An Efficient Scheme to Detect Evil Twin Rogue Access Point Attack in 802.11 Wi-Fi Networks

被引:16
|
作者
Agarwal, Mayank [1 ]
Biswas, Santosh [2 ]
Nandi, Sukumar [2 ]
机构
[1] Ben Gurion Univ Negev, Dept ISE, Beer Sheva, Israel
[2] IIT Guwahati, Dept Comp Sci & Engn, Gauhati, India
关键词
Intrusion Detection System; Evil Twin Rogue Access Point Attack; WiFi networks; False alarms;
D O I
10.1007/s10776-018-0396-1
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The MAC layer of 802.11 protocol possess inherent weakness making it vulnerable to various security attacks like denial of service, deauthentication attack, flooding attacks, rogue access point (RAP) etc. In this manuscript we focus on evil twin attack. An evil twin is a RAP setup by cloning the MAC address and the Service Set IDentifier of an existing wireless access point (AP). An evil twin is setup so that the client(s) unknowingly connect to them under the pretext that they are connected to a genuine AP. Once a client is connected, an attacker eavesdrops on its communication to hijack client's communication, re-direct clients to malicious websites, steal credentials of the clients connecting to it. Existing methods to detect the evil twin include maintaining white lists, patching AP/client, timing based solutions, protocol modifications etc. These methods usually require extensive setup and maintenance, have scalability and compatibility issues, require changes in protocol stack making them expensive to deploy and manage. The network conditions under normal and evil twin attack are almost similar thereby crafting a signature or defining an anomaly pattern usually leads to large amount of false positives. In this manuscript, we propose an IDS for detecting the evil twin attack, which addresses most of these issues associated with the existing detection mechanisms. Further the scheme is also proved to detect a single evil twin, multiple evil twins for single AP and multiple evil twins for multiple APs. The proposed IDS has been deployed in a lab environment and its detection rate exceeds 92% mark and the accuracy is 100% in all the runs.
引用
收藏
页码:130 / 145
页数:16
相关论文
共 50 条
  • [31] Design of an enhanced access point to optimize TCP performance in Wi-Fi hotspot networks
    Raffaele Bruno
    Marco Conti
    Enrico Gregori
    Wireless Networks, 2007, 13 : 259 - 274
  • [32] Preemptive Channel Access Scheme for Next Generation Wi-Fi
    Moon, Juseong
    Kim, Ronny Yongho
    2024 IEEE INTERNATIONAL CONFERENCE ON BIG DATA AND SMART COMPUTING, IEEE BIGCOMP 2024, 2024, : 131 - 135
  • [33] Energy-aware Restricted Access Window Control with Retransmission Scheme for IEEE 802.11 ah (Wi-Fi HaLow) based Networks
    Wang, Yanru
    Chai, Kok Keong
    Chen, Yue
    Schormans, John
    Loo, Jonathan
    2017 13TH ANNUAL CONFERENCE ON WIRELESS ON-DEMAND NETWORK SYSTEMS AND SERVICES (WONS), 2017, : 69 - 76
  • [34] A Reliable Multicast MAC Protocol for Wi-Fi Direct 802.11 Networks
    Khan, Gul Zameen
    Gonzalez, Ruben
    Park, Eun-Chan
    Wu, Xin-Wen
    2015 EUROPEAN CONFERENCE ON NETWORKS AND COMMUNICATIONS (EUCNC), 2015, : 224 - 228
  • [35] Draft 802.11n Wi-Fi networks move to mainstream
    Wright, Maury
    EDN, 2007, 52 (10) : 14 - 14
  • [36] Get 16 radios in one WI-FI access point
    Electron Des, 2006, 27 (58):
  • [37] Wi-Fi User Profiling via Access Point Honeynets
    Ryan, Fergus
    Schukat, Michael
    2019 30TH IRISH SIGNALS AND SYSTEMS CONFERENCE (ISSC), 2019,
  • [38] Optimization of Wi-Fi Access Point Placement in an Indoor environment
    Chariete, Abderrahim
    Guillet, Valery
    Thiriet, Jean-Yves
    2016 13TH INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES FOR DISTRIBUTED SYSTEMS (NOTERE), 2016,
  • [39] Design and Implementation of Access Point for the Wi-Fi Broadcasting System
    Kim, Dong Hyun
    Sun, Sheng Hao
    Kim, Jong Deok
    2016 INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN), 2016, : 398 - 401
  • [40] A Trust-Based Cooperative System for Efficient Wi-Fi Radio Access Networks
    Raschella, Alessandro
    Eiza, Max Hashem
    Mackay, Michael
    Shi, Qi
    Banton, Matthew
    IEEE ACCESS, 2023, 11 : 136136 - 136149