• DocumentCode
    1966637
  • Title

    RAPiD: An indirect rogue access points detection system

  • Author

    Qu, Guangzhi ; Nefcy, M.M.

  • Author_Institution
    Comput. Sci. & Eng. Dept., Oakland Univ., Rochester, MI, USA
  • fYear
    2010
  • fDate
    9-11 Dec. 2010
  • Firstpage
    9
  • Lastpage
    16
  • Abstract
    Rogue wireless access points (RWAPs) bypass physical endpoint security of local area networks and present significant security threats by creating network attack vectors behind firewalls, exposing confidential information, and allowing unauthorized utilization of network resources. A family of more promising methods detects RWAPs indirectly by identifying unauthorized wireless hosts through using temporal TCP/IP characteristics of SYN, FIN, and ACK local round trip times (LRTT). Thus any unauthorized wireless hosts found indicate the presence of a RWAP. With these session-based temporal characteristics, traffic from wireless and wired nodes can be differentiated by exploiting the fundamental differences between Ethernet and 802.11b/g/n. In this work, we empirically analyzed extensive LRTT data and designed a light system - RAPiD with several algorithms for effective wireless hosts detection. Ultimately, SYN, FIN, and ACK LRTTs can be compared against each other to discover wireless hosts regardless of network speeds. The results show first time how merging 802.11n wireless technology can still be accurately separated from Ethernet hosts, even as it continues to improve.
  • Keywords
    authorisation; computer network security; telecommunication traffic; transport protocols; wireless LAN; 802.11b/g/n; 802.11n wireless technology merging; ACK local round trip times; Ethernet; FIN; RAPiD; SYN; firewall; indirect rogue access points detection system; local area network; network attack vector; physical endpoint security; rogue wireless access points; security threat; session-based temporal characteristics; temporal TCP/IP characteristics; traffic; unauthorized wireless host identification; wireless hosts detection; Classification algorithms; Communication system security; Equations; Ethernet networks; IP networks; Logic gates; Wireless communication; 802.11b/g/n; Rogue Access Point; TCP/IP; Temporal Analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Performance Computing and Communications Conference (IPCCC), 2010 IEEE 29th International
  • Conference_Location
    Albuquerque, NM
  • ISSN
    1097-2641
  • Print_ISBN
    978-1-4244-9330-2
  • Type

    conf

  • DOI
    10.1109/PCCC.2010.5682342
  • Filename
    5682342