DocumentCode :
1966637
Title :
RAPiD: An indirect rogue access points detection system
Author :
Qu, Guangzhi ; Nefcy, M.M.
Author_Institution :
Comput. Sci. & Eng. Dept., Oakland Univ., Rochester, MI, USA
fYear :
2010
fDate :
9-11 Dec. 2010
Firstpage :
9
Lastpage :
16
Abstract :
Rogue wireless access points (RWAPs) bypass physical endpoint security of local area networks and present significant security threats by creating network attack vectors behind firewalls, exposing confidential information, and allowing unauthorized utilization of network resources. A family of more promising methods detects RWAPs indirectly by identifying unauthorized wireless hosts through using temporal TCP/IP characteristics of SYN, FIN, and ACK local round trip times (LRTT). Thus any unauthorized wireless hosts found indicate the presence of a RWAP. With these session-based temporal characteristics, traffic from wireless and wired nodes can be differentiated by exploiting the fundamental differences between Ethernet and 802.11b/g/n. In this work, we empirically analyzed extensive LRTT data and designed a light system - RAPiD with several algorithms for effective wireless hosts detection. Ultimately, SYN, FIN, and ACK LRTTs can be compared against each other to discover wireless hosts regardless of network speeds. The results show first time how merging 802.11n wireless technology can still be accurately separated from Ethernet hosts, even as it continues to improve.
Keywords :
authorisation; computer network security; telecommunication traffic; transport protocols; wireless LAN; 802.11b/g/n; 802.11n wireless technology merging; ACK local round trip times; Ethernet; FIN; RAPiD; SYN; firewall; indirect rogue access points detection system; local area network; network attack vector; physical endpoint security; rogue wireless access points; security threat; session-based temporal characteristics; temporal TCP/IP characteristics; traffic; unauthorized wireless host identification; wireless hosts detection; Classification algorithms; Communication system security; Equations; Ethernet networks; IP networks; Logic gates; Wireless communication; 802.11b/g/n; Rogue Access Point; TCP/IP; Temporal Analysis;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Performance Computing and Communications Conference (IPCCC), 2010 IEEE 29th International
Conference_Location :
Albuquerque, NM
ISSN :
1097-2641
Print_ISBN :
978-1-4244-9330-2
Type :
conf
DOI :
10.1109/PCCC.2010.5682342
Filename :
5682342
Link To Document :
بازگشت