The packet field of wireless local area network(WLAN)medium access control(MAC)layer is taken for the analytical object of detecting intrusion. An intrusion detection method of WLAN MAC layer is proposed based on the hidden Markov model(HMM). A three layers frame including console
server and agents is given; the data of WLAN MAC layer is used to model the HMM; then the normal data of WLAN is used to train the HMM and to memorialize the normal action of WLAN. An intrusion will be detected when the occuring probability of a packet data or a sequence of packet data is smaller than a given threshold. Experimental results show that the proposed method has low false positive rate and missing report rate when detecting the known attacks on WLAN MAC layers
and also detects unknown attacks.
关键词
Keywords
references
Andrew Lockhart. Snort-wireless [EB/OL]. [2009-01-15]. http:∥www. snort-wireless. org/.
Fatblock Working Group.WIDZ [EB/OL]. [2009-01-15].http:∥www.loud-fat-bloke. co.uk/w80211.html.
RABINER L R, JUANG B H. An introduction to hidden Markov models [J]. ASSP Magazine, 1986,3(1):4-16.
RABINER L R.A tutorial on hidden Markov models and selected applications in speech recognition[J]. Proceedings of the IEEE, 1989, 77(2):257-286.
WARRENDER C, FORREST S, PEARLMUTTER B. Detecting intrusions using system calls: alternative data models [C]∥Proceedings of the 1999 IEEE Symposium on Security and Privacy. Los Alamitos, CA, USA: IEEE Computer Society,1999:133-145.
IEEE. Telecommunications and information exchange between systems: local and metropolitan area networks-specific requirements part 11( wireless LAN medium access control(MAC)and physical layer(PHY)specifications 2007)[EB/OL]. [2009-01-02].http:∥standards.ieee.org/getieee802/download/802.11-2007.pdf.