A Framework for Detecting MAC and IP Spoofing Attacks with Network Characteristics

Jaegwan Yu, Eun‐Soo Kim, Hyoungshick Kim, Jun‐Ho Huh · 2016

This paper presents a spoofing attack detection framework based on physical network characteristics (e.g., received signal strength indicator round trip time and link quality indicator) that cannot easily be mimicked by artificial means. Unlike most previous studies that are sensitive to changes in network conditions, we propose a spoofing attack detection method, which is highly robust to the changes of network conditions over time. The proposed framework can monitor devices' physical network characteristics in real time and check if any significant changes have been made in the monitored measurements to effectively detect device spoofing attacks. To demonstrate the feasibility of the proposed framework, we analyzed how the RSSI values of packets were changed with varying physical distances in a real ZigBee (IEEE 802.15.4) network environment.

Read the paper · More papers on PaperTik