A wireless security detection method
By managing the periodic reception of radio frequency scanning reports by wireless access points and combining threat detection strategies, the problem of incomplete detection of malicious access points in wireless networks is solved, and efficient and flexible wireless LAN security detection is achieved.
Patent Information
- Application Number
- CN202411624369.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-14
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2044-11-14
AI Technical Summary
Traditional wireless network security detection methods have problems such as incomplete detection, inefficiency, and difficulty in detecting malicious access points in a timely manner.
By managing the wireless access point to receive radio frequency scanning reports periodically, combined with the pre-configured threat detection strategy, we judge whether there is a malicious access point in the wireless LAN, and record the information of the malicious access point into the security log of the wireless intrusion detection system to notify the network administrator.
It realizes comprehensive detection of wireless LANs, improves detection efficiency, shortens the response time of security incidents, and enhances the flexibility and targeted detection.
Smart Images

Figure CN119277388B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field, and in particular to a wireless security detection method. Background Art
[0002] With the rapid development and widespread adoption of wireless network technology, wireless local area networks (WLANs), while bringing convenience, also face numerous security challenges. Due to the open nature of WLAN channels, wireless networks are vulnerable to various network threats. Unauthorized wireless access points (such as malicious access points masquerading as authorized access points, transmitting wireless signals), malicious users stealing information, and maliciously interfering with normal network usage are common. Traditional wireless network security detection methods often suffer from incomplete detection, low efficiency, and difficulty in timely detecting malicious access points. Summary of the Invention
[0003] In view of the above-mentioned defects or deficiencies in the prior art, the present application aims to provide a wireless security detection method, comprising the following steps:
[0004] periodically receiving a radio frequency scanning report uploaded by a management wireless access point via wireless radio frequency communication, wherein the radio frequency scanning report is a report of the management wireless access point monitoring the surrounding radio frequency environment in real time; the radio frequency scanning report includes information about the managed wireless access points and neighboring wireless access points of the management wireless access point, wherein the neighboring wireless access points are other wireless access points that have overlapping signal coverage with the management wireless access point and are not managed by the management wireless access point;
[0005] Retrieving a pre-configured threat detection policy, and determining whether there is a malicious wireless access point in the wireless local area network based on the threat detection policy and the radio frequency scanning report uploaded by the management wireless access point; the threat detection policy includes multiple illegal access types and a determination condition corresponding to each illegal access type; the malicious wireless access point is the neighboring wireless access point whose information meets the determination condition corresponding to any one of the illegal access types;
[0006] If there is a malicious wireless access point in the wireless local area network, the information of the malicious wireless access point is recorded in the security log of the wireless intrusion detection system, and a Trap message is sent to the network administrator through the network connection to notify the network administrator that there is a malicious wireless access point in the wireless local area network.
[0007] According to the technical solution provided by the embodiment of the present application, each wireless access point has a unique MAC address, and the MAC address can be set as an illegal attribute or a legal attribute by a network administrator; the threat detection strategy includes at least one type of illegal access type and a type of determination condition corresponding to the type of illegal access type; the method also includes pre-configuring the threat detection strategy, and the pre-configuring the threat detection strategy includes at least the following steps:
[0008] Determine whether the MAC address of the neighbor wireless access point is in the wireless access point database list;
[0009] If the MAC address of the neighboring wireless access point is not in the wireless access point database list, determining whether the setting of the MAC address of the neighboring wireless access point is an illegal attribute;
[0010] If the MAC address of the neighboring wireless access point is set to an illegal attribute, the neighboring wireless access point is determined to be a type of illegal access.
[0011] According to the technical solution provided in the embodiment of the present application, the threat detection strategy also includes a second type of illegal access type and a second type of determination condition corresponding to the second type of illegal access type; after determining whether the MAC address setting of the neighboring wireless access point is an illegal attribute, the following steps are also included:
[0012] If the setting of the MAC address of the neighboring wireless access point is not an illegal attribute, determining whether the MAC address of the neighboring wireless access point releases a legal SSID;
[0013] If the MAC address of the neighboring wireless access point releases a legal SSID, the neighboring wireless access point is determined to be a type II illegal access point.
[0014] According to the technical solution provided in the embodiment of the present application, the threat detection strategy also includes three types of illegal access and three types of judgment conditions corresponding to the three types of illegal access; after determining whether the MAC address of the neighboring wireless access point is in the wireless access point database list, the following steps are also included:
[0015] If the MAC address of the neighboring wireless access point is in the wireless access point database list, determining whether the neighboring wireless access point is in a managed online state;
[0016] If the neighboring wireless access point is not in a managed online state, determining whether the beacon frame of the neighboring wireless access point contains legitimate vendor information;
[0017] If the beacon frame of the neighboring wireless access point does not contain legal vendor information, determining whether the neighboring wireless access point has released a legal SSID;
[0018] If the neighboring wireless access point does not release the legal SSID, the neighboring wireless access point is determined to be a type three illegal access point.
[0019] According to the technical solution provided in the embodiment of the present application, the threat detection strategy also includes four types of illegal access and four types of judgment conditions corresponding to the four types of illegal access; after determining whether the MAC address of the neighboring wireless access point has released a legal SSID, the following steps are also included:
[0020] If the MAC address of the neighboring wireless access point has not released a legal SSID, determining whether the neighboring wireless access point has released and reported a hidden SSID;
[0021] If the neighboring wireless access point releases and reports the hidden SSID, the neighboring wireless access point is determined to be a type 4 illegal access point.
[0022] According to the technical solution provided in the embodiment of the present application, the threat detection strategy also includes five types of illegal access and five types of judgment conditions corresponding to the five types of illegal access; after determining whether the beacon frame of the neighboring wireless access point contains legitimate vendor information, the following steps are also included:
[0023] If the beacon frame of the neighboring wireless access point contains legal vendor information, determining whether the channel information of the neighboring wireless access point is correct;
[0024] If the channel information of the neighboring wireless access point is wrong, the neighboring wireless access point is determined to be a type 5 illegal access point.
[0025] According to the technical solution provided in the embodiment of the present application, the threat detection strategy also includes six types of illegal access and six types of judgment conditions corresponding to the six types of illegal access; after determining whether the neighboring wireless access point has released a legitimate SSID, the following steps are also included:
[0026] If the neighboring wireless access point releases a valid SSID, determining whether the encryption method of the valid SSID released by the neighboring wireless access point is correct;
[0027] If the encryption mode of the legal SSID released by the neighboring wireless access point is wrong, the neighboring wireless access point is determined to be a type 6 illegal access point.
[0028] According to the technical solution provided in the embodiment of the present application, the threat detection strategy also includes seven types of illegal access and seven types of judgment conditions corresponding to the seven types of illegal access; after determining whether the neighboring wireless access point is in a managed online state, the following steps are also included:
[0029] If the neighboring wireless access point is in a managed online state, determining whether the management wireless access point corresponding to the neighboring wireless access point has released a valid SSID;
[0030] If the management wireless access point corresponding to the neighbor wireless access point does not release the legal SSID, the neighbor wireless access point is determined to be a type 7 illegal access point.
[0031] According to the technical solution provided in the embodiment of the present application, the threat detection strategy also includes eight types of illegal access and eight types of judgment conditions corresponding to the eight types of illegal access; after determining whether the neighboring wireless access point is in a managed online state, the following steps are also included:
[0032] If the neighboring wireless access point is not in a managed online state, further determining whether the channel of the neighboring wireless access point is legal;
[0033] If the channel of the neighboring wireless access point is illegal, the neighboring wireless access point is determined to be of type eight illegal access type.
[0034] According to the technical solution provided in the embodiment of the present application, after determining whether the channel information of the neighboring wireless access point is correct, the following steps are further included:
[0035] If the channel information of the neighboring wireless access point is correct, the process proceeds to determining whether the neighboring wireless access point has released a valid SSID.
[0036] Compared with the existing technology, the present application has the following advantages: by managing wireless access points to monitor the surrounding RF environment in real time and upload RF scan reports, it can cover the information of managed wireless access points and neighboring wireless access points, realize comprehensive detection of the entire wireless local area network, and effectively avoid detection blind spots. The pre-configured threat detection strategy includes multiple illegal access types and corresponding judgment conditions, which can be customized and adjusted according to different network security requirements, improving the flexibility and targeting of detection. Periodically receiving RF scan reports and performing real-time analysis can promptly detect malicious wireless access points that meet the illegal access type judgment conditions, improve detection efficiency, and greatly shorten the response time of security incidents. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 A flowchart of the steps of the wireless security detection method provided in an embodiment of the present application. DETAILED DESCRIPTION
[0038] The present application will be further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are merely for the purpose of explaining the relevant invention and are not intended to limit the invention. It should also be noted that, for ease of description, only portions relevant to the invention are shown in the accompanying drawings.
[0039] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0040] As mentioned in the background technology, in order to solve the problems in the prior art, this application proposes a wireless security detection method. The method is implemented based on a wireless security detection system, which includes:
[0041] The UWScontroller is the core control unit of the entire detection system, responsible for managing and coordinating various detection strategies and functions. Users use it to enable or disable threat detection strategies and wireless access point (AP) countermeasures.
[0042] AP: wireless access point, including management wireless access point, which is responsible for radio frequency scanning, monitoring the surrounding radio frequency environment in real time, and periodically reporting the monitored information to the UWS controller.
[0043] Furthermore, the AP's RF Scan mode can be configured in two modes: Active and Sentry. In Active mode, the radio processes user traffic normally but periodically scans for monitoring information at set intervals. However, it only monitors its own operating frequency band, such as 2.4 GHz or 5 GHz. In Sentry mode, the radio does not process user traffic but focuses solely on RF scanning, monitoring all channels within the 2.4 GHz and 5 GHz bands. This allows it to obtain more comprehensive, accurate, and rapid RF information. Some threats can only be detected based on RF scan reports from Sentry-mode APs, including APs operating on illegal channels and unmanaged access points connected to the wired network. These two modes can be configured by the network administrator. Sentry mode is used when detection of neighboring wireless access points is high, while Active mode is used when detection of neighboring wireless access points is low.
[0044] WIDS is a wireless intrusion detection system used to detect malicious user attacks and intrusions into wireless networks at an early stage. Its security log is used to record information about APs that are determined to be illegal.
[0045] Network administrator: Responsible for configuring network threat detection policies and receiving trap messages from the UWS controller to promptly understand the presence of rogue wireless access points (rouge APs) on the network.
[0046] APs connect to the UWS controller via wireless radio frequency communication and periodically upload their detected radio frequency scan reports to the UWS controller, providing the controller with basic data for determining whether a router AP is present. The UWS controller interacts with the WIDS. When the UWS controller identifies an AP as a router based on the AP's reported information and pre-configured threat detection policies, it records the information in the WIDS security log for subsequent query and analysis of network security events. The UWS controller sends trap messages to network administrators via a network connection, notifying them of the presence of a router AP, enabling them to take timely action. Network administrators interact with the UWS controller through a specific management interface or tool to configure parameters such as rogue device detection rules to tailor threat detection policies to their network environment. Administrators can also access the WIDS security log for more detailed network security information, enabling comprehensive assessment and management of network security. This detection system, with the UWS controller as the core hub, connects APs, the WIDS, and network administrators. This system effectively detects, logs, and notifies users of rogue wireless access points, and, when necessary, takes countermeasures against them, thereby ensuring the secure operation of the wireless network. Therefore, the following detection method is described based on the UWS controller.
[0047] Please refer to Figure 1 As shown, the control method includes the following steps:
[0048] S1. Periodically receiving a radio frequency scanning report uploaded by a management wireless access point via wireless radio frequency communication, wherein the radio frequency scanning report is a report of the management wireless access point monitoring the surrounding radio frequency environment in real time; the radio frequency scanning report includes information about the managed wireless access points and neighboring wireless access points of the management wireless access point, wherein the neighboring wireless access points are other wireless access points that have overlapping signal coverage with the management wireless access point and are not managed by the management wireless access point;
[0049] Specifically, based on the wireless LAN's coverage and signal strength requirements, select an appropriate location to deploy the management AP to ensure it can effectively monitor the surrounding RF environment. Consider the management AP's signal coverage range and ensure it covers key areas and areas where neighboring wireless access points may exist. Configure the management AP's parameters, including operating frequency band, channel, and transmit power, to optimize its performance and monitoring effectiveness. Enable the management AP's RF scanning function and set the scanning cycle to ensure real-time monitoring of the surrounding RF environment. Collect information about surrounding wireless access points, such as the media access control address (MAC address), service set identifier (SSID), signal strength, operating frequency band, and channel.
[0050] S2. Retrieving a pre-configured threat detection policy and determining whether there is a malicious wireless access point in the wireless local area network based on the threat detection policy and the radio frequency scanning report uploaded by the management wireless access point; the threat detection policy includes multiple illegal access types and a determination condition corresponding to each illegal access type; the malicious wireless access point is the neighboring wireless access point whose information meets the determination condition corresponding to any one of the illegal access types;
[0051] S3. If there is a malicious wireless access point in the wireless local area network, the information of the malicious wireless access point is recorded in the security log of the wireless intrusion detection system, and a Trap message is sent to the network administrator through the network connection to notify the network administrator that there is a malicious wireless access point in the wireless local area network.
[0052] Specifically, upon receiving a trap message (a notification message in the network management protocol), the network administrator should immediately review the message content to understand the malicious wireless access point. They should then log in to the WIDS system and review the detailed records in the security log to further analyze the activities and impact of the malicious wireless access point. Based on the type and severity of the malicious wireless access point, appropriate measures should be taken, such as shutting down the illegal access point, adjusting the network configuration, and strengthening security protections. Continuous network monitoring ensures that malicious wireless access points are effectively addressed and network security is maintained.
[0053] In a preferred embodiment, each wireless access point has a unique MAC address, and the MAC address can be set as an illegal attribute or a legal attribute by a network administrator; the threat detection strategy includes at least one illegal access type and a determination condition corresponding to the illegal access type; the method further includes pre-configuring the threat detection strategy, and the pre-configuring the threat detection strategy includes at least the following steps:
[0054] Determine whether the MAC address of the neighbor wireless access point is in the wireless access point database list;
[0055] If the MAC address of the neighboring wireless access point is not in the wireless access point database list, determining whether the setting of the MAC address of the neighboring wireless access point is an illegal attribute;
[0056] If the MAC address of the neighboring wireless access point is set to an illegal attribute, the neighboring wireless access point is determined to be a type of illegal access.
[0057] Specifically, the network administrator compiles and records the MAC addresses and other information of all authorized wireless access points to form a wireless access point database. This database can be stored in a dedicated database management system or saved as a file on a network management server. If a matching MAC address is found in the database, the neighboring wireless access point is considered a known authorized access point, and no further illegal attribute determination is performed. If no matching MAC address is found, the neighboring wireless access point is determined to be a Type 1 illegal access point.
[0058] In this embodiment, if an administrator manually sets the attributes of an AP with a specific MAC address as an unauthorized AP in the AC's wireless access point database, this AP will be detected as a threat. The AC searches the AP database based on the scanned AP's MAC address. If the AP is found and marked as unauthorized, it is considered a rogue wireless access point (Type I).
[0059] In a preferred embodiment, the threat detection strategy further includes a second type of illegal access and a second type of determination condition corresponding to the second type of illegal access; after determining whether the MAC address of the neighboring wireless access point is set to an illegal attribute, the following steps are further included:
[0060] If the setting of the MAC address of the neighboring wireless access point is not an illegal attribute, determining whether the MAC address of the neighboring wireless access point releases a legal SSID;
[0061] If the MAC address of the neighboring wireless access point releases a legal SSID, the neighboring wireless access point is determined to be a type II illegal access point.
[0062] Specifically, the definition and scope of legal SSIDs are clearly defined. The network administrator determines which SSIDs are authorized and legal, and records them. Once the MAC address of a neighboring wireless access point is determined not to be in the wireless access point database and is not an illegal attribute, the WIDS begins analyzing the SSID broadcast by the neighboring wireless access point. The received SSID is compared with pre-determined legal SSIDs. If the SSID broadcast by the neighboring wireless access point matches any legal SSID, the neighboring wireless access point is considered to have released a legal SSID and is classified as a Type II rogue access point.
[0063] This embodiment takes into account the possibility that hackers may use rogue APs to impersonate legitimate SSIDs, defrauding clients of their access and obtaining security information such as usernames and passwords. This scenario is quite common in practice. To detect such rogue APs, the AC determines whether the rogue AP's MAC address is in the authorized AP database. If the rogue AP impersonates a legitimate SSID and its MAC address is not in the authorized AP database, it is considered a Type II rogue wireless access point.
[0064] In a preferred embodiment, the threat detection strategy further includes three types of illegal access and three types of determination conditions corresponding to the three types of illegal access; after determining whether the MAC address of the neighboring wireless access point is in the wireless access point database list, the following steps are further included:
[0065] If the MAC address of the neighboring wireless access point is in the wireless access point database list, determining whether the neighboring wireless access point is in a managed online state;
[0066] If the neighboring wireless access point is not in a managed online state, determining whether the beacon frame of the neighboring wireless access point contains legitimate vendor information;
[0067] If the beacon frame of the neighboring wireless access point does not contain legal vendor information, determining whether the neighboring wireless access point has released a legal SSID;
[0068] If the neighboring wireless access point does not release the legal SSID, the neighboring wireless access point is determined to be a type three illegal access point.
[0069] Beacon frames are management frames in wireless local area networks (WLANs), and vendor information refers to information related to the device manufacturer. In wireless networks, it is often included in beacon frames or other frames to identify the device manufacturer.
[0070] Specifically, the scope of legal vendor information is determined. The network administrator compiles legal device vendor information as a basis for determining the validity of the vendor information. The WIDS checks the access point status information corresponding to the MAC address in the database to determine whether it is in a managed online state. This can be determined through communication with the management system or through specific status indicators. If the access point is in a managed online state, it is considered normal and no further determination is made. If it is not in a managed online state, the WIDS proceeds to the next step. The WIDS analyzes the beacon frames sent by neighboring wireless access points and extracts the vendor information. The extracted vendor information is compared with pre-determined legal vendor information. If a match is found, the beacon frame of the neighboring wireless access point is considered to contain legal vendor information. If no match is found, the WIDS proceeds to the next step. If the beacon frame of the neighboring wireless access point does not contain legal vendor information, the WIDS determines whether the neighboring wireless access point has released a legal SSID. Similar to the determination of Type II unauthorized access, the SSID broadcast by the neighboring wireless access point is compared with the legal SSID. If the legal SSID is not released, the neighboring wireless access point is determined to be a type 3 illegal access point.
[0071] This embodiment takes into account the possibility that a hacker may impersonate a legitimate AP's MAC address and send a legitimate SSID, but the Vendor field in its beacon frame may be empty. The AC will check whether the beacon frame sent by the AP contains the vendor field. If not, the AP is a Type 3 rogue wireless access point.
[0072] In a preferred embodiment, the threat detection strategy further includes four types of illegal access and four types of determination conditions corresponding to the four types of illegal access; after determining whether the MAC address of the neighboring wireless access point has released a legitimate SSID, the following steps are further included:
[0073] If the MAC address of the neighboring wireless access point has not released a legal SSID, determining whether the neighboring wireless access point has released and reported a hidden SSID;
[0074] If the neighboring wireless access point releases and reports the hidden SSID, the neighboring wireless access point is determined to be a type 4 illegal access point.
[0075] Specifically, you can use the NetStumbler tool for active detection, sending probe requests to each possible wireless channel to observe whether there is a response. If the probing AP detects that the neighboring AP's MAC address is not in the authorized AP database and that the Beacon frame does not contain the SSID field, that is, the neighboring AP has released a hidden SSID, then the neighboring AP is classified as a Type 4 illegal access type.
[0076] This embodiment takes into account that a hacker may not include the SSID field in the beacon frame to avoid detection. However, a hacker may still send a probe response frame to the client that sent the probe request, thereby deceiving the client into accessing the network and obtaining security information. To detect this situation, four types of illegal access determination conditions are set.
[0077] In a preferred embodiment, the threat detection strategy further includes five types of illegal access and five types of determination conditions corresponding to the five types of illegal access; after determining whether the beacon frame of the neighboring wireless access point contains legitimate vendor information, the following steps are further included:
[0078] If the beacon frame of the neighboring wireless access point contains legal vendor information, determining whether the channel information of the neighboring wireless access point is correct;
[0079] If the channel information of the neighboring wireless access point is wrong, the neighboring wireless access point is determined to be a type 5 illegal access point.
[0080] Specifically, the scope and standards for legal channel information are first clarified. The network administrator determines which channels are legally permitted for use within a specific wireless LAN environment. WIDS analyzes the channel settings of neighboring wireless access points and compares them with pre-determined legal channel information. This can be determined by reading channel parameters from RF scan reports or directly monitoring the wireless signal channel. If a neighboring wireless access point's channel information is found to be incorrect, meaning it is not within the legal channel range, the neighboring wireless access point is identified as a Type V illegal access point.
[0081] This embodiment takes into account the possibility that a hacker may impersonate a legitimate AP's MAC, but send beacon frames on a different channel than the legitimate AP's. The legitimate AP's operating channel is reported to the AC by the AP, so the AC knows the AP's current channel. APs can change their channels for legitimate reasons, such as manual configuration and radar detection. This information is updated asynchronously with the arrival of radio scan reports. Therefore, it's possible that a radio scan report may indicate a change in the AP's operating channel before the actual configuration change has been received. Therefore, this detection condition requires that a channel mismatch is detected in two radio scan reports within 2 x Scan-Report-Interval (radio scan report interval) for the AP to be considered a threat.
[0082] In a preferred embodiment, the threat detection strategy further includes six types of illegal access and six types of determination conditions corresponding to the six types of illegal access; after determining whether the neighboring wireless access point has released a legitimate SSID, the following steps are further included:
[0083] If the neighboring wireless access point releases a valid SSID, determining whether the encryption method of the valid SSID released by the neighboring wireless access point is correct;
[0084] If the encryption mode of the legal SSID released by the neighboring wireless access point is wrong, the neighboring wireless access point is determined to be a type 6 illegal access point.
[0085] Specifically, the encryption method standard for a legitimate SSID is determined. The network administrator specifies which encryption methods are recognized and legal in the wireless local area network. WIDS analyzes the encryption method of the legitimate SSID released by the neighboring wireless access point and compares it with the predetermined legal encryption method standard. This can be determined by monitoring the encryption parameters of the wireless signal or reading the encryption information in the RF scan report. If it is found that the encryption method of the legitimate SSID released by the neighboring wireless access point is incorrect, that is, it does not meet the legal encryption method standard, the neighboring wireless access point is determined to be a type 6 illegal access type.
[0086] In a preferred embodiment, the threat detection strategy further includes seven types of illegal access and seven types of determination conditions corresponding to the seven types of illegal access; after determining whether the neighboring wireless access point is in a managed online state, the following steps are further included:
[0087] If the neighboring wireless access point is in a managed online state, determining whether the management wireless access point corresponding to the neighboring wireless access point has released a valid SSID;
[0088] If the management wireless access point corresponding to the neighbor wireless access point does not release the legal SSID, the neighbor wireless access point is determined to be a type 7 illegal access point.
[0089] Specifically, the definition and scope of legal SSIDs are clearly defined. The network administrator determines which SSIDs are authorized and legal, and records them. Once a neighboring wireless access point is determined to be managed and online, the WIDS checks the SSID broadcast by its corresponding management wireless access point. The management wireless access point's SSID is compared with pre-determined legal SSIDs. If the management wireless access point does not broadcast a legal SSID, the access is considered a Type 7 unauthorized access.
[0090] In a preferred embodiment, the threat detection strategy further includes eight types of illegal access and eight types of determination conditions corresponding to the eight types of illegal access; after determining whether the neighboring wireless access point is in a managed online state, the following steps are further included:
[0091] If the neighboring wireless access point is not in a managed online state, further determining whether the channel of the neighboring wireless access point is legal;
[0092] If the channel of the neighboring wireless access point is illegal, the neighboring wireless access point is determined to be of type eight illegal access type.
[0093] For example, different countries have different regulations on radio resources. Some channels are legal in some countries but illegal in others. This step can detect if an AP is operating on an illegal channel. Legal channels in China (CN) are 1-13, while those in the United States (US) are 1-11. If the country code is set to US on the AC, an AP operating on channel 12 or 13 will be detected as a threat.
[0094] In a preferred embodiment, after determining whether the channel information of the neighboring wireless access point is correct, the following steps are further included:
[0095] If the channel information of the neighboring wireless access point is correct, the process proceeds to determining whether the neighboring wireless access point has released a valid SSID.
[0096] This article uses specific examples to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the method and core ideas of this application. The above is only the preferred implementation method of this application. It should be pointed out that due to the limitations of textual expression, there are objectively infinite specific structures. For ordinary technicians in this technical field, without departing from the principles of the present invention, they can also make several improvements, modifications or changes, and can also combine the above technical features in an appropriate manner; these improvements, modifications, changes or combinations, or the direct application of the inventive concept and technical solution to other occasions without improvement, should be regarded as the scope of protection of this application.
Claims
1. A wireless security detection method, characterized in that: The following steps are involved: periodically receiving a radio frequency scanning report uploaded by a management wireless access point via wireless radio frequency communication, wherein the radio frequency scanning report is a report of the management wireless access point monitoring the surrounding radio frequency environment in real time; the radio frequency scanning report includes information about the managed wireless access points and neighboring wireless access points of the management wireless access point, wherein the neighboring wireless access points are other wireless access points that have overlapping signal coverage with the management wireless access point and are not managed by the management wireless access point; Retrieving a pre-configured threat detection policy, and determining whether there is a malicious wireless access point in the wireless local area network based on the threat detection policy and the radio frequency scanning report uploaded by the management wireless access point; the threat detection policy includes multiple illegal access types and a determination condition corresponding to each illegal access type; the malicious wireless access point is the neighboring wireless access point whose information meets the determination condition corresponding to any one of the illegal access types; If there is a malicious wireless access point in the wireless local area network, the information of the malicious wireless access point is recorded in the security log of the wireless intrusion detection system, and a Trap message is sent to the network administrator through the network connection to notify the network administrator that there is a malicious wireless access point in the wireless local area network.
2. The wireless security detection method according to claim 1, wherein: Each wireless access point has a unique MAC address, and the MAC address can be set as an illegal attribute or a legal attribute by a network administrator; the threat detection strategy includes at least one illegal access type and a determination condition corresponding to the illegal access type; the method further includes pre-configuring the threat detection strategy, and the pre-configuring the threat detection strategy includes at least the following steps: Determine whether the MAC address of the neighbor wireless access point is in the wireless access point database list; If the MAC address of the neighboring wireless access point is not in the wireless access point database list, determining whether the setting of the MAC address of the neighboring wireless access point is an illegal attribute; If the MAC address of the neighboring wireless access point is set to an illegal attribute, the neighboring wireless access point is determined to be a type of illegal access.
3. The wireless security detection method according to claim 2, wherein: The threat detection strategy also includes a second type of illegal access type and a second type of determination condition corresponding to the second type of illegal access type; after determining whether the setting of the MAC address of the neighboring wireless access point is an illegal attribute, the following steps are further included: If the setting of the MAC address of the neighboring wireless access point is not an illegal attribute, determining whether the MAC address of the neighboring wireless access point releases a legal SSID; If the MAC address of the neighboring wireless access point releases a legal SSID, the neighboring wireless access point is determined to be a type II illegal access point.
4. The wireless security detection method according to claim 2, wherein: The threat detection strategy also includes three types of illegal access and three types of determination conditions corresponding to the three types of illegal access; after determining whether the MAC address of the neighboring wireless access point is in the wireless access point database list, the following steps are further included: If the MAC address of the neighboring wireless access point is in the wireless access point database list, determining whether the neighboring wireless access point is in a managed online state; If the neighboring wireless access point is not in a managed online state, determining whether the beacon frame of the neighboring wireless access point contains legitimate vendor information; If the beacon frame of the neighboring wireless access point does not contain legal vendor information, determining whether the neighboring wireless access point has released a legal SSID; If the neighboring wireless access point does not release the legal SSID, the neighboring wireless access point is determined to be a type three illegal access point.
5. The wireless security detection method according to claim 3, wherein: The threat detection strategy also includes four types of illegal access and four types of determination conditions corresponding to the four types of illegal access; after determining whether the MAC address of the neighboring wireless access point has released a legal SSID, the following steps are further included: If the MAC address of the neighboring wireless access point has not released a legal SSID, determining whether the neighboring wireless access point has released and reported a hidden SSID; If the neighboring wireless access point releases and reports the hidden SSID, the neighboring wireless access point is determined to be a type 4 illegal access point.
6. The wireless security detection method according to claim 4, wherein: The threat detection strategy also includes five types of illegal access and five types of determination conditions corresponding to the five types of illegal access; after determining whether the beacon frame of the neighboring wireless access point contains legitimate vendor information, the following steps are further included: If the beacon frame of the neighboring wireless access point contains legal vendor information, determining whether the channel information of the neighboring wireless access point is correct; If the channel information of the neighboring wireless access point is wrong, the neighboring wireless access point is determined to be a type 5 illegal access point.
7. The wireless security detection method according to claim 4, wherein: The threat detection strategy also includes six types of illegal access and six types of determination conditions corresponding to the six types of illegal access. After determining whether the neighboring wireless access point has released a legitimate SSID, the following steps are further included: If the neighboring wireless access point releases a valid SSID, determining whether the encryption method of the valid SSID released by the neighboring wireless access point is correct; If the encryption mode of the legal SSID released by the neighboring wireless access point is wrong, the neighboring wireless access point is determined to be a type 6 illegal access point.
8. The wireless security detection method according to claim 4, wherein: The threat detection strategy further includes seven types of illegal access and seven types of determination conditions corresponding to the seven types of illegal access; after determining whether the neighboring wireless access point is in a managed online state, the following steps are further included: If the neighboring wireless access point is in a managed online state, determining whether the management wireless access point corresponding to the neighboring wireless access point has released a valid SSID; If the management wireless access point corresponding to the neighbor wireless access point does not release the legal SSID, the neighbor wireless access point is determined to be a type 7 illegal access point.
9. The wireless security detection method according to claim 7, wherein: The threat detection strategy also includes eight types of illegal access and eight types of determination conditions corresponding to the eight types of illegal access; after determining whether the neighboring wireless access point is in a managed online state, the following steps are further included: If the neighboring wireless access point is not in a managed online state, further determining whether the channel of the neighboring wireless access point is legal; If the channel of the neighboring wireless access point is illegal, the neighboring wireless access point is determined to be of type eight illegal access type.
10. The wireless security detection method according to claim 6, wherein: After determining whether the channel information of the neighboring wireless access point is correct, the following steps are further included: If the channel information of the neighboring wireless access point is correct, the process proceeds to determining whether the neighboring wireless access point has released a valid SSID.
Citation Information
Patent Citations
Method and system for detecting rogue wireless access point in local area network
CN102843684A
Method for detecting illegally cut-in point in radio cocal network
CN1588878A