Scan-Based Self Anomaly Detection: Client-Side Mitigation of Channel-Based Man-in-the-Middle Attacks Against Wi-Fi
Sheng Gong, Hideya Ochiai, Hiroshi Esaki · 2020
In recent years, Wi-Fi has been used as a means of near-field high-speed communication across personal computers, smartphones and IoT devices such as hospital healthcare devices. Meanwhile, there have been many attempts to exploit equipment leveraging Wi-Fi. Among those exploits and attacks, an attack called channel-based man-in-the-middle (MITM) attack is a serious threat, since it can be used to exploit WPA2, which is a standard encryption and authentication scheme currently and widely in use. In this paper, we propose a scan-based self anomaly detection (SSAD), which is a client-side solution to detect and mitigate channel-based man-in-the-middle attacks using access point (AP) scans. SSAD enables wireless devices to verify the authenticity of wireless access points without the support of the access points, but running anomaly detection by themselves. This characteristic of SSAD, independent from access points, is especially favorable to mobile clients such as smartphones and IoT devices since they usually connect to multiple wireless access points. We implemented SSAD into an open source Wi-Fi client software and evaluated the effectiveness. With our experiments in some operational fields, we achieved 99% detection rate if an attacker was in the same room of a legitimate AP, and over 91% detection rate if an attacker and a legitimate AP were in different rooms.