Monitoring device, monitoring method, and monitoring program

The monitoring device generates a non-repetitive device identification information group, cut off the communication connection between the illegal access point and the victim client, solves the problem of setting up illegal access points in the PMF environment, realizes the countermeasures that it cannot be reconnected after being cut off, and improves the security of the Wi-Fi network.

CN120548726APending Publication Date: 2025-08-26MITSUBISHI ELECTRIC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202380089978.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-01-17
Publication Date
2025-08-26

AI Technical Summary

Technical Problem

In a Wi-Fi network with an effective PMF, the prior art cannot effectively deal with the settings of illegal access points, and cannot effectively prevent reconnection after cutting off the communication connection, especially when the forced cut-off function of authentication and defragment frames is invalid in the WPA3 environment.

Method used

The monitoring device repeatedly connects and cuts off communication between the illegal access point and the victim client by generating a non-repeating device identification information group with each other, and uses different device identification information to fill the connection slot of the illegal access point to prevent reconnection.

Benefits of technology

After cutting off the communication between the illegal access point and the victim client, fill in the connection slot to prevent the victim client from reconnecting with the illegal access point, protect the security of the Wi-Fi network, and provide effective countermeasures in PMF to avoid information theft and malware download.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120548726A_ABST
    Figure CN120548726A_ABST
Patent Text Reader

Abstract

The monitoring device (100) has a communication connection unit (124). The communication connection unit (124), in order to fill slots of the number of simultaneous connections of illegal APs in the presence of illegal APs in the surroundings, repeatedly executes connections with respect to illegal APs using each of one or more pieces of device identification information generated so as not to overlap each other, and, in the case of a connection failure with respect to illegal APs, repeatedly executes connections with respect to illegal APs using each of the one or more pieces of device identification information generated so as not to overlap each other. The communication connection between the illegal AP and the victim CL is cut off by connecting the device identification information of the victim CL connected to the illegal AP to the illegal AP, and the other device identification information is used to connect to the illegal AP in order to fill the slot of the number of simultaneous connections of the illegal AP that is vacant due to the cut-off of the communication connection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a monitoring device, a monitoring method, and a monitoring program. Background Art

[0002] Wi-Fi (registered trademark) security standards up to WPA2 (Wi-Fi (registered trademark) Protected Access 2) contain a vulnerability known as DoS (Denial of Service) that can disrupt communications forcibly established by a third party using deauthentication frames. To address this vulnerability, WPA3 mandates a structure based on Protected Management Frames (PMFs).

[0003] On the other hand, WIPS (Wireless Intrusion Prevention System) has previously used a vulnerability related to forced disconnection of communications using deauthentication frames to cut off communications with unauthorized devices (including both access points and clients). Fundamental countermeasures against unauthorized devices include physical removal of the device or powering off the device. However, these fundamental countermeasures cannot be implemented immediately after detecting unauthorized communications. Therefore, forced disconnection of communications using deauthentication frames is used to minimize damage incurred between the detection of unauthorized communications and the implementation of fundamental countermeasures.

[0004] However, with the widespread use of WPA3, forced disconnection of communications using deauthentication frames is no longer effective. Therefore, a method other than using deauthentication frames to disconnect communications from unauthorized devices is needed.

[0005] Patent Document 1 discloses the following technology: When an unauthorized client is detected in a PMF environment, a WIPS monitoring device masquerades as the unauthorized client's MAC (Media Access Control) address to connect to a legitimate access point, thereby updating the encryption key used to encrypt communication frames associated with that MAC address. As a result of the updated encryption key, the unauthorized client is unaware of the new encryption key and, therefore, cannot communicate with the legitimate access point.

[0006] Prior art literature

[0007] Patent Literature

[0008] Patent Document 1: Japanese Patent Application No. 2018-511282 Summary of the Invention

[0009] Problems to be solved by the invention

[0010] Patent Document 1 has the problem of not disclosing a countermeasure when an unauthorized access point is installed, and the problem of not disclosing a countermeasure that prevents easy reconnection after a communication connection is disconnected.

[0011] The present disclosure aims to provide a countermeasure when an illegal access point is installed in a Wi-Fi (registered trademark) network in which PMF is valid, and to provide a countermeasure that prevents easy reconnection after a communication connection is disconnected.

[0012] Means for solving problems

[0013] A monitoring device disclosed herein includes a communication connection unit. When an unauthorized access point exists in a group of surrounding devices, the communication connection unit repeatedly connects to the unauthorized access point using each piece of device identification information in a device identification information group consisting of one or more pieces of device identification information generated so as to not overlap with each other, in order to fill a slot for simultaneous connections of the unauthorized access point. If the connection to the unauthorized access point fails, the communication connection unit connects to the unauthorized access point using the device identification information of a victim client, which is a communication device connected to the unauthorized access point, thereby severing the communication connection between the unauthorized access point and the victim client. To fill the slot for simultaneous connections of the unauthorized access point vacated by the severance of the communication connection, the communication connection unit connects to the unauthorized access point using device identification information that is different from any piece of device identification information in the device identification information group. The surrounding device group consists of one or more devices that are present in the vicinity of the monitoring device and perform wireless communication, and each piece of device identification information in the device identification information group is different from the device identification information of the victim client.

[0014] Effects of the Invention

[0015] According to the present disclosure, after the communication connection between the illegal access point and the victim client is severed, the slot for the number of simultaneous connections of the illegal access point is filled. Therefore, after the communication connection is severed, the victim client cannot easily reconnect to the illegal access point. In addition, the present disclosure also functions in a Wi-Fi (registered trademark) network with PMF enabled. Therefore, according to the present disclosure, it is possible to provide a countermeasure for the situation where an illegal access point is set up in a Wi-Fi (registered trademark) network with PMF enabled, and a countermeasure that prevents easy reconnection after the communication connection is severed. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 This is a diagram illustrating a wireless communication network according to Embodiment 1.

[0017] Figure 2 This is a diagram showing a configuration example of the monitoring device 100 according to the first embodiment.

[0018] Figure 3 This is a diagram showing a hardware configuration example of the monitoring device 100 according to the first embodiment.

[0019] Figure 4 This is a flowchart showing the operation of the monitoring device 100 according to the first embodiment.

[0020] Figure 5 This is a diagram showing a hardware configuration example of a monitoring device 100 according to a modified example of the first embodiment.

[0021] Figure 6 This is a diagram showing a configuration example of a monitoring device 100 according to the second embodiment.

[0022] Figure 7 This is a flowchart showing the operation of the monitoring device 100 according to the second embodiment.

[0023] Figure 8 This is a flowchart showing the operation of the monitoring device 100 according to the modified example of the second embodiment.

[0024] Figure 9 This is a diagram showing a configuration example of a monitoring device 100 according to a third embodiment.

[0025] Figure 10 This is a flowchart showing the operation of the monitoring device 100 according to the third embodiment.

[0026] Figure 11 This is a diagram showing a configuration example of a monitoring device 100 according to a fourth embodiment.

[0027] Figure 12 This is a flowchart showing the operation of the monitoring device 100 according to the fourth embodiment.

[0028] Figure 13 This is a diagram showing a configuration example of a monitoring device 100 according to a modified example of the fourth embodiment.

[0029] Figure 14 This is a flowchart showing the operation of the monitoring device 100 according to the modification of the fourth embodiment.

[0030] Figure 15 This is a diagram showing a configuration example of a monitoring device 100 according to the fifth embodiment.

[0031] Figure 16 This is a flowchart showing the operation of the monitoring device 100 according to the fifth embodiment.

[0032] Figure 17It is a diagram illustrating a wireless communication network according to a modification of the fourth embodiment and a modification of the fifth embodiment. DETAILED DESCRIPTION

[0033] In the description of the embodiments and the accompanying drawings, identical or corresponding elements are denoted by the same reference numerals. The description of elements denoted by the same reference numerals is omitted or simplified as appropriate. Arrows in the figures primarily represent data flow or process flow. Furthermore, "unit" may be appropriately rewritten as "circuit," "process," "step," "processing," or "loop."

[0034] Implementation Method 1

[0035] Hereinafter, this embodiment will be described in detail with reference to the accompanying drawings.

[0036] In this embodiment, if Figure 1 As shown, the countermeasures against rogue access points are measures taken when an rogue AP (access point) 10 has invaded a wireless communication network and a communication connection has already been established between the rogue AP 10 and a legitimate client (client) 20. As a specific example, the wireless communication network is a Wi-Fi (registered trademark) network that supports PMF (Protected Management Frames). The legitimate client 20 is a communication device, specifically a communication terminal such as a smartphone or a PC (Personal Computer). Specifically, the legitimate client 20 that has established a communication connection with the rogue AP 10 is referred to as the victim client 21. The victim client 21 is a communication device connected to the rogue AP 10. Furthermore, communication between the victim client 21 and the rogue AP 10 is referred to as rogue communication. During rogue communication, PMF is enabled, and there is a risk that the rogue AP 10 may steal information from the victim client 21 or download malware to the victim client 21.

[0037] This embodiment describes countermeasures that monitoring device 100 can implement in the aforementioned situation. Monitoring device 100 can be at least a portion of a legitimate AP 30, or a separate device from the legitimate AP 30. Furthermore, if monitoring device 100 is at least a portion of a legitimate AP 30, the legitimate AP 30 can have multiple radios, with the AP's operations and the countermeasures described in this embodiment being shared across the multiple radios.

[0038] ***Description of the structure***

[0039] Figure 2 FIG. 1 shows a configuration example of the monitoring device 100 according to the first embodiment. Figure 2As shown, the monitoring device 100 includes a communication unit 110, a control unit 120, and a storage unit 130. The monitoring device 100 is also referred to as a wireless intrusion prevention device. Furthermore, when the monitoring device 100 is implemented in a legitimate AP 30, the monitoring device 100 may also include a communication processing unit that functions as an access point.

[0040] The communication unit 110 includes an antenna for wireless communication, and has a function of transmitting and receiving data with other devices through wireless communication.

[0041] The control unit 120 includes a communication monitoring unit 121 , an information analyzing unit 122 , an unauthorized device determining unit 123 , a communication connecting unit 124 , and a MAC (Medium Access Control) address generating unit 125 .

[0042] The communication monitoring unit 121 obtains communication frames from each device in the surrounding device group. Here, the surrounding device group is composed of one or more devices that are present around the monitoring device 100 and perform wireless communication. The surrounding device group includes at least one of the rogue AP 10, the legitimate CL 20, and the victim CL 21.

[0043] The information analysis unit 122 analyzes the communication frame acquired by the communication monitoring unit 121 .

[0044] The unauthorized device determination unit 123 determines whether each device in the surrounding device group is an unauthorized device. Specifically, the unauthorized device determination unit 123 determines whether an unauthorized AP 10 exists in the surrounding device group based on communication frames transmitted by each device in the surrounding device group.

[0045] The communication connection unit 124 performs a process of connecting to other devices via wireless communication. In this specification, the term "connection" basically refers to a connection based on wireless communication.

[0046] Next, a specific example of the processing of the communication connection unit 124 will be described. In this example, PMF can also be effective in wireless communication between the rogue AP 10 and the victim CL 21.

[0047] First, if an unauthorized AP 10 is present in the surrounding device group, the communication connection unit 124 repeatedly connects to the unauthorized AP 10 using each piece of device identification information in the device identification information group to fill the slot for the number of simultaneous connections for the unauthorized AP 10. Here, the device identification information group consists of one or more pieces of device identification information generated so as to avoid duplication. Furthermore, each piece of device identification information in the device identification information group differs from the device identification information of the victim CL 21. Specifically, each piece of device identification information is a MAC address.

[0048] Next, when the connection to the unauthorized AP 10 fails, the communication connection unit 124 connects to the unauthorized AP 10 using the device identification information of the victim CL 21 , thereby disconnecting the communication connection between the unauthorized AP 10 and the victim CL 21 .

[0049] Next, in order to fill the slot of the number of simultaneous connections of the rogue AP 10 vacated by the disconnection of the communication connection, the communication connection unit 124 connects to the rogue AP 10 using device identification information different from any device identification information in the device identification information group.

[0050] The MAC address generation unit 125 generates a MAC address as appropriate.

[0051] The storage unit 130 stores communication frame information 131 , unauthorized device information 132 , victim device information 133 , and a used MAC address table 134 .

[0052] The communication frame information 131 is composed of communication frames transmitted by each device in the peripheral device group.

[0053] The illegal device information 132 is composed of device information of each illegal device. An illegal device is a device that is not an authorized device. An illegal device may be a device that is not registered in the list showing authorized devices or a device that is registered in the list showing illegal devices.

[0054] The victim device information 133 is composed of device information of each victim device. A victim device is a device connected to an illegal device.

[0055] The used MAC address table 134 is table data indicating a list of used MAC addresses.

[0056] Figure 3 The following is an example of the hardware configuration of the monitoring device 100 according to this embodiment. The monitoring device 100 is configured as a computer. The monitoring device 100 may also be configured as multiple computers. Alternatively, the monitoring device 100 may have a built-in computer.

[0057] As shown in this figure, monitoring device 100 is a computer having hardware such as processor 51, memory 52, auxiliary storage device 53, input / output IF (Interface) 54, and communication device 55. These hardware are connected via signal lines 59 as appropriate.

[0058] The processor 51 is an IC (Integrated Circuit) that performs calculations and controls the hardware of the computer. Specific examples of the processor 51 include a CPU (Central Processing Unit), a DSP (Digital Signal Processor), or a GPU (Graphics Processing Unit).

[0059] The monitoring device 100 may include a plurality of processors instead of the processor 51. The plurality of processors may share the role of the processor 51.

[0060] Typically, the memory 52 is a volatile storage device that constitutes the storage unit 130. A specific example is RAM (Random Access Memory). The memory 52 is also called a main storage device or main memory. Data stored in the memory 52 is stored in the auxiliary storage device 53 as needed.

[0061] Typically, auxiliary storage device 53 is a nonvolatile storage device, also known as a storage device. Specific examples include ROM (Read Only Memory), HDD (Hard Disk Drive), or flash memory. Data stored in auxiliary storage device 53 is loaded into memory 52 as needed.

[0062] The memory 52 and the auxiliary storage device 53 may be integrally configured.

[0063] The input / output interface 54 is a port for connecting input devices and output devices. Specifically, the input / output interface 54 is a USB (Universal Serial Bus) terminal. Specifically, the input devices are a keyboard and a mouse. Specifically, the output device is a display.

[0064] The communication device 55 is a receiver and a transmitter. As a specific example, the communication device 55 is a communication chip or a NIC (Network Interface Card).

[0065] When communicating with other devices, the components of the monitoring device 100 may appropriately use the input / output IF 54 and the communication device 55 .

[0066] The auxiliary storage device 53 stores a monitoring program. This program causes a computer to implement the functions of the various components of the monitoring device 100. The monitoring program stored in the auxiliary storage device 53 is loaded into the memory 52 and executed by the processor 51, thereby implementing the functions of this embodiment. The functions of the various components of the monitoring device 100 are implemented using software.

[0067] Data used when executing the monitoring program and data obtained by executing the monitoring program are appropriately stored in a storage device. Each component of monitoring device 100 utilizes a storage device as appropriate. Specifically, the storage device comprises at least one of the following: memory 52, auxiliary storage device 53, registers within processor 51, and cache memory within processor 51. The terms "data" and "information" may have equivalent meanings. The storage device may also be independent of the computer.

[0068] The functions of the memory 52 and the auxiliary storage device 53 may also be implemented by other storage devices.

[0069] The monitoring program may also be recorded on a computer-readable nonvolatile recording medium. As a specific example, the nonvolatile recording medium is an optical disc or a flash memory. The monitoring program may also be provided as a program product.

[0070] ***Description of the action***

[0071] The operation procedure of the monitoring device 100 corresponds to the monitoring method. In addition, the program that realizes the operation of the monitoring device 100 corresponds to the monitoring program.

[0072] Figure 4 This is a flowchart showing an example of the operation of the monitoring device 100 according to the first embodiment. Figure 4 The operation of the monitoring device 100 according to the first embodiment will be described.

[0073] (Step S101)

[0074] First, the communication unit 110 receives communication radio waves from each device in the peripheral device group using an antenna, demodulates the received radio waves, and performs analog-to-digital conversion on the demodulation results to obtain digital signals.

[0075] Next, the communication unit 110 transmits the obtained digital signal to the communication monitoring unit 121 .

[0076] Next, the communication monitoring unit 121 interprets the received digital signal as a communication frame, thereby acquiring the communication frames transmitted and received by each device in the peripheral device group. The communication monitoring unit 121 stores the acquired communication frames as part of the communication frame information 131 in the storage unit 130 .

[0077] (Step S102)

[0078] First, the information analysis unit 122 analyzes the communication frame information 131 to obtain information about each device in the surrounding device group. Specifically, information about the rogue AP 10 is obtained from beacon frames periodically transmitted by the rogue AP 10, and includes at least one of the rogue AP's BSSID (Basic Service Set Identifier), ESSID (Extended Service Set Identifier), channel (communication frequency), PMF validity / invalidity, authentication method, encryption method, and MAC address (usually the same as the BSSID). Furthermore, information about the legitimate CL 20 or victim CL 21 is obtained from communication frames destined for an AP or probe request frames sent to detect an AP, and includes at least one of the legitimate CL 20 or victim CL 21's MAC address, and the ESSID and BSSID of an AP to which the legitimate CL 20 or victim CL 21 is connected (or searching).

[0079] Next, the unauthorized device determination unit 123 determines whether an unauthorized AP 10 exists in the surrounding device group based on the information obtained by the information analysis unit 122. Specifically, the method for determining whether an unauthorized AP 10 exists includes determining that an unauthorized AP 10 exists when a device matching the devices indicated in the predetermined list of unauthorized device information is included in the surrounding device group; determining that an unauthorized AP 10 exists when a device not shown in the predetermined list of authorized device information is included in the surrounding device group; determining that an unauthorized AP 10 exists when a device having the same device information as that of the monitoring device 100 is included in the surrounding device group; or determining that an unauthorized AP 10 exists when an access is made to the AP indicated by the obtained information via a wired network connected to the authorized AP 30 and an unexpected response (or no response) is received.

[0080] (Step S103)

[0081] If an illegal AP 10 is present in the surrounding device group, the monitoring apparatus 100 proceeds to step S104. If an illegal AP 10 is not present in the surrounding device group, the monitoring apparatus 100 returns to step S101.

[0082] (Step S104)

[0083] The illegal device determination unit 123 stores the device information of the illegal AP 10 detected in step S102 in the storage unit 130 as part of the illegal device information 132. Here, it is assumed that the device information corresponding to each device includes a countermeasure implementation flag corresponding to each device. The countermeasure implementation flag corresponding to each device is a flag used to clearly indicate whether a countermeasure has been implemented for each device. Setting the countermeasure implementation flag corresponding to a certain device indicates that a countermeasure has been implemented for that certain device. In addition, it is also possible to consider the situation where an illegal AP 10 that has been subjected to a countermeasure once recovers by restarting or the like and attempts to attack again. Therefore, it is also possible to install it so that after a specified time has passed since the countermeasure implementation flag corresponding to each device was set, the countermeasure implementation flag corresponding to each device is released (reset to a state indicating that a countermeasure has not been implemented).

[0084] The illegal device information 132 may be deleted after a specified time has passed since each piece of device information was added to the illegal device information 132, or the illegal device information 132 may be reset each time step S104 is executed. Alternatively, the illegal device determination unit 123 may determine an upper limit on the number of illegal APs 10, and when the number of illegal APs 10 exceeds the determined upper limit, the oldest piece of device information may be deleted from the illegal device information 132 and new device information may be added to the illegal device information 132.

[0085] (Step S105)

[0086] If there is no device information without a countermeasure implementation flag set in the unauthorized device information 132 (i.e., if the countermeasure implementation flag is set for all the device information of unauthorized APs 10 indicated by the unauthorized device information 132), the monitoring device 100 returns to step S101. Otherwise, the monitoring device 100 proceeds to step S106.

[0087] (Step S106)

[0088] The unauthorized device determination unit 123 selects one piece of device information for which a countermeasure implementation flag is not set from the device information of the unauthorized AP 10 indicated by the unauthorized device information 132. Hereinafter, the unauthorized AP 10 selected in step 306 is referred to as a selected unauthorized AP.

[0089] (Step S107)

[0090] First, the unauthorized device determination unit 123 requests the information analysis unit 122 to obtain device information of each victim CL 21 connected to the selected unauthorized AP.

[0091] Next, the information analysis unit 122 obtains the device information of each victim CL 21 connected to the selected unauthorized AP, and transmits the obtained device information to the unauthorized device determination unit 123 .

[0092] (Step S108)

[0093] The unauthorized device determination unit 123 stores the device information of each victim CL 21 connected to the selected unauthorized AP sent by the information analysis unit 122 in the storage unit 130 as part of the victim device information 133. Here, the device information corresponding to each device includes a corresponding countermeasure implementation flag.

[0094] Victim device information 133 may be deleted after a specified time has passed since each piece of device information was added to victim device information 133, or it may be reset each time step S108 is executed. Alternatively, the rogue device determination unit 123 may determine an upper limit on the number of victim CLs 21. If the number of victim CLs 21 exceeds the upper limit, the oldest piece of device information may be deleted from victim device information 133, and new device information may be added to victim device information 133. However, when two of the three methods described above, excluding the method of resetting victim device information 133 each time step S108 is executed, there may be multiple pairs of rogue APs 10 and victim CLs 21. Therefore, it is necessary to store information indicating the rogue AP 10 to which each victim CL 21 is connected (specifically, the BSSID of the rogue AP 10) in association with each piece of device information.

[0095] (Step S109)

[0096] The MAC address generation unit 125 generates a single MAC address. The MAC address generation unit 125 can generate a MAC address using a random number or by adding a value to the MAC address indicated by the victim device information 133. The MAC address generation unit 125 references the victim device information 133 and the used MAC address table to verify that the generated MAC address is different from any MAC address in the verification target MAC address group. The verification target MAC address group consists of the MAC addresses of each victim CL 21 and the MAC addresses stored in the used MAC address table.

[0097] If the MAC address generation unit 125 confirms that the generated MAC address is different from any MAC address in the confirmation target MAC address group, it adds the generated MAC address to the used MAC address table 134 and transmits data indicating the generated MAC address to the communication connection unit 124. If the generated MAC address is the same as any MAC address in the confirmation target MAC address group, the MAC address generation unit 125 generates a new MAC address and then re-confirms that the newly generated MAC address is different from any MAC address in the confirmation target MAC address group.

[0098] Here, if the generated MAC addresses are permanently stored in the used MAC address table 134, the MAC addresses may be exhausted, thereby causing an infinite loop of MAC address generation and verification failures. Therefore, each MAC address stored in the used MAC address table 134 may be deleted after a specified time has passed since it was added to the used MAC address table 134, or the used MAC address table 134 may be reset each time step S106 is executed. Alternatively, the MAC address generation unit 125 may determine an upper limit on the number of MAC addresses that can be stored. If the number of MAC addresses exceeds the determined upper limit, the oldest MAC address may be deleted from the used MAC address table 134 and a new MAC address may be stored in the used MAC address table 134.

[0099] (Step S110)

[0100] The communication connection unit 124 generates a communication frame required for the connection process as a digital signal. At this time, the communication connection unit 124 sets the MAC address generated in step S109 as the MAC address of the transmission source.

[0101] (Step S111)

[0102] The communication connection unit 124 transmits an authentication request frame and an association request frame to the rogue AP 10 via the communication unit 110, thereby performing a connection process. The communication connection unit 124 confirms the response from the communication unit 110 and confirms that the connection process was successfully completed. Furthermore, if encryption is enabled for communication, the communication connection unit 124 may continue the connection process until the encryption key is shared.

[0103] (Step S112)

[0104] If the monitoring device 100 can be normally connected to the rogue AP 10 , the monitoring device 100 returns to step S109 .

[0105] If the monitoring device 100 cannot successfully connect to the rogue AP 10, it is determined that the maximum number of simultaneously connected devices for the rogue AP 10 has been reached, and the monitoring device 100 proceeds to step S113. Specifically, the monitoring device 100 cannot successfully connect to the rogue AP 10 if an error message is returned or if the monitoring device 100 cannot successfully connect to the rogue AP 10 due to a communication timeout or other reason.

[0106] (Step S113)

[0107] If there is no device information in the victim device information 133 for which the countermeasure implementation flag is not set (i.e., if the countermeasure implementation flag is set for the device information of all victim CLs 21 represented by the victim device information 133), the unauthorized device determination unit 123 determines that the countermeasure against the selected unauthorized AP has been implemented, sets the countermeasure implementation flag for the device information of the selected unauthorized AP in the unauthorized device information 132, and the monitoring device 100 returns to step S105. In all other cases, the monitoring device 100 proceeds to step S114.

[0108] (Step S114)

[0109] The communication connection unit 124 generates the communication frame required for the connection process as a digital signal. At this point, the communication connection unit 124 refers to the victim device information 133 and selects a victim CL 21 for which no countermeasures have been implemented. The MAC address of the selected victim CL 21 is set as the source MAC address of the communication frame. The victim CL 21 for which no countermeasures have been implemented is the victim CL 21 corresponding to the device information included in the victim device information 133 for which the countermeasure implementation flag is not set. The victim CL 21 selected in step S114 is referred to as the first selected victim CL.

[0110] (Step S115)

[0111] The communication connection unit 124 transmits an authentication request frame and an association request frame to the rogue AP 10 via the communication unit 110, thereby performing a connection process. The communication connection unit 124 confirms the response from the communication unit 110 and confirms that the connection process was successfully completed. If encryption is set for communication, the communication connection unit 124 continues the connection process until the encryption key is shared.

[0112] After completing the connection process with the rogue AP 10, the communication connection unit 124 transmits a deauthentication frame to the rogue AP 10, with the MAC address of the first selected victim CL as the source MAC address, thereby severing the communication connection between the rogue AP 10 and the first selected victim CL. If communication encryption is enabled, the monitoring device 100 can obtain the communication encryption key by performing the encryption key sharing process until the encryption key is shared. Therefore, even if PMF is enabled, the rogue AP 10 can process the deauthentication frame normally.

[0113] In addition, when encryption of communication is set, by installing an illegal AP 10, even if the connection process is not carried out until the encryption key is shared, it is possible to cut off the communication connection between the illegal AP 10 and the first selected victim CL by simply sending a deauthentication frame to the illegal AP 10 in the middle of the connection process, in which the MAC address of the sending source is set to the MAC address of the first selected victim CL.

[0114] Through the above-described processing, the illegal communication is cut off between the first selected victim CL and the illegal AP 10. The communication connection unit 124 sets a countermeasure implementation flag in the device information of the first selected victim CL in the victim device information 133 to store that the illegal communication has been cut off.

[0115] On the other hand, due to the disconnection of the communication connection, one slot for the number of simultaneous connections of the rogue AP 10 becomes vacant. To prevent the victim CL 21 from reconnecting to the vacant slot, after executing step S115, the monitoring device 100 returns to step S109.

[0116] ***Description of the Effects of Embodiment 1***

[0117] As described above, in this embodiment, the illegal communication between the victim CL 21 and the rogue AP 10 is cut off. Furthermore, the monitoring device 100 fills the slot corresponding to the number of simultaneous connections of the rogue AP 10. Therefore, after the illegal communication is cut off, the victim CL 21 cannot reconnect to the rogue AP 10. Therefore, according to this embodiment, it is possible to mitigate the risk of the rogue AP 10 stealing the victim CL 21's information or downloading malware to the victim CL 21. Furthermore, according to this embodiment, it is possible to buy time to implement fundamental countermeasures such as physically removing the rogue device or shutting off its power supply.

[0118] ***Other structures***

[0119] <Variation 1>

[0120] Figure 5 A hardware configuration example of the monitoring device 100 according to this modification is shown.

[0121] The monitoring device 100 includes a processing circuit 58 instead of the processor 51 , the processor 51 and the memory 52 , the processor 51 and the auxiliary storage device 53 , or the processor 51 , the memory 52 , and the auxiliary storage device 53 .

[0122] The processing circuit 58 is hardware that realizes at least a part of each unit included in the monitoring device 100 .

[0123] The processing circuit 58 may be dedicated hardware, or may be a processor that executes a program stored in the memory 52 .

[0124] When the processing circuit 58 is dedicated hardware, as a specific example, the processing circuit 58 is a single circuit, a complex circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof.

[0125] The monitoring device 100 may include a plurality of processing circuits instead of the processing circuit 58. The plurality of processing circuits may share the role of the processing circuit 58.

[0126] In the monitoring device 100 , some functions may be implemented by dedicated hardware, and the remaining functions may be implemented by software or firmware.

[0127] As a specific example, the processing circuit 58 is implemented by hardware, software, firmware, or a combination thereof.

[0128] The processor 51 , the memory 52 , the auxiliary storage device 53 , and the processing circuit 58 are collectively referred to as a “processing circuit.” That is, the functions of the functional components of the monitoring device 100 are implemented by the processing circuit.

[0129] The monitoring device 100 according to other embodiments may have the same configuration as that of this modification.

[0130] Implementation Method 2

[0131] Hereinafter, differences from the above-described embodiment will be mainly described with reference to the drawings.

[0132] In the first embodiment, if there are a large number of victim CLs 21, it may take some time to implement countermeasures for all of the victim CLs 21. Therefore, the second embodiment shows a method in which the victim CLs 21 are moved to other channels in preparation for filling the slots with the number of simultaneous connections of the rogue AP 10.

[0133] ***Description of the structure***

[0134] Figure 6 A configuration example of the monitoring device 100 according to the second embodiment is shown.

[0135] like Figure 6 As shown, compared with the control unit 120 of the first embodiment, the control unit 120 of the second embodiment further includes a probe response generation unit 126 and a channel selection unit 127 .

[0136] The probe response generator 126 generates a communication frame including information for switching the channel of the victim CL 21 to the channel selected by the channel selector 127. As a specific example, the communication frame is a beacon frame or a probe response frame.

[0137] As a specific example, the probe response generator 126 transmits the first transmission data to the victim CL 21, thereby switching the channel of the victim CL 21 to the first channel. The first transmission data is communication data including a communication frame with the device identification information of the unauthorized AP 10 set as the device identification information of the transmission source so that the monitoring device 100 is identified as the unauthorized AP 10, and is communication data including a communication frame with the first channel set as the channel switching destination. The first channel is a channel where the unauthorized AP 10 does not exist. Furthermore, setting the device identification information of the unauthorized AP 10 as the device identification information of the transmission source so that the monitoring device 100 is identified as the unauthorized AP 10 is equivalent to the monitoring device 100 disguising itself as the unauthorized AP 10.

[0138] The channel selection unit 127 selects a channel where no rogue AP 10 exists as the channel to which the victim CL 21 is to switch.

[0139] like Figure 6 As shown, compared with the storage unit 130 of the first embodiment, the storage unit 130 of the second embodiment further stores a relationship table 135 .

[0140] The association table 135 is table data indicating the pairs of each victim device and the channels in which the victim device exists, and is also referred to as a "victim device and channel association table."

[0141] ***Description of the action***

[0142] Figure 7 This is a flowchart showing an example of the operation of the monitoring device 100 according to the second embodiment. Figure 7 The operation of the monitoring device 100 according to the second embodiment will be described.

[0143] (Step S201)

[0144] First, the channel selection unit 127 refers to the victim device information 133 and selects one victim CL 21 for which no countermeasures have been taken. Hereinafter, the victim CL 21 selected in step S201 is referred to as the second selected victim CL.

[0145] Next, the channel selection unit 127 refers to the association table 135 and selects a channel with no rogue APs 10 and the fewest associated victim CLs 21 as the channel to which the second selected victim CL will be transferred. If there are multiple corresponding channels, the channel selection unit 127 may select the channel with the smallest channel number, or may select a channel using a random number. Hereinafter, the channel selected in step S201 will be referred to as the first selected channel. Furthermore, if rogue APs 10 are present on all channels, there is no effect in transferring the second selected victim CL to another channel. Therefore, the monitoring device 100 terminates processing in step S201 and proceeds to step S109.

[0146] Next, the channel selector 127 adds the pair of the second selected victim CL and the first selected channel to the association table 135. Furthermore, the channel selector 127 transmits data indicating the pair of the second selected victim CL and the first selected channel to the probe response generator 126.

[0147] (Step S202)

[0148] A CSA (Channel Switch Announcement) is information sent to the CL when the AP switches the communication channel. The CSA is included in beacon frames, probe response frames, and other frames.

[0149] The probe response generator 126 sets the MAC address of the rogue AP 10 as the source MAC address and transmits a probe response frame with the first selected channel set as the channel switching destination in the CSA to the second victim CL via the communicator 110. Changing the contents of the CSA is equivalent to tampering with the CSA.

[0150] After completing the transmission, the probe response generator 126 stores the channel switch information and sets a countermeasure implementation flag for the device information of the second victim CL in the victim device information 133. Furthermore, since the rogue AP 10 cannot communicate with the victim CL 21 when the victim CL 21 is moved to a different channel from the rogue AP 10, the flag indicating the channel switch and the countermeasure implementation flag may be used together. Channel switching is equivalent to frequency hopping.

[0151] (Step S203)

[0152] If there is no device information in the victim device information 133 for which the countermeasure implementation flag is not set (i.e., if the countermeasure implementation flag is set for the device information of all victim CLs 21 represented by the victim device information 133), the monitoring device 100 proceeds to step S109 to fill the slot for the number of simultaneous connections of the rogue AP 10. In all other cases, the monitoring device 100 proceeds to step S201.

[0153] ***Description of the Effects of Implementation Method 2***

[0154] As described above, in this embodiment, the channel is switched before the slot for the number of simultaneous connections of the rogue AP 10 is filled, thereby disconnecting the unauthorized communication between the victim CL 21 and the rogue AP 10. Furthermore, by filling the slot for the number of simultaneous connections of the rogue AP 10, the disconnected victim CL 21 is prevented from reconnecting to the rogue AP 10. Furthermore, this embodiment achieves the same advantages as those of Embodiment 1.

[0155] Furthermore, in the first embodiment, the process of filling the slot for the number of simultaneous connections of the rogue AP 10 is performed first, so it takes time to cut off the illegal communication between the victim CL 21 and the rogue AP 10. However, according to the present embodiment, the illegal communication can be cut off before the process of filling the slot for the number of simultaneous connections of the rogue AP 10 is performed, thereby further reducing the damage compared to the first embodiment.

[0156] ***Other structures***

[0157] <Variation 2>

[0158] In the second embodiment, the victim CL 21 is moved to an appropriately determined channel. Therefore, if no authorized AP 30 exists at the destination, the victim CL 21 is unable to perform any communications. Therefore, in this variation, multiple wireless devices are assumed to exist, and legitimate communications and countermeasures against the unauthorized AP 10 are implemented in parallel. Multiple wireless devices can be implemented by providing the authorized AP 30 with multiple wireless devices, or by providing the authorized AP 30 and the monitoring device 100, which is independent of the authorized AP 30, with one or more wireless devices each.

[0159] This variation shows a method in which, after executing step S203 and before executing step S109, the victim CL 21, which has moved to a different channel, is relocated to the channel of the legitimate AP 30. This allows legitimate communication to be carried out using one wireless device while simultaneously filling the slot for the rogue AP 10's simultaneous connections using other wireless devices.

[0160] The following mainly describes the differences from the second embodiment.

[0161] ***Description of the structure***

[0162] The configuration of the monitoring device 100 of this modification is the same as that of the monitoring device 100 of the second embodiment.

[0163] When monitoring device 100 functions as legitimate AP 30, probe response generator 126 of this variation transmits second transmission data to victim CL 21, whose channel has been switched to the first channel, thereby switching victim CL 21's channel to the second channel. The second transmission data is communication data containing a communication frame with the device identification information of the unauthorized AP 10 set as the source, identifying monitoring device 100 as an unauthorized AP 10, and a communication frame with the second channel set as the destination. The second channel is a channel where unauthorized AP 10 does not exist. Then, probe response generator 126 switches the monitoring device 100's channel to the second channel, thereby establishing legitimate communication with victim CL 21.

[0164] ***Description of the action***

[0165] Figure 8 This is a flowchart showing an example of the operation of the monitoring device 100 according to this modification. Figure 8 The operation of the monitoring device 100 will be described.

[0166] (Step S221)

[0167] The channel selection unit 127 selects a channel where no rogue AP 10 exists as a channel for resuming legitimate communication. Hereinafter, the channel selected in step S221 is referred to as a second selected channel.

[0168] However, in this variation, it is also assumed that the unauthorized AP 10 moves channels following the CSA sent in step S202. The channel selection unit 127 reacquires surrounding communication frames before selecting a channel and confirms the channel where the unauthorized AP 10 exists based on the acquired communication frames.

[0169] (Step S222)

[0170] The probe response generator 126 sequentially sets the MAC address of the rogue AP 10 as the source MAC address to the victim CL 21 indicated in the association table 135 and transmits a probe response frame with the second selected channel set as the channel switching destination in the CSA via the communicator 110 .

[0171] Furthermore, when transmitting a probe response frame, the monitoring device 100 that transmits the probe response frame needs to switch to a channel where the victim CL 21 that is the transmission destination of the probe response frame exists.

[0172] (Step S223)

[0173] The probe response generator 126 switches the channel of the legitimate AP 30 to the second selected channel, and transmits a probe response frame to the victim CL 21 as the legitimate AP 30. This allows the victim CL 21 to connect to the legitimate AP 30 and resume legitimate communication.

[0174] On the other hand, the wireless device responsible for filling the slot for the number of simultaneous connections of the illegal AP 10 transfers the channel to the channel where the illegal AP 10 exists, and proceeds to step S109 to continue processing.

[0175] ***Description of Effects of Modification 2***

[0176] In the second embodiment, the victim CL 21 is moved to an appropriately determined channel. Therefore, if no legitimate AP 30 exists at the destination, the victim CL 21 is unable to perform any communications. However, according to this variation, communication between the legitimate AP 30 and the legitimate CL 20 and countermeasures against the rogue AP 10 can be performed in parallel.

[0177] Implementation 3

[0178] Hereinafter, differences from the above-described embodiment will be mainly described with reference to the drawings.

[0179] In Embodiments 1 and 2, countermeasures must be implemented for each victim CL 21, which takes a relatively long time. Therefore, in Embodiment 3, when there are a large number of victim CLs 21, the damage is mitigated by interfering with illegal communications earlier.

[0180] ***Description of the structure***

[0181] Figure 9 A configuration example of a monitoring device 100 according to a third embodiment is shown.

[0182] like Figure 9 As shown, the control unit 120 of the third embodiment further includes a deauthentication frame generation unit 128 , compared to the control unit 120 of the first embodiment.

[0183] If PMF is enabled in wireless communication between the rogue AP 10 and the victim CL 21, the deauthentication frame generator 128 generates a deauthentication frame using the encryption key received from the rogue AP 10 and transmits communication data including the generated deauthentication frame to the victim CL 21. The encryption key is a common key in the wireless communication network in which the rogue AP 10 participates.

[0184] ***Description of the action***

[0185] Figure 10 This is a flowchart showing an example of the operation of the monitoring device 100 according to the third embodiment. Figure 10 The operation of the monitoring device 100 will be described.

[0186] (Step S301)

[0187] If the monitoring device 100 can be normally connected to the rogue AP 10 , the monitoring device 100 proceeds to step S302 .

[0188] If the monitoring device 100 cannot be normally connected to the rogue AP 10 , the monitoring device 100 returns to step S109 .

[0189] (Step S302)

[0190] The deauthentication frame generator 128 transmits a deauthentication frame, with the source MAC address set to the MAC address of the rogue AP 10, a specified number of times via broadcast within the LAN (Local Area Network) of the rogue AP. Broadcast communications within the PMF are protected by the Broadcast Integrity Protocol (BIP). The integrity verification of broadcast communication frames within the BIP uses the LAN-wide public encryption key (IGTK) received from the AP. Therefore, the monitoring device 100, as a CL, receives the IGTK while being properly connected to the rogue AP 10. Using the received IGTK, the monitoring device 100 transmits a broadcast deauthentication frame disguised as the rogue AP 10, thereby disrupting communication between the rogue AP 10 and the victim CL 21 within the LAN in which the rogue AP 10 participates. Furthermore, setting the source MAC address to the MAC address of the rogue AP 10 is equivalent to impersonating the rogue AP 10.

[0191] (Step S303)

[0192] First, the communication monitoring unit 121 obtains a communication frame from each device in the peripheral device group via the communication unit 110 .

[0193] Next, the information analysis unit 122 checks whether there is a communication frame from the selected unauthorized AP (that is, a communication frame having the MAC address of the selected unauthorized AP as a transmission source) among the communication frames acquired by the communication monitoring unit 121 .

[0194] In addition, in step S303 , the communication monitoring unit 121 and the information analysis unit 122 appropriately execute at least a part of step S101 and step S102 .

[0195] (Step S304)

[0196] If there is a communication frame between the selected rogue AP and the victim CL 21, it indicates that the communication has not been properly disconnected or that the victim CL 21 has reconnected to the selected rogue AP after the communication has been properly disconnected. Therefore, the monitoring device 100 returns to step S109.

[0197] If there is no communication frame from the selected unauthorized AP, the monitoring device 100 returns to step S101 .

[0198] ***Description of the Effects of Implementation Method 3***

[0199] As described above, according to this embodiment, the deauthentication frame can be used to interfere with illegal communication between the victim CL 21 and the illegal AP 10. In addition, according to this embodiment, the same effects as those of the first embodiment can be obtained.

[0200] Implementation 4

[0201] Hereinafter, differences from the above-described embodiment will be mainly described with reference to the drawings.

[0202] In the third embodiment, there is a problem: if the rogue AP 10 has very high processing capabilities, the load on the rogue AP 10 cannot be increased sufficiently, and therefore the interference function may not be achieved. Therefore, in the fourth embodiment, rather than performing interference on the rogue AP 10, a method is shown in which the victim CL 21 is caused to suppress communication with the rogue AP 10 to interfere with the rogue communication.

[0203] ***Description of the structure***

[0204] Figure 11 A configuration example of a monitoring device 100 according to a fourth embodiment is shown.

[0205] like Figure 11 As shown, the control unit 120 of the fourth embodiment includes a probe response generation unit 126 instead of the communication connection unit 124 and the MAC address generation unit 125 .

[0206] The probe response generation unit 126 of this embodiment generates a beacon frame or a probe response frame.

[0207] As a specific example, the probe response generator 126 transmits fourth transmission data to the victim CL 21 to extend the time until the victim CL 21's next communication. The fourth transmission data includes a communication frame in which the device identification information of the rogue AP 10 is set as the source device identification information, thereby identifying the monitoring device 100 as the rogue AP 10. It also includes a communication frame in which either a QoS (Quality of Service)-related field or a communication control-related field is set so that the waiting time until the victim CL 21 transmits a communication frame to the rogue AP 10 is greater than or equal to a first reference waiting time. The first reference waiting time can also be arbitrarily determined.

[0208] like Figure 11 As shown, the storage unit 130 of the fourth embodiment stores QoS parameters 136 instead of storing the used MAC address table 134 .

[0209] In the fourth embodiment, QoS parameter 136 is the value of the QoS Association field in the IEEE (Institute of Electrical and Electronics Engineers) 802.11 frame format. Specifically, it is the CWmin (Contention Windows minimum, the minimum value of the communication waiting counter) or the AIFSN (Arbitration Interframe Space Number, the unit time of communication waiting time) parameter of the Enhanced Distributed Channel Access (EDCA) protocol. Specifically, QoS parameter 136 is pre-set to a large value. By sending a beacon frame or probe response frame with a large value set for QoS parameter 136 to the victim CL 21, the waiting time before the victim CL 21 transmits a communication frame can be forcibly increased. Furthermore, setting the value of QoS parameter 136 is equivalent to tampering with QoS parameter 136.

[0210] Furthermore, depending on the implementation of the victim CL 21, the waiting time counter may be reset every time the victim CL 21 receives a tampered beacon frame or probe response frame. In this case, the victim CL 21 can be completely prevented from communicating.

[0211] ***Description of the action***

[0212] Figure 12This is a flowchart showing an example of the operation of the monitoring device 100 according to the fourth embodiment. Figure 12 The operation of the monitoring device 100 will be described.

[0213] (Step S401)

[0214] The probe response generator 126 refers to the victim device information 133 and transmits a probe response frame, with the QoS parameters 136 appropriately configured, to each victim CL 21 indicated in the victim device information 133 via the communication unit 110. At this time, the probe response generator 126 sets the destination MAC address to the MAC address of each victim CL 21. The probe response generator 126 may also transmit a broadcast beacon frame instead of a probe response frame.

[0215] ***Description of the Effects of Implementation Method 4***

[0216] As described above, according to this embodiment, each victim CL 21 is caused to suppress communication using the QoS parameter 136, thereby interfering with illegal communication between each victim CL 21 and the illegal AP 10. In addition, according to this embodiment, the same effects as those of the first embodiment can be obtained.

[0217] ***Other structures***

[0218] <Variation 3>

[0219] In the fourth embodiment, the waiting time of the victim CL 21 is extended. Therefore, if the waiting time expires, there is a risk that the victim CL 21 will communicate with the rogue AP 10. Therefore, this modification shows a method for causing the victim CL 21 to suppress communication by utilizing the RTS / CTS (Request To Send / Clear To Send) method, which is one of the communication control methods.

[0220] The RTS / CTS method controls communications by assigning transmission rights to CLs using the AP. In this method, a CL can send an RTS frame to the AP, and the AP can specify a CL as a reply to the RTS using a CTS frame. Only the specified CL can then send data to the AP. This structure allows all affected CLs 21 to suppress transmission by replacing the CL assigned transmission rights in the CTS frame with a CL not present in the surrounding device group and then sending the modified CTS frame.

[0221] This modification is based on the premise of using the RTS / CTS method, and therefore cannot always be applied to the monitoring device 100. However, most APs have a function of switching to the RTS / CTS method when communication quality deteriorates.

[0222] The following mainly describes the differences from Implementation 4.

[0223] ***Description of the structure***

[0224] Figure 13 A configuration example of a monitoring device 100 according to this modification is shown.

[0225] like Figure 13 As shown, the control unit 120 of this modification includes a CTS generation unit 129 and a MAC address generation unit 125 instead of the probe response generation unit 126 .

[0226] The CTS generation unit 129 generates a CTS frame.

[0227] As a specific example, when the RTS / CTS method is used in a wireless communication network in which an illegal AP 10 and a victim CL 21 participate, in order to cause the victim CL 21 to suppress communication, the CTS generation unit 129 broadcasts data of a communication frame containing device identification information of a device that is different from any of the device identification information of devices in the surrounding device group as the device identification information of the device to which the transmission right is allocated to the wireless communication network.

[0228] ***Description of the action***

[0229] Figure 14 This is a flowchart showing an example of the operation of the monitoring device 100 according to this modification. Figure 14 The operation of the monitoring device 100 will be described.

[0230] (Step S421)

[0231] The MAC address generation unit 125 generates a MAC address. The MAC address generation unit 125 can generate a MAC address using a random number or by adding a value to the MAC address indicated by the victim device information 133. The MAC address generation unit 125 refers to the victim device information 133 and confirms that the generated MAC address is different from the MAC address of the victim CL 21 indicated by the victim device information 133.

[0232] If the MAC address generation unit 125 confirms that the generated MAC address is different from any of the MAC addresses of the victim CL 21 indicated in the victim device information 133, it transmits data indicating the generated MAC address to the CTS generation unit 129. Furthermore, if the generated MAC address is the same as any of the MAC addresses of the victim CL 21 indicated in the victim device information 133, the MAC address generation unit 125 regenerates a MAC address and reconfirms that the regenerated MAC address is different from any of the MAC addresses of the victim CL 21 indicated in the victim device information 133.

[0233] (Step S422)

[0234] First, the CTS generation unit 129 specifies the MAC address indicated by the data received from the MAC address generation unit 125 as a target to which the transmission right is to be allocated.

[0235] Next, the CTS generation unit 129 generates a CTS frame with the MAC address of the unauthorized AP 10 as the transmission source MAC address, and transmits the generated CTS frame by broadcasting to the LAN of the unauthorized AP 10 via the communication unit 110 .

[0236] Alternatively, the CTS generation unit 129 may unconditionally generate a CTS frame each time step S422 is executed, and transmit the generated CTS frame each time a CTS frame is generated. Alternatively, the communication monitoring unit 121 may reacquire communication frames from each device in the surrounding device group each time step S422 is executed, and the CTS generation unit 129 may transmit the generated CTS frame only when the information analysis unit 122 detects an RTS frame from the victim CL 21 in the communication frames acquired by the communication monitoring unit 121.

[0237] ***Description of Effects of Modification 3***

[0238] As described above, according to this modification, the victim CL 21 is caused to suppress communication using the RTS / CTS method, thereby interfering with illegal communication between the victim CL 21 and the illegal AP 10. In addition, according to this modification, the same effects as those of the first embodiment can be obtained.

[0239] Furthermore, in this modification, the victim CL 21 can suppress communication regardless of the waiting time of the victim CL 21. Therefore, according to this modification, damage can be further alleviated compared to the fourth embodiment.

[0240] <Variation 4>

[0241] Implementation 4 and Modification 3 are countermeasures against the rogue AP 10. Figure 17As shown, the access point and client can be switched, and the monitoring device 100 can disguise itself as a legitimate AP 30 to suppress communication of the rogue CL 22. That is, by appropriately using the configurations of the fourth embodiment and the third modification, countermeasures can be taken against the rogue CL 22.

[0242] Next, a description will be given of a case where the configuration of Embodiment 4 is used. It is assumed that a legitimate AP 30 exists in the surrounding device group, and a rogue CL 22 is connected to the legitimate AP 30 .

[0243] The probe response generator 126 transmits the fifth transmission data to the unauthorized CL 22 to suppress the unauthorized CL 22. The fifth transmission data includes a communication frame in which the device identification information of the authorized AP 30 is set as the source device identification information, so that the monitoring device 100 is identified as the authorized AP 30. It also includes a communication frame in which either the QoS-related field or the communication control-related field is set so that the waiting time before the unauthorized CL 22 transmits a communication frame to the authorized AP 30 is equal to or longer than the second reference waiting time. The second reference waiting time can also be arbitrarily determined.

[0244] Next, a description will be given of a case where the configuration of Modification 3 is used. It is assumed that a legitimate AP 30 exists in the surrounding device group, and a rogue CL 22 is connected to the legitimate AP 30 .

[0245] When the authorized AP 30 and the unauthorized CL 22 participate in the wireless communication network, the CTS generation unit 129 broadcasts data of a communication frame containing device identification information of the device assigned the transmission right, in which device identification information different from any of the device identification information of the devices in the surrounding device group is set, to the wireless communication network in order to cause the unauthorized CL 22 to refrain from communication.

[0246] Furthermore, Patent Document 1 presents the following problem: an unauthorized client that has become unable to communicate due to an updated encryption key can relatively easily reconnect to the authorized access point by requesting a reconnection to the authorized access point using the same MAC address as the WIPS monitoring device does. According to this variation, the unauthorized client is prevented from requesting a reconnection to the authorized access point, thereby preventing it from easily reconnecting to the authorized access point.

[0247] Implementation 5

[0248] Hereinafter, differences from the above-described embodiment will be mainly described with reference to the drawings.

[0249] In Embodiment 2 and its variations, the victim CL 21 is prevented from communicating by first switching to another channel. Therefore, it takes time for the victim CL 21 to resume legitimate communications. Therefore, in Embodiment 5, a method is described in which the monitoring device 100 directly seizes the communication connection with the victim CL 21 from the rogue AP 10 in order to more quickly mitigate the damage and resume legitimate communications.

[0250] ***Description of the structure***

[0251] Figure 15 A configuration example of a monitoring device 100 according to a fifth embodiment is shown.

[0252] The configuration of the monitoring device 100 is obtained by removing the MAC address generation unit 125 and the used MAC address table 134 from the configuration of the monitoring device 100 of the first embodiment.

[0253] The communication connection unit 124 of this embodiment transmits the sixth transmission data to the victim CL 21 to disconnect the communication connection between the rogue AP 10 and the victim CL 21. The sixth transmission data is communication data including a communication frame in which the device identification information of the rogue AP 10 is set as the device identification information of the transmission source so that the monitoring device 100 is identified as the rogue AP 10. Furthermore, the sixth transmission data includes communication frames configured to disconnect the communication connection between the rogue AP 10 and the victim CL 21 and to establish a communication connection with the victim CL 21.

[0254] ***Description of the action***

[0255] Figure 16 This is a flowchart showing an example of the operation of the monitoring device 100 according to the fifth embodiment. Figure 16 The operation of the monitoring device 100 will be described.

[0256] (Step S501)

[0257] The communication connection unit 124 refers to the victim device information 133 and selects one victim CL 21 for which no countermeasures have been implemented. Hereinafter, the victim CL 21 selected in step S501 is referred to as a third selected victim CL.

[0258] (Step S502)

[0259] The communication connection unit 124 sets the MAC address of the rogue AP 10 as the transmission source and transmits a probe response frame with the MAC address of the third selected victim CL as the transmission destination to the third selected victim CL via the communication unit 110, thereby performing connection processing with the third selected victim CL.

[0260] After the connection process is normally completed, the communication connection unit 124 sets a countermeasure implementation flag for the device information of the third selected victim CL in the victim device information 133 .

[0261] (Step S503)

[0262] If there is no device information with no countermeasure implementation flag set in the victim device information 133 (ie, if the countermeasure implementation flag is set for all victim CLs 21 indicated by the victim device information 133), the monitoring apparatus 100 proceeds to step S504. Otherwise, the monitoring apparatus 100 proceeds to step S501.

[0263] (Step S504)

[0264] The unauthorized device determination unit 123 assumes that a countermeasure is implemented against the selection of an unauthorized AP, and sets a countermeasure implementation flag for the device information of the selected unauthorized AP in the unauthorized device information 132 .

[0265] Furthermore, each victim CL 21 may have previously communicated with the selected rogue AP and, therefore, may have downloaded malware, potentially sending attack frames to the legitimate AP 30. Therefore, after the monitoring device 100 seizes the communication connection of each victim CL 21, the legitimate AP 30 may monitor the communications of each victim CL 21 for a certain period of time and implement countermeasures as needed. Specific examples of countermeasures include displaying a warning screen to each victim CL 21, reducing the communication bandwidth of each victim CL 21, or ignoring communications from each victim CL 21.

[0266] After the process of step S504 is completed, the monitoring device 100 returns to step S101.

[0267] ***Description of the Effects of Implementation 5***

[0268] As described above, according to the fifth embodiment, the monitoring device 100 directly seizes the communication connection with each victim CL 21 from the unauthorized AP 10, thereby cutting off the unauthorized communication between the unauthorized AP 10 and each victim CL 21. In addition, according to this embodiment, the same effects as those of the first embodiment can be obtained.

[0269] Furthermore, according to the fifth embodiment, the monitoring device 100 provides legitimate communication to each victim CL 21 . Therefore, compared with the second embodiment, it is possible to provide legitimate communication to each victim CL 21 earlier.

[0270] ***Other structures***

[0271] <Variation 5>

[0272] Implementation 5 is a countermeasure against the illegal AP 10. However, Figure 17 As shown, the positions of the access point and the client can be reversed, and the monitoring device 100 can directly seize the communication with the rogue CL 22 from the legitimate AP 30. That is, by appropriately adopting the structure of the fifth embodiment, it is also possible to take measures against the rogue CL 22.

[0273] Next, a description will be given of a case where the configuration of Embodiment 5 is used. It is assumed that a legitimate AP 30 exists in the surrounding device group, and a rogue CL 22 is connected to the legitimate AP 30 .

[0274] The communication connection unit 124 transmits the seventh transmission data to the unauthorized CL 22 to disconnect the communication connection between the authorized AP 30 and the unauthorized CL 22. The seventh transmission data is communication data including a communication frame in which the device identification information of the authorized AP 30 is set as the device identification information of the transmission source so that the monitoring device 100 is identified as the authorized AP 30. Furthermore, the seventh transmission data includes communication frames configured to disconnect the communication connection between the authorized AP 30 and the unauthorized CL 22 and to establish a communication connection with the unauthorized CL 22.

[0275] Furthermore, according to this modification, the problem of Patent Document 1 described above can be solved.

[0276] ***Other Implementations***

[0277] The aforementioned embodiments can be freely combined, arbitrary components of the embodiments can be modified, or arbitrary components of the embodiments can be omitted.

[0278] The embodiments are not limited to those described in Embodiments 1 to 5, and various modifications can be made as needed. The steps described using flowcharts and the like can also be modified as appropriate.

[0279] Description of labels

[0280] 10: Illegal AP; 20: Legal CL; 21: Victim CL; 22: Illegal CL; 30: Legal AP; 51: Processor; 52: Memory; 53: Auxiliary storage device; 54: Input / output IF; 55: Communication device; 58: Processing circuit; 59: Signal line; 100: Monitoring device; 110: Communication unit; 120: Control unit; 121: Communication monitoring unit; 122: Information analysis unit; 123: Illegal device determination unit; 124: Communication connection unit; 125: MAC address generation unit; 126: Probe response generation unit; 127: Channel selection unit; 128: Deauthentication frame generation unit; 129: CTS generation unit; 130: Storage unit; 131: Communication frame information; 132: Illegal device information; 133: Victim device information; 134: Used MAC address table; 135: Association table; 136: QoS parameters.

Claims

1. A monitoring device comprising: a communication connection unit, wherein, when an unauthorized access point exists in a group of surrounding devices, the communication connection unit repeatedly connects to the unauthorized access point using each piece of device identification information in a device identification information group consisting of one or more pieces of device identification information generated so as not to overlap with each other, in order to fill a slot for simultaneous connections of the unauthorized access point; When the connection to the illegal access point fails, the communication connection unit uses the device identification information of the victim client, which is a communication device connected to the illegal access point, to connect to the illegal access point, thereby cutting off the communication connection between the illegal access point and the victim client. In order to fill the slot of the number of simultaneous connections of the rogue access point vacated due to the disconnection of the communication connection, the communication connection unit connects to the rogue access point using device identification information that is different from any device identification information in the device identification information group. in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication. Each device identification information of the device identification information group is different from the device identification information of the victim client.

2. The monitoring device according to claim 1, wherein The monitoring apparatus further includes an unauthorized device determination unit configured to determine whether the unauthorized access point exists in the surrounding device group based on a communication frame transmitted by each device in the surrounding device group.

3. The monitoring device according to claim 1 or 2, wherein: Each device identification information of the device identification information group is a MAC address, and the device identification information of the victim client is a MAC address.

4. The monitoring device according to any one of claims 1 to 3, wherein: In wireless communications between the rogue access point and the victim client, protected management frames are effective.

5. The monitoring device according to any one of claims 1 to 4, wherein: The monitoring device further includes a probe response generating unit that transmits transmission data as communication data to the victim client, thereby switching the channel of the victim client to the first channel, which is a channel in which the illegal access point does not exist. The communication data includes a communication frame in which the device identification information of the illegal access point is set as the device identification information of the transmission source in such a manner that the monitoring device is identified as the illegal access point, and includes a communication frame in which the first channel is set as the channel switching destination. The monitoring device according to claim 5 , wherein: When the monitoring device functions as a legitimate access point, the probe response generation unit transmits transmission data as communication data to the victim client whose channel has been switched to the first channel, thereby switching the channel of the victim client to the second channel, which is a channel in which the illegal access point does not exist. The communication data includes a communication frame in which the device identification information of the illegal access point is set as the device identification information of the transmission source so that the monitoring device is identified as the illegal access point, and includes a communication frame in which the second channel is set as the channel switching destination. In order to establish legitimate communication with the victim client, the probe response generation unit switches the channel of the monitoring device to the second channel.

7. A monitoring device, comprising: a communication connection unit that repeatedly connects to the unauthorized access point using each piece of device identification information in a device identification information group consisting of one or more pieces of device identification information generated so as not to overlap with each other, in order to fill a slot for the number of simultaneous connections of the unauthorized access point; and a deauthentication frame generating unit that generates a deauthentication frame using the encryption key received from the illegal access point and transmits communication data including the generated deauthentication frame to the victim client; in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication. The encryption key is a public key in the wireless communication network in which the illegal access point participates.

8. A monitoring device that monitors communications of illegal access points present in a surrounding device group. The monitoring device includes a probe response generating unit that transmits transmission data as communication data to the victim client, the communication data including a communication frame in which device identification information of the illegal access point is set as device identification information of a transmission source so that the monitoring device is identified as the illegal access point, and including a communication frame in which either a quality of service-related field or a field related to communication control is set so that a waiting time until a communication device connected to the illegal access point, i.e., the victim client, transmits a communication frame to the illegal access point becomes equal to or longer than a first reference waiting time. in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication.

9. The monitoring device according to claim 8, wherein: In the case where there is a legitimate access point in the surrounding device group and the illegal client is connected to the legitimate access point, The probe response generator transmits transmission data as communication data to the unauthorized client, the communication data including a communication frame in which the device identification information of the authorized access point is set as the device identification information of the transmission source so that the monitoring device is identified as the authorized access point, and including a communication frame in which either a quality of service-related field or a field associated with communication control is set so that a waiting time until the unauthorized client transmits a communication frame to the authorized access point becomes equal to or longer than a second reference waiting time.

10. A monitoring device comprising a CTS generating unit, wherein when a request-to-send / clear-to-send method is used in a wireless communication network in which an unauthorized access point existing in a surrounding device group and a communication device connected to the unauthorized access point, i.e., a victim client, participate, the CTS generating unit broadcasts data including a communication frame to the wireless communication network, wherein device identification information different from any of the device identification information of devices existing in the surrounding device group is set as device identification information of a device to which a transmission right is allocated, in order to cause the victim client to suppress communication. in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication.

11. The monitoring device according to claim 10, wherein: In the case where there is a legitimate access point in the surrounding device group and the illegal client is connected to the legitimate access point, When the legitimate access point and the illegal client participate in the wireless communication network, in order to make the illegal client suppress communication, the CTS generation unit sends data including a communication frame to the wireless communication network by broadcasting, and the communication frame sets device identification information that is different from any of the device identification information of the devices existing in the surrounding device group as the device identification information of the device to which the transmission right is allocated.

12. A monitoring device for monitoring communications of an illegal access point existing in a surrounding device group. The monitoring device includes a communication connection unit that transmits transmission data as communication data to a victim client, the communication data including a communication frame in which device identification information of the illegal access point is set as device identification information of a transmission source so that the monitoring device is identified as the illegal access point, a communication frame set so that a communication connection between the illegal access point and a communication device connected to the illegal access point, i.e., the victim client, is severed, and a communication frame set so that a communication connection with the victim client is established. in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication.

13. The monitoring device according to claim 12, wherein: In the case where there is a legitimate access point in the surrounding device group and the illegal client is connected to the legitimate access point, The communication connection unit transmits transmission data as communication data to the illegal client, the communication data including a communication frame in which the device identification information of the legitimate access point is set as the device identification information of the transmission source so that the monitoring device is identified as the legitimate access point, a communication frame set so that the communication connection between the legitimate access point and the illegal client is severed, and a communication frame set so that the communication connection with the illegal client is established.

14. A monitoring method comprising: when an unauthorized access point exists in a group of surrounding devices, a computer serving as a monitoring device repeatedly connects to the unauthorized access point using each device identification information of a device identification information group consisting of one or more device identification information generated in a manner that does not overlap with each other, in order to fill a slot for the number of simultaneous connections of the unauthorized access point; When the connection to the illegal access point fails, the computer uses the device identification information of the communication device connected to the illegal access point, that is, the victim client, to connect to the illegal access point, thereby cutting off the communication connection between the illegal access point and the victim client. In order to fill the slot of the number of simultaneous connections of the rogue access point vacated due to the disconnection of the communication connection, the computer connects to the rogue access point using device identification information that is different from any device identification information in the device identification information group. in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication. Each device identification information of the device identification information group is different from the device identification information of the victim client.

15. A monitoring method, comprising: when a protected management frame is valid in wireless communication between an illegal access point existing in a peripheral device group and a communication device connected to the illegal access point, namely, a victim client; In order to fill the slot for the number of simultaneous connections to the unauthorized access point, the computer as the monitoring device repeatedly connects to the unauthorized access point using each device identification information of a device identification information group consisting of one or more device identification information generated in a non-repeating manner. The computer generates a deauthentication frame using the encryption key received from the illegal access point, and transmits communication data including the generated deauthentication frame to the victim client. in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication. The encryption key is a public key in the wireless communication network in which the illegal access point participates.

16. A monitoring method, wherein a computer serving as a monitoring device for monitoring communications of an unauthorized access point present in a surrounding device group transmits transmission data as communication data to a victim client, the communication data including a communication frame in which device identification information of the unauthorized access point is set as device identification information of a transmission source so as to identify the monitoring device as the unauthorized access point, and including a communication frame in which either a quality of service-related field or a communication control-related field is set so as to ensure that a waiting time for a communication device connected to the unauthorized access point, i.e., the victim client, to transmit a communication frame to the unauthorized access point becomes equal to or longer than a first reference waiting time, in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication.

17. A monitoring method, wherein, when a request-to-send / clear-to-send method is used in a wireless communication network involving an unauthorized access point present in a surrounding device group and a communication device connected to the unauthorized access point, i.e., a victim client, the computer serving as a monitoring device broadcasts data including a communication frame to the wireless communication network, wherein the communication frame sets, as the device identification information of a device assigned a transmission right, device identification information that is different from any of the device identification information of devices present in the surrounding device group. in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication.

18. A monitoring method, wherein a computer serving as a monitoring device for monitoring communications of an unauthorized access point present in a group of surrounding devices transmits transmission data as communication data to a victim client, the communication data including a communication frame in which device identification information of the unauthorized access point is set as device identification information of a transmission source so as to identify the monitoring device as the unauthorized access point, a communication frame configured to disconnect a communication connection between the unauthorized access point and a communication device connected to the unauthorized access point, i.e., the victim client, and a communication frame configured to establish a communication connection with the victim client. in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication.

19. A monitoring program that causes a monitoring device, which is a computer, to execute the following communication connection processing: When an unauthorized access point exists in the surrounding device group, connections to the unauthorized access point are repeatedly performed using each device identification information of a device identification information group consisting of one or more device identification information generated in a non-repeating manner in order to fill the slot for the number of simultaneous connections of the unauthorized access point. If the connection to the illegal access point fails, the device identification information of the victim client, which is a communication device connected to the illegal access point, is used to connect to the illegal access point, thereby cutting off the communication connection between the illegal access point and the victim client. In order to fill the slot of the number of simultaneous connections of the rogue access point vacated due to the disconnection of the communication connection, the rogue access point is connected using device identification information that is different from any device identification information in the device identification information group. in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication. Each device identification information of the device identification information group is different from the device identification information of the victim client.

20. A monitoring program, wherein, when a protected management frame is valid in wireless communication between an illegal access point existing in a peripheral device group and a communication device connected to the illegal access point, namely, a victim client, The monitoring program causes the monitoring device, which is a computer, to execute the following processing: a communication connection process of repeatedly performing connection to the unauthorized access point using each device identification information of a device identification information group consisting of one or more device identification information generated in a non-repeating manner in order to fill a slot for the number of simultaneous connections of the unauthorized access point; and a deauthentication frame generation process, generating a deauthentication frame using the encryption key received from the illegal access point, and sending communication data including the generated deauthentication frame to the victim client; in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication. The encryption key is a public key in the wireless communication network in which the illegal access point participates.

21. A monitoring program executed by a monitoring device, which is a computer, for monitoring communications of an unauthorized access point existing in a peripheral device group. The monitoring program causes the monitoring device to perform the following probe response generation processing: transmitting transmission data as communication data to the victim client, the communication data including a communication frame in which the device identification information of the unauthorized access point is set as the device identification information of the transmission source so that the monitoring device is identified as the unauthorized access point, and including a communication frame in which either a quality of service-related field or a communication control-related field is set so that a waiting time until the victim client, which is a communication device connected to the unauthorized access point, transmits a communication frame to the unauthorized access point becomes equal to or longer than a first reference waiting time; in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication.

22. A monitoring program that causes a monitoring device, which is a computer, to execute the following CTS generation processing: when a request-to-send / clear-to-send method is used in a wireless communication network in which an unauthorized access point existing in a surrounding device group and a communication device connected to the unauthorized access point, i.e., a victim client, participate, data including a communication frame is broadcasted to the wireless communication network, wherein device identification information different from any of the device identification information of devices existing in the surrounding device group is set as the device identification information of a device to which a transmission right is allocated, in order to cause the victim client to suppress communication; in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication.

23. A monitoring program executed by a monitoring device, which is a computer, for monitoring communications of an unauthorized access point existing in a peripheral device group. The monitoring program causes the monitoring device to perform the following communication connection processing: transmitting transmission data as communication data to the victim client, the communication data including a communication frame in which the device identification information of the illegal access point is set as the device identification information of the transmission source so that the monitoring device is identified as the illegal access point, including a communication frame set so that the communication connection between the illegal access point and the victim client, which is a communication device connected to the illegal access point, is severed, and including a communication frame set so that the communication connection with the victim client is established, in, The surrounding device group is composed of one or more devices that are present around the monitoring device and perform wireless communication.

Citation Information

Patent Citations

  • WIPS Sensor and Terminal Blocking Method Using the Same

    JP2018511282A