Controlled Deception for WLAN Attack Disruption and Service Preservation
编号:97
访问权限:仅限参会人
更新:2026-10-04 23:39:43 浏览:10次
In-person
摘要
IEEE 802.11 wireless local area networks (WLANs) expose management exchanges and network identifiers to nearby devices. This information can support reconnaissance, Evil Twin attacks, and management traffic disruption. Wireless intrusion detection systems (WIDS) and wireless intrusion prevention systems (WIPS) can detect or contain suspicious activity but generally leave the adversary’s observable environment unchanged. This paper introduces Controlled WLAN Deception (CWD), a governed framework that coordinates decoys, controlled exposure changes, hardening based on protected management frames (PMF), and quarantine within an authorized WLAN. The controller combines four evidence sources and admits an action only after checking authorization, client compatibility, service impact, finite duration, and rollback availability. CWD Sim evaluates four adversarial objectives across seven defense profiles, using 160 matched trials for each profile. Exact McNemar tests and Wilcoxon signed-rank tests, with Holm correction, assess paired completion outcomes and restricted time to objective (TTO). Under the configured parameters, CWD achieves an objective completion rate (CR) of 22.5%, compared with 73.8% for the baseline, 41.9% for active WIPS, and 35.6% for static deception. Its restricted mean TTO is 341.4 s over a 360 s observation horizon, while false activation occurs in 2.5% of trials. Taken together, the results indicate that CWD can coordinate multiple defensive mechanisms while limiting disruption to legitimate service under the evaluated conditions.
关键词
cyber deception,IEEE 802.11,moving target defense,WLAN security,wireless intrusion prevention
稿件作者
Viktor Stoynov
Technical University of Sofia
Georgi Iliev
Technical University of Sofia
发表评论