Skip to content
Review Open access

ANOMALY-BASED WIRELESS INTRUSION DETECTION FOR MITIGATING IEEE 802.11 DEAUTHENTICATION ATTACKS: DESIGN AND EMPIRICAL EVALUATION

Aug 2026 · World Journal of Advanced Engineering Technology and Sciences · 0 citations

Abstract

Wireless local-area networks remain exposed at the data-link layer because legacy 802.11 management traffic can be forged, enabling impersonation and denial-of-service (DoS) conditions. Before Protected Management Frames (PMF) became widespread, deauthentication abuse was the standard technique for disrupting connectivity and for setting up later cryptographic attacks. This paper describes the design, implementation, and empirical evaluation of an anomaly-based Wireless Intrusion Detection System (WIDS) targeting such deauthentication activity. The detector, built on Python 3.11 and Scapy 2.5 operating in monitor mode, inspects management frames, evaluates reason codes, and applies threshold-based anomaly scoring to separate spoofed traffic from ordinary client roaming. A forensic logging component additionally assembles incident timelines suitable for digital-evidence collection. Whereas conventional signature-based products concentrate on known patterns, the proposed framework unites anomaly detection with automated timeline generation for post-incident review. In controlled trials the system attained a true positive rate (TPR) of 96.4%, a false positive rate (FPR) of 3.6%, and precision, recall, and F1-score values of 96.4%. The findings indicate that the detector can serve network administrators as an open-source instrument for continuous security monitoring and forensic reconstruction.

Read PDF