Wireless Anomaly Detection Based on IEEE 802.11 Behavior Analysis

被引:46
作者
Alipour, Hamid [1 ]
Al-Nashif, Youssif B. [1 ]
Satam, Pratik [1 ]
Hariri, Salim [1 ]
机构
[1] Univ Arizona, Dept Elect & Comp Engn, Tucson, AZ 85721 USA
基金
美国国家科学基金会;
关键词
Anomaly detection; IEEE; 802.11; security; intrusion detection; wireless network security; protocol analysis; wireless networks; NETWORKS;
D O I
10.1109/TIFS.2015.2433898
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Wireless communication networks are pervading every aspect of our lives due to their fast, easy, and inexpensive deployment. They are becoming ubiquitous and have been widely used to transfer critical information, such as banking accounts, credit cards, e-mails, and social network credentials. The more pervasive the wireless technology is going to be, the more important its security issue will be. Whereas the current security protocols for wireless networks have addressed the privacy and confidentiality issues, there are unaddressed vulnerabilities threatening their availability and integrity (e.g., denial of service, session hijacking, and MAC address spoofing attacks). In this paper, we describe an anomaly based intrusion detection system for the IEEE 802.11 wireless networks based on behavioral analysis to detect deviations from normal behaviors that are triggered by wireless network attacks. Our anomaly behavior analysis of the 802.11 protocols is based on monitoring the n-consecutive transitions of the protocol state machine. We apply sequential machine learning techniques to model the n-transition patterns in the protocol and characterize the probabilities of these transitions being normal. We have implemented several experiments to evaluate our system performance. By cross validating the system over two different wireless channels, we have achieved a low false alarm rate (<0.1%). We have also evaluated our approach against an attack library of known wireless attacks and has achieved more than 99% detection rate.
引用
收藏
页码:2158 / 2170
页数:13
相关论文
共 24 条
[1]  
Alipour H., 2013, THESIS U ARIZONA TUC
[2]  
Alipour H., 2013, P INT C COMP NETW CO, P369
[3]  
[Anonymous], 2005, IEEE Std 802.11
[4]  
[Anonymous], P 4 IEEE IFIP ANN IN
[5]  
[Anonymous], 2010, P FUTURE NETW MOB SU
[6]  
[Anonymous], 1997, 802111997 IEEE, DOI [http://dx.doi.org/10.1109/IEEESTD.1997.85951, DOI 10.1109/IEEESTD.1997.85951]
[7]  
[Anonymous], 2004, 80211I2004 IEEE
[8]  
[Anonymous], P IEEE 27 C COMP COM
[9]   Denial-of-Service attacks and countermeasures in IEEE 802.11 wireless networks [J].
Bicakci, Kemal ;
Tavli, Bulent .
COMPUTER STANDARDS & INTERFACES, 2009, 31 (05) :931-941