...
首页> 外文期刊>Computer Communications >A solution to detect the existence of a malicious rogue AP
【24h】

A solution to detect the existence of a malicious rogue AP

机译:一种检测恶意流氓AP存在的解决方案

获取原文
获取原文并翻译 | 示例

摘要

A malicious rogue AP works like an evil twin; however, instead of using a good twin to connect to the Internet, a malicious rogue AP uses a 3G/4G mobile network to connect to the Internet. While administrators have sufficient information to distinguish rogue APs, it is difficult for client users to know whether they are using a wireless network with malicious an AP. To solve evil twin problems at client-side, many solutions make their detection based on some time metrics or evil twin features. However, time metrics may be influenced by pre-fetching, network topology, traffic volume, or network types. And the evil twin features such as packet forwarding cannot distinguish malicious rogue APs because they behave just like a legitimate AP. To solve above problem, this paper proposes an active user-side solution, called Wi-Fi Malicious Rogue AP Finder (RAF). RAF can be installed in any computer or laptop without any special requirement. RAF detect the existence of a malicious rogue AP based on different reverse tracerout e information collected by a remote server. To the best of our knowledge, RAF is the first one client-side solution which could detect malicious rogue APs based on path information but not time metrics.
机译:恶意流氓AP像一个邪恶的双胞胎工作;但是,不使用良好的双胞胎连接到互联网,恶意流氓AP使用3G / 4G移动网络连接到互联网。虽然管理员具有足够的信息来区分流氓APS,但客户端用户很难知道他们是否正在使用具有恶意AP的无线网络。为了解决客户端的邪恶双胞胎问题,许多解决方案基于一些时间指标或邪恶的双胞胎特征来进行检测。然而,时间指标可能受预取,网络拓扑,流量或网络类型的影响。而邪恶的双胞胎特征如包转发不能区分恶意流氓AP,因为它们就像合法的AP一样。为了解决上述问题,本文提出了一个活跃的用户端解决方案,称为Wi-Fi恶意流氓AP Finder(RAF)。 RAF可以安装在任何计算机或笔记本电脑中,没有任何特殊要求。 RAF根据远程服务器收集的不同反向描绘e信息检测恶意rogue AP的存在。据我们所知,RAF是第一个客户端解决方案,它可以根据路径信息而不是时间指标来检测恶意流氓AP。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号