A detection method and system for unknown Wi-Fi drones

By using dual WiFi wireless network cards to work together, detect and analyze the communication characteristics of unknown WiFi drones, the problems of low detection accuracy and high false alarm rate in the existing technology are solved, and efficient identification and monitoring of the drone are achieved.

CN119697627BActive Publication Date: 2025-05-30BEIJING LIZHENG TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510214666.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-05-30
Estimated Expiration
2045-02-26

AI Technical Summary

Technical Problem

When monitoring and identifying unauthorized WiFi drones, the prior art lacks high-precision and low false alarm detection methods, making it difficult to effectively distinguish normal equipment from drones, and in-depth analysis of the communication characteristics of suspected targets.

Method used

The first WiFi wireless network card detects hot spots that are not on the whitelist, and uses the second WiFi wireless network card to perform data sniffing and analysis, filters out messages containing suspected target MAC addresses, and combines encryption methods and video streaming protocol analysis to determine whether there is a downlink unidirectional video stream or conforms to the communication characteristics of the drone.

Benefits of technology

It realizes accurate identification of unknown WiFi drones, improves detection accuracy and efficiency, reduces false alarm rates, and can deeply analyze communication characteristics to ensure effective monitoring of airspace in sensitive areas.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119697627B_ABST
    Figure CN119697627B_ABST
Patent Text Reader

Abstract

The present application provides a detection method and system for unknown Wi-Fi drones. Among them, when a hotspot not in the whitelist is detected by the first Wi-Fi wireless network card, the hotspot is determined as a suspected target, and the communication parameters of the suspected target are sent to the second Wi-Fi wireless network card; according to the channel number where the suspected target is located, the second Wi-Fi wireless network card performs data sniffing and packet capture on the channel where the suspected target is located to obtain data packets, and all packets containing the MAC address of the suspected target within a preset time are screened out from the data packets, and the MAC address of the suspected target is the source MAC address; in the case that the target MAC address in all packets containing the MAC address of the suspected target is the MAC address of the same communication terminal, according to the network type created by the suspected target and the Wi-Fi drone judgment strategy corresponding to the network type, it is determined whether the suspected target is an unknown Wi-Fi drone. The technical solution provided by the present application improves the wireless network security monitoring ability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the technical fields of wireless network security and drone monitoring, and in particular, to a detection method and system for unknown Wi-Fi drones. Background Art

[0002] With the popularization of drone technology, wireless networks have become an important means of drone communication. In sensitive areas such as airports, military bases, and important public facilities, there is an urgent need to monitor and identify unauthorized Wi-Fi drones to ensure airspace security and prevent potential security threats. To meet this need, a technical solution capable of real-time monitoring, identifying, and analyzing the activities of unknown Wi-Fi drones is required, which should have high accuracy, low false alarm rate, and be able to respond quickly.

[0003] Currently, the detection of Wi-Fi drones mainly relies on the scanning and detection functions of a single wireless network card. Such systems usually maintain a whitelist of known legitimate devices, and when a hotspot not in the whitelist is detected, it is marked as a suspicious object. However, this detection method can only provide a preliminary judgment and has limited ability to further confirm whether a suspected target is an unknown Wi-Fi drone.

[0004] The traditional single wireless network card detection method has several obvious deficiencies: First, it lacks the ability to deeply analyze suspected targets and cannot effectively distinguish normal devices from drones; Second, since it cannot listen to multiple channels simultaneously, it may miss important communication data, resulting in false alarms or missed reports; Finally, the existing methods do not fully utilize MAC addresses and communication patterns to accurately locate and identify specific types of devices, such as Wi-Fi drones. Summary of the Invention

[0005] The embodiments of the present application provide a detection method and system for unknown Wi-Fi drones to solve the problem of poor wireless network security monitoring ability in the prior art.

[0006] In a first aspect, the embodiments of the present application provide a detection method for unknown Wi-Fi drones, including:

[0007] When a hotspot not in the whitelist is detected by a first Wi-Fi wireless network card, the hotspot is determined as a suspected target, and the communication parameters of the suspected target are sent to a second Wi-Fi wireless network card. The hotspot is any wireless network node that emits a Wi-Fi signal and allows other devices to connect to it. The communication parameters of the suspected target include the MAC address of the suspected target, the channel number where the suspected target is located, and the encryption method.

[0008] According to the channel number where the suspected target is located, use the second Wi-Fi wireless network card to perform data sniffing and packet capture on the channel where the suspected target is located to obtain data packets, and screen out all the packets containing the MAC address of the suspected target within a preset time from the data packets. The MAC address of the suspected target is the source MAC address;

[0009] In the case where the target MAC address in all the packets containing the MAC address of the suspected target is the MAC address of the same communication terminal, when the encryption method indicates that the network type created by the suspected target is an unencrypted open network, perform video stream transmission protocol analysis on the packets, and determine whether there is a downstream unidirectional video stream according to the analysis result, so as to determine whether the suspected target is an unknown Wi-Fi drone. The video stream transmission protocol includes at least one of the Real-Time Streaming Protocol (RTSP) and the Real-Time Transport Protocol (RTP); or, when the encryption method indicates that the network type created by the suspected target is an encrypted network, determine whether the suspected target is an unknown Wi-Fi drone according to whether the communication characteristics in the packets conform to the known Wi-Fi drone communication characteristics.

[0010] Optionally, the determining whether the suspected target is an unknown Wi-Fi drone according to whether there is a downstream unidirectional video stream indicated by the analysis result includes:

[0011] If the analysis result indicates that there is a downstream unidirectional video stream, then determine that the suspected target is an unknown Wi-Fi drone; or, if the analysis result indicates that there is no downstream unidirectional video stream, then determine that the suspected target is not an unknown Wi-Fi drone.

[0012] Optionally, the determining whether the suspected target is an unknown Wi-Fi drone according to whether the communication characteristics in the packets conform to the known Wi-Fi drone communication characteristics includes:

[0013] Extract communication characteristics from the packets. The communication characteristics include at least one of the following: the transmission rate of the packets in the upstream and downstream directions, the size distribution of the packets, the time distribution of the packets, and the frame type distribution;

[0014] Use a pre-trained machine learning model to classify the communication characteristics to obtain a classification result indicating whether the communication characteristics conform to the known Wi-Fi drone communication characteristics;

[0015] If the classification result indicates that the communication characteristics conform to the known Wi-Fi drone communication characteristics, then determine that the suspected target is an unknown Wi-Fi drone; or, if the classification result indicates that the communication characteristics do not conform to the known Wi-Fi drone communication characteristics, then determine that the suspected target is not an unknown Wi-Fi drone.

[0016] Optionally, after determining that the suspected target is an unknown Wi-Fi drone, the method further includes:

[0017] Sending the detection result of the unknown Wi-Fi drone to a second terminal device through the second Wi-Fi wireless network card, where the detection result of the unknown Wi-Fi drone includes a MAC address and an analysis result, or includes a MAC address and communication characteristics.

[0018] Optionally, after screening out all packets containing the MAC address of the suspected target within a preset time from the data packets, the method further includes:

[0019] Determining whether the target MAC addresses in all packets containing the MAC address of the suspected target are MAC addresses of the same communication terminal;

[0020] If the target MAC addresses in all packets containing the MAC address of the suspected target are not MAC addresses of the same communication terminal, it is determined that the suspected target is not an unknown Wi-Fi drone.

[0021] Optionally, after determining that the suspected target is not an unknown Wi-Fi drone, the method further includes:

[0022] Storing the communication parameters of the suspected target into the whitelist through the second Wi-Fi wireless network card, where the communication parameters further include a wireless network identifier.

[0023] Optionally, generating a whitelist includes:

[0024] Obtaining scan parameters, where the scan parameters include a scan mode, a scan frequency, and a channel list;

[0025] Determining any channel in the channel list as an initial channel, and sequentially selecting different channels in a predefined order or randomly. For each channel, performing a scan action corresponding to the scan mode according to the scan frequency to obtain a scan result including multiple hotspots;

[0026] Receiving label information on whether each hotspot is a Wi-Fi drone, and screening out all hotspots that are not Wi-Fi drones based on the label information, and generating a whitelist of hotspots including all hotspots that are not Wi-Fi drones.

[0027] In a second aspect, an embodiment of the present application provides a detection system for an unknown Wi-Fi drone, including:

[0028] A determination sending module, configured to, when detecting a hotspot not in the whitelist through a first Wi-Fi wireless network card, determine the hotspot as a suspected target, and send communication parameters of the suspected target to a second Wi-Fi wireless network card, where the hotspot is any wireless network node that emits a Wi-Fi signal and allows other devices to connect to it, and the communication parameters of the suspected target include the MAC address of the suspected target, the channel number where the suspected target is located, and the encryption method;

[0029] A packet capture and screening module, configured to, according to the channel number where the suspected target is located, perform data sniffing and packet capture on the channel where the suspected target is located through the second Wi-Fi wireless network card to obtain data packets, and screen out all packets containing the MAC address of the suspected target within a preset time from the data packets, where the MAC address of the suspected target is the source MAC address;

[0030] A determination module, configured to, when the target MAC address in all packets containing the MAC address of the suspected target is the MAC address of the same communication terminal, when the encryption method indicates that the network type created by the suspected target is an unencrypted open network, perform video stream transmission protocol analysis on the packets, and determine whether there is a downstream unidirectional video stream according to the analysis result, to determine whether the suspected target is an unknown Wi-Fi drone, where the video stream transmission protocol includes at least one of the Real-Time Streaming Protocol (RTSP) and the Real-Time Transport Protocol (RTP); or, when the encryption method indicates that the network type created by the suspected target is an encrypted network, determine whether the suspected target is an unknown Wi-Fi drone according to whether the communication characteristics in the packets conform to the known communication characteristics of Wi-Fi drones.

[0031] In a third aspect, an embodiment of the present application provides a computing device, including a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a detection method for an unknown Wi-Fi drone as described in the first aspect above.

[0032] In a fourth aspect, an embodiment of the present application provides a computer storage medium, storing a computer program, where when the computer program is executed by a computer, it implements a detection method for an unknown Wi-Fi drone as described in the first aspect.

[0033] In an embodiment of the present application, when a hotspot not in the whitelist is detected by the first Wi-Fi wireless network card, the hotspot is determined as a suspected target, and communication parameters of the suspected target are sent to the second Wi-Fi wireless network card. The hotspot is any wireless network node that emits a Wi-Fi signal and allows other devices to connect to it. The communication parameters of the suspected target include the MAC address of the suspected target and the channel number where the suspected target is located. According to the channel number where the suspected target is located, data sniffing and packet capture are performed on the channel where the suspected target is located through the second Wi-Fi wireless network card to obtain data packets, and all packets containing the MAC address of the suspected target within a preset time are filtered out from the data packets. The MAC address of the suspected target is the source MAC address. In the case where the target MAC address in all packets containing the MAC address of the suspected target is the MAC address of the same communication terminal, it is determined whether the suspected target is an unknown Wi-Fi drone according to the network type created by the suspected target and the Wi-Fi drone judgment strategy corresponding to the network type.

[0034] The technical solution of the present application has the following beneficial effects:

[0035] In the present application, a hotspot not in the whitelist is detected by the first Wi-Fi wireless network card, and targeted data sniffing and analysis are performed using the second Wi-Fi wireless network card, which can effectively identify potential unknown Wi-Fi drones. This way of collaborative work of the two network cards not only improves the detection accuracy and efficiency but also ensures in-depth analysis of communication data within a specific channel, thereby accurately filtering out all network traffic related to the suspected target within a preset time window. By identifying the one-to-one communication mode, interference from ordinary multi-terminal wireless networks is excluded, and the recognition accuracy is improved.

[0036] Further, in an embodiment of the present application, when the encryption method indicates that the network type created by the suspected target is an unencrypted open network, protocol analysis of video stream transmission is performed on the packets. If the analysis result indicates the existence of a downstream unidirectional video stream, it is determined that the suspected target is an unknown Wi-Fi drone. Or, if the analysis result indicates the non-existence of a downstream unidirectional video stream, it is determined that the suspected target is not an unknown Wi-Fi drone. The video stream transmission protocol includes at least one of the Real-Time Streaming Protocol (RTSP) and the Real-Time Transport Protocol (RTP).

[0037] According to the above method, by identifying the downstream unidirectional video stream communication mode, different from other communication scenarios, the recognition accuracy is improved.

[0038] These aspects or other aspects of the present application will be more clearly understood in the following description of the embodiments. Description of the Drawings

[0039] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0040] Figure 1 Flowchart of a detection method for unknown Wi-Fi drones provided by an embodiment of the present application;

[0041] Figure 2 Structural schematic diagram of a detection system for unknown Wi-Fi drones provided by an embodiment of the present application;

[0042] Figure 3 Structural schematic diagram of a computing device provided by an embodiment of the present application. Detailed implementation manners

[0043] To enable those skilled in the art of the present technology to better understand the solutions of the present application, the following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application.

[0044] In some processes described in the specification and claims of the present application and the above drawings, a plurality of operations appear in a specific order. However, it should be clearly understood that these operations may not be executed in the order in which they appear herein or may be executed in parallel. The serial numbers of the operations, such as 11, 12, etc., are only used to distinguish different operations, and the serial numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions such as "first", "second", etc. in this article are used to distinguish different messages, devices, modules, etc., and do not represent a sequence, nor do they limit that "first" and "second" are of different types.

[0045] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.

[0046] Figure 1 Flowchart of a detection method for unknown Wi-Fi drones provided by an embodiment of the present application, as Figure 1 shown, the method includes:

[0047] Step 101: When a hotspot not in the whitelist is detected by the first Wi-Fi wireless network card, determine the hotspot as a suspected target and send the communication parameters of the suspected target to the second Wi-Fi wireless network card.

[0048] In this step, the first Wi-Fi wireless network card is used to perform network scanning tasks. It can identify and collect information about all available wireless access points (i.e., hotspots) in the surrounding environment. A hotspot is any wireless network node that emits a Wi-Fi signal and allows other devices to connect to it. When a hotspot not in the whitelist is detected, the hotspot is regarded as a potential security threat and marked as a suspected target. The communication parameters of the suspected target include the MAC address of the suspected target, the channel number where the suspected target is located, and the encryption method.

[0049] In actual operation, the first Wi-Fi wireless network card continuously monitors the Wi-Fi signals in the environment. By comparing with the preset whitelist, it quickly filters out unknown or unauthorized hotspots. Once a suspected target is found, the system automatically records its communication parameters and transfers this information to the second Wi-Fi wireless network card through an internal communication mechanism for more in-depth data collection and analysis.

[0050] For example, in an airport security monitoring scenario, the first Wi-Fi wireless network card is installed at a fixed location to monitor the surrounding airspace all day long. Suppose a drone enters the monitoring area without authorization and turns on its Wi-Fi module to attempt to establish a communication link. At this time, since the Wi-Fi signal of the drone does not appear in the whitelist, it will immediately be marked as a suspected target and a further inspection process will be initiated.

[0051] Step 102: According to the channel number where the suspected target is located, use the second Wi-Fi wireless network card to perform data sniffing and packet capturing on the channel where the suspected target is located to obtain data packets. Screen out all packets containing the MAC address of the suspected target within a preset time from the data packets, and the MAC address of the suspected target is the source MAC address.

[0052] In this step, data sniffing and packet capturing is a technology that refers to capturing and analyzing transmitted data packets at the network level to understand the content and pattern of network traffic. A channel is a specific frequency range for radio wave transmission. In a Wi-Fi network, different channels can reduce interference and allow multiple networks to coexist. The MAC address appears as the source address in the data packet header, indicating the sender of the data.

[0053] In actual operation, after the second WiFi wireless network card receives the communication parameters regarding the suspected target, it will switch to the corresponding channel and start monitoring all data transmission activities on that channel. The system will capture all packets from the suspected target within a preset time window and filter out those packets that contain the suspected target's MAC address as the source address for subsequent analysis.

[0054] For example, continuing with the previous example, when the WiFi signal of the drone is marked as a suspected target, the second WiFi wireless network card will adjust its settings to synchronize with the same channel used by the drone and then start collecting all packets for a period of time. This step helps to obtain detailed information about the communication behavior of the suspected target.

[0055] Step 103: In the case where the target MAC address in all packets containing the MAC address of the suspected target is the MAC address of the same communication terminal, determine whether the suspected target is an unknown WiFi drone according to the network type created by the suspected target and the WiFi drone judgment strategy corresponding to the network type.

[0056] In this step, MAC address matching is a method used in network communication to verify whether there is a communication relationship between two devices. If the target MAC addresses of multiple packets are the same, it indicates the existence of a fixed communication terminal. The WiFi drone judgment strategy is a set of rules based on network type and other behavioral characteristics for evaluating whether a wireless node is likely to be an unknown WiFi drone.

[0057] In actual operation, the system will check all packets that contain the MAC address of the suspected target as the source address to determine whether their target MAC addresses point to the same communication terminal. Combining the network type created by the suspected target and its characteristics, and following the predefined WiFi drone judgment strategy, the system can make a final determination to confirm whether the suspected target is an unknown WiFi drone.

[0058] For example, continuing with the above case, the analysis shows that all packets from the suspected drone are sent to the same ground control station. Based on the common network configuration and operating habits of drones, the system applies the WiFi drone judgment strategy and determines that the suspected target is very likely an unauthorized WiFi drone and triggers an alarm to notify the security personnel to take action.

[0059] This three-step process quickly screens for abnormal hotspots through the first Wi-Fi wireless network card, the second Wi-Fi wireless network card focuses on data collection on specific channels, and finally, through in-depth analysis of data packets, it achieves accurate identification of unknown Wi-Fi drones. This method not only improves the efficiency and accuracy of detection but also reduces the possibility of false alarms, effectively enhancing the protection ability of air security in sensitive areas.

[0060] To address the problem of insufficient accuracy in detecting unknown Wi-Fi drones in traditional methods, in some embodiments, the communication parameters of the suspected target in step 103 further include the encryption method. Determining whether the suspected target is an unknown Wi-Fi drone based on the network type created by the suspected target and the Wi-Fi drone judgment strategy corresponding to the network type includes:

[0061] When the encryption method indicates that the network type created by the suspected target is an unencrypted open network, perform video stream transmission protocol analysis on the packet. If the analysis result indicates the existence of a downstream unidirectional video stream, then determine that the suspected target is an unknown Wi-Fi drone; or, if the analysis result indicates the non-existence of a downstream unidirectional video stream, then determine that the suspected target is not an unknown Wi-Fi drone. The video stream transmission protocol includes at least one of the Real-Time Streaming Protocol (RTSP) and the Real-Time Transport Protocol (RTP).

[0062] In this embodiment, to further improve the accuracy of identifying the suspected target, in addition to the MAC address and channel number, the encryption method of the network type created by the suspected target is also considered. By analyzing the encryption method, it is possible to more accurately determine whether the network is likely to be created by an unknown Wi-Fi drone and adjust the subsequent analysis strategy accordingly.

[0063] In the embodiments of the present application, when the encryption method indicates that the suspected target creates an unencrypted open network, the system will perform additional analysis of the packet content, especially for video stream transmission protocols (such as the Real-Time Streaming Protocol RTSP or the Real-Time Transport Protocol RTP). This analysis aims to confirm the existence of a downstream unidirectional video stream, that is, the continuous video data transmission from the suspected target to the ground control station or other receiving devices. If such a video stream is detected, given that drones usually send real-time video feedback to the ground station, it can be reasonably inferred that the suspected target is likely to be an unknown Wi-Fi drone. Conversely, if no such video stream is found, the possibility of it being an unknown Wi-Fi drone can be preliminarily excluded.

[0064] The following is a specific embodiment:

[0065] In a security monitoring scenario of a large commercial park, the second WiFi wireless network card has captured data packets from a suspected WiFi drone that is not on the whitelist. Further analysis shows that the suspected target has created a completely open and unencrypted WiFi network. According to the pre-set WiFi drone judgment strategy, the system starts to analyze the captured data packets for the video streaming protocol. After detailed protocol parsing, a unidirectional downstream video stream conforming to the RTP standard is found, and these video streams are being transmitted from the suspected target to a fixed IP address, most likely the location of the ground control station. Based on this information and combined with other behavioral characteristics, the system finally determines that the suspected target is an unauthorized WiFi drone and immediately notifies the security team to take corresponding measures to ensure the safety of the park.

[0066] To solve the problem of insufficient detection accuracy for unknown WiFi drones in traditional methods, in some embodiments, the communication parameters of the suspected target described in step 103 further include the encryption method, and determining whether the suspected target is an unknown WiFi drone according to the network type created by the suspected target and the WiFi drone judgment strategy corresponding to the network type further includes:

[0067] When the encryption method indicates that the network type created by the suspected target is an encrypted network, extract communication characteristics from the packet, and the communication characteristics include at least one of the following: the transmission rate of the packet in the upstream and downstream directions, the size distribution of the packet, the time distribution of the packet, and the frame type distribution; use a pre-trained machine learning model to classify the communication characteristics to obtain a classification result indicating whether the communication characteristics conform to the communication characteristics of known WiFi drones; if the classification result indicates that the communication characteristics conform to the communication characteristics of known WiFi drones, determine that the suspected target is an unknown WiFi drone, or, if the classification result indicates that the communication characteristics do not conform to the communication characteristics of known WiFi drones, determine that the suspected target is not an unknown WiFi drone.

[0068] In this embodiment, the encryption method refers to the security protocol used by the wireless network, such as WEP, WPA, or WPA2, etc., for protecting the security of data transmission. "Communication characteristics" refer to the data attributes that can describe and quantify wireless communication behaviors, including but not limited to the transmission rate in the upstream and downstream directions (measuring the speed of the data stream), the size distribution of the packet (the proportion of packets of different sizes), the time distribution of the packet (the time interval pattern of packet transmission), and the frame type distribution (the proportion of various types of data frames, such as management frames, control frames, and data frames). These communication characteristics can be used to depict the behavior pattern of a wireless device and are important bases for identifying and classifying device types.

[0069] In the embodiments of the present application, when the suspected target creates an encrypted network, the system will no longer rely on simple MAC address matching and video stream analysis, but will deeply explore the communication characteristics in the captured data packets. After these characteristics are extracted, they will be passed as input to a pre-trained machine learning model. This model is trained based on a large number of known WiFi drone samples and can identify communication patterns that match known WiFi drones. By comparing the newly captured communication characteristics with the knowledge learned by the model, the system can determine whether the suspected target conforms to the behavioral characteristics of known WiFi drones. If the classification result shows that the communication characteristics match, the suspected target is considered likely to be an unknown WiFi drone; otherwise, the possibility of it being an unknown WiFi drone is excluded.

[0070] The following is a specific embodiment:

[0071] In an airspace monitoring scenario of a military base, the second WiFi wireless network card has captured data packets from a suspected WiFi drone that is not on the whitelist. Further analysis shows that the suspected target creates a WiFi network encrypted with WPA2. According to the pre-set WiFi drone judgment strategy, the system starts to extract deeper communication characteristics from the captured data packets. Specifically, the system measures the transmission rates in the uplink and downlink directions, counts the packet size distribution, records the packet time distribution, and analyzes the frame type distribution.

[0072] Next, these communication characteristics are input into a pre-trained machine learning model. This model is obtained by training on a large dataset of known WiFi drones and can effectively distinguish different types of wireless devices. After the classification process of the model, the results show that the captured communication characteristics highly match the behavioral patterns of known WiFi drones. In particular, the uplink and downlink transmission rates show obvious asymmetry and specific time distribution patterns, which are typical operating characteristics of drones. Therefore, the system finally confirms that the suspected target is an unauthorized WiFi drone and triggers an alarm to notify the security personnel to take necessary actions.

[0073] In order to further improve the utilization efficiency of the detection results of unknown WiFi drones and ensure that relevant security measures can respond in a timely manner, in some embodiments, after determining that the suspected target is an unknown WiFi drone in step 103, the method further includes:

[0074] Sending the detection result of the unknown WiFi drone to a second terminal device through the second WiFi wireless network card, where the detection result of the unknown WiFi drone includes the MAC address and the analysis result, or includes the MAC address and the communication characteristics.

[0075] In this embodiment, the second terminal device refers to a device used to receive and process alarm information and technical data from the monitoring system, such as a computer in the security control center, a mobile command platform, or a dedicated security management system. The detection results are not limited to simple confirmation information (such as whether it is an unknown WiFi drone), but also include detailed MAC addresses (used to uniquely identify wireless devices) and in-depth analysis results or communication characteristics. The analysis results can be conclusions about the behavior patterns of drones, such as whether there is video stream transmission; while the communication characteristics provide a more detailed description of the packet attributes, such as transmission rate, packet size distribution, etc., which are very important for subsequent threat assessment and countermeasure formulation.

[0076] In the embodiment of the present application, once the system confirms that the suspected target is an unknown WiFi drone through the above steps, it will generate a detailed detection report. This report contains the MAC address of the unknown WiFi drone and the basis for its identification as a drone, which may be the analysis result based on the behavior pattern or the specific communication characteristics extracted from the captured data packets. Then, the system uses the second WiFi wireless network card to send this detection report to the specified second terminal device. This process ensures that relevant information can be quickly and accurately transmitted to the personnel responsible for security monitoring and emergency response, enabling them to take appropriate actions based on the received information.

[0077] The following is a specific embodiment:

[0078] In the security monitoring system of a large airport, when the second WiFi wireless network card captures and analyzes the data packets from a suspected WiFi drone not on the whitelist, the system finally confirms that the hotspot indeed belongs to an unauthorized WiFi drone according to the pre-set judgment strategy. Subsequently, the system automatically generates a detailed detection report, which includes key communication characteristics such as the MAC address of the drone, the uplink and downlink transmission rates, and the packet size distribution, as well as the analysis result of the behavior pattern obtained through the machine learning model, indicating the existence of a downlink unidirectional video stream.

[0079] Next, the system sends this detection report to the dedicated terminal device in the airport security command center through the second WiFi wireless network card. After receiving the notice, the security team immediately activates the emergency plan, dispatches a ground patrol team to the suspected drone activity area for on-site verification, and coordinates with the air traffic control department to adjust the flight path to avoid potential conflicts. In addition, technicians also use the detailed information in the detection report to track the location of the drone operator and prepare the necessary legal procedures. This real-time feedback mechanism greatly improves the speed and accuracy of dealing with the threat of unknown WiFi drones, ensuring the safety and order of airport operations.

[0080] To further improve the accuracy of identifying suspected WiFi drones and reduce false alarms, in some embodiments, after filtering out all the packets containing the MAC address of the suspected target within a preset time in step 102, the method further includes:

[0081] Determine whether the target MAC addresses in all the packets containing the MAC address of the suspected target are the MAC addresses of the same communication terminal; if the target MAC addresses in all the packets containing the MAC address of the suspected target are not the MAC addresses of the same communication terminal, then determine that the suspected target is not an unknown WiFi drone.

[0082] In this embodiment, the target MAC address refers to the MAC address of the receiving party in the data packet, which identifies the destination device of the data packet. If the target MAC addresses of multiple data packets are the same, it indicates that these data packets are all sent to the same communication terminal. This consistency check helps to distinguish normal wireless network traffic from the communication mode specific to drones, because drones usually communicate with a fixed ground control station, that is, all the uplink or downlink data packets will point to the same MAC address. In addition, a communication terminal refers to a device participating in communication, such as the two-way communication link between a drone and its corresponding ground control station.

[0083] In the embodiments of the present application, after the second WiFi wireless network card completes channel monitoring and filters out all the data packets containing the suspected target MAC address within a preset time, the system will further analyze the target MAC addresses in these data packets. The purpose is to confirm whether all these data packets are sent to the same communication terminal. If so, the possibility that the suspected target is an unknown WiFi drone is increased; on the contrary, if the target MAC addresses are inconsistent, this may mean that the captured is normal network traffic rather than communication behavior specific to drones. In this case, the system will rule out the possibility that the suspected target is an unknown WiFi drone and terminate the further investigation process.

[0084] The following is a specific embodiment:

[0085] In a security monitoring scenario of an urban park, the second Wi-Fi wireless network card has completed capturing data packets on a certain channel and screened out all the packets containing the suspected target MAC address. Next, the system starts to analyze the target MAC addresses of these data packets. Suppose after analysis, it is found that although the source MAC addresses (suspected targets) of all the data packets are the same, their target MAC addresses are scattered and point to multiple different communication terminals, which does not conform to the typical one-to-one communication mode of drones. Therefore, based on this feature, the system concludes that the suspected target is not an unknown Wi-Fi drone, but other types of wireless devices, such as the communication between smart watches, mobile phones or other portable electronic devices carried by tourists.

[0086] To solve the false alarm problem and further improve the system's adaptability and accuracy, in some embodiments, after determining that the suspected target is not an unknown Wi-Fi drone, the method further includes:

[0087] Storing the communication parameters of the suspected target into the whitelist through the second Wi-Fi wireless network card.

[0088] In this embodiment, the communication parameters not only include the MAC address and channel number of the suspected target, but also extend to the wireless network identifier (Service Set Identifier, SSID), which is the name used to distinguish different wireless networks. By recording these detailed communication parameters, the system can more accurately identify and remember legal wireless devices or networks, thus avoiding unnecessary detections and alarms for them in the future. The whitelist is a database containing all known secure devices or networks, used to quickly screen and exclude normal traffic, ensuring that monitoring resources are concentrated on potential threats.

[0089] In the embodiment of the present application, when the system confirms through a series of analyses that a certain suspected target is not an unknown Wi-Fi drone, it does not simply ignore this device, but takes active learning measures. Specifically, the second Wi-Fi wireless network card will store the complete communication parameters of the suspected target, including its MAC address, the channel number used, and the wireless network identifier, into the whitelist. This update operation enables the system to directly mark the same device or network as known and harmless in future scanning processes without starting complex detection processes. This not only reduces the processing burden of the system, but also reduces the possibility of false alarms and improves the overall security management efficiency.

[0090] The following is a specific embodiment:

[0091] In a security monitoring system of a smart city, the second Wi-Fi wireless network card captures a hotspot signal that is not in the whitelist. After detailed packet analysis, the system confirms that the hotspot is not an unknown Wi-Fi drone, but may be a portable device such as a smartphone or smartwatch of an ordinary user. To prevent repeated inspections of this device in the future, the system decides to incorporate its communication parameters into the whitelist. Therefore, in addition to recording the MAC address of the device and the channel number used, the system also specifically notes its wireless network identifier (e.g., the home Wi-Fi SSID to which the mobile phone is connected). In this way, when this user enters the monitoring area again, even if the signal emitted by their device is captured by the first Wi-Fi wireless network card, since its communication parameters are already in the whitelist, the system will directly skip the further analysis steps, ensuring efficient resource utilization and accurate security assessment.

[0092] In order to solve the problems of incomplete data or false alarms in the whitelist generation process, and further improve the automation degree and accuracy of the system, in some embodiments, generating a whitelist includes:

[0093] Obtain scanning parameters, where the scanning parameters include a scanning mode, a scanning frequency, and a channel list; determine any channel in the channel list as an initial channel, and sequentially select different channels in a predefined order or randomly. For each channel, perform the scanning action corresponding to the scanning mode according to the scanning frequency to obtain a scanning result including multiple hotspots; receive the annotation information on whether each hotspot is a Wi-Fi drone, and based on the annotation information, filter out all hotspots that are not Wi-Fi drones, and generate a whitelist including all hotspots that are not Wi-Fi drones.

[0094] In this embodiment, the scanning parameters refer to the specific settings for guiding the wireless network scanning, mainly including the following. The scanning mode defines the scanning method, such as active scanning (sending a probe request and waiting for a response) or passive scanning (listening for broadcast frames on the channel), which determines how the system discovers the surrounding wireless access points. The scanning frequency specifies the interval time or rate of the scanning operation to ensure that the system can regularly update its perception of the environment. The channel list enumerates all Wi-Fi channels that need to be monitored so that the system can conduct a comprehensive search on different frequency bands. The annotation information is a label provided by manual or other intelligent means about the nature of each hotspot, clearly indicating which hotspots belong to Wi-Fi drones and which do not. This information is crucial for constructing an accurate whitelist because it helps the system distinguish between legitimate devices and potential threats.

[0095] In the embodiments of the present application, in order to generate a reliable whitelist, the system first needs to collect detailed scanning parameters to ensure comprehensive coverage of possible wireless access points. Then, it selects an initial channel from the channel list to start scanning and switches to other channels according to a preset order or randomly. Each scan follows the specified scanning mode and frequency. During this process, the system records all hotspot information as the preliminary scan result. Next, by receiving externally provided annotation information, the system can identify which hotspots are not WiFi drones and add these non-threatening hotspots to the whitelist. This process not only improves the accuracy of the whitelist but also enhances the system's self-learning ability, enabling it to more effectively filter out known secure devices in the future.

[0096] The following is a specific embodiment:

[0097] In the security management scenario of a large commercial park, the administrator hopes to create a whitelist to distinguish legal wireless devices in the park from potential unknown WiFi drones. To this end, the system first configures the scanning parameters, selects the active scanning mode, sets the scanning frequency of once per minute, and lists all common 2.4GHz and 5GHz WiFi channels as the channel list. The system then starts the scanning process, starting from the first channel in the 2.4GHz band and gradually switching to other channels in a predetermined order while maintaining the specified scanning frequency to ensure that no active wireless access points are missed.

[0098] As the scanning progresses, the system captures a large number of hotspot information, including employees' smartphones, visitors' tablets, and various IoT devices deployed in the park. To determine which hotspots should not be regarded as threats, the administrator provides annotation information through a dedicated interface to mark known non-drone devices. Based on these annotations, the system automatically filters out all hotspots that are not WiFi drones and adds their communication parameters (such as MAC address, SSID, etc.) to the whitelist.

[0099] Finally, the generated whitelist not only includes existing legal devices but also has the ability to self-update. When new non-threatening devices enter the park, if they are correctly annotated in subsequent scans, they will also be automatically included in the whitelist. This method greatly simplifies the workload of the administrator and also improves the reliability and response speed of the entire security system, ensuring that only truly suspicious wireless activities will trigger further inspection or alarm mechanisms.

[0100] Figure 2 The structural schematic diagram of a detection system for unknown WiFi drones provided by the embodiments of the present application is as Figure 2 shown, and the system includes:

[0101] A determining sending module 21, configured to determine a hotspot not in the whitelist as a suspected target when detecting the hotspot through a first Wi-Fi wireless network card, and send communication parameters of the suspected target to a second Wi-Fi wireless network card. The hotspot is any wireless network node that emits a Wi-Fi signal and allows other devices to connect to it. The communication parameters of the suspected target include the MAC address of the suspected target, the channel number where the suspected target is located, and the encryption method.

[0102] A packet capture and screening module 22, configured to perform data sniffing and packet capture on the channel where the suspected target is located through the second Wi-Fi wireless network card according to the channel number where the suspected target is located, obtain data packets, and screen out all packets containing the MAC address of the suspected target within a preset time from the data packets. The MAC address of the suspected target is the source MAC address.

[0103] A determining module 23, configured to determine whether the suspected target is an unknown Wi-Fi drone according to the network type created by the suspected target and the Wi-Fi drone judgment strategy corresponding to the network type when the target MAC address in all packets containing the MAC address of the suspected target is the MAC address of the same communication terminal.

[0104] Determining whether the suspected target is an unknown Wi-Fi drone according to the network type created by the suspected target and the Wi-Fi drone judgment strategy corresponding to the network type includes:

[0105] When the encryption method indicates that the network type created by the suspected target is an unencrypted open network, perform video stream transmission protocol analysis on the packets, and determine whether the suspected target is an unknown Wi-Fi drone according to whether there is a downstream unidirectional video stream in the analysis result. The video stream transmission protocol includes at least one of the Real-Time Streaming Protocol (RTSP) and the Real-Time Transport Protocol (RTP); or, when the encryption method indicates that the network type created by the suspected target is an encrypted network, determine whether the suspected target is an unknown Wi-Fi drone according to whether the communication characteristics in the packets conform to the communication characteristics of known Wi-Fi drones.

[0106] Figure 2 The described detection system for unknown Wi-Fi drones can execute Figure 1 The detection method for unknown Wi-Fi drones described in the illustrated embodiment. Its implementation principle and technical effects will not be elaborated further. For the detection system for unknown Wi-Fi drones in the above embodiment, the specific manners in which each module and unit perform operations have been described in detail in the embodiment related to the method, and will not be elaborated here.

[0107] In a possible design, Figure 2 A detection system for unknown Wi-Fi drones in the illustrated embodiment can be implemented as a computing device, such as Figure 3 as shown, the computing device may include a storage component 31 and a processing component 32.

[0108] The storage component 31 stores one or more computer instructions, wherein the one or more computer instructions are called and executed by the processing component 32.

[0109] The processing component 32 is configured to: when detecting a hotspot not in the whitelist through a first Wi-Fi wireless network card, determine the hotspot as a suspected target, and send communication parameters of the suspected target to a second Wi-Fi wireless network card, where the hotspot is any wireless network node that emits a Wi-Fi signal and allows other devices to connect to it, and the communication parameters of the suspected target include the MAC address of the suspected target, the channel number where the suspected target is located, and the encryption method; according to the channel number where the suspected target is located, perform data sniffing and packet capturing on the channel where the suspected target is located through the second Wi-Fi wireless network card to obtain data packets, and screen out all packets containing the MAC address of the suspected target within a preset time from the data packets, where the MAC address of the suspected target is the source MAC address; in the case where the target MAC address in all packets containing the MAC address of the suspected target is the MAC address of the same communication terminal, when the encryption method indicates that the network type created by the suspected target is an unencrypted open network, perform video stream transmission protocol analysis on the packets, and determine whether there is a downstream unidirectional video stream according to the analysis result to determine whether the suspected target is an unknown Wi-Fi drone, where the video stream transmission protocol includes at least one of the Real-Time Streaming Protocol (RTSP) and the Real-Time Transport Protocol (RTP); or, when the encryption method indicates that the network type created by the suspected target is an encrypted network, determine whether the suspected target is an unknown Wi-Fi drone according to whether the communication characteristics in the packets conform to the communication characteristics of known Wi-Fi drones.

[0110] Among them, the processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above methods. Of course, the processing component may also be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors or other electronic components, and are used to execute the above methods.

[0111] The storage component 31 is configured to store various types of data to support the operation of the terminal. The storage component can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as random access memory (RAM), static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0112] Of course, the computing device may also necessarily include other components, such as input / output interfaces, display components, communication components, etc.

[0113] The input / output interface provides an interface between the processing component and the peripheral interface module, and the above peripheral interface module may be an output device, an input device, etc.

[0114] The communication component is configured to facilitate communication between the computing device and other devices in a wired or wireless manner, etc.

[0115] Among them, the computing device may be a physical device or an elastic computing host provided by a cloud computing platform, etc. At this time, the computing device may refer to a cloud server, and the above processing component, storage component, etc. may be basic server resources leased or purchased from a cloud computing platform.

[0116] The embodiments of the present application also provide a computer storage medium storing a computer program, and when the computer program is executed by a computer, it can implement the above-mentioned Figure 1 detection method for unknown wifi drones shown in the embodiments.

[0117] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0118] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0119] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., including several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0120] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of each embodiment of the present application.

Claims

1. A detection method for unknown WiFi drones, characterized in that: Applied to the first terminal device, including: When a hotspot not in the whitelist is detected by the first wifi wireless network card, the hotspot is determined as a suspected target, and the communication parameters of the suspected target are sent to the second wifi wireless network card, the hotspot is any wireless network node that transmits wifi signals and allows other devices to connect to it, and the communication parameters of the suspected target include the mac address of the suspected target, the channel number of the suspected target, and the encryption method; According to the channel number of the suspected target, the second WiFi wireless network card performs data sniffing and packet capture on the channel where the suspected target is located to obtain a data packet, and all messages containing the MAC address of the suspected target within a preset time are filtered out from the data packet, where the MAC address of the suspected target is the source MAC address; In the case where the target MAC address in all messages containing the MAC address of the suspected target is the MAC address of the same communication terminal, when the encryption method indicates that the network type created by the suspected target is an unencrypted open network, a video stream transmission protocol analysis is performed on the message, and whether the suspected target is an unknown WiFi drone is determined based on whether the analysis result indicates whether there is a downlink unidirectional video stream, and the video stream transmission protocol includes at least one of the real-time streaming protocol RTSP and the real-time transport protocol RTP; or, when the encryption method indicates that the network type created by the suspected target is an encrypted network, whether the suspected target is an unknown WiFi drone is determined based on whether the communication characteristics in the message conform to the communication characteristics of known WiFi drones.

2. The method according to claim 1, characterized in that: The step of determining whether the suspected target is an unknown WiFi drone based on the analysis result indicating whether there is a downlink unidirectional video stream comprises: If the analysis result indicates that there is a downlink unidirectional video stream, it is determined that the suspected target is an unknown WiFi drone. Alternatively, if the analysis result indicates that there is no downlink unidirectional video stream, it is determined that the suspected target is not an unknown WiFi drone.

3. The method according to claim 1, characterized in that The determining whether the suspected target is an unknown WiFi drone according to whether the communication characteristics in the message conform to the communication characteristics of a known WiFi drone includes: Extracting communication features from the message, the communication features including at least one of the following: a transmission rate of the message in an uplink and downlink direction, a size distribution of the message, a time distribution of the message, and a frame type distribution; Using a pre-trained machine learning model to classify the communication features, and obtain a classification result indicating whether the communication features meet the known WiFi drone communication features; If the classification result indicates that the communication feature conforms to the communication feature of a known WiFi drone, then the suspected target is determined to be an unknown WiFi drone; or, if the classification result indicates that the communication feature does not conform to the communication feature of a known WiFi drone, then the suspected target is determined not to be an unknown WiFi drone.

4. The method according to claim 2 or 3, characterized in that: After determining that the suspected target is an unknown WiFi drone, the method further includes: The detection result of the unknown WiFi drone is sent to the second terminal device through the second WiFi wireless network card, and the detection result of the unknown WiFi drone includes a MAC address and an analysis result, or includes a MAC address and a communication feature.

5. The method according to claim 1, characterized in that: After filtering out all messages containing the MAC address of the suspected target within a preset time from the data packet, the method further includes: Determine whether the target MAC address in all messages containing the MAC address of the suspected target is the MAC address of the same communication terminal; If the target MAC address in all messages containing the MAC address of the suspected target is not the MAC address of the same communication terminal, it is determined that the suspected target is not an unknown WiFi drone.

6. The method according to claim 2, 3 or 5, characterized in that: After determining that the suspected target is not an unknown WiFi drone, the method further includes: The communication parameters of the suspected target are stored in the white list through the second Wi-Fi wireless network card, and the communication parameters also include a wireless network identifier.

7. A detection system for unknown WiFi drones, characterized in that: Applied to the first terminal device, including: A determination and sending module is used to determine the hotspot as a suspected target when a hotspot not in the whitelist is detected by the first wifi wireless network card, and send the communication parameters of the suspected target to the second wifi wireless network card, wherein the hotspot is any wireless network node that transmits wifi signals and allows other devices to connect to it, and the communication parameters of the suspected target include the mac address of the suspected target, the channel number of the suspected target, and the encryption method; A packet capture and screening module, used to perform data sniffing and packet capture on the channel where the suspected target is located through the second WiFi wireless network card according to the channel number where the suspected target is located, to obtain a data packet, and to screen out from the data packet all messages containing the MAC address of the suspected target within a preset time, where the MAC address of the suspected target is the source MAC address; A determination module is used to, when the target MAC address in all messages containing the MAC address of the suspected target is the MAC address of the same communication terminal, perform video stream transmission protocol analysis on the message when the encryption method indicates that the network type created by the suspected target is an unencrypted open network, and determine whether the suspected target is an unknown WiFi drone based on whether the analysis result indicates whether there is a downlink unidirectional video stream, wherein the video stream transmission protocol includes at least one of a real-time streaming protocol RTSP and a real-time transport protocol RTP; or, when the encryption method indicates that the network type created by the suspected target is an encrypted network, determine whether the suspected target is an unknown WiFi drone based on whether the communication characteristics in the message conform to the communication characteristics of known WiFi drones.

8. A computing device, characterized in that It comprises a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a detection method for unknown wifi drones as described in any one of claims 1 to 6.

9. A computer storage medium, characterized in that: A computer program is stored, and when the computer program is executed by a computer, a detection method for an unknown wifi drone as described in any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Unmanned aerial vehicle monitoring method based on WiFi features

    CN115665283A

  • Video tracking method and system, and storage medium

    WO2020114102A1