DocumentCode
614706
Title
The effect of probe interval estimation on attack detection performance of a WLAN independent intrusion detection system
Author
Milliken, Jonny ; Selis, Valerio ; Yap, K.M. ; Marshall, Andrew
Author_Institution
Dept. of Electr. & Electron. Eng., Queens Univ. Belfast, Belfast, UK
fYear
2012
fDate
8-10 Oct. 2012
Firstpage
1
Lastpage
6
Abstract
A new niche of densely populated, unprotected networks is becoming more prevalent in public areas such as Shopping Malls, defined here as independent open-access networks, which have attributes that make attack detection more challenging than in typical enterprise networks. To address these challenges, new detection systems which do not rely on knowledge of internal device state are investigated here. This paper shows that this lack of state information requires an additional metric (The exchange timeout window) for detection of WLAN Denial of Service Probe Flood attacks. Variability in this metric has a significant influence on the ability of a detection system to reliably detect the presence of attacks. A parameter selection method is proposed which is shown to provide reliability and repeatability in attack detection in WLANs. Results obtained from ongoing live trials are presented that demonstrate the importance of accurately estimating probe request and probe response timeouts in future Independent Intrusion Detection Systems.
Keywords
computer network reliability; computer network security; parameter estimation; wireless LAN; WLAN; attack detection performance; attack detection reliability; attack detection repeatability; denial of service probe flood attacks; exchange timeout window; independent intrusion detection system; parameter selection method; probe interval estimation effect; state information; unprotected networks; Frames; Intrusion; MAC; Probe; WLAN;
fLanguage
English
Publisher
iet
Conference_Titel
Wireless Communications and Applications (ICWCA 2012), IET International Conference on
Conference_Location
Kuala Lumpur
Electronic_ISBN
978-1-84919-550-8
Type
conf
DOI
10.1049/cp.2012.2110
Filename
6552453
Link To Document