An Anomaly based Wireless Intrusion Detection System | Davide Papini
| Abstract | Wireless networks have shown several security holes and many weaknesses since the standard has been released. Such weaknesses come directly from design and security algorithms flaws and from undefined behavior due to unusual frame values. Moreover wireless promotes malicious activity since network is no more confined into the wires but is spread over the air out in the open, beyond houses or companies walls.
Anomaly based Intrusion Detection Systems have proved to be very effective since they detect suspicious trac just by comparison with the normal one. The purpose of this project is to show that employing accurate and precise features of different communication layers, and cross referencing their data, could be very effective in detecting attacks that usually are very hard to detect. As a matter of fact such attacks usually exploit single layer vulnerabilities, therefore anomaly detection with single layer features can be often useless.
A monitor application has been developed and it has been used to gather data from different prepared scenarios. Afterward analysis has shown that anomalies in gathered traffic were remarkable, consistent and rather easy to track. Along with this performance has been evaluated in terms of real time application and packet loss. Moreover requirements of a fully functional anomaly based intrusion detection system were assessed. Despite hardware availability for developing and testing was limited, results are promising and they show that an effective Wireless IDS can be developed. | Type | Master's thesis [Academic thesis] | Year | 2008 | Publisher | Technical University of Denmark, DTU Informatics, E-mail: reception@imm.dtu.dk | Address | Asmussens Alle, Building 305, DK-2800 Kgs. Lyngby, Denmark | Series | IMM-M.Sc.-2008-110 | Note | DTU supervisor: Robin Sharp, ris@imm.dtu.dk, DTU Informatics | Electronic version(s) | [pdf] | Publication link | http://www.imm.dtu.dk/English.aspx | BibTeX data | [bibtex] | IMM Group(s) | Computer Science & Engineering |
|