Graduate School, State University of Northern Negros, Old Sagay, Sagay City, Negros Occidental, 6122, Philippines.
* Corresponding Author
ORCID Details
Jay-ar B. Base: https://orcid.org/0009-0009-2906-7317
World Journal of Advanced Engineering Technology and Sciences, 2026, 20(02), 150–157
Article DOI: 10.30574/wjaets.2026.20.2.0402
Received on 04 July 2026; revised on 11 August 2026; accepted on 13 August 2026
Wireless local-area networks remain exposed at the data-link layer because legacy 802.11 management traffic can be forged, enabling impersonation and denial-of-service (DoS) conditions. Before Protected Management Frames (PMF) became widespread, deauthentication abuse was the standard technique for disrupting connectivity and for setting up later cryptographic attacks. This paper describes the design, implementation, and empirical evaluation of an anomaly-based Wireless Intrusion Detection System (WIDS) targeting such deauthentication activity. The detector, built on Python 3.11 and Scapy 2.5 operating in monitor mode, inspects management frames, evaluates reason codes, and applies threshold-based anomaly scoring to separate spoofed traffic from ordinary client roaming. A forensic logging component additionally assembles incident timelines suitable for digital-evidence collection. Whereas conventional signature-based products concentrate on known patterns, the proposed framework unites anomaly detection with automated timeline generation for post-incident review. In controlled trials the system attained a true positive rate (TPR) of 96.4%, a false positive rate (FPR) of 3.6%, and precision, recall, and F1-score values of 96.4%. The findings indicate that the detector can serve network administrators as an open-source instrument for continuous security monitoring and forensic reconstruction.
802.11 Deauthentication Attack; Anomaly Detection; Digital Forensics; Network Security Monitoring; Scapy; Wireless Intrusion Detection System (Wids)
Get Your e Certificate of Publication using below link
Preview Article PDF
Jay-ar B. Base, Serafin C. Palmares and Kristine T. Soberano. ANOMALY-BASED WIRELESS INTRUSION DETECTION FOR MITIGATING IEEE 802.11 DEAUTHENTICATION ATTACKS: DESIGN AND EMPIRICAL EVALUATION. World Journal of Advanced Engineering Technology and Sciences, 2026, 20(02), 150–157. Article DOI: https://doi.org/10.30574/wjaets.2026.20.2.0402