arrow
Return

Active User-Side Evil Twin Access Point Detection Using Statistical Techniques

delete2012-10-01
delete53
PRE
AI
杨超 cover
杨超 (Chao Yang) *
Y
Yimin Song
G
Guofei Gu
DOI:10.1109/TIFS.2012.2207383delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
In this paper, we consider the problem of evil twin attacks in wireless local area networks (WLANs). An evil twin is essentially a rogue (phishing) Wi-Fi access point (AP) that looks like a legitimate one (with the same SSID). It is set up by an adversary, who can eavesdrop on wireless communications of users' Internet access. Existing evil twin detection solutions are mostly for wireless network administrators to verify whether a given AP is in an authorized list or not, instead of for a wireless client to detect whether a given AP is authentic or evil. Such administrator-side solutions are limited, expensive, and not available for many scenarios. Thus, a lightweight, effective, and user-side solution is highly desired. In this work, we propose a novel user-side evil twin detection technique that outperforms traditional administrator-side detection methods in several aspects. Unlike previous approaches, our technique does not need a known authorized AP/host list, thus it is suitable for users to identify and avoid evil twins. Our technique does not strictly rely on training data of target wireless networks, nor depend on the types of wireless networks. We propose to exploit fundamental communication structures and properties of such evil twin attacks in wireless networks and to design new active, statistical and anomaly detection algorithms. Our preliminary evaluation in real-world widely deployed 802.11b and 802.11 g wireless networks shows very promising results. We can identify evil twins with a very high detection rate while maintaining a very low false positive rate.
Keywords:
Evil twin attack
rogue AP detection
wireless security
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.3K
Citations:
2.3W

Organization

T
Texas A&M University System
Scholars:
4.4W
Papers: 4.0W
Citations: 4.0K
Cited Papers

Cited Papers

A Timing-Based Scheme for Rogue AP Detection
err2011-11-01
err95
errOAAI
errHan, Hao; Sheng, Bo; Tan, Chiu C.; Li, Qun; Lu, Sanglu
errShare
errSave
Wide-area Internet traffic patterns and characteristics
err1997-01-01
err656
PREAI
errThompson, K; Miller, GJ; Wilder, R
errShare
errSave
errShare
errSave
FSL
err
IF0
err
err0
PREAI
err
errShare
errSave
Positive immunohistochemical staining of p53 and cyclin D in advanced mouse skin tumors, but not in precancerous lesions produced by benzo[a]pyrene
err1995-01-01
err0
PREAI
errS.I. Mitsunaga; S.Y. Zhang; B.A. Ruggeri; I. Gimenez-Conti; A.I. Robles; C.J. Conti; A.J.P. Klein-Szanto
errShare
errSave
researcher View more