Font Size: a A A

Research On Fake AP Detection Technology Rased On WLAN Phvsical Laver Channel Characteristics

Posted on:2024-08-11Degree:MasterType:Thesis
Country:ChinaCandidate:Z Y MeiFull Text:PDF
GTID:2568306944468554Subject:Information and Communication Engineering
Abstract/Summary:
With the rapid development of Wireless Local Area Networks(WLAN)technology,mobile users accessing the Internet through WLAN has become one of the main ways to obtain information.However,the openness of wireless networks makes them vulnerable to attacks from fake Access Point(AP).In the face of such problems,the traditional identity authentication mechanism based on cryptography has shown many shortcomings,and channel characteristic of the physical layer have become one of the main research objects of physical layer security technology because of their uniqueness and difficulty in forgery.Therefore,how to use the physical layer channel characteristics to perform fake AP detection is important.Based on the above background,this thesis deeply explores the characteristics of Channel State Information in the physical layer,uses signal processing and machine learning to analyze and process the acquired data,and integrates these methods to enhance the security of wireless networks.The main contributions of this thesis are as follows:Aiming at the characteristics of nonlinear phase error caused by I/Q imbalance of wireless network card and imperfect oscillator,this thesis proposes a new feature extraction method,which uses phase unwrapping and phase filter to preprocess sample data,remove irrelevant interference items and retain hardware fingerprint features.At the same time,this thesis evaluates the method from two aspects of complexity and separation.Among them,the measurement of complexity is mainly from the perspective of time and space;the measurement of separability mainly starts from two perspectives:intra-class distance and inter-class distance.The experimental results show that the feature has low complexity,and the distance within the same device fingerprint feature class is small,and the distance between different device fingerprint feature classes is large,which proves the feasibility and effectiveness of the feature for fake AP detection.Aiming at the familiar scene with the fingerprint database of legal equipment,this thesis proposes a fake AP detection method based on single classification algorithm.Considering that the fingerprint database only contains positive samples,One-class Support Vector Machine and Support Vector Data Description are selected.At the same time,the grid search method and K-fold cross-validation are used to optimize the hyperparameter selection of the algorithm.In order to find the global optimal parameters.The experimental results show that for 10 wireless devices,the average detection accuracy of the two algorithms reaches more than 96%,and the misjudgment rate is below 2%.At the same time,this thesis compares the effects of power amplifier amplitude offset,carrier frequency shift and nonlinear phase error on fake AP detection.The experimental results show that the extracted features are about 2%higher in detection accuracy than other features,and the time consumed is reduced by about 2s.In addition,this thesis conducts fake AP detection experiments in multiple environments.The results show that the average detection accuracy of the proposed method in different environments is above 96%,and the false alarm rate is below 2%.In practical applications,considering that the fingerprint database cannot be constructed in advance in unfamiliar scenarios,this thesis proposes a fake AP detection method based on unsupervised clustering algorithm.This method uses Density-Based Spatial Clustering of Applications with Noise(DBSCAN)and nonlinear phase error fingerprint features to cluster fingerprint data of different devices into different clusters,and by verifying the correspondence between fingerprints and identifiers,the existence of fake AP attacks can be judged.At the same time,this thesis improves the algorithm and introduces the K-means nearest neighbor idea into the DBSCAN algorithm,so that it can adaptively select the parameters according to the characteristics of the sample itself,avoiding the problem of consuming a lot of time and resources caused by manually determining the parameters.The experimental results show that the proposed method can effectively distinguish different devices and accurately detect fake AP attacks in unfamiliar scenes.
Keywords/Search Tags:WLAN, physical layer channel characteristics, channel state information, machine learning, fake AP detection
Related items