Rogue access point detection using temporal traffic characteristics
Raheem Beyah, S. Kangude, Guosong Yu, B. Strickland, John A. Copeland · 2005
As the cost of IEEE 802.11 hardware continues to fall, the appeal of inserting unauthorized wireless access into enterprise networks grows. These rogue access points (AP) expose the enterprise network to a barrage of security vulnerabilities in that they are typically connected to a network port behind the firewall. Most of the current approaches to detecting rogue AP are rudimentary and are easily evaded by hackers. We propose the use of temporal traffic characteristics to detect rogue AP at a central location. This detection is independent of the wireless technology (IEEE 802.11a, 802.11b, or 802.11g), is scalable, does not possess the inefficiencies of the current solutions, and is independent of the signal range of the rogue AP.