Title :
RAPiD: An indirect rogue access points detection system
Author :
Qu, Guangzhi ; Nefcy, M.M.
Author_Institution :
Comput. Sci. & Eng. Dept., Oakland Univ., Rochester, MI, USA
Abstract :
Rogue wireless access points (RWAPs) bypass physical endpoint security of local area networks and present significant security threats by creating network attack vectors behind firewalls, exposing confidential information, and allowing unauthorized utilization of network resources. A family of more promising methods detects RWAPs indirectly by identifying unauthorized wireless hosts through using temporal TCP/IP characteristics of SYN, FIN, and ACK local round trip times (LRTT). Thus any unauthorized wireless hosts found indicate the presence of a RWAP. With these session-based temporal characteristics, traffic from wireless and wired nodes can be differentiated by exploiting the fundamental differences between Ethernet and 802.11b/g/n. In this work, we empirically analyzed extensive LRTT data and designed a light system - RAPiD with several algorithms for effective wireless hosts detection. Ultimately, SYN, FIN, and ACK LRTTs can be compared against each other to discover wireless hosts regardless of network speeds. The results show first time how merging 802.11n wireless technology can still be accurately separated from Ethernet hosts, even as it continues to improve.
Keywords :
authorisation; computer network security; telecommunication traffic; transport protocols; wireless LAN; 802.11b/g/n; 802.11n wireless technology merging; ACK local round trip times; Ethernet; FIN; RAPiD; SYN; firewall; indirect rogue access points detection system; local area network; network attack vector; physical endpoint security; rogue wireless access points; security threat; session-based temporal characteristics; temporal TCP/IP characteristics; traffic; unauthorized wireless host identification; wireless hosts detection; Classification algorithms; Communication system security; Equations; Ethernet networks; IP networks; Logic gates; Wireless communication; 802.11b/g/n; Rogue Access Point; TCP/IP; Temporal Analysis;
Conference_Titel :
Performance Computing and Communications Conference (IPCCC), 2010 IEEE 29th International
Conference_Location :
Albuquerque, NM
Print_ISBN :
978-1-4244-9330-2
DOI :
10.1109/PCCC.2010.5682342