Title of article :
A wireless multi-step attack pattern recognition method for WLAN
Author/Authors :
Chen، نويسنده , , Guanlin and Zhang، نويسنده , , Yujia and Wang، نويسنده , , Can، نويسنده ,
Issue Information :
روزنامه با شماره پیاپی سال 2014
Abstract :
Intrusion detection and prevention technology has been broadly applied to wired networks as an important means to protect network security. However, few work in this area has been extended to the WLAN. In this paper, we propose a wireless multi-step attack pattern recognition method (WMAPRM) based on correlation analysis with the main attributes of the IEEE 802.11 frame. The method consists of six steps: clustering wireless intrusion alerts, constructing a global attack database, building candidate attack chains, filtering candidate attack chains, correlating multi-step attack behaviors and recognizing multi-step attack patterns. Experimental results in real world environment show that WMAPRM is capable of identifying highly correlated multi-step attack patterns such as WEP crack with ARP + Deauthentication Flood, WEP crack with wesside-ng, config file stealing attack and authentication session hijack attack etc. The method is expected to improve both wireless intrusion detection and prevention performance in practical WLAN security scenarios.
Keywords :
Multi-stage attack , Pattern recognition , WLAN , network security , Correlation analysis
Journal title :
Expert Systems with Applications
Journal title :
Expert Systems with Applications