Wireless local area network management frame denial- of-service attack detection and mitigation schemes

Wireless Local Area Networks (WLAN) are increasingly deployed and in widespread use worldwide due to its convenience and low cost. However, due to the broadcasting and the shared nature of the wireless medium, WLANs are vulnerable to a myriad of attacks. Although there have been concerted efforts to...

Full description

Saved in:
Bibliographic Details
Main Author: Abdallah Elhigazi, Abdallah Elhigazi
Format: Thesis
Language:English
Published: 2020
Subjects:
Online Access:http://eprints.utm.my/id/eprint/98238/1/AbdallahElhigaziAbdallahPSC2020.pdf
http://eprints.utm.my/id/eprint/98238/
http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:143721
Tags: Add Tag
No Tags, Be the first to tag this record!
id my.utm.98238
record_format eprints
spelling my.utm.982382022-11-23T08:07:32Z http://eprints.utm.my/id/eprint/98238/ Wireless local area network management frame denial- of-service attack detection and mitigation schemes Abdallah Elhigazi, Abdallah Elhigazi TK Electrical engineering. Electronics Nuclear engineering Wireless Local Area Networks (WLAN) are increasingly deployed and in widespread use worldwide due to its convenience and low cost. However, due to the broadcasting and the shared nature of the wireless medium, WLANs are vulnerable to a myriad of attacks. Although there have been concerted efforts to improve the security of wireless networks over the past years, some attacks remain inevitable. Attackers are capable of sending fake de-authentication or disassociation frames to terminate the session of active users; thereby leading to denial of service, stolen passwords, or leakage of sensitive information amongst many other cybercrimes. The detection of such attacks is crucial in today's critical applications. Many security mechanisms have been proposed to effectively detect these issues, however, they have been found to suffer limitations which have resulted in several potential areas of research. This thesis aims to address the detection of resource exhaustion and masquerading DoS attacks problems, and to construct several schemes that are capable of distinguishing between benign and fake management frames through the identification of normal behavior of the wireless stations before sending any authentication and de-authentication frames. Thus, this thesis proposed three schemes for the detection of resource exhaustion and masquerading DoS attacks. The first scheme was a resource exhaustion DoS attacks detection scheme, while the second was a de- authentication and disassociation detection scheme. The third scheme was to improve the detection rate of the de-authentication and disassociation detection scheme using feature derived from an unsupervised method for an increased detection rate. The effectiveness of the performance of the proposed schemes was measured in terms of detection accuracy under sophisticated attack scenarios. Similarly, the efficiency of the proposed schemes was measured in terms of preserving the resources of the access point such as memory consumptions and processing time. The validation and analysis were done through experimentation, and the results showed that the schemes have the ability to protect wireless infrastructure networks against denial of service attacks. 2020 Thesis NonPeerReviewed application/pdf en http://eprints.utm.my/id/eprint/98238/1/AbdallahElhigaziAbdallahPSC2020.pdf Abdallah Elhigazi, Abdallah Elhigazi (2020) Wireless local area network management frame denial- of-service attack detection and mitigation schemes. PhD thesis, Universiti Teknologi Malaysia, Faculty of Engineering - School of Computing. http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:143721
institution Universiti Teknologi Malaysia
building UTM Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Teknologi Malaysia
content_source UTM Institutional Repository
url_provider http://eprints.utm.my/
language English
topic TK Electrical engineering. Electronics Nuclear engineering
spellingShingle TK Electrical engineering. Electronics Nuclear engineering
Abdallah Elhigazi, Abdallah Elhigazi
Wireless local area network management frame denial- of-service attack detection and mitigation schemes
description Wireless Local Area Networks (WLAN) are increasingly deployed and in widespread use worldwide due to its convenience and low cost. However, due to the broadcasting and the shared nature of the wireless medium, WLANs are vulnerable to a myriad of attacks. Although there have been concerted efforts to improve the security of wireless networks over the past years, some attacks remain inevitable. Attackers are capable of sending fake de-authentication or disassociation frames to terminate the session of active users; thereby leading to denial of service, stolen passwords, or leakage of sensitive information amongst many other cybercrimes. The detection of such attacks is crucial in today's critical applications. Many security mechanisms have been proposed to effectively detect these issues, however, they have been found to suffer limitations which have resulted in several potential areas of research. This thesis aims to address the detection of resource exhaustion and masquerading DoS attacks problems, and to construct several schemes that are capable of distinguishing between benign and fake management frames through the identification of normal behavior of the wireless stations before sending any authentication and de-authentication frames. Thus, this thesis proposed three schemes for the detection of resource exhaustion and masquerading DoS attacks. The first scheme was a resource exhaustion DoS attacks detection scheme, while the second was a de- authentication and disassociation detection scheme. The third scheme was to improve the detection rate of the de-authentication and disassociation detection scheme using feature derived from an unsupervised method for an increased detection rate. The effectiveness of the performance of the proposed schemes was measured in terms of detection accuracy under sophisticated attack scenarios. Similarly, the efficiency of the proposed schemes was measured in terms of preserving the resources of the access point such as memory consumptions and processing time. The validation and analysis were done through experimentation, and the results showed that the schemes have the ability to protect wireless infrastructure networks against denial of service attacks.
format Thesis
author Abdallah Elhigazi, Abdallah Elhigazi
author_facet Abdallah Elhigazi, Abdallah Elhigazi
author_sort Abdallah Elhigazi, Abdallah Elhigazi
title Wireless local area network management frame denial- of-service attack detection and mitigation schemes
title_short Wireless local area network management frame denial- of-service attack detection and mitigation schemes
title_full Wireless local area network management frame denial- of-service attack detection and mitigation schemes
title_fullStr Wireless local area network management frame denial- of-service attack detection and mitigation schemes
title_full_unstemmed Wireless local area network management frame denial- of-service attack detection and mitigation schemes
title_sort wireless local area network management frame denial- of-service attack detection and mitigation schemes
publishDate 2020
url http://eprints.utm.my/id/eprint/98238/1/AbdallahElhigaziAbdallahPSC2020.pdf
http://eprints.utm.my/id/eprint/98238/
http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:143721
_version_ 1751536167062339584
score 13.211869