DocumentCode
3006934
Title
An Experimental Evaluation of Over-The-Air (OTA) Wireless Intrusion Prevention Techniques
Author
Vartak, A. ; Ahmad, Sahar ; Gopinath, K.N.
Author_Institution
R&D Group, Pune, India
fYear
2007
fDate
7-12 Jan. 2007
Firstpage
1
Lastpage
7
Abstract
Wireless Local Area Networks (WLANs) can open certain security backdoors which cannot be mitigated by conventional security mechanisms such as firewalls. This has lead to the development and quick adoption of a new suite of products that specialize in securing a network from the WLAN based security threats. Such products, known as Wireless Intrusion Prevention System (WIPS), not only detect wireless intrusions, but can also prevent them. One of the popular methods used in a WIPS for intrusion prevention is Over-The-Air (OTA) prevention which involves the transmission of specially crafted Medium Access Control (MAC) level packets over the wireless medium. Although OTA prevention is generally based on known MAC level denial-of-service techniques, there is little information available on the strengths and limitations of such techniques in mitigating unauthorized communication. In this paper, we first provide a test-bed based experimental evaluation of several (four) OTA prevention techniques in mitigating unauthorized wireless communication. Experimental results demonstrate that: (i) none of the considered OTA techniques may individually be able to prevent all the wireless threat scenarios reliably, (ii) certain techniques can fail against devices from certain vendors, and, (iii) OTA techniques require continual transmission of MAC level packets for effective blockage. Finally, we discuss the implications of the experimental results on the design of a WIPS.
Keywords
access protocols; authorisation; telecommunication security; wireless LAN; MAC level denial-of-service techniques; OTA prevention techniques; WLAN based security threats; firewalls; medium access control; over-the-air prevention; wireless intrusion prevention system; wireless local area networks; Communication system security; Computer crime; Internet telephony; Jamming; Media Access Protocol; Radio frequency; Research and development; Switches; Wireless LAN; Wireless networks; experimental evaluation; intrusion prevention; wireless;
fLanguage
English
Publisher
ieee
Conference_Titel
Communication Systems Software and Middleware, 2007. COMSWARE 2007. 2nd International Conference on
Conference_Location
Bangalore
Print_ISBN
1-4244-0613-7
Type
conf
DOI
10.1109/COMSWA.2007.382464
Filename
4268107
Link To Document