Skip to content
Review Open access

ANOMALY-BASED WIRELESS INTRUSION DETECTION FOR MITIGATING IEEE 802.11 DEAUTHENTICATION ATTACKS: DESIGN AND EMPIRICAL EVALUATION

Aug 2026 · World Journal of Advanced Engineering Technology and Sciences · 0 citations

TL;DR

The findings indicate that the detector can serve network administrators as an open-source instrument for continuous security monitoring and forensic reconstruction.

Abstract

Wireless local-area networks remain exposed at the data-link layer because legacy 802.11 management traffic can be forged, enabling impersonation and denial-of-service (DoS) conditions. Before Protected Management Frames (PMF) became widespread, deauthentication abuse was the standard technique for disrupting connectivity and for setting up later cryptographic attacks. This paper describes the design, implementation, and empirical evaluation of an anomaly-based Wireless Intrusion Detection System (WIDS) targeting such deauthentication activity. The detector, built on Python 3.11 and Scapy 2.5 operating in monitor mode, inspects management frames, evaluates reason codes, and applies threshold-based anomaly scoring to separate spoofed traffic from ordinary client roaming. A forensic logging component additionally assembles incident timelines suitable for digital-evidence collection. Whereas conventional signature-based products concentrate on known patterns, the proposed framework unites anomaly detection with automated timeline generation for post-incident review. In controlled trials the system attained a true positive rate (TPR) of 96.4%, a false positive rate (FPR) of 3.6%, and precision, recall, and F1-score values of 96.4%. The findings indicate that the detector can serve network administrators as an open-source instrument for continuous security monitoring and forensic reconstruction.

Read PDF

Similar papers

Open access Sep 2026

Anomaly-Based Intrusion Detection for IoT Microcontrollers Using Power Side-Channel Fingerprinting

This study introduces a unified evaluation framework for device-level intrusion detection using power side-channel fingerprints under an open-set threat model. We target post-enrollment device substitution: an adversary replaces a legitimate Commercial Off-The-Shelf (COTS) node with a counterfeit of the same model and...

S. M. H. Shukry, Frank Kargl, Tallal Elshabrawy et al. · 0 citations
Conference Open access 2025

Transparent Threat Detection in Mobile Networks: A Real-Time IDS with Scapy

: The increased reliance on wireless and mobile communication has intensified the need for practical, real-time cybersecurity measures. This paper presents a smart Intrusion Detection System (IDS) that inspects live network traffic and identifies malicious activity with minimal delay. Built on dynamic packet sniffing w...

M. R., V. Y, Y. R. et al. · 0 citations
Conference Aug 2026

Real-Time DDoS Detection by Integrated eBPF Telemetry and Machine Learning-enhanced SIEM

Distributed Denial-of-Service (DDoS) attacks remain one of the most disruptive threats to modern web services, overwhelming application resources and degrading service availability. This paper presents a lightweight, virtualized system architecture for real-time DDoS detection that combines kernellevel telemetry collec...

Dr Zeeshan Ali, A. Marotta, W. Tiberti et al. · 0 citations
Conference Aug 2026

A Host-Based Multi Module Intrusion Detection Framework for Secure Public Wi-Fi Using Metadata Based Analysis and Real Time Risk Advisory

Public Wi-Fi networks are widely used for convenient internet access, yet they expose users to major cyber security threats such as rogue access points, DNS manipulation, encrypted malware command and control (C2) communication and unsafe access to sensitive web applications. Traditional intrusion detection systems hav...

Dewmini Liyanage, D. Anuradha, Dineth Thv et al. · 0 citations
Book Open access Aug 2026

Towards High-Performance Intrusion Detection with Robustness Guarantees on Programmable Switches at ISP Scale

SiteGuard, an inline network intrusion detection system with programmable switches specifically developed to protect enterprise campus sites connecting to ISP, is designed and implemented and proposes a dual-plane feature extraction model to extract extensive traffic features at near line-speed.

Han Zhang, X. Liu, Linqiang Qian et al. · 0 citations
Conference Open access Sep 2026

AI-ENHANCED DETECTION OF ARP SPOOFING-BASED MAN-IN-THE-MIDDLE ATTACKS IN LOCAL AREA NETWORKS

A hybrid LAN protection architecture that combines DAI with an AI-based behavioral detection module to improve the identification of stealthy and context-dependent MitM activity is proposed and indicates that AI can effectively complement traditional infrastructure-level network defenses by providing behavioral awarene...

Penka Markova, Georgi A. Markov · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.