• DocumentCode
    3346762
  • Title

    Detecting 802.11 MAC Layer Spoofing Using Received Signal Strength

  • Author

    Yong Sheng ; Tan, Kokkiong ; Guanling Chen ; Kotz, David ; Campbell, Arnett

  • Author_Institution
    Google, Inc., Mountain View, CA
  • fYear
    2008
  • fDate
    13-18 April 2008
  • Abstract
    MAC addresses can be easily spoofed in 802.11 wireless LANs. An adversary can exploit this vulnerability to launch a large number of attacks. For example, an attacker may masquerade as a legitimate access point to disrupt network services or to advertise false services, tricking nearby wireless stations. On the other hand, the received signal strength (RSS) is a measurement that is hard to forge arbitrarily and it is highly correlated to the transmitter´s location. Assuming the attacker and the victim are separated by a reasonable distance, RSS can be used to differentiate them to detect MAC spoofing, as recently proposed by several researchers. By analyzing the RSS pattern of typical 802.11 transmitters in a 3-floor building covered by 20 air monitors, we observed that the RSS readings followed a mixture of multiple Gaussian distributions. We discovered that this phenomenon was mainly due to antenna diversity, a widely-adopted technique to improve the stability and robustness of wireless connectivity. This observation renders existing approaches ineffective because they assume a single RSS source. We propose an approach based on Gaussian mixture models, building RSS profiles for spoofing detection. Experiments on the same testbed show that our method is robust against antenna diversity and significantly outperforms existing approaches. At a 3% false positive rate, we detect 73.4%, 89.6% and 97.8% of attacks using the three proposed algorithms, based on local statistics of a single AM, combining local results from AMs, and global multi-AM detection, respectively.
  • Keywords
    Gaussian distribution; access protocols; wireless LAN; 802.11 MAC layer spoofing; 802.11 transmitters; 802.11 wireless LAN; Gaussian mixture models; antenna diversity; false services; multiple Gaussian distributions; network services; received signal strength; wireless connectivity; wireless stations; Antenna measurements; Communications Society; Cryptography; Diversity reception; Microprogramming; Radio frequency; Radio transmitters; Robust stability; Semiconductor device measurement; Tin;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM 2008. The 27th Conference on Computer Communications. IEEE
  • Conference_Location
    Phoenix, AZ
  • ISSN
    0743-166X
  • Print_ISBN
    978-1-4244-2025-4
  • Type

    conf

  • DOI
    10.1109/INFOCOM.2008.239
  • Filename
    4509834