User-side evil twin attack detection using time-delay statistics of TCP connection termination

En-Chun Kuo, M. Chang, Da-Yu Kao
{"title":"User-side evil twin attack detection using time-delay statistics of TCP connection termination","authors":"En-Chun Kuo, M. Chang, Da-Yu Kao","doi":"10.23919/ICACT.2018.8323699","DOIUrl":null,"url":null,"abstract":"Open wireless network services are now freely shared in the most of the public areas but have barely protection about communication data between the web server and the client-side. Evil Twin Attack (ETA) appears to be a legitimate Wi-Fi Access Point (AP) and becomes a common attack in smart home environments where attackers can compromise the security of the connected devices. By setting up a rogue access point, deceiving users into establishing the network connection with the same SSID as the legitimate one, the attacker can launch the man-in-the-middle attack and steal some private information. To identify the fake APs, this paper presents an improved and practical client-side detection method to mathematically detect the ETA by observing the time-delay of TCP connection termination between the client and the server. This proposed time-delay model is further experimented and measured from the following three date-time intervals: Initial Ending, Ending Response, and Confirmed Ending. The utility of this model is illustrated by applying it to the client side which makes it more convenient for users to deploy and ensure their security with high detection rate.","PeriodicalId":228625,"journal":{"name":"2018 20th International Conference on Advanced Communication Technology (ICACT)","volume":"96 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-02-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"14","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 20th International Conference on Advanced Communication Technology (ICACT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.23919/ICACT.2018.8323699","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 14

Abstract

Open wireless network services are now freely shared in the most of the public areas but have barely protection about communication data between the web server and the client-side. Evil Twin Attack (ETA) appears to be a legitimate Wi-Fi Access Point (AP) and becomes a common attack in smart home environments where attackers can compromise the security of the connected devices. By setting up a rogue access point, deceiving users into establishing the network connection with the same SSID as the legitimate one, the attacker can launch the man-in-the-middle attack and steal some private information. To identify the fake APs, this paper presents an improved and practical client-side detection method to mathematically detect the ETA by observing the time-delay of TCP connection termination between the client and the server. This proposed time-delay model is further experimented and measured from the following three date-time intervals: Initial Ending, Ending Response, and Confirmed Ending. The utility of this model is illustrated by applying it to the client side which makes it more convenient for users to deploy and ensure their security with high detection rate.
基于TCP连接终止延时统计的用户端恶意孪生攻击检测
开放的无线网络服务现在在大多数公共领域免费共享,但对web服务器和客户端之间的通信数据几乎没有保护。邪恶孪生攻击(ETA)似乎是一个合法的Wi-Fi接入点(AP),并成为智能家居环境中的常见攻击,攻击者可以破坏连接设备的安全性。攻击者通过设置流氓接入点,欺骗用户建立与合法SSID相同的网络连接,进行中间人攻击,窃取用户的个人信息。为了识别假ap,本文提出了一种改进的实用的客户端检测方法,通过观察客户端与服务器之间TCP连接终止的时间延迟,从数学上检测ETA。我们从以下三个日期-时间间隔(初始结束、结束响应和确认结束)进一步实验和测量了所提出的时滞模型。通过将该模型应用于客户端,说明了该模型的实用性,方便了用户的部署,并以较高的检测率保证了用户的安全性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信