MEDIUM ACCESS CONTROL SPOOF DETECTION AND PREVENTION ALGORITHM (MAC SDP DoS) FOR SPOOFING ATTACKS IN WLAN
نویسندگان
چکیده
Wireless Local Area Network (WLAN) is widely used today because of its mobility and ease of deployment. Providing complete security to the WLAN users is a challenge due to the open nature and undefined boundaries of the wireless networks. This paper is intended to protect the 802.11 WLAN environments from Medium Access Control (MAC) layer Denial of Service (DoS) attacks especially, the deauthentication and disassociation attacks. This paper proposes an algorithm to detect and prevent deauthentication/ disassociation DoS attacks. These attacks are launched due to the vulnerability of the management frames which carries the MAC address of the client or Access Points (AP) that are not encrypted. So, there is an urgent requirement for a security mechanism to prevent MAC layer DoS attacks which does not require any change in the hardware or protocols. In this paper, an algorithm is proposed to detect and prevent MAC spoofing DoS attacks with an exchange of passkey values. The proposed algorithm, MAC Spoof Detection and Prevention (MAC SDP DoS) is compared with the existing algorithm which is used for MAC spoof detection. This algorithm is validated by NS2, a network simulator tool. The proposed algorithm improves the performance of WLAN by increasing the throughput and reduces the packet resend rates to a greater extend. The recovery time has also been reduced compared with the existing method.
منابع مشابه
Intrusion Detection in MANET using Neural Networks and ZSBT
Mobile ad-hoc network is a collection of mobile nodes that organize themselves into a network without any predefined infrastructure. The characteristics of MANET are dynamic topology; bandwidth and energy constrained and limited physical security. Due to the dynamic nature of the network, these networks can be easily vulnerable to attacks. Many type of attacks can threat the MANET and the class...
متن کاملWLAN Intrusion Detection System
This is an implementation of the Wireless LAN Intrusion Detection System (WIDS ) using clock-skews as a fingerprinting property as suggested by Jana-Kasera [1]. Our objective is to detect the presence of a fake access point (AP) in a Wireless LAN (WLAN). Use of clock -skew enables us to effectively detect Medium Access Control (MAC) Address spoofing. The principle used in this project is that c...
متن کاملRogue Access Point Detection Using Time Stamp
This is an implementation of the Wireless LAN Intrusion Detection System (WIDS ) using clock-skews as a fingerprinting property as suggested by Jana-Kasera [1]. Our objective is to detect the presence of a fake access point (AP) in a Wireless LAN (WLAN). Use of clock -skew enables us to effectively detect Medium Access Control (MAC) Address spoofing. The principle used in this project is that c...
متن کاملOn investigating ARP spoofing security solutions
The address resolution protocol (ARP) has proven to work well under regular circumstances, but it was not designed to cope with malicious hosts. By performing ARP spoofing attacks, a malicious host can either impersonate another host [man-in-the-middle attack (MiM)] and gain access to sensitive information, or perform denial of service attack (DoS) on target hosts. Several security solutions, s...
متن کاملPacket Resonance Strategy: A Spoof Attack Detection and Prevention Mechanism in Cloud Computing Environment
Distributed Denial of Service (DDoS) is a major threat to server availability. The attackers hide from view by impersonating their IP addresses as the legitimate users. This Spoofed IP helps the attacker to pass through the authentication phase and to launch the attack. Surviving spoof detection techniques could not resolve different styles of attacks. Packet Resonance Strategy (PRS) armed to d...
متن کامل