Wireless intrusion prevention system, wireless network system including the same, and operation method of the wireless network system

Wireless Intrusion Prevention System (WIPS) prevents specific terminals from accessing the network by monitoring and blocking signals, solving the problems of unauthorized access points and denial of service attacks in wireless networks and achieving effective defense against specific terminals.

CN115176488BActive Publication Date: 2025-09-19SAMSUNG COMPUTER SECURITY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202080097599.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-03-11
Filing Date
2020-04-03
Publication Date
2025-09-19
Estimated Expiration
2040-04-03

AI Technical Summary

Technical Problem

Existing wireless network systems are difficult to effectively block access by specific terminals when facing unauthorized access points and denial-of-service attacks, especially when using protected deauthentication frames of IEEE 802.11w technology, which lacks an effective defense mechanism.

Method used

The wireless intrusion prevention system (WIPS) monitors wireless frames, sends interference signals to specific terminals, prevents access points from responding to specific terminals, and terminates the connection between specific terminals and access points through means such as connection release request and authentication request frames.

Benefits of technology

It effectively blocks access by unauthorized terminals, prevents denial of service attacks, and ensures the security and stability of the wireless network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115176488B_ABST
    Figure CN115176488B_ABST
Patent Text Reader

Abstract

The present invention provides a wireless intrusion prevention system, a wireless network system including the system, and an operating method for the wireless network system. The wireless intrusion prevention system includes: an access point; multiple terminals that transmit wireless frames to or receive wireless frames from the access point via a wireless network; and a wireless intrusion prevention system that monitors the wireless frames. The wireless intrusion prevention system transmits a connection release request to a specific terminal among the multiple terminals and prevents the access point from responding to the specific terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a wireless intrusion prevention system (WIPS), a wireless network system including the same, and an operating method of the wireless network system. Background Art

[0002] With the rapid development and widespread adoption of the internet, the network environment has become increasingly complex, driven by its ease of access and the diverse services it provides. However, the internet remains at risk due to various cyberattacks, including viruses, hacker attacks, system intrusions, administrator privilege escaping, hidden intrusions, and denial-of-service attacks. Consequently, internet-related intrusions are increasing, and the scale of damage to public institutions, social infrastructure, and financial institutions is increasing, significantly impacting them. To address these internet security challenges, there is a growing demand for network security technologies, such as antivirus software, firewalls, integrated security management, and intrusion detection systems.

[0003] A wireless network system for wireless Internet communication includes a wireless LAN access point (AP) and a wireless LAN terminal. An AP is used by installing a device called an access point.

[0004] Recently, integrated network systems utilizing both wired and wireless networks have been widely developed and deployed. While harmful traffic via wired access is difficult to reliably block, wireless access is even more challenging. To address this issue, wireless intrusion prevention systems (WIPS) are being developed. WIPS monitor wireless networks to detect and prevent wireless intrusions, such as unauthorized access points (APs) or denial of service (DoS) attacks. Summary of the Invention

[0005] (1) Technical issues to be solved

[0006] The technical problem to be solved by the present invention is to provide a wireless intrusion prevention system (WIPS) and a wireless network system including the WIPS for preventing a specific terminal from accessing an AP when the specific terminal accesses the AP via a protected deauthentication frame such as IEEE 802.11w technology.

[0007] The technical problems of the present invention are not limited to the above technical problems, and those skilled in the art will clearly understand other technical problems not mentioned through the following description.

[0008] (2) Technical solution

[0009] A wireless network system according to an embodiment of the present invention for solving the above-mentioned technical problem includes: an access point; a plurality of terminals that send wireless frames to the access point or receive wireless frames from the access point via a wireless network; and a wireless intrusion prevention system that monitors the wireless frames, wherein the wireless intrusion prevention system sends a connection release request to a specific terminal among the plurality of terminals and prevents the access point from responding to the specific terminal.

[0010] The wireless intrusion prevention system may send an interference signal to the access point to prevent the access point from responding to the specific terminal.

[0011] The obstruction signal may include a clear to send (CTS) frame and a request to send (RTS) frame.

[0012] The obstruction signal may include a signal for increasing a congestion level of the access point.

[0013] The interfering signal may include a spoofed data packet.

[0014] The disguised data packet may include a frame requesting a new connection, a frame requesting a reconnection, or a frame requesting to release a current connection state.

[0015] The specific terminal may send a protected query to the access point in response to the connection release request.

[0016] The specific terminal may instruct the access point to respond to the protected query within a predetermined first time. When there is no response within the first time, the specific terminal may terminate the connection with the access point.

[0017] After the connection between the specific terminal and the access point is terminated, the specific terminal may send an authentication request frame to the access point.

[0018] After sending the authentication request frame, the wireless intrusion prevention system may send a deauthentication frame to the access point or the specific terminal.

[0019] The specific terminal may be an unauthorized terminal or a terminal connected to an unauthorized attacker through a network.

[0020] The wireless network may include IEEE 802.11w technology.

[0021] An operating method of a wireless network system according to an embodiment of the present invention for solving the above-mentioned technical problem includes the following steps: an access point maintains a connection with a specific terminal among a plurality of terminals that send wireless frames to the access point or receive wireless frames from the access point via a wireless network; and a wireless intrusion prevention system that monitors the wireless frames sends an interference signal to prevent the access point from responding to the specific terminal or preventing the access point from sending a protected query to the specific terminal.

[0022] The operating method of the wireless network system may further include the following steps: the wireless intrusion prevention system that monitors the wireless frame sends a connection release request to the specific terminal; the specific terminal sends a protected query to the access point; the specific terminal instructs the access point to respond to the protected query within a predetermined first time; and when there is no response within the first time, the specific terminal terminates the connection between the access point.

[0023] The operating method of the wireless network system may further include the following steps: after the connection between the specific terminal and the access point is terminated, the specific terminal sends an authentication request frame to the access point; and after sending the authentication request frame, the wireless intrusion prevention system sends a deauthentication frame to the access point or the specific terminal.

[0024] The operation method of the wireless network system may further include the following steps: the specific terminal sends an access request to the access point, wherein the obstruction signal may include the access point sending a signal to the specific terminal to reject the access request or a signal to prevent the access point from sending the protected inquiry to the specific terminal.

[0025] The operating method of the wireless network system may further include the step of: the wireless intrusion prevention system sending an access request to the access point, wherein the obstruction signal may include a signal preventing the access point from sending the protected query to the specific terminal.

[0026] A wireless intrusion prevention system according to an embodiment of the present invention for solving the above-mentioned technical problem includes: a sensing device for monitoring wireless frames transmitted and received by an access point and a plurality of terminals over a wireless network and processing information based on the wireless frames; and a server for determining, based on the processed information, whether the access point and the plurality of terminals are unauthorized and whether they are operating abnormally, wherein the wireless intrusion prevention system includes a function of providing an interference signal for terminating a connection with the access point to a specific terminal among the plurality of terminals.

[0027] The wireless intrusion prevention system may further include a function of sending a deauthentication frame to the access point or the specific terminal when the specific terminal sends an authentication request frame to the access point to request access.

[0028] The obstruction signal may include a signal preventing the access point from responding to the specific terminal or a signal preventing the access point from sending a protected inquiry to the specific terminal.

[0029] Details of other embodiments are included in the detailed description and accompanying drawings.

[0030] (3) Beneficial effects

[0031] According to an embodiment of the present invention, when multiple terminals access an AP through a protected deauthentication frame such as the IEEE 802.11w technology, a specific terminal among the multiple terminals may be disconnected and blocked from accessing the AP.

[0032] Effects according to the embodiment are not limited to the above-exemplified contents, and more effects are included in this specification. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 is a block diagram showing a schematic configuration of a WIPS.

[0034] Figure 2 1 is a flowchart illustrating an access blocking method of a WIPS.

[0035] Figure 3 is a conceptual diagram for explaining a connection technology in a wireless intrusion prevention system according to an embodiment of the present invention.

[0036] Figure 4 is a conceptual diagram for explaining a connection defense technology in a wireless intrusion prevention system according to an embodiment of the present invention.

[0037] Figure 5 is a conceptual diagram for explaining a connection technology in a wireless intrusion prevention system according to an embodiment of the present invention.

[0038] Figure 6 This is a conceptual diagram for explaining a connection release defense technology in a wireless intrusion prevention system according to an embodiment of the present invention.

[0039] Figure 7 This is a conceptual diagram for explaining a specific terminal disconnection technology in a wireless intrusion prevention system according to an embodiment of the present invention.

[0040] Figure 8 and Figure 9 They are Figure 7A variation of FIG. 1 is a conceptual diagram for illustrating a specific terminal connection release technology.

[0041] Figure 10 This is a conceptual diagram for explaining a specific terminal disconnection technology in a wireless intrusion prevention system according to another embodiment of the present invention.

[0042] Figure 11 and Figure 12 They are Figure 10 A modified example is shown in which Figure 8 or Figure 9 The embodiments are additionally applied to a conceptual diagram of a wireless intrusion prevention system.

[0043] Figures 13 to 15 They are conceptual diagrams for illustrating a specific terminal connection release technology in a wireless intrusion prevention system according to another embodiment of the present invention.

[0044] Figure 16 This is a conceptual diagram for explaining a specific terminal disconnection technology in a wireless intrusion prevention system according to another embodiment of the present invention.

[0045] Best Practice

[0046] The advantages and features of the present invention and methods for achieving the same will become apparent through the embodiments described below in detail with reference to the accompanying drawings. However, the present invention is not limited to the embodiments disclosed below, but may be implemented in various forms. These embodiments are provided only to complete the disclosure of the present invention and to fully inform those skilled in the art of the present invention of the scope of the present invention. The present invention is limited only by the scope of the claims.

[0047] Although terms such as first and second are used to describe various components, these components are not limited by these terms. These terms are only used to distinguish one component from another. Therefore, the first component mentioned below may be the second component within the technical concept of the present invention. Unless the context clearly stipulates otherwise, the singular expression includes the plural expression.

[0048] The wireless intrusion prevention system (WIPS) described below is a system that detects and prevents wireless intrusions such as unauthorized access points (rouge APs) or denial of service (DoS) attacks by monitoring wireless networks.

[0049] The general wireless networks described in this specification may refer to wireless networks that utilize IEEE 802.11 technologies, while wireless networks that utilize specific security technologies may refer to wireless networks that utilize IEEE 802.11w technologies. IEEE 802.11w is a modified version of IEEE 802.11 that enhances the security of management frames. However, the present invention is not limited thereto; embodiments of the present invention may be applied to wireless networks that utilize various security technologies.

[0050] A wireless network system consists of one or more Basic Service Sets (BSSs). A BSS represents a collection of devices that can successfully synchronize and communicate with each other. Generally, BSSs can be categorized as either infrastructure BSSs or independent BSSs (IBSSs).

[0051] An access point (hereinafter referred to as AP) is an entity that provides access to a distribution system for terminals associated with the AP through a wireless medium. AP can be used as a concept including PCP (Personal BSS Coordination Point), and in a broad sense, can include concepts such as a centralized controller, a base station (BS), a Node-B, a base transceiver system (BTS) or a site controller. In the present invention, AP can also be referred to as a base station wireless communication terminal, and in a broad sense, a base station wireless communication terminal can be used as a term including AP, base station, eNB (eNodeB) and a transmitting point (TP). In addition, a base station wireless communication terminal may include various types of wireless communication terminals for allocating communication medium resources and performing scheduling in communications with multiple wireless communication terminals.

[0052] A terminal (station) is any device that includes a medium access control (MAC) and a physical layer interface for a wireless medium that complies with the IEEE 802.11 standard. Broadly speaking, it includes not only non-AP stations but also access points (APs). In this specification, "terminal" refers to a non-AP station, but depending on the embodiment, it can be used as a term to refer to both non-AP stations and APs. A station used for wireless communication includes a processor and a transmit / receive unit, and depending on the embodiment, may further include a user interface unit, a display unit, and the like. The processor can generate frames to be transmitted over a wireless network or process frames received over the wireless network, and can perform various processes for controlling the station. Furthermore, the transmit / receive unit is functionally connected to the processor and transmits and receives frames for the station over the wireless network. A terminal can send frames to and receive frames from an AP over a wireless network.

[0053] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings. The same or similar reference numerals are used for the same components in the drawings.

[0054] Figure 1 is a block diagram showing a schematic configuration of a WIPS.

[0055] Reference Figure 1 , the WIPS 10 may include a sensing device 100 and a server 130. On the other hand, in an enterprise network capable of simultaneously configuring wireless network services and sensing devices, an AP controller may be additionally included if necessary.

[0056] The operation of the WIPS 10 to determine the blocking policy may be as follows.

[0057] For example, the sensing device 100 may monitor wireless frames and process information such as the MAC address of the terminal or AP that sends the wireless frames, security settings, frame frequency, transmission rate, data volume, SSID, IEEE802.11a / b / g / n, etc., channel, RSSI, etc. based on the monitored wireless frames. In addition, the sensing device 100 may transmit the processed information to the server 130.

[0058] The server 130 can compare the processed information with the signature information stored in the database to determine whether the corresponding terminal or AP is unauthorized and whether it is operating abnormally. At this time, the signature information may include the header information of the wireless frame or information such as the frequency of occurrence of the frame.

[0059] Server 130 can determine whether a detected AP is unauthorized based on two scenarios. Server 130 can determine whether an AP is unauthorized based on its SSID, MAC address, and other information stored in the database. Alternatively, server 130 can determine an AP as unauthorized when the AP fails to connect to the company's internal wired network. Various methods can be used to determine whether an AP is connected to the company's internal wired network. Similar methods can also be used to determine unauthorized terminals.

[0060] When the server 130 determines that the corresponding AP is unauthorized or the AP or terminal is operating abnormally, it can automatically block according to the blocking policy or generate an alarm for the administrator to perform manual blocking. According to the blocking decision, the server 130 can send a blocking target list or blocking policy information to the sensing device 100.

[0061] The sensing device 100 may select APs and terminals that need to be blocked and perform blocking according to a judgment based on the blocking target list and the blocking policy.

[0062] For example, the blocking of the sensing device 100 based on the blocking target list and the blocking policy may include the following types.

[0063] As an example, the blocking of the sensing device 100 may include blocking an AP. In this case, when the BSSID of the blocking target AP is sensed, the sensing device 100 may block all terminals accessing the AP instead of a specific terminal target.

[0064] As another example, the blocking by the sensing device 100 may include blocking a terminal. In this case, if the sensing device 100 determines that the terminal is an unauthorized terminal or detects that the terminal has been tampered with to be an authorized terminal, the sensing device 100 may block the terminal. When the MAC address of the terminal is present, the sensing device 100 may block the terminal from accessing all APs.

[0065] As another example, the blocking function of the sensing device 100 may include blocking a specific AP-terminal. In this case, the sensing device 100 may block the connection when an authorized terminal connects to an unauthorized AP or when an unauthorized terminal connects to an authorized AP. When the corresponding terminal MAC is present, the sensing device 100 may only block the corresponding terminal from accessing the specified AP and may not interfere with the corresponding terminal's access to other APs.

[0066] For example, the sensing device 100 may include a controller 105 and a communication module 125 .

[0067] The communication module 125 may monitor the wireless frame and may transmit a block message to the terminal and the AP when a block message is generated.

[0068] The controller 105 can generate a blocking message related to the wireless frame received as a result of monitoring based on the policy information and blocking list related to wireless intrusion prevention. In addition, the controller 105 can control to send the generated blocking message to the AP and terminal that are set to send / receive the wireless frame.

[0069] For example, the controller 105 may include a sensor receiving unit 110 , a sensor analyzing unit 115 , and a sensor blocking unit 120 .

[0070] The sensor receiving unit 110 may control the communication module 125 to monitor wireless frames in a plurality of channels.

[0071] The sensor analysis unit 115 can analyze wireless frames received as a result of monitoring to add / update information about the AP or terminal that sent the wireless frame. The sensor analysis unit 115 can determine whether the AP or terminal violates the policy based on the blocking target list and the blocking policy, and generate a blocking event. The sensor analysis unit 115 can send the generated blocking event to the server 130.

[0072] The sensor blocking unit 120 may execute the generated blocking event.The sensor blocking unit 120 may generate a blocking message and send it to the AP and the terminal that are set to transmit / receive the wireless frame.

[0073] For example, when an AP and a terminal are connected to each other, the sensor blocking unit 120 can perform blocking by generating a deauthentication frame and sending it to the AP and the terminal. The sensor blocking unit 120 may set the address for sending the deauthentication frame to the AP's BSSID and the receiving address to the terminal's MAC address, and then send the generated deauthentication frame to the terminal. Furthermore, the sensor blocking unit 120 may set the address for sending the deauthentication frame to the terminal's MAC address and the receiving address to the AP's BSSID, and then send the generated deauthentication frame to the AP. Upon receiving the deauthentication frame sent from the sensing device 100, the AP and the terminal may determine that the other party has sent a deauthentication frame notifying the termination of the connection and terminate the connection.

[0074] Figure 2 1 is a flowchart illustrating an access blocking method of a WIPS.

[0075] The server 130 may send wireless intrusion prevention related policy information and a blocking list to the sensing device 100 in step 205 .

[0076] The sensor receiving unit 110 may monitor wireless frames in a plurality of channels in step 210. When a wireless frame is received as a result of the monitoring, the sensor receiving unit 110 may call the sensor analyzing unit 115 to analyze the corresponding wireless frame in step 215.

[0077] The sensor analysis unit 115 may analyze the corresponding wireless frame in step 220 and add or update information about the AP or terminal that sent the corresponding wireless frame in step 225. The sensor analysis unit 115 may determine whether the corresponding AP or terminal violates the policy in step 230. If the policy is violated, the sensor analysis unit 115 may generate a blocking event in step 235. The sensor analysis unit 115 may transmit the generated blocking event to the server 130 in step 240.

[0078] When the sensor blocking unit 120 is notified that a blocking event has occurred in step 245, the sensor blocking unit 120 may execute the blocking event in step 250. For example, the sensor blocking unit 120 may generate a deauthentication frame as described above and send it to the AP and terminal configured to transmit / receive wireless frames.

[0079] Figure 3 is a conceptual diagram for explaining a connection technology in a wireless intrusion prevention system according to an embodiment of the present invention.

[0080] In the following figures, each step over time is shown in a downward direction in the figure.

[0081] For example, the connection technique may be performed in the event that the terminal 30 loses the encryption key.

[0082] Reference Figure 3 , AP 20 and terminal 30 are connected to each other, and due to a specific reason, terminal 30 may lose the encryption key (S101). For example, the specific reason may include resetting or restarting the terminal 30. At this time, terminal 30 may be in a state of losing the encryption key (S101).

[0083] In the state where the encryption key is lost, the terminal 30 may request access to the AP 20 (S102). At this time, since the terminal 30 has lost all encryption keys, it may send an unprotected access request frame to the AP 20.

[0084] Since the AP 20 still determines that the terminal 30 has a valid connection using the encryption key, the AP 20 rejects the access request from the terminal 30 and may instruct the terminal 30 to try again after a predetermined first time (S103).

[0085] Thereafter, AP 20 may perform a check (S104) to determine whether such an access request (S102) is an attack. As an embodiment, the check (S104) mechanism may include a Security Association (SA) query step. For example, the SA query step may include a step in which AP 20 sends at least one protected query (Protected Security Association Query) to terminal 30.

[0086] When the terminal 30 does not respond until the predetermined terminal 30 response time (second time) of the SA inquiry step has passed, the AP 20 may transmit a connection release to the existing terminal 30 ( S105 ) and discard the no longer valid encryption key.

[0087] After the first time, the terminal 30 may transmit a (re)access request frame to the AP 20 (S106). Thereafter, the AP 20 allows access of the terminal 30 (S107), and the AP 20 and the terminal 30 may be connected to each other (S108).

[0088] Figure 4 is a conceptual diagram for explaining a connection defense technology in a wireless intrusion prevention system according to an embodiment of the present invention.

[0089] For example, connection prevention techniques may be performed if an attacker attempts to access AP 20 .

[0090] Reference Figure 4 First, the AP 20 and the terminal 30 may be in a state of being connected to each other (S200). The attacker 40 may request access to the AP 20 (S201). Here, the attacker 40 may be an unauthorized terminal or an externally controlled terminal 30, including a terminal 30 that can be regarded as a substantially unauthorized terminal.

[0091] Since the AP 20 still determines that the terminal 30 has a valid connection using the encryption key, the AP 20 rejects the access request from the attacker 40 and may instruct to try again after a predetermined third time (S202).

[0092] Afterwards, AP 20 may perform a check to confirm whether such an access request is an attack. AP 20 may send protected queries to attacker 40 and terminal 30 respectively (S203a, S203b). As an embodiment, AP 20 may send protected queries to attacker 40 and terminal 30 respectively at the same time, but the timing (sequence) of sending the protected queries is not limited thereto.

[0093] The terminal 30 may respond to the AP 20 with a protected reply in response to the protected query (S204).

[0094] The AP 20 may determine the attacker's 40 request as a fake association request and ignore the attacker's 40 access request ( S205 ).

[0095] Figure 5 is a conceptual diagram for explaining a connection technology in a wireless intrusion prevention system according to an embodiment of the present invention.

[0096] For example, the connection technique may be performed in the event that the AP 20 loses the encryption key.

[0097] Reference Figure 5 , AP 20 and terminal 30 are connected to each other, and AP 20 may lose the encryption key due to a specific reason (S301). For example, the specific reason may include reset or restart of AP 20. At this time, AP 20 may be in a state of losing the encryption key (S301).

[0098] When the previously connected terminal 30 sends an encrypted data frame to AP 20 (S302), AP 20 sends an unprotected frame to terminal 30 (S303) to retry the connection. Because terminal 30 still determines that it maintains a valid connection with AP 20, including the encryption key, it can perform a check to confirm whether AP 20's connection attempt is an attack. As an example, the check mechanism may include a security association (SA) query step. For example, the SA query step may include the step of terminal 30 sending a protected query (SA query) to AP 20 at least once (S304).

[0099] When the protected challenge cannot be responded to even after the predetermined fourth time has passed, the terminal 30 may judge that the connection with the AP 20 is released and discard the invalid encryption key with the AP 20 .

[0100] Thereafter, the terminal 30 transmits an unprotected query to the AP 20 (S305), and when the AP 20 responds to the terminal 30 with an unprotected reply in response to the unprotected query (S306), the AP 20 and the terminal 30 can be connected to each other.

[0101] Figure 6 This is a conceptual diagram for explaining a connection release defense technology in a wireless intrusion prevention system according to an embodiment of the present invention.

[0102] For example, the connection release defense technology may be used to prevent an attacker 40 from releasing the connection of the terminal 30 that has accessed the AP 20 .

[0103] Reference Figure 6 , first, the AP 20 and the terminal 30 may maintain connection with each other (S401).

[0104] In this regard, the attacker 40 may request the terminal 30 to disconnect (S402) to disconnect the terminal 30 from the AP 20. According to an embodiment, the attacker 40 may send the above-mentioned connection disconnection request (S402) to the terminal 30 to disconnect multiple terminals 30 from the AP 20.

[0105] In response to the connection release request (S402) from the attacker 40, the terminal 30 may perform a check to determine whether it is an attack. The terminal 30 may send a protected query to the AP 20 at least once (S403). Since the connection between the AP 20 and the terminal 30 is still valid, the AP 20 may respond to the terminal 30 with a protected reply (S404).

[0106] Thus, the terminal 30 can determine that the connection termination request from the attacker 40 is an attack, ignore the connection termination request from the attacker 40 , and maintain the connection with the AP 20 .

[0107] Figure 7 This is a conceptual diagram for explaining a specific terminal disconnection technology in a wireless intrusion prevention system according to an embodiment of the present invention.

[0108] For example, the technique for disconnecting a specific terminal 31 can be used to disconnect an unauthorized specific terminal 31, or to disconnect a specific terminal 31 that is controlled by an attacker 40 and can be considered substantially unauthorized, among multiple terminals connected to the AP 20 as shown in the figure. In this specification, "specific terminal 31" refers to at least some of the multiple terminals 30 connected to the AP 20 that are the target of disconnection. As an example, the specific terminal 31 can be connected to the attacker 40 via a network.

[0109] Reference Figure 7 , the wireless network system may include an AP 20 , terminals 30 including a specific terminal 31 , and a WIPS 10 .

[0110] The AP 20 can connect to a plurality of terminals 30 and can maintain mutual connection between the AP 20 and a specific terminal 31 (S501). Depending on the embodiment, the specific terminal 31 may be an unauthorized terminal or may include a terminal 30 that can be regarded as a substantially unauthorized terminal as being in a state controlled by the attacker 40 (S500).

[0111] As an example, the WIPS 10 may send a connection release request to multiple terminals 30 connected to the AP 20. At this point, the connection release request may also be sent to a specific terminal 31 (S502). The connection release request (S502) may include a forged frame. For example, the forged frame may include a disguised data packet such as a frame requesting a new connection (Association frame), a frame requesting a reconnection (Re-Association frame), or a frame requesting the termination of a current connection (Dis-Association frame).

[0112] Therefore, the specific terminal 31 may check whether the received disconnection request (S502) with the AP 20 is an attack. That is, the specific terminal 31 may retry mutual authentication with the AP 20. The specific terminal 31 may send a protected query to the AP 20 (S503). According to an embodiment, the specific terminal 31 may send the protected query (S503) to the AP 20 multiple times.

[0113] At this time, the WIPS 10 may prevent the AP 20 from responding to the specific terminal 31 (S504). To prevent the AP 20 from responding to the specific terminal 31 (S504), according to an embodiment, the WIPS 10 may send a prevention signal to the AP 20 and / or the specific terminal 31. The AP 20 should respond to the protected query sent by the specific terminal 31, but the prevention (S504) may prevent the AP 20 from responding to the specific terminal 31 (S505).

[0114] As a result, since the specific terminal 31 does not receive a response from the AP 20 within the predetermined fifth time, the connection with the AP 20 may be released after the predetermined fifth time. Therefore, the mutual connection between the specific terminal 31 and the AP 20 may be terminated (S506).

[0115] Below, refer to Figure 8 and Figure 9 The blocking signal sent in the blocking (S504) step is described in detail. Figure 8 and Figure 9 In the description of the Figure 7 The same components are described herein using the same or similar reference numerals.

[0116] Figure 8 and Figure 9 They are Figure 7 A variation of FIG. 1 is a conceptual diagram for illustrating a specific terminal connection release technology.

[0117] Reference Figure 8, the WIPS 10 may block the channel by sending a CST frame and / or an RTS frame ( S504 a ) to block the AP 20 from responding to the specific terminal 31 .

[0118] A terminal performing wireless LAN communication performs carrier sensing to check whether the channel is busy before sending data. If a wireless signal above a predetermined strength is sensed, the corresponding channel is judged to be busy, and the terminal delays access to the corresponding channel. Such a process is called Clear Channel Assessment (CCA), and the level of the corresponding signal is determined to be detected. It is called the CCA threshold. If the terminal receives a wireless signal above the CCA threshold with the corresponding terminal as the receiver, the terminal processes the received wireless signal. On the other hand, when no wireless signal is sensed in the corresponding channel or a wireless signal with an intensity less than the CCA threshold is sensed, the channel is judged to be idle.

[0119] When it is determined that the channel is in an idle state, each terminal with data to send performs a backoff process after an interframe space (IFS) according to the situation of each terminal, such as an arbitration interframe space (AIFS), a point coordination function interframe space (PCF IFS, PIFS), etc. According to an embodiment, the AIFS can be used as a configuration to replace the existing distributed interframe space (DCF IFS, DIFS). During the interval of the channel idle state, each terminal waits while reducing the slot time corresponding to the random number allocated to the corresponding terminal, and the terminal that has used up all the slot time attempts to access the corresponding channel. In this way, the interval in which each terminal performs the backoff process is called a contention window interval.

[0120] If a terminal successfully accesses the channel, it can send data via the channel. However, if a terminal attempting access collides with another terminal, the colliding terminals each receive a new random number and perform the backoff process again. According to one embodiment, the random number newly assigned to each terminal can be determined within a range that is twice the range of the random number previously assigned to the corresponding terminal. Alternatively, each terminal attempts access by performing the backoff process again during the next contention window interval, in which case each terminal begins performing the backoff process from the remaining time slot of the previous contention window interval. Using this method, each terminal performing wireless LAN communication can avoid mutual collisions on a specific channel.

[0121] Terminals compete for the right to send data. When the data transmission in the previous step is completed, each terminal that has data to send performs a backoff process while reducing the backoff counter (or backoff timer) of the random number assigned to each terminal after the AIFS time. The terminal whose backoff counter ends sends a Request to Send (RTS) frame to notify the corresponding terminal that there is data to send. The RTS frame includes information such as the receiver address, the transmitter address, and the duration. The AP 20 that receives the RTS frame waits for the short interframe space (SIFS) time, and then sends a Clear to Send (CTS) frame to notify the specific terminal 31 that it can send data. The CTS frame includes information such as the receiving address and duration. At this time, the receiving address of the CTS frame can be set to be the same as the sending address of the corresponding RTS frame, that is, the address of the specific terminal 31.

[0122] The AP 20 that receives the CTS frame sends data after a SIFS period of time. When the data transmission is completed, the AP 20 sends an ACK frame after a SIFS period of time to notify the completion of the data transmission. When the ACK frame is received within a preset time, the sending terminal considers that the data transmission is successful. However, when no ACK frame is received within a preset time, the sending terminal considers that the data transmission has failed. On the other hand, the peripheral terminal 30 that receives at least one of the RTS frame and the CTS frame during the transmission process sets a network allocation vector (NAV) and does not perform data transmission until the set NAV ends. At this time, the NAV of each terminal can be set based on the duration field of the received RTS frame or CTS frame.

[0123] As an embodiment, the specific terminal 31 may send a protected query to the AP 20 (S503), and may instruct the AP 20 to respond within a predetermined sixth time.

[0124] As an embodiment, the WIPS 10 may collect information that the specific terminal 31 sends a protected query to the AP 20 (S503). In response, the WIPS 10 may send a CST frame and / or an RTS frame to the AP 20 and / or the specific terminal 31 (S504a).

[0125] AP 20 should respond to the protected query received from specific terminal 31 within the sixth time period. However, since a CST frame and / or RTS frame is received from WIPS 10, data transmission may not be performed until the set NAV expires. In other words, AP 20 may be prevented from responding to specific terminal 31 within the sixth time period (S505). Therefore, specific terminal 31 may determine that the connection release request sent from WIPS 10 (S502) is correct and terminate the connection with AP 20 (S506).

[0126] Reference Figure 9 , the WIPS 10 may obstruct the channel by increasing the congestion level of the AP 20 and / or the specific terminal 31 ( S504 b ) to prevent the AP 20 from responding to the specific terminal 31 .

[0127] As an example, the WIPS 10 collects protected queries sent by a specific terminal 31 to the AP 20 (S503) and, in response, may increase the congestion level of the AP 20 and / or the specific terminal 31 (S504b). For example, the WIPS 10 may generate multiple disguised packets including frames requesting a new connection (Association frame), frames requesting a reconnection (Re-Association frame), or frames requesting the termination of a current connection (Dis-Association frame) to increase the congestion level when sending the protected queries (S503), thereby inducing a mutual authentication failure between the AP 20 and the specific terminal 31. Alternatively, for example, the WIPS 10 may increase the congestion level by adjusting the bit rate of the signal sent by the AP 20 or adjusting the transmission delay time, thereby inducing a mutual authentication failure between the AP 20 and the specific terminal 31. That is, the WIPS 10 may increase the congestion level of the AP 20 and / or the specific terminal 31 ( S504 ) to induce termination of the connection between the AP 20 and the specific terminal 31 connected through IEEE 802.11w ( S506 ).

[0128] Figure 10 This is a conceptual diagram for explaining a specific terminal disconnection technology in a wireless intrusion prevention system according to another embodiment of the present invention.

[0129] Reference Figure 10 ,and Figure 7 The embodiment of the present invention is different in that the embodiment further includes a step in which the WIPS 10 sends a blocking connection (S508) command to the AP 20 and / or the specific terminal 31.

[0130] According to an embodiment, after the connection between the specific terminal 31 and the AP 20 is terminated ( S506 ), the specific terminal 31 may request access to the AP 20 again ( S507 ). For example, the specific terminal 31 may send an authentication request frame to the AP 20 .

[0131] As an example, in response to the specific terminal 31 sending an authentication request frame to the AP 20, the WIPS 10 may send a management frame such as a deauthentication frame to the AP 20 and / or the specific terminal 31. As a result, the connection between the specific terminal 31 and the AP 20 may fail.

[0132] Figure 11 and Figure 12 They are Figure 10 A modified example is shown in which Figure 8 or Figure 9 The embodiments are additionally applied to a conceptual diagram of a wireless intrusion prevention system.

[0133] Reference Figure 11 and Figure 12 , the WIPS 10 may obstruct the channel by sending a CTS frame and / or an RTS frame ( S504 a ) or may obstruct the channel by increasing the congestion level of the AP 20 and / or the specific terminal 31 ( S504 b ) to prevent the AP 20 from responding to the specific terminal 31 .

[0134] After the connection between the specific terminal 31 and the AP 20 is terminated (S506), even if the specific terminal 31 sends an authentication request frame to the AP 20, the WIPS 10 may send a block connection (S508) command such as a deauthentication frame to the AP 20 and / or the specific terminal 31 to induce a connection failure between the specific terminal 31 and the AP 20.

[0135] Figures 13 to 15 They are conceptual diagrams for illustrating a specific terminal connection release technology in a wireless intrusion prevention system according to another embodiment of the present invention.

[0136] First, refer to Figure 13 , the AP 20 and the specific terminal 31 are connected to each other (S601), and due to a specific reason, the specific terminal 31 may lose the encryption key (S101).

[0137] In the state where the encryption key is lost, the specific terminal 31 can request access to the AP 20 (S603). At this time, since the specific terminal 31 has lost all encryption keys, it can send an unprotected access request frame to the AP 20.

[0138] Since AP 20 still determines that specific terminal 31 has a valid connection using the encryption key, AP 20 rejects the access request from specific terminal 31 and may instruct to try again after a predetermined seventh time (S604a). According to an embodiment, a protected query may be sent together (S604b).

[0139] After the seventh time, the specific terminal 31 may transmit a re-access request frame to the AP 20 (S605).

[0140] On the other hand, as an embodiment, the WIPS 10 may prevent the AP 20 from transmitting a protected query to the specific terminal 31 in response to the re-access request frame (S606a). For the prevention (S606a), according to an embodiment, the WIPS 10 may transmit a prevention signal to the AP 20 and / or the specific terminal 31. The AP 20 should transmit a protected query to the specific terminal 31 in response to the re-access request frame, but the prevention (S606a) may prevent the AP 20 from transmitting the protected query to the specific terminal 31 (S607a).

[0141] Therefore, the mutual connection between the AP 20 and the specific terminal 31 may be terminated (S608).

[0142] Reference Figure 14 According to an embodiment, the WIPS 10 may prevent the AP 20 from sending a protected query (S606b) to the specific terminal 31 in response to the frame requesting access (S603). For the prevention (S606b), according to an embodiment, the WIPS 10 may send a prevention signal to the AP 20 and / or the specific terminal 31. The AP 20 should send a protected query to the specific terminal 31 in response to the access request frame, but the prevention (S606b) may prevent the AP 20 from sending the protected query (S604c) to the specific terminal 31. According to an embodiment, the AP 20 rejects the access request from the specific terminal 31 and may also refrain from sending an instruction to try again after a predetermined seventh time.

[0143] Therefore, the mutual connection between the AP 20 and the specific terminal 31 may be terminated (S608).

[0144] Reference Figure 15According to an embodiment, the WIPS 10 may prevent the AP 20 from sending a protected query (S606b) to the specific terminal 31 in response to the access request frame (S603). For the prevention (S606b), according to an embodiment, the WIPS 10 may send a prevention signal to the AP 20 and / or the specific terminal 31. The AP 20 should send a protected query to the specific terminal 31 in response to the access request frame, but the prevention (S606b) may prevent the AP 20 from sending the protected query (S604c) to the specific terminal 31. According to an embodiment, the AP 20 rejects the access request from the specific terminal 31 and may also prevent the AP 20 from sending an instruction to try again after a predetermined seventh time.

[0145] Afterwards, the connection between the AP 20 and the specific terminal 31 is not terminated, and the specific terminal 31 can send a re-access request frame to the AP 20 (S605). At this point, the WIPS 10 can again prevent the AP 20 from sending a protected query to the specific terminal 31 in response to the re-access request frame (S606a). To prevent this (S606a), the WIPS 10 can send a blocking signal to the AP 20 and / or the specific terminal 31, according to an embodiment. The AP 20 should send a protected query to the specific terminal 31 in response to the re-access request frame, but the blocking (S606a) can prevent the AP 20 from sending the protected query to the specific terminal 31 (S607a).

[0146] Therefore, the mutual connection between the AP 20 and the specific terminal 31 may be terminated (S608).

[0147] Figures 13 to 15 The obstruction signal described in the Figure 9 and Figure 10 At least one of the interfering signals described as examples in .

[0148] Figure 16 This is a conceptual diagram for explaining a specific terminal disconnection technology in a wireless intrusion prevention system according to another embodiment of the present invention.

[0149] Reference Figure 16 First, the AP 20 and the specific terminal 31 may be in a connected state (S701). The WIPS 10 may request access from the AP 20 (S702).

[0150] Since the AP 20 still determines that the specific terminal 31 has a valid connection using the encryption key, it rejects the access request from the WIPS 10 and may instruct the WIPS 10 to try again after a predetermined eighth time (S703).

[0151] Thereafter, the AP 20 should send protected queries to the WIPS 10 and the specific terminal 31 respectively to perform a check to confirm whether such an access request is an attack, but this can be blocked by the WIPS 10. As an embodiment, the WIPS 10 can send an interference signal to the AP 20 and / or the specific terminal 31 (S703a). The interference signal can prevent the AP 20 from sending protected queries to the WIPS 10 and / or the specific terminal 31 (S704a).

[0152] Therefore, the mutual connection between the AP 20 and the specific terminal 31 may be terminated (S705).

[0153] Figure 16 The obstruction signal described in the Figure 9 and Figure 10 At least one of the interfering signals described as examples in .

[0154] pass Figures 7 to 16 By using the method described in

[15] , WIPS 10 can disconnect a specific terminal 31 that can be considered as a substantially unauthorized terminal connected to AP 20. Specifically, WIPS 10 can target and disconnect a specific terminal among all terminals connected to AP 20 via a wireless network applying IEEE 802.11w technology.

[0155] Although the embodiments of the present invention have been described above with reference to the accompanying drawings, it will be understood by those skilled in the art that the present invention may be implemented in other specific forms without changing its technical concept or basic features. Therefore, it should be understood that the above embodiments are illustrative in all aspects and are not restrictive.

Claims

1. A wireless network system, comprising: Access point; a plurality of terminals, transmitting wireless frames to the access point or receiving wireless frames from the access point via a wireless network in which protection management frames are activated; as well as A wireless intrusion prevention system monitors the wireless frames, wherein the wireless intrusion prevention system sends a connection release request to at least one target terminal among a plurality of terminals, and prevents the access point from responding to a protected query received from the at least one target terminal, The at least one target terminal sends the protected query to the access point in response to the connection release request.

2. The wireless network system according to claim 1, wherein: The wireless intrusion prevention system sends an interference signal to the access point to prevent the access point from responding to the at least one target terminal.

3. The wireless network system according to claim 2, wherein: The blocking signal includes a clear-to-send frame, ie, a CTS frame, and a request-to-send frame, ie, an RTS frame.

4. The wireless network system according to claim 2, wherein: The obstruction signal includes a signal for increasing a congestion level of the access point.

5. The wireless network system according to claim 4, wherein: The interfering signal includes a spoofed data packet. The wireless network system according to claim 5 , wherein: The disguised data packet includes a frame requesting a new connection, a frame requesting a reconnection, or a frame requesting to release a current connection state.

7. The wireless network system according to claim 1, wherein: The at least one target terminal instructs the access point to respond to the protected query within a predetermined first time, When there is no response within the first time, the at least one target terminal terminates the connection with the access point.

8. The wireless network system according to claim 7, wherein: After the connection between the at least one target terminal and the access point is terminated, the at least one target terminal sends an authentication request frame to the access point.

9. The wireless network system according to claim 8, wherein: After sending the authentication request frame, the wireless intrusion prevention system sends a deauthentication frame to the access point or the at least one target terminal.

10. The wireless network system according to claim 1, wherein: The at least one target terminal is an unauthorized terminal or a terminal connected to an unauthorized attacker through a network. The wireless network system according to claim 1 , wherein: The wireless network in which protection of management frames is activated includes IEEE 802.11w technology.

12. A method for operating a wireless network system, comprising the following steps: The access point maintains a connection with at least one target terminal among a plurality of terminals that transmit wireless frames to the access point or receive wireless frames from the access point through a wireless network activated by protecting a management frame; A wireless intrusion prevention system that monitors the wireless frame sends a connection release request to the at least one target terminal; The at least one target terminal sends a protected query to the access point in response to the connection release request; as well as The wireless intrusion prevention system monitoring the wireless frame sends an interference signal to the access point, wherein the interference signal is used to prevent the access point from responding to the at least one target terminal or preventing the access point from sending the protected query to the at least one target terminal.

13. The method for operating a wireless network system according to claim 12, further comprising the following steps: The at least one target terminal instructs the access point to respond to the protected query within a predetermined first time; as well as When there is no response within the first time, the at least one target terminal terminates the connection with the access point.

14. The method for operating a wireless network system according to claim 13, further comprising the following steps: After the connection between the at least one target terminal and the access point is terminated, the at least one target terminal sends an authentication request frame to the access point; as well as After sending the authentication request frame, the wireless intrusion prevention system sends a deauthentication frame to the access point or the at least one target terminal.

15. The method for operating a wireless network system according to claim 12, further comprising the following steps: The at least one target terminal sends an access request to the access point, The obstruction signal includes a signal sent by the access point to the at least one target terminal to reject an access request or a signal preventing the access point from sending the protected query to the at least one target terminal.

16. The method for operating a wireless network system according to claim 12, further comprising the following steps: The wireless intrusion prevention system sends an access request to the access point, The obstruction signal comprises a signal preventing the access point from transmitting the protected query to the at least one target terminal.

17. A wireless intrusion prevention system comprising: a sensing device that monitors wireless frames transmitted and received by an access point and a plurality of terminals over a wireless network in which protection management frames are activated, and processes information based on the wireless frames; as well as The server determines whether the access point and the plurality of terminals are unauthorized and whether they are operating abnormally based on the processed information, wherein the wireless intrusion prevention system includes a function of providing an interference signal for terminating a connection with the access point to at least one target terminal among the plurality of terminals, The obstruction signal includes a signal that prevents the access point from responding to a protected query received from the at least one target terminal or a signal that prevents the access point from sending the protected query to the at least one target terminal.

18. The wireless intrusion prevention system according to claim 17, wherein: The wireless intrusion prevention system further includes a function of sending a deauthentication frame to the access point or the at least one target terminal when the at least one target terminal sends an authentication request frame to the access point to request access.

Citation Information

Patent Citations

  • Method and apparatus for preventing connection in wireless intrusion prevention system

    KR1020170062301A