Master'sOpen Access

Session hijacking attacks on wireless networks detection and prevention

2023
0 views
0 downloads
Advisor: Prof. Dr. Celal Çeken

Abstract (EN)

Wireless networks are provided and spread everywhere that drive people to run their businesses and daily lives, communicate with the community, ةanaging bank accounts. travel, and others through internet access, and the availability of these networks in public places increases the risk of users being hacked, which is not what many people know. The ease of use and access to networks by middle-aged people leads them not to think about the risks of being hacked, and the presence of experts in theft and the exploitation of security vulnerabilities may expose the sessions provided by internet networks and web servers to users for theft. Generating the session is one of the complex problems wireless users may face. The web server grants the session to users wishing to obtain certain services from the server. These services may be bank accounts, social security data, or companie's activity management data, and as we know this is very sensitive data. The session goes through many stages, from generation, encryption and ensuring that it is safely transferred between the server and the client. Obtaining this session data and cookies data is a serious risk that gives the attacker full power to impersonate the victim's user and steals his sensitive data. A man-in-the-middle attack represents a great extremity risk because it is difficult to detect and the normal user cannot determine whether a session has been hijacked. The attacker is running in parallel with the user and has the same access privileges to data. Accessing the server with different permissions may expose not only the user's sensitive data, but all data on the server. In this study, we will develop a comprehensive vision of this problem, which began with analysis and then a simulated session hijacking process in two virtual environments. We believe that solving the problem begins with a careful characterization of it and focusing on how the attacker thinks and how to predicate the place and style of the attack. Then we worked on employing artificial intelligence and machine learning model using Bayesian Belief Networks as a system to detect the possibility of session hijacking and finally, we provided some solutions that will reduce the risk of session being hijacking.

Author

Dr. Taha Alı Mohammed Garoon

How to Cite

Taha Alı Mohammed Garoon (Master Thesis). Session hijacking attacks on wireless networks detection and prevention, 2023, Sakarya University.

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Sakarya University