Genetic Programming (GP) based Intrusion Detection Systems (IDS) use connection state network data during their training phase. These connection states are recorded as a set of features that the GP uses to train and test solutions which allow for the efficient and accurate detection of given attack patterns. However, when applied to a 802.11 network that is faced with attacks specific to the 802.11 protocol, the GP’s detection rate reduces dramatically. In this work we discuss what causes this effect, and what can be done to improve the GP’s performance on 802.11 networks. Categories and Subject Descriptors I.2.6 [Artificial Intelligence]: Learning—Parameter learning General Terms Algorithms, Security Keywords Genetic Programming, 802.11, WiFi, Intrusion Detection, Denial of Service
Patrick LaRoche, A. Nur Zincir-Heywood