Norbert Awinbod Akparibo1, Edem Kwedzo Bankas2*
1 Department of Information Systems and Technology, School of Computing and Information Sciences, University of Technology and Applied Sciences, Navrongo, Ghana
2 Department of Business Computing, School of Computing and Information Sciences, University of Technology and Applied Sciences, Navrongo, Ghana
AbstractEvil Twin attacks are a significant threat to wireless networks because a malicious access point can impersonate a legitimate access point and induce clients to associate with attacker-controlled infrastructure. Existing detection approaches include received-signal-strength analysis, client-side traffic analysis, rogue-access-point monitoring, and multi-parameter detection. This study developed and evaluated a supervised machine-learning framework for detecting Evil Twin attacks using the Aegean WiFi Intrusion Dataset 3 (AWID3). The experimental pipeline included data cleaning, feature selection, standardization, class-imbalance handling, model training, comparative evaluation, and deployment of the best-performing model in a real-time monitoring interface. Random Forest, Logistic Regression, and Decision Tree classifiers were evaluated using accuracy, precision, recall, F1-score, false-positive rate, and the area under the receiver operating characteristic curve (AUC). Based on the experimental results, Random Forest and Decision Tree achieved 99.99% accuracy, while Random Forest obtained an AUC of 1.0000. Logistic Regression produced lower recall and a substantially higher false-positive rate. The selected Random Forest model was subsequently integrated with a real-time monitoring dashboard. Active wireless countermeasures were not executed; mitigation actions were simulated to avoid unauthorized disruption. The results indicate that multi-feature supervised learning offers a promising approach to Evil Twin detection.
Keywords1. Agarwal, M., Biswas, S., & Nandi, S. (2018). An efficient scheme to detect evil twin rogue access point attack in 802.11 wifi networks. International Journal of Wireless Information Networks, 25(2), 130-145.
2. Lu, Q., Qu, H., Zhuang, Y., et al. (2018). Clientside evil twin attacks detection using statistical characteristics of 802.11 data frames. IEICE Transactions on Information and Systems, E101-D(10), 2465-2473.
3. Kim, T., Park, H., Jung, H., et al. (2012). Online detection of fake access points using received signal strengths. 2012 IEEE 75th Vehicular Technology Conference (VTC Spring), 1-5.
4. Vanjale, S., & Mane, P. (2018). Multiparameterbased robust and efficient rogue AP detection approach. Wireless Personal Communications, 98, 139-156.
5. Chatzoglou, E., Kambourakis, G., & Kolias, C. (2021). Empirical evaluation of attacks against IEEE 802.11 enterprise networks: The AWID3 dataset. IEEE Access, 9, 34188-34201.
6. Chawla, N., Bowyer, K., Hall, L., et al. (2002). SMOTE: Synthetic minority oversampling technique. Journal of Artificial Intelligence Research, 16, 321-357.
7. Breiman, L. (2001). Random forests. Machine Learning, 45, 5-32.
8. Hastie, T., Tibshirani, R., & Friedman, J. (2009). The elements of statistical learning: Data mining, inference, and prediction (2nd ed.). Springer.
9. Fernández, A., García, S., Galar, M., et al. (2018). Learning from imbalanced data sets. Springer.
Copyright: © International Society for Translational Sciences, except Open Access articles