Spider-Sense: Wi-Fi CSI as a Sixth Sense for Early Detection in Network Intrusion Detection SystemsShow others and affiliations
2024 (English)In: Proceedings - IEEE Global Communications Conference, GLOBECOM, Institute of Electrical and Electronics Engineers (IEEE), 2024, p. 2437-2442Conference paper, Published paper (Refereed)
Abstract [en]
Recent advancements in Network Intrusion Detection Systems (NIDS) primarily focus on detecting intrusions at the network layer. However, most solutions identify malicious activities when the attacker is already inside the network. This study introduces an innovative approach to NIDS, utilizing the Wi-Fi Channel State Information (CSI) combined with machine learning to proactively detect threats at the physical and link layers. Unlike traditional methods, our system leverages physical layer data, significantly enhancing early detection capabilities.
We evaluated the performance of classical machine learning models, including SVM, Random Forest, Decision Tree, KNN, and Naive Bayes, on 800, 000 instances across three different environments: laptops, iPhones, and Android devices. The Decision Tree algorithm emerged as the most effective, achieving an accuracy and F1-score of 99.95%.
This research demonstrates that the amplitude variations of Wi-Fi signals across subcarriers during brute-force attacks are markedly distinct from benign activities, providing a robust indicator for early threat detection. To the best of our knowledge, our approach advances the state-of-the-art in NIDS by integrating data from layers 1 and 2, enabling the identification of malicious users before they associate with the target Wi-Fi network.
Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2024. p. 2437-2442
Keywords [en]
early intrusion detection, machine learning, Network IDS, Network security, physical and link layer, Wi-Fi Sensing, Adversarial machine learning, Decision trees, Intrusion detection, Wi-Fi, Intrusion-Detection, Link layers, Machine-learning, Network intrusion detection systems, Networks security, Physical layers, WI - FI, Network intrusion
National Category
Signal Processing
Identifiers
URN: urn:nbn:se:bth-27686DOI: 10.1109/GLOBECOM52923.2024.10901597ISI: 001511158700405Scopus ID: 2-s2.0-105000828197ISBN: 9798350351255 (print)OAI: oai:DiVA.org:bth-27686DiVA, id: diva2:1950295
Conference
43rd Global Communications Conference-GLOBECOM, Cape Town, Dec 8-12, 2024
2025-04-072025-04-072025-09-30Bibliographically approved