WIDS - A Wireless Intrusion Detection System for Detecting Man-in-the-middle Attacks



Journal of Information System Security
Volume 1, Number 3 (2005)
Pages 1844
ISSN 1551-0123
Robert Shanley — Iowa State University, USA
G. Premkumar — Iowa State University, USA
Information Institute Publishing, Washington DC, USA




The dramatic growth in wireless networking has resulted in many organizations and government agencies installing networks with poor security configurations seriously jeopardizing the security of their wired networks. Intrusion detection becomes more important in wireless networks due to the inherent nature of the network. Wired networks typically implement monitoring at layer 3 while assuming that physical security can prevent access to layer 2 and below. By its very nature of broadcasting its presence and sending data in the open, wireless networks create security hazards at layer 2. Man-in-the-middle attacks using MAC address spoofing is one technique to take control of an access point and monitor all traffic. In this paper we examine the technique for this attack and develop an intrusion detection system to identify and warn against such attacks. Using an experimental setup the performance of the intrusion detection system is evaluated in different environmental contexts. The results of the experiment indicated that the system performed very well in most situations, except in the context of very high traffic where the slowness in the traffic data acquisition tool resulted in some errors.




Network Security, Intrusion Detection Systems, Wireless Networking, Man-in-the Middle Attack, MAC Address Spoofing




