. Omni-directional Antenna: Anten omni-directional c th truyn tn hiu n n mi hng, rt thch hp dng lm anten khch i tn hiu trong kiu point-to-multi-point (im n nhiu im).

Page 36

Tm hiu mng WLAN v cc phng thc bo mt

Mt vi kiu Omni-directional thng dng

M hnh pht sng ca Omni-derectional

ng dng ca Omni-directional trong kiu truyn point-to-multi-point Parabolic Antenna, Dish Antenna: Anten parabolic thng dng trong kiu kt ni point-to-point (kt ni im n im).

Page 37

Tm hiu mng WLAN v cc phng thc bo mt

Anten parabol v Anten Dish

M hnh truyn sng ca anten parabol v anten dish

ng dng ca Parabol trong kiu truyn point-to-point Yagi Antenna: Yagi Antenna c kh nng khch i sng cao.

Page 38

Tm hiu mng WLAN v cc phng thc bo mt

Anten Yagi Highly-directional Parabolic Dish Antenna:

M hnh truyn sng ca anten Yagi

Kt hp c u im ca Parabol v Yagi dng truyn sng trong khon cch rt xa .

Vi kiu Highly-directional Parabolic dish Antenna

M hnh truyn sng ca Highly-directional Parabolic dish Antenna 2.5.2. Wireless Access Point: L 1 thit b ngoi vi dng song thu phat tn hiu, truyn ti thng tin gia cc thit bi wireless va mang dung dy.Trn thi trng ph bin la cac AP chun B(11 Mb/s) ,va G(54Mb/s), AP cung cp cho client mt im truy cp vo mng.

Page 39

Tm hiu mng WLAN v cc phng thc bo mt

Access Point c 3 ch c bn : - Root Mode hay AP Mode - Repeater Mode - Bridge Mode Root Mode: La kiu thng dung nht, khi Access Point kt ni trc tip vi mang dy thng thng thi o la Root mode. Trong ch root mode, AP kt ni ngang hang vi cac oan mang dy khac va co th truyn tai thng tin nh trong mt mang dung dy binh thng. Root mode c s dng khi AP c kt ni vi mng backbone c dy thng qua giao din c dy (thng l Ethernet) ca n. Hu ht cc AP s h tr cc mode khc ngoi root mode, tuy nhin root mode l cu hnh mc nh. Khi mt AP c kt ni vi phn on c dy thng qua cng ethernet ca n, n s c cu hnh hot ng trong root mode. Khi trong root mode, cc AP c kt ni vi cng mt h thng phn phi c dy c th ni chuyn c vi nhau thng qua phn on c dy. AP giao tip vi nhau thc hin cc chc nng ca roaming nh reassociation. Cc client khng dy c th giao tip vi cc client khng dy khc nm trong nhng cell ( t bo, hay vng ph sng ca AP) khc nhau thng qua AP tng ng m

Page 40

Tm hiu mng WLAN v cc phng thc bo mt

chng kt ni vo, sau cc AP ny s giao tip vi nhau thng qua phn on c dy nh v d trong hnh di

Repeater Mode: Access Point trong ch repeater kt ni vi client nh 1 AP va kt ni nh 1 client vi AP server. Ch Repeater thng c s dung m rng vung phu song. Trong Repeater mode, AP c kh nng cung cp mt ng kt ni khng dy upstream vo mng c dy thay v mt kt ni c dy bnh thng. Nh bn thy trong hnh di, mt AP hot ng nh l mt root AP v AP cn li hot ng nh l mt Repeater khng dy. AP trong repeater mode kt ni vi cc client nh l mt AP v kt ni vi upstream AP nh l mt client. Vic s dng AP trong Repeater mode l hon ton khng nn tr khi cc k cn thit bi v cc cell xung quanh mi AP trong trng hp ny phi chng ln nhau t nht l 50%. Cu hnh ny s gim trm trng phm vi m mt client c th kt ni n repeater AP. Thm vo , Repeater AP giao tip c vi client v vi upstream AP thng qua kt ni khng dy, iu ny s lm gim throughput trn on mng khng dy. Ngi s dng c kt ni vi mt Repeater

Page 41

Tm hiu mng WLAN v cc phng thc bo mt

AP s cm nhn c throughput thp v tr cao. Thng thng th bn nn disable cng Ethernet khi hot ng trong repeater mode.M hinh di y se din ta ch Repeater

Bridge Mode: Ch Bridge mode thng c s dung khi mun kt ni 2 oan mang c lp vi nhau. Trong Bride mode, AP hot ng hon ton ging vi mt Bridge khng dy. Tht vy, AP s tr thnh mt Bridge khng dy khi c cu hnh theo cch ny. Ch mt s t cc AP trn th trng c h tr chc nng Bridge, iu ny s lm cho thit b c gi cao hn ng k. Bn c th thy t hnh di rng Client khng kt ni vi Bridge, nhng thay vo , Bridge c s dng kt ni 2 hoc nhiu on mng c dy li vi nhau bng kt ni khng dy.

Page 42

Tm hiu mng WLAN v cc phng thc bo mt

Advanced Filtering Capability (Kh nng lc cao cp): Cc chc nng lc MAC hay protocol c th c bao gm trong AP. Lc thng c s dng ngn chn k xm nhp vo mng WLAN ca bn. Nh l mt phng thc bo mt c bn, mt AP c th c cu hnh lc nhng thit b khng nm trong danh sch lc a ch MAC ca AP. Vic lc protocol cho php admin quyt nh v iu khin giao thc no nn c s dng trong mng WLAN. V d, nu Admin ch mun cho php truy cp http trong mng WLAN ngi dng c th lt web v truy cp mail dng web (yahoo), th vic cu hnh lc giao thc http s ngn chn tt c cc loi giao thc khc (iu ny gip gim thiu nguy c b tn cng). Cu hnh v qun l Access Point: Cc phng php c s dng cu hnh v qun l AP s khc nhau ty nh sn xut. Hu ht h u cung cp t nht l console, telnet, USB, hay giao din web. Mt s AP cn c phn mm cu hnh v qun l ring Cc chc nng trn AP l khc nhau. Tuy nhin AP c cng nhiu tnh nng th gi ca n cng cao. V d, mt s AP SOHO s c WEP, MAC filter v thm ch l Web server. Nu cc tnh nng nh xem bng association, h tr 802.1x/EAP, VPN, Routing, Inter AP Protocol, RADIUS th gi s gp nhiu ln so vi AP thng thng. Small Office, Home Office (SOHO) + Mac filter + WEP (64 hay 128 bit) + Giao din cu hnh USB hay console + Giao din cu hnh Web n gin + Cc phn mm cu hnh n gin Enterprise + Phn mm cu hnh cao cp + Giao din cu hnh web cao cp + Telnet + SNMP

Page 43

Tm hiu mng WLAN v cc phng thc bo mt

+ 802.1x/EAP + RADIUS client + VPN client v server + Routing (dynamic hoc static) + Chc nng Repeater + Chc nng Bridge 2.5.3. End-user wireless devices: c hiu nh nhng thanh phn ma AP coi la client trong mang Wireless. Gm co: - PCMCIA va Compact flash Cards - Ethernet va Serial Convertes - USB Adapter - PCI va ISA Adapter

CardwirelessPCMCIA - Dng cho Laptop - WI-FI Security WEP, WAP, 802.11x INTEL Wireless Centrino Certified - Tnh nng c bn : Hot ng ti di tn s 2.4Ghz vi tc truyn d liu c th t 54Mbps

Page 44

Tm hiu mng WLAN v cc phng thc bo mt

2.6. C ly truyn sng, tc truyn d liu: Truyn sng in t trong khng gian s gp hin tng suy hao. V th i vi kt ni khng dy ni chung, khong cch cng xa th kh nng thu tn hiu cng km, t l li s tng ln, dn n tc truyn d liu s phi gim xung. Cc tc ca chun khng dy nh 11 Mbps hay 54 Mbps khng lin quan n tc kt ni hay tc download, v nhng tc ny c quyt nh bi nh cung cp dch v Internet. Vi mt h thng mng khng dy, d liu c gi qua sng radio nn tc c th b nh hng bi cc tc nhn gy nhiu hoc cc vt th ln. Thit b nh tuyn khng dy s t ng iu chnh xung cc mc tc thp hn. (V d nh l t 11 Mbps s gim xung cn 5,5 Mbps v 2 Mbps hoc thm ch l 1 Mbps).

Page 45

Tm hiu mng WLAN v cc phng thc bo mt

Chng 3: L THUYT TRI PH c th qun l v troubleshoot mng WLAN mt cch hiu qu th kin thc v cc cng ngh tri ph l khng th thiu. 3.1. Gii thiu v tri ph: Tri ph l mt k thut truyn thng c c trng bi bng thng rng v cng sut thp. Tn hiu tri ph trng ging nh nhiu, kh pht hin v thm ch kh chn ng hay gii iu ch (demodulation) nu khng c cc thit b thch hp. Jamming v nhiu (interference) thng c nh hng vi truyn thng tri ph t hn so vi truyn thng bng hp. V nhng l do ny m tri ph c s dng trong qun s trong mt thi gian di. Mt tn hiu c gi l mt tn hiu tri ph khi bng thng ca n rng hn nhiu so vi mc cn thit truyn thng tin. Mt chng c thuyt phc chng li truyn thng bng hp (ngoi vic yu cu s dng cng sut nh cao) l tn hiu bng hp c th b jammed (tt nghn) hay interference (nhiu) rt d dng. Jamming l mt hnh ng c s dng cng sut rt ln truyn tn hiu khng mong mun vo cng dy tn s vi tn hiu mong mun. Bi v bng tn ca n l kh hp, nn cc tn hiu bng hp khc bao gm c nhiu c th hy hoi hon ton thng tin bng cch truyn tn hiu bng hp cng sut rt cao, cng ging nh

Page 46

Tm hiu mng WLAN v cc phng thc bo mt

hai ngi ang tr chuyn m c on tu chy ngang qua lm mt tn hiu m thanh gia hai ngi. 3.2. Cng ngh tri ph: Cng ngh tri ph cho php chng ta ly cng mt lng thng tin nh trong v d truyn bng hp trc v tri chng ra trn mt vng tn s ln hn nhiu. V d, chng ta c th s dng 1 MHz v 10 Watt i vi bng hp nhng 20 MHz v 100 mW i vi tri ph. Bng vic s dng ph tn s rng hn, chng ta s gim c kh nng d liu s b h hng hay jammed. Mt tn hiu bng hp c gng jamming tn hiu tri ph s ging nh l vic ngn chn mt phn nh thng tin nm trong dy tn s bng hp. Nn hu ht thng tin s c nhn m khng thy li. Trong khi bng tn tri ph l tng i rng, th cng sut nh ca tn hiu li rt thp. y chnh l yu cu th 2 i vi mt tn hiu c xem nh l tri ph. Mt tn hiu c xem l tri ph khi n c cng sut thp. Hai c im ny ca tri ph (s dng bng tn s rng v cng sut rt thp) lm cho bn nhn (receiver) nhn chng ging nh l mt tn hiu nhiu. Noise (nhiu) cng l tn hiu bng rng cng sut thp nhng s khc bit l nhiu thng l khng mong mun. Hn na, v b nhn tn hiu xem cc tn hiu tri ph nh l nhiu, nn cc receiver s khng c gng demodulate (gii iu ch) hay din gii n lm cho vic truyn thng c thm mt t s bo mt. 3.3. Cc loi tri ph c s dng: 3.3.1. Frequency Hopping Spread Spectrum (FHSS): Tri ph nhy tn (FHSS) l mt cng ngh s dng s nhanh nhn ca tn s tri d liu ra hn 83 MHz. S nhanh nhn ca tn s chnh l kh nng ca b pht tn s (Radio) c th thay i tn s truyn mt cch t ngt trong dy bng tn s c th s dng. Trong trng hp nhy tn i vi mng WLAN th dy tn s c th s dng c (trong bng tn 2.4 GHz ISM) l 83.5 MHz. - Nguyn l lm vic ca FHSS: Trong h thng nhy tn, sng mang s thay i tn s (hay nhy) ty thuc vo chui Pseudorandom. Chui Pseudorandom l mt danh sch ca nhiu tn s m sng mang c th nhy trong mt khong thi gian xc nh trc khi lp li danh sch ny. Transmitter s dng

Page 47

Tm hiu mng WLAN v cc phng thc bo mt

chui nhy ny chn tn s truyn cho n. Sng mang s vn mt mc tn s no trong mt khong thi gian xc nh (khong thi gian ny cn c gi l Dwell time) v sau s dng mt khong thi gian ngn nhy sang tn s tip theo (khong thi gian ngn ny c gi l Hop time). Khi danh sch tn s c nhy ht, transmitter s lp li t u danh sch ny. Hnh di minh ha mt h thng nhy tn s dng mt chui nhy gm 5 tn s qua dy tn s 5 MHz. Trong v d ny th chui nhy l 1. 2.449 GHz 2. 2.452 GHz 3. 2.448 GHz 4. 2.450 GHz

Page 48

Tm hiu mng WLAN v cc phng thc bo mt

5. 2.451 GHz

Sau khi radio truyn thng tin trn sng mang 2.451 GHz (tc l nhy n cui chui nhy) th radio s lp li chui nhy t u 2.449 GHz. Tin trnh lp li ny s cn tip tc cho n khi thng tin c nhn hon ton. Radio ca bn nhn s ng b ha chui nhy vi radio ca bn truyn c th nhn c thng tin trn nhng tn s thch hp vo nhng thi im thch hp. Tn hiu sau c demodulate v s dng bi my tnh nhn. - Tc dng ca nhy tn: Nhy tn l mt phng php truyn d liu trong h thng truyn v nhn nhy theo mt dng chp nhn c ca tn s. Cng ging nh cc cng ngh tri ph khc, h thng nhy tn l khng c (nhng khng min nhim) i vi nhiu bng hp. Trong v d ca chng ta

Page 49

Tm hiu mng WLAN v cc phng thc bo mt

trn, nu tn hiu b nhiu trn tn s 2.451 GHz th ch phn ca tn hiu tri ph s b mt, phn cn li ca tn hiu tri ph s vn c gi nguyn v d liu b mt s c truyn li (c th tn s khc). Trong thc t, nhiu tn hiu bng hp c th xut hin trong nhiu Megahertz ca bng thng. V bng nhy tn tri rng 83.5 MHz nn nhiu bng hp ch gy s gim cp nh i vi tn hiu tri ph. 3.3.2 Direct Sequence Spread Spectrum: DSSS rt ph bin v c s dng rng ri nht trong s cc cng ngh tri ph v n d dng ci t v c tc cao. Hu ht cc thit b WLAN trn th trng u s dng cng ngh tri ph DSSS (nhng s b thay th bng OFDM c tc cao hn). DSSS l mt phng php truyn d liu trong h thng truyn v h thng nhn u s dng mt tp cc tn s c rng 22 MHz. Cc knh rng ny cho php cc thit b truyn thng tin vi tc cao hn h thng FHSS nhiu. - Nguyn l lm vic ca DSSS: DSSS kt hp tn hiu d liu ti trm truyn vi mt chui bit d liu tc cao (qu trnh ny c gi l Chipping code hay Processing gain). Processing gain cao s lm tng tnh khng c ca tn hiu i vi nhiu. Processing gain ti thiu m FCC cho php l 10 v hu ht cc sn phm thng mi u hot ng di 20. Nhm lm vic IEEE 802.11 thit lp yu cu processing gain ti thiu l 11. Tin trnh ca DSSS bt u vi mt sng mang c modulate vi mt chui m (code sequence). S lng chip trong code s xc nh tri rng bao nhiu, v s lng chip trn mt bit (chip per bit) v tc ca code (tnh bng chip per second) s xc nh tc d liu. -nh hng ca nhiu bng hp: Cng ging nh h thng nhy tn, h thng DSSS cng c tnh khng c i vi nhiu bng hp bi v c tnh tri ph ca n. Mt tn hiu DSSS l d b nhiu bng hp hn so vi tn hiu FHSS bi v bng tn DSSS s dng nh hn so vi FHSS (rng 22 MHz so vi rng 79 MHz nh trong FHSS) v thng tin c truyn trn ton b bng tn mt cch ng thi thay v ch mt tn s ti mt thi im nh trong FHSS. Vi FHSS, s nhanh nhy

Page 50

Tm hiu mng WLAN v cc phng thc bo mt

ca tn s v rng bng tn s bo m rng nhiu ch nh hng ch trong mt thi gian ngn lm hng ch mt phn nh d liu. 3.4. So snh FHSS v DSSS: C cng ngh FHSS v DSSS u c im thun li v bt li. V nhim v ca WLAN administrator l phi quyt nh chn la s dng cng ngh no khi ci t mng WLAN mi. Phn ny s m t mt s yu t nn xem xt xc nh xem cng ngh no l thch hp vi bn nht. Cc yu t ny bao gm: + Nhiu bng hp + Co-location + Chi ph + Tnh tng thch v tnh sn c ca thit b + Tc v bng thng d liu + Bo mt + H tr chun. - Nhiu bng hp: im thun li ca FHSS l kh nng khng nhiu bng hp cao hn so vi DSSS. H thng DSSS c th b nh hng bi nhiu bng hp nhiu hn FHSS bi v chng s dng bng tn rng 22 MHz thay v 79 MHz. Yu t ny c th c xem nh l yu t quyt nh khi bn d nh trin khai mng WLAN trong mi trng c nhiu nhiu. - Chi ph: Khi ci t mng WLAN, nhng im thun li ca DSSS i khi hp dn hn FHSS c bit l khi c ngn sch hn ch. Chi ph ca vic ci t mt h thng DSSS thng thp hn rt nhiu so vi FHSS. Thit b DSSS rt ph bin trn th trng v ngy cng gim gi. Ch mt vi nm gn y, gi ca thit b c th chp nhn c i vi khch hng doanh nghip. - Co-location: im thun li ca FHSS so vi DSSS l kh nng c nhiu h thng FHSS cng hot ng vi nhau (co-located). Nu nh mc tiu l chi ph thp v bng thng cao th cng ngh

Page 51

Tm hiu mng WLAN v cc phng thc bo mt

DSSS s c la chn. Nu nh mc tiu l phn chia ngi dng s dng cc AP khc nhau trong mt mi trng co-located dy c th FHSS s thch hp hn. - Tnh tng thch v tnh sn c ca thit b: Bi v tnh ph bin ca cc thit b 802.11b nn rt d dng mua c chng. Nhu cu ngy cng pht trin cho cc thit b tng thch Wi-Fi trong khi nhu cu cho FHSS gn nh bo ha v i xung. - Tc v bng thng d liu: Nh chng ta bit l tc ca FHSS (2 Mbps) thp hn nhiu so vi DSSS (11 Mbps). Mc d mt s h thng FHSS c th hot ng tc 3 Mbps hay ln hn nhng cc h thng ny l khng tng thch vi chun 802.11 v c th khng giao tip c vi h thng FHSS khc. H thng FHSS v DSSS c thng lng (d liu tht s c truyn) ch khong mt na tc d liu. Khi kim tra thng lng lc ci t mt mng WLAN mi thng ch t c 5 6 Mbps i vi DSSS v 1 Mbps i vi FHSS cho d thit lp tc ti a. - Security: FHSS s dng h thng nhy tn nn d dng b pht hin bi cc chui nhy tn thng l theo mt danh sch xc nh trc do cc t chc nh IEEE hay WLIF a ra. - H tr chun: DSSS ginh c s chp nhn rng ri do chi ph thp, tc cao, chun tng thch WiFi v nhiu yu t khc. S chp nhn ny lm thc y nghnh cng nghip chuyn sang cng ngh mi hn v nhanh hn DSSS nh 802.11g hay 802.11n. Cc chun mi cho h thng FHSS nh HomeRF 2.0 v 802.15 (h tr cho WPAN nh Bluetooth) nhng u khng nng cp h thng FHSS trong doanh nghip.

Page 52

Tm hiu mng WLAN v cc phng thc bo mt

Chng 4: BO MT MNG KHNG DY 4.1. Ti sao phi bo mt mng WLAN: kt ni ti mt mng LAN hu tuyn ta cn phi truy cp theo ng truyn bng dy cp, phi kt ni mt PC vo mt cng mng. Vi mng khng dy ta ch cn c my ca ta trong vng sng bao ph ca mng khng dy. iu khin cho mng c dy l n gin: ng truyn bng cp thng thng c i trong cc ta nh cao tng v cc port khng s dng c th lm cho n disable bng cc ng dng qun l. Cc mng khng dy (hay v tuyn) s dng sng v tuyn xuyn qua vt liu ca cc ta nh v nh vy s bao ph l khng gii hn bn trong mt ta nh. Sng v tuyn c th xut hin trn ng ph, t cc trm pht t cc mng LAN ny, v nh vy ai c th truy cp nh thit b thch hp. Do

Page 53

Tm hiu mng WLAN v cc phng thc bo mt

mng khng dy ca mt cng ty cng c th b truy cp t bn ngoi ta nh cng ty ca h.

4.2. Cc loi hnh tn cng trong WLAN: 4.2.1. Tn cng b ng Passive attacks: 4.2.1.1. nh ngha: Tn cng b ng l kiu tn cng khng tc ng trc tip vo thit b no trn mng, khng lm cho cc thit b trn mng bit c hot ng ca n, v th kiu tn cng ny nguy him ch n rt kh pht hin. V d nh vic ly trm thng tin trong khng gian truyn sng ca cc thit b s rt kh b pht hin d thit b ly trm nm trong vng ph sng ca mng ch cha ni n vic n c t khong cch xa v s dng anten c nh hng ti ni pht sng, khi cho php k tn cng gi c khong cch thun li m khng b pht hin. Cc phng thc thng dng trong tn cng b ng: nghe trm (Sniffing, Eavesdropping), phn tch lung thng tin (Traffic analyst).

Page 54

Tm hiu mng WLAN v cc phng thc bo mt

Passive Attacks

Eavesdropping

Traffic Analysis

4.2.1.2. Kiu tn cng b ng c th - Phng thc bt gi tin (Sniffing): - Nguyn l thc hin: Bt gi tin Sniffing l khi nim c th ca khi nim tng qut Nghe trm Eavesdropping s dng trong mng my tnh. C l l phng php n gin nht, tuy nhin n vn c hiu qu i vi vic tn cng WLAN. Bt gi tin c th hiu nh l mt phng thc ly trm thng tin khi t mt thit b thu nm trong hoc nm gn vng ph sng. Tn cng kiu bt gi tin s kh b pht hin ra s c mt ca thit b bt gi d thit b nm trong hoc nm gn vng ph sng nu thit b khng thc s kt ni ti AP thu cc gi tin. Vic bt gi tin mng c dy thng c thc hin da trn cc thit b phn cng mng, v d nh vic s dng phn mm bt gi tin trn phn iu khin thng tin ra vo ca mt card mng trn my tnh, c ngha l cng phi bit loi thit b phn cng s dng, phi tm cch ci t phn mm bt gi ln , vv.. tc l khng n gin. i vi mng khng dy, nguyn l trn vn ng nhng khng nht thit phi s dng v c nhiu cch ly thng tin n gin, d dng hn nhiu. Bi v i vi mng khng dy, thng tin c pht trn mi trng truyn sng v ai cng c th thu c. Nhng chng trnh bt gi tin c kh nng ly cc thng tin quan trng, mt khu, .. t cc qu trnh trao i thng tin trn my bn vi cc site HTTP, email, cc instant messenger, cc phin FTP, cc phin telnet nu nhng thng tin trao i di dng vn bn khng m ha (clear text). C nhng chng trnh c th ly c mt khu trn mng khng dy ca qu trnh trao i gia Client v Server khi ang thc hin qu trnh nhp mt khu ng nhp. Cng t vic bt gi tin, c th nm c thng tin, phn tch c lu lng ca mng (Traffic analysis) , ph nng lng trong khng gian ca cc vng. T m k tn cng c th bit ch no sng truyn tt, ch no km, ch no tp trung nhiu my.

Page 55

Tm hiu mng WLAN v cc phng thc bo mt

Nh bt gi tin ngoi vic trc tip gip cho qu trnh ph hoi, n cn gin tip l tin cho cc phng thc ph hoi khc. Bt gi tin l c s ca cc phng thc tn cng nh an trm thng tin, thu thp thng tin phn b mng (wardriving), d m, b m (Key crack), vv ..

Wardriving: l mt thut ng ch thu thp thng tin v tnh hnh phn b cc thit b, vng ph sng, cu hnh ca mng khng dy. Vi tng ban u dng mt thit b d sng, bt gi tin, k tn cng ngi trn xe t v i khp cc ni thu thp thng tin, chnh v th m c tn l wardriving. Ngy nay nhng k tn cng cn c th s dng cc thit b hin i nh b thu pht v tinh GPS xy dng thnh mt bn thng tin trn mt phm vi ln.

Page 56

Tm hiu mng WLAN v cc phng thc bo mt

Hnh 4.3: Phn mm thu thp thng tin h thng mng khng dy NetStumbler Bin php i ph V bt gi tin l phng thc tn cng kiu b ng nn rt kh pht hin v do c im truyn sng trong khng gian nn khng th phng nga vic nghe trm ca k tn cng. Gii php ra y l nng cao kh nng m ha thng tin sao cho k tn cng khng th gii m c, khi thng tin ly c s thnh v gi tr i vi k tn cng. 4.2.2. Tn cng ch ng Active attacks: 4.2.2.1. nh ngha: Tn cng ch ng l tn cng trc tip vo mt hoc nhiu thit b trn mng v d nh vo AP, STA. Nhng k tn cng c th s dng phng php tn cng ch ng thc hin cc chc nng trn mng. Cuc tn cng ch ng c th c dng tm cch truy nhp ti mt server thm d, ly nhng d liu quan trng, thm ch thc hin thay i cu hnh c s h tng mng. Kiu tn cng ny d pht hin nhng kh nng ph hoi ca n rt nhanh v nhiu, khi pht hin ra chng ta cha kp c phng php i ph th n thc hin xong qu trnh ph hoi. So vi kiu tn cng b ng th tn cng ch ng c nhiu phng thc a dng hn, v d nh: Tn cng t chi dch v (DOS), Sa i thng tin (Message Modification), ng gi, mo danh, che du (Masquerade), Lp li thng tin (Replay), Bomb, spam mail, v v...Message Modification Denied of service

Active Attacks

Masquerade

Replay

4.2.2.2. Cc kiu tn cng ch ng c th: 4.2.2.2.1. Mo danh, truy cp tri php:

Page 57

Tm hiu mng WLAN v cc phng thc bo mt

- Nguyn l thc hin: Vic mo danh, truy cp tri php l hnh ng tn cng ca k tn cng i vi bt k mt loi hnh mng my tnh no, v i vi mng khng dy cng nh vy. Mt trong nhng cch ph bin l mt my tnh tn cng bn ngoi gi mo l my bn trong mng, xin kt ni vo mng ri truy cp tri php ngun ti nguyn trn mng. Vic gi mo ny c thc hin bng cch gi mo a ch MAC, a ch IP ca thit b mng trn my tn cng thnh cc gi tr ca my ang s dng trong mng, lm cho h thng hiu nhm v cho php thc hin kt ni. V d vic thay i gi tr MAC ca card mng khng dy trn my tnh s dng h iu hnh Windows hay UNIX u ht sc d dng, ch cn qua mt s thao tc c bn ca ngi s dng. Cc thng tin v a ch MAC, a ch IP cn gi mo c th ly t vic bt trm gi tin trn mng. - Bin php i ph: Vic gi gn bo mt my tnh mnh ang s dng, khng cho ai vo dng tri php l mt nguyn l rt n gin nhng li khng tha ngn chn vic mo danh ny. Vic mo danh c th xy ra cn do qu trnh chng thc gia cc bn cn cha cht ch, v vy cn phi nng cao kh nng ny gia cc bn. 4.2.2.2.2. Tn cng t chi dch v - DOS: - Nguyn l thc hin: Vi mng my tnh khng dy v mng c dy th khng c khc bit c bn v cc kiu tn cng DOS ( Denied of Service ) cc tng ng dng v vn chuyn nhng gia cc tng mng, lin kt d liu v vt l li c s khc bit ln. Chnh iu ny lm tng nguy him ca kiu tn cng DOS trong mng my tnh khng dy. Trc khi thc hin tn cng DOS, k tn cng c th s dng chng trnh phn tch lu lng mng bit c ch no ang tp trung nhiu lu lng, s lng x l nhiu, v k tn cng s tp trung tn cng DOS vo nhng v tr nhanh t c hiu qu hn. - Tn cng DOS tng vt l: Tn cng DOS tng vt l mng c dy mun thc hin c th yu cu k tn cng phi gn cc my tnh trong mng. iu ny li khng ng trong mng khng dy. Vi mng ny, bt k mi trng no cng d b tn cng v k tn cng c th xm nhp vo tng

Page 58

Tm hiu mng WLAN v cc phng thc bo mt

vt l t mt khong cch rt xa, c th l t bn ngoi thay v phi ng bn trong ta nh. Trong mng my tnh c dy khi b tn cng th thng li cc du hiu d nhn bit nh l cp b hng, dch chuyn cp, hnh nh c ghi li t camera, th vi mng khng dy li khng li bt k mt du hiu no. 802.11 PHY a ra mt phm vi gii hn cc tn s trong giao tip. Mt k tn cng c th to ra mt thit b lm bo ha di tn 802.11 vi nhiu. Nh vy, nu thit b to ra nhiu tn s v tuyn th s lm gim tn hiu / t l nhiu ti mc khng phn bit c dn n cc STA nm trong di tn nhiu s b ngng hot ng. Cc thit b s khng th phn bit c tn hiu mng mt cch chnh xc t tt c cc nhiu xy ra ngu nhin ang c to ra v do s khng th giao tip c. Tn cng theo kiu ny khng phi l s e do nghim trng, n kh c th thc hin ph bin do vn gi c ca thit b, n qu t trong khi k tn cng ch tm thi v hiu ha c mng. - Tn cng DOS tng lin kt d liu: Do tng lin kt d liu k tn cng cng c th truy cp bt k u nn li mt ln na to ra nhiu c hi cho kiu tn cng DOS. Thm ch khi WEP c bt, k tn cng c th thc hin mt s cuc tn cng DOS bng cch truy cp ti thng tin lp lin kt. Khi khng c WEP, k tn cng truy cp ton b ti cc lin kt gia cc STA v AP chm dt truy cp ti mng. Nu mt AP s dng khng ng anten nh hng k tn cng c nhiu kh nng t chi truy cp t cc client lin kt ti AP. Anten nh hng i khi cn c dng ph sng nhiu khu vc hn vi mt AP bng cch dng cc anten. Nu anten nh hng khng ph sng vi khong cch cc vng l nh nhau, k tn cng c th t chi dch v ti cc trm lin kt bng cch li dng s sp t khng ng ny, iu c th c minh ha hnh di y:

Page 59

Tm hiu mng WLAN v cc phng thc bo mt

Hnh 4.3: M t qu trnh tn cng DOS tng lin kt d liu Gi thit anten nh hng A v B c gn vo AP v chng c sp t ph sng c hai bn bc tng mt cch c lp. Client A bn tri bc tng, v vy AP s chn anten A cho vic gi v nhn cc khung. Client B bn tri bc tng, v vy chn vic gi v nhn cc khung vi anten B. Client B c th loi client A ra khi mng bng cch thay i a ch MAC ca Client B ging ht vi Client A. Khi Client B phi chc chn rng tn hiu pht ra t anten B mnh hn tn hiu m Client A nhn c t anten A bng vic dng mt b khuch i hoc cc k thut khuch i khc nhau. Nh vy AP s gi v nhn cc khung ng vi a ch MAC anten B. Cc khung ca Client A s b t chi chng no m Client B tip tc gi lu lng ti AP. - Tn cng DOS tng mng: Nu mt mng cho php bt k mt client no kt ni, n d b tn cng DOS tng mng. Mng my tnh khng dy chun 802.11 l mi trng chia s ti nguyn. Mt ngi bt hp php c th xm nhp vo mng, t chi truy cp ti cc thit b c lin kt vi AP. V d nh k tn cng c th xm nhp vo mng 802.11b v gi i hng lot cc gi tin ICMP qua cng gateway. Trong khi cng gateway c th vn thng sut lu lng mng, th di tn chung ca 802.11b li d dng b bo ha. Cc Client khc lin kt vi AP ny s gi cc gi tin rt kh khn. - Bin php i ph:

Page 60

Tm hiu mng WLAN v cc phng thc bo mt

Bin php mang tnh cc oan hiu qu nht l chn v lc b i tt c cc bn tin m DOS hay s dng, nh vy c th s chn b lun c nhng bn tin hu ch. gii quyt tt hn, cn c nhng thut ton thng minh nhn dng tn cng attack detection, da vo nhng c im nh gi bn tin lin tc, bn tin ging ht nhau, bn tin khng c ngha, vv.. Thut ton ny s phn bit bn tin c ch vi cc cuc tn cng, c bin php lc b. 4.2.2.2.3. Tn cng cng ot iu khin v sa i thng tin Hijacking and Modification: - Nguyn l thc hin: C rt nhiu k thut tn cng cng ot iu khin. Khc vi cc kiu tn cng khc, h thng mng rt kh phn bit u l k tn cng cng ot iu khin, u l mt ngi s dng hp php. C nhiu cc phn mm thc hin Hijack. Khi mt gi tin TCP/IP i qua Switch, Router hay AP, cc thit b ny s xem phn a ch ch n ca gi tin, nu a ch ny nm trong mng m thit b qun l th gi tin s chuyn trc tip n a ch ch, cn nu a ch khng nm trong mng m thit b qun l th gi tin s c a ra cng ngoi (default gateway) tip tc chuyn n thit b khc.Nu k tn cng c th sa i gi tr default gateway ca thit b mng tr vo my tnh ca hn, nh vy c ngha l cc kt ni ra bn ngoi u i vo my ca hn. V ng nhin l k tn cng c th ly c ton b thng tin la chn ra cc bn tin yu cu, cp php chng thc gii m, b kha mt m. mt mc tinh vi hn, k tn cng ch la chn mt s bn tin cn thit nh tuyn n n, sau khi ly c ni dung bn tin, k tn cng c th sa i li ni dung theo mc ch ring sau li tip tc chuyn tip (forward) bn tin n ng a ch ch. Nh vy bn tin b chn, ly, sa i trong qu trnh truyn m pha gi ln pha nhn khng pht hin ra. y cng ging nguyn l ca kiu tn cng thu ht (man in the back), tn cng s dng AP gi mo (rogue AP).

Page 61

Tm hiu mng WLAN v cc phng thc bo mt

Hnh 4.4: M t qu trnh tn cng mng bng AP gi mo AP gi mo - Rogue AP: l mt kiu tn cng bng cch s dng 1 AP t trong vng gn vi vng ph sng ca mng WLAN. Cc Client khi di chuyn n gn Rogue AP, theo nguyn l chuyn giao vng ph sng gia m cc AP qun l, my Client s t ng lin kt vi AP gi mo v cung cp cc thng tin ca mng WLAN cho AP. Vic s dng AP gi mo, hot ng cng tn s vi cc AP khc c th gy ra nhiu sng ging nh trong phng thc tn cng chn p, n cng gy tc hi ging tn cng t chi dch v - DOS v khi b nhiu sng, vic trao i cc gi tin s b khng thnh cng nhiu v phi truyn i truyn li nhiu ln, dn n vic tc nghn, cn kit ti nguyn mng - Bin php i ph: Tn cng kiu Hijack thng c tc nhanh, phm vi rng v vy cn phi c cc bin php ngn chn kp thi. Hijack thng thc hin khi k tn cng t nhp kh su trong h thng, v th cn phi ngn chn t nhng du hiu ban u. Vi kiu tn cng AP Rogue, bin php ngn chn gi mo l phi c s chng thc 2 chiu gia Client v AP thay cho vic chng thc mt chiu t Client n AP. 4.2.2.2.4. D mt khu bng t in Dictionary Attack: - Nguyn l thc hin: Vic d mt khu da trn nguyn l qut tt c cc trng hp c th sinh ra t t hp ca cc k t. Nguyn l ny c th c thc thi c th bng nhng phng php khc nhau nh qut t trn xung di, t di ln trn, t s n ch, vv... Vic qut th ny tn nhiu thi gian ngay c trn nhng th h my tnh tin tin bi v s trng hp t hp ra l cc k

Page 62

Tm hiu mng WLAN v cc phng thc bo mt

nhiu. Thc t l khi t mt mt m (password), nhiu ngi thng dng cc t ng c ngha, n l hoc ghp li vi nhau, v d nh cuocsong, hanhphuc, cuocsonghanhphuc, vv.. Trn c s mt nguyn l mi c a ra l s qut mt khu theo cc trng hp theo cc t ng trn mt b t in c sn, nu khng tm ra lc y mi qut t hp cc trng hp. B t in ny gm nhng t ng c s dng trong cuc sng, trong x hi, vv.. v n lun c cp nht b xung tng kh nng thng minh ca b ph m. - Bin php i ph: i ph vi kiu d mt khu ny, cn xy dng mt quy trnh t mt khu phc tp hn, a dng hn trnh nhng t hp t, v gy kh khn cho vic qut t hp cc trng hp. V d quy trnh t mt khu phi nh sau: - Mt khu di ti thiu 10 k t - C c ch thng v ch hoa - C c ch, s, v c th l cc k t c bit nh !,@,#,$ - Trnh trng vi tn ng k, tn ti khon, ngy sinh, vv.. - Khng nn s dng cc t ng ngn n gin c trong t in 4.2.3. Tn cng kiu chn p - Jamming attacks: Ngoi vic s dng phng php tn cng b ng, ch ng ly thng tin truy cp ti mng ca bn, phng php tn cng theo kiu chn p. Jamming l mt k thut s dng n gin lm mng ca bn ngng hot ng. Phng thc jamming ph bin nht l s dng my pht c tn s pht ging tn s m mng s dng p o lm mng b nhiu, b ngng lm vic. Tn hiu RF c th di chuyn hoc c nh.

Page 63

Tm hiu mng WLAN v cc phng thc bo mt

Hnh 4.5: M t qu trnh tn cng theo kiu chn p Cng c trng hp s Jamming xy ra do khng ch thng xy ra vi mi thit b m dng chung di tn 2,4Ghz. Tn cng bng Jamming khng phi l s e da nghim trng, n kh c th c thc hin ph bin do vn gi c ca thit b, n qu t trong khi k tn cng ch tm thi v hiu ha c mng. 4.2.4. Tn cng theo kiu thu ht - Man in the middle attacks : Tn cng theo kiu thu ht - Man in the middle attacks c ngha l dng mt kh nng mnh hn chen vo gia hot ng ca cc thit b v thu ht, ginh ly s trao i thng tin ca thit b v mnh. Thit b chn gia phi c v tr, kh nng thu pht tri hn cc thit b sn c ca mng. Mt c im ni bt ca kiu tn cng ny l ngi s dng khng th pht hin ra c cuc tn cng, v lng thng tin m thu nht c bng kiu tn cng ny l gii hn.

Page 64

Tm hiu mng WLAN v cc phng thc bo mt

Hnh 4.6: M t qu trnh tn cng theo kiu thu ht Phng thc thng s dng theo kiu tn cng ny l Mo danh AP (AP rogue), c ngha l chn thm mt AP gi mo vo gia cc kt ni trong mng. 4.2.5. De-authentication Flood Attack(tn cng yu cu xc thc li ):

Page 65

Tm hiu mng WLAN v cc phng thc bo mt

Hnh 4.7: m t kiu tn cng yu cu xc thc li -K tn cng xc nh mc tiu tn cng l cc ngi dng trong mng wireless v cc kt ni ca h(Access Point n cc kt ni ca n). -Chn cc frame yu cu xc thc li vo mng WLAN bng cch gi mo a ch MAC ngun v ch ln lt ca Access Point v cc ngi dng. -Ngi dng wireless khi nhn c frame yu cu xc thc li th ngh rng chng do Access Point gi n. -Sau khi ngt c mt ngi dng ra khi dch v khng dy, k tn cng tip tc thc hin tng t i vi cc ngi dng cn li. -Thng thng ngi dng s kt ni li phc hi dch v, nhng k tn cng nhanh chng tip tc gi cc gi yu cu xc thc li cho ngi dng. 4.2.6. Fake Access Point: K tn cng s dng cng c c kh nng gi cc gi beacon vi a ch vt l(MAC) gi mo v SSID gi to ra v s Access Point gi lp.iu ny lm xo trn tt c cc phn mm iu khin card mng khng dy ca ngi dng.

Page 66

Tm hiu mng WLAN v cc phng thc bo mt

hnh 4.8: kiu tn cng Fake AP 4.2.7. Tn cng da trn s cm nhn sng mang lp vt l: Ta c th hiu nm na l : K tt cng li dng giao thc chng ng CSMA/CA, tc l n s lm cho tt c ngi dng ngh rng lc no trong mng cng c 1 my tnh ang truyn thng. iu ny lm cho cc my tnh khc lun lun trng thi ch i k tn cng y truyn d liu xong => dn n tnh trng ngn trong mng. Tn s l mt nhc im bo mt trong mng khng dy. Mc nguy him thay i ph thuc vo giao din ca lp vt l. C mt vi tham s quyt nh s chu ng ca mng l: nng lng my pht, nhy ca my thu, tn s RF, bng thng v s nh hng ca anten. Trong 802.11 s dng thut ton a truy cp cm nhn sng mang (CSMA) trnh va chm. CSMA l mt thnh phn ca lp MAC. CSMA c s dng chc chn rng s khng c va chm d liu trn ng truyn. Kiu tn cng ny khng s dng tp m to ra li cho mng nhng n s li dng chnh chun . C nhiu cch khai thc giao thc cm nhn sng mang vt l. Cch n gin l lm cho cc nt trong mng u tin tng rng

Page 67

Tm hiu mng WLAN v cc phng thc bo mt

c mt nt ang truyn tin ti thi im hin ti. Cch d nht t c iu ny l to ra mt nt gi mo truyn tin mt cch lin tc. Mt cch khc l s dng b to tn hiu RF. Mt cch tn cng tinh vi hn l lm cho card mng chuyn vo ch kim tra m n truyn i lin tip mt mu kim tra. Tt c cc nt trong phm vi ca mt nt gi l rt nhy vi sng mang v trong khi c mt nt ang truyn th s khng c nt no c truyn. 4.2.8.Tn cng ngt kt ni (Disassociation flood attack):

Hnh 4.9: m t tn cng ngt kt ni -K tn cng xc nh mc tiu ( wireless clients ) v mi lin kt gia AP vi cc clients -K tn cng gi disassociation frame bng cch gi mo Source v Destination MAC n AP v cc client tng ng -Client s nhn cc frame ny v ngh rng frame hy kt ni n t AP. ng thi k tn cng cng gi disassociation frame n AP. -Sau khi ngt kt ni ca mt client, k tn cng tip tc thc hin tng t vi cc client cn li lm cho cc client t ng ngt kt ni vi AP.

Page 68

Tm hiu mng WLAN v cc phng thc bo mt

-Khi cc clients b ngt kt ni s thc hin kt ni li vi AP ngay lp tc. K tn cng tip tc gi disassociation frame n AP v client. C th ta s rt d nhm ln gia 2 kiu tn cng :Disassociation flood attack v Deauthentication Flood Attack . Ging nhau: v hnh thc tn cng , c th cho rng chng ging nhau v va tn cng Access Point va tn cng Client. V quan trng hn ht , chng lin tip gi cc frame n AP v Client tng ng. Khc nhau: + De-authentication Flood Attack : yu cu c AP v client gi li frame xc thc=> xc thc failed + Disassociation flood attack : gi disassociation frame lm cho AP v client tin tng rng kt ni gia chng b ngt.

Chng 5: CHNG THC V M HA cung cp mc bo mt ti thiu cho mng WLAN th ta cn hai thnh phn sau:

Page 69

Tm hiu mng WLAN v cc phng thc bo mt

-Cch thc xc nh ai c quyn s dng WLAN - yu cu ny c tha mn bng c ch xc thc( authentication). -Mt phng thc cung cp tnh ring t cho cc d liu khng dy yu cu ny c tha mn bng mt thut ton m ha ( encryption).

5.1.Chng thc( Authentication): Chng thc c ngha l chng nhn, xc thc s hp php ca mt ngi, mt qu trnh tham gia, s dng no qua cc phng thc, cng c nh m kha, cha kha, ti khon, ch k, vn tay, vv.. Qua c th cho php hoc khng cho php cc hot ng tham gia, s dng. Ngi c quyn tham gia, s dng s c cp mt hay nhiu phng thc chng nhn, xc thc trn. Trong mt mng khng dy, gi s l s dng mt AP lin kt cc my tnh li vi nhau, khi mt my tnh mi mun gia nhp vo mng khng dy , n cn phi kt ni vi AP. chng thc my tnh xin kt ni , c nhiu phng php AP c s dng nh MAC Address, SSID, WEP, RADIUS, vv...

Page 70

Tm hiu mng WLAN v cc phng thc bo mt

Kim tra( Audit) l qu trnh xem xt li qu trnh thc hin c ng theo yu cu ra khng, pht hin ra xem nhng vn , li pht sinh no khng. Qu trnh kim tra c th nh k thng xuyn hoc bt thng. M ha d liu( Data Encryption) m bo thng tin truyn i, ngi ta s dng cc phng php m ha (encryption). D liu c bin i t dng nhn thc c sang dng khng nhn thc c theo mt thut ton no (to mt m) v s c bin i ngc li (gii m) trm nhn. Phng tin s dng trong qu trnh m ha gi l mt m. Nhim v ca mt m l to ra kh nng lin lc trn cc knh cng khai sao cho i phng khng th hiu c thng tin c truyn i. Knh cng khai y c th l mng in thoi cng cng, mng my tnh ton cu, mng thu pht v tuyn, vv.. Mt m cn c dng bo v cc d liu mt trong cc CSDL nhiu ngi s dng. Ngy nay phm vi ng dng mt m kh rng ri v ph bin, c bit trn cc mng truyn thng my tnh. Cc h mt c th chia lm hai loi: - H mt kha b mt: s dng cng mt m cho lp m v gii m v th cn gi l h mt kha i xng (symmetric key). Vi h mt ny hai u ca knh thng tin phi c cung cp cng mt kha qua mt knh tin cy v kha ny phi c tn ti trc qu trnh truyn tin. H mt kha cng khai PKI-Public Key Infrastructure: dng mt kha lp m v dng kha khc gii m, h mt ny cn c gi l h mt khng i xng. Vi h mt ny kha lp m lun c cng b cng khai trn knh tin chung, ch kha gii m l c gi b mt. Chui k t bn tin khi cha m ha c gi l Clear text, chui k t bn tin khi m ha gi l cipher text. 5.1.1. Chng thc bng a ch MAC MAC Address: Nguyn l thc hin: Trc ht chng ta cng nhc li mt cht v khi nim a ch MAC. a ch MAC Media Access Control l a ch vt l ca thit b c in nhp vo Card mng khi ch to, mi Card mng c mt gi tr a ch duy nht. a ch ny gm 48 bit chia thnh 6 byte, 3 byte u xc nh nh sn xut, v d nh:

Page 71

Tm hiu mng WLAN v cc phng thc bo mt

00-40-96 : Cisco 00-00-86 : 3COM 00-02-2D : Agere Communications (ORiNOCO) 00-10-E7 : Breezecom 00-E0-03 : Nokia Wireless 00-04-5A : Linksys 3 byte cn li l s th t, do hng t cho thit b a ch MAC nm lp 2 (lp Datalink ca m hnh OSI) Khi Client gi yu cu chng thc cho AP, AP s ly gi tr a ch MAC ca Client , so snh vi bng cc a ch MAC c php kt ni quyt nh xem c cho php Client chng thc hay khng.

hnh 5.2: M t qu trnh chng thc bng a ch MAC Nhc im: V nguyn l th a ch MAC l do hng sn xut quy nh ra nhng nhc im ca phng php ny k tn cng li c th thay i a ch MAC mt cch d dng, t c th chng thc gi mo. - Gi s ngi s dng b mt my tnh, k cp c th d dng truy cp v tn cng mng bi v chic my tnh mang a ch MAC c AP cho php, trong khi ngi mt my tnh

Page 72

Tm hiu mng WLAN v cc phng thc bo mt

mua mt chic my tnh mi lc u gp kh khn v AP cha kp cp nht a ch MAC ca chic my tnh . - Mt s cc Card mng khng dy loi PCMCIA dng cho chun 802.11 c h tr kh nng t thay i a ch MAC, nh vy k tn cng ch vic thay i a ch ging a ch ca mt my tnh no trong mng c cp php l hn c nhiu c hi chng thc thnh cng. Bin php i ph: Nguyn l ny qu yu km v mt an ninh nn bin php tt nht l khng s dng n na hoc l dng n nh mt phn ph tr cho cc nguyn l khc 5.1.2. Chng thc bng SSID: Nguyn l thc hin: Chng thc bng SSID - System Set Identifier, m nh danh h thng, l mt phng thc chng thc n gin, n c p dng cho nhiu m hnh mng nh, yu cu mc bo mt thp. C th coi SSID nh mt mt m hay mt cha kha, khi my tnh mi c php gia nhp mng n s c cp SSID, khi gia nhp, n gi gi tr SSID ny ln AP, lc ny AP s kim tra xem SSID m my tnh gi ln c ng vi mnh quy nh khng, nu ng th coi nh chng thc c v AP s cho php thc hin cc kt ni.

hnh 5.3: M t qu trnh chng thc bng SSID Cc bc kt ni khi s dng SSID: 1. Client pht yu cu Thm d trn tt c cc knh 2. AP no nhn c yu cu Thm d trn s tr li li (c th c nhiu AP cng tr li) 3. Client chn AP no ph hp gi yu cu xin Chng thc

Page 73

Tm hiu mng WLAN v cc phng thc bo mt

4. AP gi tr li yu cu Chng thc 5. Nu tha mn cc yu cu chng thc, Client s gi yu cu Lin kt n AP 6. AP gi tr li yu cu Lin kt 7. Qu trnh Chng thc thnh cng, 2 bn bt u trao i d liu SSID l mt chui di 32 bit. Trong mt s tnh hung cng khai (hay cn gi l Chng thc m - Open System Authentication), khi AP khng yu cu chng thc chui SSID ny s l mt chui trng (null). Trong mt s tnh hung cng khai khc, AP c gi tr SSID v n pht BroadCast cho ton mng. Cn khi gi b mt (hay cn gi l Chng thc ng - Close System Authentication), ch khi c SSID ng th my tnh mi tham gia vo mng c. Gi tr SSID cng c th thay i thng xuyn hay bt thng, lc phi thng bo n tt c cc my tnh c cp php v ang s dng SSID c, nhng trong qu trnh trao i SSID gia Client v AP th m ny nguyn dng, khng m ha (clear text). Nhc im ca SSID: S dng SSID l kh n gin nhng n cng c nhiu nhc im, c th : - Cc hng thng c m SSID ngm nh sn (default SSID), nu ngi s dng khng thay i th cc thit b AP gi nguyn gi tr SSID ny, k tn cng li dng s li lng , d ra SSID. Cc SSID ngm nh ca AP ca mt s hng nh sau: Manufacturer 3Com Addtron Cisco Compaq Dlink Intel Linksys Lucent/Cabletron NetGear SMC Symbol Default SSID 101, comcomcom WLAN Tsunami, WaveLAN Network Compaq WLAN 101, 195, xlan, intel Linksys, wireless RoamAbout Wireless WLAN 101

Page 74

Tm hiu mng WLAN v cc phng thc bo mt

Teletronics Zcomax Zyxel

any any, mello, Test Wireless

- Nhiu mng s dng m SSID rng (null), nh vy ng nhin mi my tnh c th truy nhp vo mng c, k c my tnh ca k tn cng - AP bt ch Broadcast gi SSID, nh vy gi tr SSID ny s c gi i khp ni trong vng ph sng, to iu kin cho k tn cng ly c m ny - Kiu chng thc dng SSID l n gin, t bc. V vy nu k tn cng thc hin vic bt rt nhiu gi tin trn mng phn tch theo cc thut ton qut gi tr nh kiu Brute Force th s c nhiu kh nng d ra c m SSID m AP ang s dng - Tt c mng WLAN dng chung mt SSID, ch cn mt my tnh trong mng l th s nh hng an ninh ton mng. Khi AP mun i gi tr SSID th phi thng bo cho tt c cc my tnh trong mng S dng phng php bt gi tin d m SSID: Nu AP pht Broadcast gi tr SSID, bt k mt my tnh kt ni khng dy no cng c th d ra gi tr ny. Cn khi AP khng ph bin gi tr ny, k tn cng vn c th d ra c mt cch n gin bng phng php bt cc bn tin chng trao i gia Client v AP bi v cc gi tr SSID trong bn tin khng c m ha. Di y l gi tr SSID thu c bng phn mm bt gi Sniffer Wireless

hnh 5.4: Gi tr SSID c AP pht ch qung b

Page 75

Tm hiu mng WLAN v cc phng thc bo mt

hnh 5.5: Gi tr SSID c AP pht ch tr li Client Bin php i ph: Vic s dng SSID ch p dng cho kt ni gia my tnh v my tnh hoc cho cc mng khng dy phm vi nh, hoc l khng c kt ni ra mng bn ngoi. Nhng m hnh phc tp vn s dng SSID nhng khng phi bo mt v n thng c ph bin cng khai, m n c dng gi ng cc nguyn l kt ni ca WLAN, cn an ninh mng s c cc nguyn l khc m nhim. 5.1.3. Chng thc bng WEP: Phng thc chng thc ca WEP cng phi qua cc bc trao i gia Client v AP, nhng n c thm m ha v phc tp hn

Page 76

Tm hiu mng WLAN v cc phng thc bo mt

Wireless station

Access Point

Authen tication reques t nge

Challe

Generate random number to challenge station

Encrypt challenge using RC4 algorithm

Respon se s s ucces Confirm

Decrypt response to recover challenge. Verify that challenges equate

hnh 5.6: M t qu trnh chng thc gia Client v AP Cc bc c th nh sau: Bc 1: Client gi n AP yu cu xin chng thc Bc 2: AP s to ra mt chui mi kt ni (challenge text) ngu nhin gi n Client Bc 3: Client nhn c chui ny ny s m ha chui bng thut ton RC4 theo m kha m Client c cp, sau Client gi li cho AP chui m ha Bc 4: AP sau khi nhn c chui m ha ca Client, n s gii m li bng thut ton RC4 theo m kha cp cho Client, nu