Protecting Wireless Networks against a Denial of Service Attack Based on Virtual Jamming
Runsheng Chen, Jing Deng, Pramod K. Varshney · 2003
In the IEEE 802.11 MAC protocol [1], virtual carrier-sense and physical carrier-sense functions are used to determine the availability of the shared medium. The medium is considered idle only when both of these two functions indicate that the medium is idle. While the physical carrier-sense function uses the physical layer to sense the carrier, the virtual carrier-sense function is based on the Network Allocation Vector (NAV). Most IEEE 802.11 frames carry a duration field, which is used to reserve the medium for a fixed time period. The NAV is a timer that indicates the amount of time for which the medium has been reserved. Transmitting nodes set the NAV to the time for which they expect to use the medium, including the transmission time of all the frames in a sequence. Other nodes set up a process to count down the NAV. When the NAV is greater than zero, the virtual carrier-sense function indicates that the medium is busy. When the NAV reaches zero, the medium is reported to be idle. This mechanism, combined with the RTS/CTS exchange, is designed to reduce frame collisions and prevent the hidden terminal problem. However, when nodes set up the NAV values, they do not know whether the expected frame exchange will actually take place. Furthermore, they do not verify if the NAV value has reserved a time that is indeed necessary for the current operation. These are vulnerabilities that a misbehaving node may exploit to block neighboring nodes from accessing the shared medium for an extended period of time. In this work, we investigate these vulnerabilities and potential virtual jamming attacks made possible by them. We also propose a backwardcompatible solution to overcome these vulnerabilities.