{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,9,27]],"date-time":"2026-09-27T07:02:25Z","timestamp":1790492545455,"version":"4.1.0"},"reference-count":39,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2016,2,24]],"date-time":"2016-02-24T00:00:00Z","timestamp":1456272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Media access control (MAC) addresses in wireless networks can be trivially spoofed using off-the-shelf devices. The aim of this research is to detect MAC address spoofing in wireless networks using a hard-to-spoof measurement that is correlated to the location of the wireless device, namely the received signal strength (RSS). We developed a passive solution that does not require modification for standards or protocols. The solution was tested in a live test-bed (i.e., a wireless local area network with the aid of two air monitors acting as sensors) and achieved 99.77%, 93.16% and 88.38% accuracy when the attacker is 8\u201313 m, 4\u20138 m and less than 4 m away from the victim device, respectively. We implemented three previous methods on the same test-bed and found that our solution outperforms existing solutions. Our solution is based on an ensemble method known as random forests.<\/jats:p>","DOI":"10.3390\/s16030281","type":"journal-article","created":{"date-parts":[[2016,2,24]],"date-time":"2016-02-24T04:09:51Z","timestamp":1456286991000},"page":"281","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":36,"title":["A New MAC Address Spoofing Detection Technique Based on Random Forests"],"prefix":"10.3390","volume":"16","author":[{"given":"Bandar","family":"Alotaibi","sequence":"first","affiliation":[{"name":"Computer Science and Engineering Department, University of Bridgeport, 126 Park Ave, Bridgeport, CT 06604, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9239-5035","authenticated-orcid":false,"given":"Khaled","family":"Elleithy","sequence":"additional","affiliation":[{"name":"Computer Science and Engineering Department, University of Bridgeport, 126 Park Ave, Bridgeport, CT 06604, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2016,2,24]]},"reference":[{"key":"ref_1","first-page":"184","article-title":"Intrusion Detection in 802.11 Networks: Empirical Evaluation of Threats and a Public Dataset","volume":"99","author":"Kolias","year":"2015","journal-title":"IEEE Commun. Surveys Tutor."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Chen, Y., Trappe, W., and Martin, R.P. (2007, January 18\u201321). Detecting and localizing wireless spoofing attacks. Proceedings of the 4th Annual IEEE Communications Society Conference on Sensor, Mesh and Ad Hoc Communications and Networks (SECON\u201907), San Diego, CA, USA.","DOI":"10.1109\/SAHCN.2007.4292831"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"2418","DOI":"10.1109\/TVT.2010.2044904","article-title":"Detecting and localizing identity-based attacks in wireless and sensor networks","volume":"59","author":"Chen","year":"2010","journal-title":"IEEE Trans. Veh. Technol."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Lanze, F., Panchenko, A., Ponce-Alcaide, I., and Engel, T. (2014, January 21\u201326). Undesired relatives: protection mechanisms against the evil twin attack in IEEE 802.11. Proceedings of the 10th ACM Symposium on QoS and Security for Wireless and Mobile Networks, Montreal, QC, Canada.","DOI":"10.1145\/2642687.2642691"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Mustafa, H., and Xu, W. (2014, January 29\u201331). CETAD: Detecting evil twin access point attacks in wireless hotspots. Proceedings of the 2014 IEEE Conference on Communications and Network Security (CNS), San Francisco, CA, USA.","DOI":"10.1109\/CNS.2014.6997491"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1638","DOI":"10.1109\/TIFS.2012.2207383","article-title":"Active user-side evil twin access point detection using statistical techniques","volume":"7","author":"Yang","year":"2012","journal-title":"IEEE Trans. Inf. Forens. Secur."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Faria, D.B., and Cheriton, D.R. (2006, January 29). Detecting identity-based attacks in wireless networks using signalprints. Proceedings of the 5th ACM Workshop on Wireless Security, Los Angeles, CA, USA.","DOI":"10.1145\/1161289.1161298"},{"key":"ref_8","first-page":"70","article-title":"A Novel WLAN Client Puzzle against DoS Attack Based on Pattern Matching","volume":"501","author":"Ordi","year":"2015","journal-title":"Math. Probl. Eng."},{"key":"ref_9","unstructured":"Ordi, A., Mousavi, H., Shanmugam, B., Abbasy, M.R., and Torkaman, M.R.N. (2011). Digital Information and Communication Technology and Its Applications, Springer."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"18009","DOI":"10.3390\/s141018009","article-title":"A survey on M2M systems for mHealth: A wireless communications perspective","volume":"14","author":"Kartsakli","year":"2014","journal-title":"Sensors"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1155\/2014\/161874","article-title":"Smart HVAC control in IoT: Energy consumption minimization with user comfort constraints","volume":"2014","author":"Serra","year":"2014","journal-title":"Sci. World J."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1023\/A:1010933404324","article-title":"Random forests","volume":"45","author":"Breiman","year":"2001","journal-title":"Mach. Learn."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"649","DOI":"10.1109\/TSMCC.2008.923876","article-title":"Random-forests-based network intrusion detection systems","volume":"8","author":"Zhang","year":"2008","journal-title":"IEEE Trans. Syst. Man Cybernet. Part C Appl. Rev."},{"key":"ref_14","unstructured":"Kim, D.S., Lee, S.M., and Park, J.S. (2006). Advances in Neural Networks-ISNN, Springer."},{"key":"ref_15","unstructured":"DeBarr, D., and Wechsler, H. (2009, January 16\u201317). Spam detection using clustering, random forests, and active learning. Proceedings of the Sixth Conference on Email and Anti-Spam, Mountain View, CA, USA."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1155\/2014\/425731","article-title":"Classification of phishing email using random forest machine learning technique","volume":"2014","author":"Akinyelu","year":"2014","journal-title":"J. Appl. Math."},{"key":"ref_17","first-page":"1","article-title":"On adaptive energy-efficient transmission in wsns","volume":"2013","author":"Tahir","year":"2013","journal-title":"Int. J. Distrib. Sens. Netw."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Sheng, Y., Tan, K., Chen, G., Kotz, D., and Campbell, A. (2008, January 13\u201318). Detecting 802.11 MAC layer spoofing using received signal strength. Proceedings of the IEEE 27th Conference on Computer Communications (INFOCOM 2008), Phoenix, AZ, USA.","DOI":"10.1109\/INFOCOM.2008.239"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"2158","DOI":"10.1109\/TIFS.2015.2433898","article-title":"Wireless Anomaly Detection based on IEEE 802.11 Behavior Analysis","volume":"10","author":"Alipour","year":"2015","journal-title":"IEEE Trans. Inf. Forens. Secur."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1378","DOI":"10.1002\/sec.1079","article-title":"On the IEEE 802.11 i security: A denial of service perspective","volume":"8","author":"Singh","year":"2015","journal-title":"Secur. Commun. Netw."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Alabdulatif, A., Ma, X., and Nolle, L. (2013, January 9\u201312). Analysing and attacking the 4-way handshake of IEEE 802.11 i standard. Proceedings of the IEEE 8th International Conference for Internet Technology and Secured Transactions (ICITST), London, UK.","DOI":"10.1109\/ICITST.2013.6750227"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Nguyen, T.D., Nguyen, D.H., Tran, B.N., Vu, H., and Mittal, N. (2008, January 3\u20137). A lightweight solution for defending against deauthentication\/disassociation attacks on 802.11 networks. Proceedings of the IEEE 17th International Conference on Computer Communications and Networks (ICCCN\u201908.), St. Thomas, US Virgin Islands.","DOI":"10.1109\/ICCCN.2008.ECP.51"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Agarwal, M., Biswas, S., and Nandi, S. (2013, January 13\u201315). Detection of De-authentication Denial of Service attack in 802.11 networks. Proceedings of the Annual IEEE India Conference (INDICON), Mumbai, India.","DOI":"10.1109\/INDCON.2013.6726015"},{"key":"ref_24","unstructured":"Tao, K., Li, J., and Sampalli, S. (2009). E-business and Telecommunications, Springer."},{"key":"ref_25","unstructured":"Guo, F, and Chiueh, T.C. (2006). Recent Advances in Intrusion Detection, Springer."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Mar, J., Yeh, Y.C., and Hsiao, I.F. (2010, January 17\u201320). An ANFIS-IDS against deauthentication DOS attacks for a WLAN. Proceedings of the International Symposium on Information Theory and its Applications (ISITA), Taichung, Taiwan.","DOI":"10.1109\/ISITA.2010.5654405"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Yang, J., Chen, Y., Trappe, W., and Cheng, J. (2009, January 19\u201325). Determining the number of attackers and localizing multiple adversaries in wireless spoofing attacks. Proceedings of the IEEE INFOCOM 2009, Rio de Janeiro, Brazil.","DOI":"10.1109\/INFCOM.2009.5061974"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"44","DOI":"10.1109\/TPDS.2012.104","article-title":"Detection and localization of multiple spoofing attackers in wireless networks","volume":"24","author":"Yang","year":"2013","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Ladd, A.M., Bekris, K.E., Rudys, A., Marceau, G., Kavraki, L.E., and Wallach, D.S. (2002, January 23\u201328). Robotics-Based Location Sensing using Wireless Ethernet. Proceedings of the 8th annual international conference on Mobile computing and networking, Atlanta, GA, USA.","DOI":"10.1145\/570645.570674"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"189","DOI":"10.1007\/s11276-004-4755-8","article-title":"Robotics-based location sensing using wireless ethernet","volume":"11","author":"Ladd","year":"2005","journal-title":"Wirel. Netw."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Chumchu, P., Saelim, T., and Sriklauy, C. (2011, January 26\u201328). A new MAC address spoofing detection algorithm using PLCP header. Proceedings of the International Conference on Information Networking (ICOIN), Barcelona, Spain.","DOI":"10.1109\/ICOIN.2011.5723112"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"2429","DOI":"10.1109\/JSAC.2015.2430515","article-title":"Fingerprint-Based Device-Free Localization Performance in Changing Environments","volume":"33","author":"Mager","year":"2015","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_33","unstructured":"Chen, X., Edelstein, A., Li, Y., Coates, M., Rabbat, M., and Men, A. (2011, January 12\u201314). Sequential Monte Carlo for simultaneous passive device-free tracking and sensor localization using received signal strength measurements. Proceedings of the IEEE 10th International Conference on Information Processing in Sensor Networks (IPSN), Chicago, IL, USA."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"947","DOI":"10.1109\/TMC.2011.102","article-title":"A fade-level skew-laplace signal strength model for device-free localization with wireless networks","volume":"11","author":"Wilson","year":"2012","journal-title":"IEEE Trans. Mob. Comput."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Xu, C., Firner, B., Moore, R.S., Zhang, Y., Trappe, W., Howard, R., Zhang, F., and An, N. (2013, January 8\u201311). Scpl: Indoor device-free multi-subject counting and localization using radio signal strength. Proceedings of the ACM\/IEEE International Conference on Information Processing in Sensor Networks (IPSN), Philadelphia, PA, USA.","DOI":"10.1145\/2461381.2461394"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"24862","DOI":"10.3390\/s151024862","article-title":"A Bluetooth\/PDR Integration Algorithm for an Indoor Positioning System","volume":"15","author":"Li","year":"2015","journal-title":"Sensors"},{"key":"ref_37","first-page":"1","article-title":"WSN4QoL: A WSN-oriented healthcare system architecture","volume":"2014","author":"Tennina","year":"2014","journal-title":"Int. J. Distrib. Sens. Netw."},{"key":"ref_38","first-page":"2825","article-title":"Scikit-learn: Machine learning in Python","volume":"12","author":"Pedregosa","year":"2011","journal-title":"J. Mach. Learn. Res."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Hastie, T., Tibshirani, R., and Friedman, J. (2009). The Elements of Statistical Learning: Data Mining, Inference, and Prediction, Springer. [2nd ed.].","DOI":"10.1007\/978-0-387-84858-7"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/16\/3\/281\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T19:19:35Z","timestamp":1760210375000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/16\/3\/281"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,2,24]]},"references-count":39,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2016,3]]}},"alternative-id":["s16030281"],"URL":"https:\/\/doi.org\/10.3390\/s16030281","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,2,24]]}}}