Wireless Intrusion Detection Verification via Statistical Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current intrusion detection systems in networks face inaccuracies due to false alerts from access points with limited processing capabilities, leading to desensitization of administrators and reduced network security, especially with the upcoming IEEE 802.11ac standard requiring more data processing for accurate detection.
Innovation Solution
A network device correlates network usage information with statistical data to verify anomalous behavior, suppressing unnecessary alerts and enhancing detection accuracy by comparing mean, standard deviation, and other statistical computations over time, thereby reducing false positives and improving network security without increasing processing demands on access points.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If access points perform more accurate intrusion detection with increased data processing, then detection accuracy improves, but processing capability requirements increase beyond what cost-constrained APs can provide
Solution Approach 1:
The intrusion detection system is segmented into two parts: the access point performs lightweight real-time monitoring and alert generation, while the centralized controller performs complex statistical analysis and verification. This division allows accurate detection without overloading the AP's processing capabilities.
Solution Approach 2:
A centralized controller acts as an intermediary between multiple access points and the network administrator. It receives alerts from APs, performs comprehensive statistical analysis using gathered network usage information, and makes final determination about genuine attacks versus false positives, thereby improving detection accuracy without increasing AP processing requirements.
2Speed
If access points issue alerts for every suspected attack without verification, then response time improves, but false alert rate increases causing administrator desensitization
Solution Approach 1:
The centralized controller performs preliminary statistical verification analysis before final alert issuance. It pre-gathers network usage information and computes statistical parameters so that when an AP sends an alert, the verification can quickly determine if it's a genuine attack without requiring lengthy analysis, thus maintaining fast response while improving accuracy.
Solution Approach 2:
The system implements feedback by having the centralized controller analyze alerts against historical network usage patterns and statistical baselines. This feedback mechanism allows the system to learn from past behavior and distinguish genuine attacks from normal anomalies, reducing false alerts while maintaining appropriate response times.
3Object-generated harmful factors
If access points perform time-out operations to suppress repeated alerts, then alert suppression improves, but network security detection capability decreases during the timeout period
Solution Approach 1:
The centralized controller serves as an intermediary that maintains continuous monitoring and analysis capabilities even when individual alerts are suppressed. It uses statistical analysis to identify sustained attack patterns over time, ensuring that security detection capability is maintained through aggregated analysis rather than individual AP timeout operations.
Data Source
AI summary
According to one embodiment, a method for suppressing erroneous alert messages for suspected network attacks comprises a first operation of determining an intrusion event. This may be conducted at a first network device. Then, the intrusion event is verified prior to transmission of the alert message. The verification may be conducted at a second network device. Thereafter, transmission of the alert message is suppressed in response to verifying that the intrusion event has been erroneously determined.


