首页> 外文期刊>Information Forensics and Security, IEEE Transactions on >Active User-Side Evil Twin Access Point Detection Using Statistical Techniques
【24h】

Active User-Side Evil Twin Access Point Detection Using Statistical Techniques

机译:使用统计技术的主动用户端邪恶双接入点检测

获取原文
获取原文并翻译 | 示例

摘要

In this paper, we consider the problem of “evil twin” attacks in wireless local area networks (WLANs). An evil twin is essentially a rogue (phishing) Wi-Fi access point (AP) that looks like a legitimate one (with the same SSID). It is set up by an adversary, who can eavesdrop on wireless communications of users'' Internet access. Existing evil twin detection solutions are mostly for wireless network administrators to verify whether a given AP is in an authorized list or not, instead of for a wireless client to detect whether a given AP is authentic or evil. Such administrator-side solutions are limited, expensive, and not available for many scenarios. Thus, a lightweight, effective, and user-side solution is highly desired. In this work, we propose a novel user-side evil twin detection technique that outperforms traditional administrator-side detection methods in several aspects. Unlike previous approaches, our technique does not need a known authorized AP/host list, thus it is suitable for users to identify and avoid evil twins. Our technique does not strictly rely on training data of target wireless networks, nor depend on the types of wireless networks. We propose to exploit fundamental communication structures and properties of such evil twin attacks in wireless networks and to design new active, statistical and anomaly detection algorithms. Our preliminary evaluation in real-world widely deployed 802.11b and 802.11 g wireless networks shows very promising results. We can identify evil twins with a very high detection rate while maintaining a very low false positive rate.
机译:在本文中,我们考虑了无线局域网(WLAN)中的“邪恶双胞胎”攻击问题。邪恶双胞胎本质上是流氓(网络钓鱼)Wi-Fi接入点(AP),看起来像合法的(具有相同的SSID)。它是由一个对手建立的,该对手可以窃听用户Internet访问的无线通信。现有的邪恶双胞胎检测解决方案主要用于无线网络管理员,以验证给定的AP是否在授权列表中,而不是让无线客户端检测给定的AP是真实的还是邪恶的。这样的管理员端解决方案是有限的,昂贵的,并且不适用于许多情况。因此,非常需要轻量,有效和用户方的解决方案。在这项工作中,我们提出了一种新颖的用户端邪恶孪生检测技术,该技术在多个方面都优于传统的管理员端检测方法。与以前的方法不同,我们的技术不需要已知的授权AP /主机列表,因此适合于用户识别并避免邪恶的双胞胎。我们的技术不严格依赖于目标无线网络的训练数据,也不依赖于无线网络的类型。我们建议利用无线网络中此类邪恶双胞胎攻击的基本通信结构和特性,并设计新的主动,统计和异常检测算法。我们对在现实世界中广泛部署的802.11b和802.11 g无线网络进行的初步评估显示了非常有希望的结果。我们可以以很高的检出率识别邪恶的双胞胎,同时保持非常低的假阳性率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号