Identifying Malicious Traffic in Software-Defined Wireless Local Area Networks

Radoslaw Cwalinski, Hartmut Koenig · 2018 International Conference on Computing, Networking and Communications (ICNC) · 2018

In this paper we propose a novel approach to secure enterprise Wireless Local Area Networks (WLANs) by leveraging the Software-defined Networking (SDN) paradigm to identify potentially malicious frames and counteract with reactive and proactive defense strategies. We exploit information from the Physical (PHY) and Medium Access Control (MAC) layers offered by current wireless chipsets to effectively localize transmitting clients. The Access Point (AP) association table is enhanced with localization information to differentiate between regular and malicious frames and create a so-called “virtual perimeter” to prevent WLAN access for clients from outside of a defined area. Our evaluation shows that the proposed solution succeeds in identifying WLAN Denial-of-Service (DoS) attacks, such as IEEE 802.11 deauthentication.

Read the paper · More papers on PaperTik