DocumentCode
1676346
Title
Substantiating Security Threats Using Group Outlier Detection Techniques
Author
Sithirasenan, Elankayer ; Muthukkumarasamy, Vallipuram
Author_Institution
Sch. of Inf. & Commun. Technol., Griffith Univ., Gold Coast, QLD
fYear
2008
Firstpage
1
Lastpage
6
Abstract
With the increasing dependence on wireless LANs (WLANs), businesses, educational institutions and other organizations are in need of a reliable security mechanism. The latest security protocol, the IEEE 802.11i assures rigid security for WLANs with the support of IEEE 802.1x protocol for authentication, authorization and key distribution. Nevertheless, fresh security threats are emerging often to oust these new defense mechanisms. Further, many organizations based on superficial vendor literature, believe their wireless security is sufficient enough to prevent any unauthorized access. Having wide ranging options for security configurations, users are camouflaged into profound uncertainty. This volatile state of affairs has prevented many organizations from fully deploying WLANs for their secure communication needs, though WLANs may be cost effective and flexible. In this paper, we present an anomaly based mechanism to detect and substantiate both known and unknown security threats in WLANs. Our method exploits both timing and behavioral anomalies. We first observe for timing and/or behavior anomalies during the security association process and use outlier based data association approaches to substantiate their legitimacy. The proposed concept was tested on our experimental setup and the results obtained from EAP TLS authenticated hosts are presented here.
Keywords
authorisation; cryptographic protocols; message authentication; telecommunication security; wireless LAN; IEEE 802.11i; IEEE 802.1x protocol; authentication; authorization; data association; group outlier detection technique; key distribution; secure communication; security protocol; wireless LAN; Access protocols; Authentication; Authorization; Communication system security; Costs; Data security; Educational institutions; Timing; Uncertainty; Wireless LAN;
fLanguage
English
Publisher
ieee
Conference_Titel
Global Telecommunications Conference, 2008. IEEE GLOBECOM 2008. IEEE
Conference_Location
New Orleans, LO
ISSN
1930-529X
Print_ISBN
978-1-4244-2324-8
Type
conf
DOI
10.1109/GLOCOM.2008.ECP.420
Filename
4698195
Link To Document