کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
382356 660760 2014 9 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
A wireless multi-step attack pattern recognition method for WLAN
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر هوش مصنوعی
پیش نمایش صفحه اول مقاله
A wireless multi-step attack pattern recognition method for WLAN
چکیده انگلیسی


• We propose a novel wireless multi-step attack pattern recognition method.
• Hyper alerts are defined to improve the recognition of wireless multi-step attacks.
• The correlation between two alerts is uncovered by wireless alert correlativity.
• The method can effectively identify typical wireless multi-step attack patterns.

Intrusion detection and prevention technology has been broadly applied to wired networks as an important means to protect network security. However, few work in this area has been extended to the WLAN. In this paper, we propose a wireless multi-step attack pattern recognition method (WMAPRM) based on correlation analysis with the main attributes of the IEEE 802.11 frame. The method consists of six steps: clustering wireless intrusion alerts, constructing a global attack database, building candidate attack chains, filtering candidate attack chains, correlating multi-step attack behaviors and recognizing multi-step attack patterns. Experimental results in real world environment show that WMAPRM is capable of identifying highly correlated multi-step attack patterns such as WEP crack with ARP + Deauthentication Flood, WEP crack with wesside-ng, config file stealing attack and authentication session hijack attack etc. The method is expected to improve both wireless intrusion detection and prevention performance in practical WLAN security scenarios.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Expert Systems with Applications - Volume 41, Issue 16, 15 November 2014, Pages 7068–7076
نویسندگان
, , ,