...
首页> 外文期刊>IEEE transactions on network and service management >EvilScout: Detection and Mitigation of Evil Twin Attack in SDN Enabled WiFi
【24h】

EvilScout: Detection and Mitigation of Evil Twin Attack in SDN Enabled WiFi

机译:EvilScout:在启用SDN的WiFi中检测和缓解邪恶双胞胎攻击

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Spoofing the identity of a WiFi access point (AP) is trivial. Consequently, an adversary can impersonate the legitimate AP (LAP) by mimicking its network name (SSID) and MAC address (BSSID). This fake AP is called the evil twin. An evil twin can perform multiple attacks such as man-in-the-middle (MITM) attack between the LAP and a wireless client as well as service blocking of LAP. Existing solutions rely on the collection and calculation of information with the AP and/or client for finding evidence of evil twins in the WiFi network. Some of them require additional hardware to acquire further information that cannot be provided by the AP/client. In this paper, we propose "EvilScout," an evil twin detection and mitigation framework that utilizes the information of the IP-prefix distribution by the LAP. EvilScout exploits the SDN potential for detection of an evil twin without the need of any additional hardware or modifications at the AP or client. Additionally, the information that becomes available at the SDN controller enables simplified and more accurate evil twin detection. This paper presents the implementation of EvilScout over a real SDN WiFi testbed with an actual evil twin. We verify the successful detection of the evil twin with high accuracy and low processing cost at the SDN WiFi. We perform a rigorous analysis of the evil twin in different WiFi setups and discover a new "AP Service Blocking" attack by the evil twin adversary in the WPA2 protected WiFi for the first time.
机译:欺骗WiFi接入点(AP)的身份很简单。因此,攻击者可以通过模仿其网络名称(SSID)和MAC地址(BSSID)来冒充合法的AP(LAP)。这个伪造的AP被称为邪恶双胞胎。邪恶的双胞胎可以执行多种攻击,例如LAP与无线客户端之间的中间人(MITM)攻击以及LAP的服务阻止。现有的解决方案依靠与AP和/或客户端的信息收集和计算来寻找WiFi网络中邪恶双胞胎的证据。其中一些需要额外的硬件来获取AP /客户端无法提供的更多信息。在本文中,我们提出“ EvilScout”,这是一个邪恶双胞胎检测和缓解框架,该框架利用了LAP的IP前缀分配信息。 EvilScout利用SDN潜力检测邪恶双胞胎,而无需在AP或客户端进行任何其他硬件或修改。此外,SDN控制器上可用的信息可简化和更准确地检测邪恶双胞胎。本文介绍了在带有实际邪恶双胞胎的真实SDN WiFi测试平台上实现EvilScout的方法。我们验证了在SDN WiFi上以高精度和低处理成本成功检测到邪恶双胞胎的情况。我们对不同WiFi设置中的邪恶双胞胎进行了严格的分析,并首次在WPA2保护的WiFi中发现了由邪恶双胞胎对手发起的新的“ AP服务阻止”攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号