Method and apparatus for managing a wireless network

The method and apparatus use fake frames with strategic channel switch announcements to efficiently block malicious wireless terminals, overcoming the challenges posed by WPA3 encryption, ensuring secure network management.

JP7734871B1Active Publication Date: 2025-09-05KORNIC GLORY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2025065428
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2024-11-19
Filing Date
2025-04-11
Publication Date
2025-09-05
Estimated Expiration
2045-04-11

AI Technical Summary

Technical Problem

Existing wireless network security technologies, such as WIPS, struggle to effectively block wireless terminals with malicious intent due to the encryption provided by the PMF function in WPA3 encryption environments, making it difficult to disconnect such terminals using deauthentication or disassociation frames.

Method used

A method and apparatus that utilize fake frames with specific channel switch announcements and capability information fields to efficiently disconnect wireless terminals violating security policies, employing a series of fake frames with varying field settings to ensure complete disconnection.

Benefits of technology

Effectively blocks wireless terminals that violate security policies by ensuring complete disconnection from the network, minimizing interference with legitimate connections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007734871000001_ABST
    Figure 0007734871000001_ABST
Patent Text Reader

Abstract

A wireless network management method and a wireless network management device are provided that efficiently block the wireless network connection of a wireless terminal that has violated a security policy and is a target for blocking. [Solution] According to one embodiment, a wireless network management method includes a step of recognizing a terminal to be blocked that is connected to an AP (Access Point), a step of transmitting a first fake frame to the terminal to be blocked for a predetermined first transmission time, a step of checking whether a connection exists between the terminal to be blocked and the AP after transmitting the first fake frame, and a step of transmitting a second fake frame to the terminal to be blocked for a predetermined second transmission time when it is confirmed that the connection between the terminal to be blocked and the AP has been released after transmitting the first fake frame.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This specification relates to a method and apparatus for managing a wireless network, and more particularly to a method and apparatus for disconnecting a wireless terminal to be blocked from a wireless network when the wireless terminal to be blocked enters the wireless network.

[0002] The contents described in this specification are the result of research supported by the Korea Institute of Information and Communications Technology (KIT) with funding from the Ministry of Science and ICT of the Republic of Korea (RS-2024-00438156, Development of Service Security Resilience Technology Based on Network Slicing in 5G Specialized Network and Wired / Wireless Integrated Environment). [Background technology]

[0003] With the development of communication technology, wireless LAN (wireless LAN) technology has become widespread. WLAN is a wireless data communication technology that connects two or more devices using a radio signal transmission method. WLAN technology allows users to continuously access the network while moving around in a short distance.

[0004] In a wireless LAN environment, wireless terminals can easily connect to a wireless network through a communication connection with an AP (Access Point). However, in recent years, there has been an increase in cases where malicious wireless terminals connect to wireless networks, and wireless network security technologies have also been developed.

[0005] A typical wireless network security technology is the Wireless Intrusion Prevention System (WIPS). A WIPS sensor detects packets transmitted between an AP and a wireless terminal, determines whether they violate a predefined security policy, and blocks the connection of a wireless terminal that is targeted for blocking and has illegal or malicious intent. For example, when a wireless terminal targeted for blocking is discovered, the WIPS sensor sends a deauthentication frame or a disassociation frame to the wireless terminal or AP, thereby disconnecting the wireless terminal.

[0006] Meanwhile, the recently announced WPA3 encryption environment of WIFI6 (IEEE802.11ax) applies the PMF (Protected Managed Frame) function based on IEEE802.11w. When the PMF function is applied, data exchanged between wireless terminals and APs is encrypted and protected, which makes it difficult to block wireless intrusions by WIPS sensors using deauthentication frames and disassociation frames. Summary of the Invention [Problem to be solved by the invention]

[0007] An object of the present specification is to provide a method and apparatus for blocking wireless intrusion, which can efficiently block the wireless network connection of a wireless terminal that has violated a security policy and is a target for blocking.

[0008] The objects of the present specification are not limited to those mentioned above, and other objects and advantages of the present specification not mentioned above can be more clearly understood from the examples of the present specification described below. In addition, the objects and advantages of the present specification can be realized by the elements and combinations thereof described in the claims. [Means for solving the problem]

[0009] According to one embodiment, a wireless network management method may include a step of recognizing a terminal to be blocked that is connected to an AP (Access Point), a step of transmitting a first fake frame to the terminal to be blocked for a predetermined first transmission time, a step of confirming whether or not a connection exists between the terminal to be blocked and the AP after transmitting the first fake frame, and a step of transmitting a second fake frame to the terminal to be blocked for a predetermined second transmission time when it is confirmed that the connection between the terminal to be blocked and the AP has been released after transmitting the first fake frame.

[0010] In one embodiment, the first fake frame may include a Channel Switch Announcement element and a Capabilities Information field for changing the channel of the blocked terminal. The Capabilities Information field may include a Spectrum Management field. A field value of the Spectrum Management field may be set to an activated state.

[0011] In one embodiment, the second fake frame may include a channel switch notification element and a capability information field for changing the channel of the blocked terminal. The capability information field may include a spectrum management field. A field value of the spectrum management field may be set to a deactivated state.

[0012] In one embodiment, the step of confirming whether or not a connection exists between the terminal to be blocked and the AP after transmitting the first fake frame may include a step of confirming that the connection between the terminal to be blocked and the AP has not been released if it is confirmed that the terminal to be blocked will transmit a QoS Null packet to the AP after transmitting the first fake frame, and a step of confirming that the connection between the terminal to be blocked and the AP has been released if it is confirmed that the terminal to be blocked will not transmit a QoS Null packet to the AP after transmitting the first fake frame.

[0013] In one embodiment, the wireless network management method may further include a step of transmitting a third fake frame to the blocked terminal for a predetermined third transmission time if it is confirmed that the connection between the blocked terminal and the AP has not been released after transmitting the first fake frame.

[0014] In one embodiment, the wireless network management method may further include a step of transmitting the third fake frame to the blocked terminal for a predetermined fourth transmission time when it is confirmed that the connection between the blocked terminal and the AP has been released after transmitting the third fake frame.

[0015] In one embodiment, the wireless network management method may further include a step of classifying the blocked terminal as an unblocked terminal and storing log data when it is confirmed that the connection between the blocked terminal and the AP has not been released after the transmission of the third fake frame.

[0016] In one embodiment, the wireless network management method may include a step of confirming that the connection between the blocked terminal and the AP has not been released when it is confirmed that the blocked terminal will transmit a QoS null packet to the AP after transmitting the third fake frame, and a step of confirming that the connection between the blocked terminal and the AP has been released when it is confirmed that the blocked terminal will not transmit a QoS null packet to the AP after transmitting the third fake frame.

[0017] In one embodiment, the third fake frame may include an Extended Channel Switch Announcement element for changing the channel of the terminal to be blocked.

[0018] According to one embodiment, a wireless network management device may include a control unit that recognizes a terminal to be blocked that is connected to an AP, a frame generation unit that generates a first fake frame and a second fake frame, and a communication unit that transmits or receives data.

[0019] In one embodiment, the control unit controls the communication unit to transmit a first fake frame to the terminal to be blocked for a predetermined first transmission time, and after transmitting the first fake frame, checks whether a connection exists between the terminal to be blocked and the AP, and if it is confirmed that the connection between the terminal to be blocked and the AP has been released after transmitting the first fake frame, controls the communication unit to transmit a second fake frame to the terminal to be blocked for a predetermined second transmission time.

[0020] In one embodiment, the first fake frame may include a channel switch notification element and a capability information field for changing the channel of the terminal to be blocked. The capability information field may include a spectrum management field. A field value of the spectrum management field may be set to an activated state.

[0021] In one embodiment, the second fake frame may include a channel switch notification element and a capability information field for changing the channel of the blocked terminal. The capability information field may include a spectrum management field. A field value of the spectrum management field may be set to a deactivated state.

[0022] In one embodiment, if the control unit determines that the terminal to be blocked transmits a QoS null packet to the AP after transmitting the first fake frame, it may determine that the connection between the terminal to be blocked and the AP has not been released, and if the control unit determines that the terminal to be blocked does not transmit a QoS null packet to the AP after transmitting the first fake frame, it may determine that the connection between the terminal to be blocked and the AP has been released.

[0023] In one embodiment, the frame generator is capable of generating a third fake frame.

[0024] In one embodiment, if the control unit confirms that the connection between the blocked terminal and the AP has not been released after transmitting the first fake frame, the control unit can control the communication unit to transmit the third fake frame to the blocked terminal for a predetermined third transmission time.

[0025] In one embodiment, when the control unit confirms that the connection between the blocked terminal and the AP has been released after transmitting the third fake frame, the control unit can control the communication unit to transmit the third fake frame to the blocked terminal for a predetermined fourth transmission time.

[0026] In one embodiment, if the control unit confirms that the connection between the blocked terminal and the AP has not been released after transmitting the third fake frame, it can classify the blocked terminal as an unblocked terminal and store log data.

[0027] In one embodiment, if the control unit confirms that the terminal to be blocked transmits a QoS null packet to the AP after transmitting the third fake frame, it may confirm that the connection between the terminal to be blocked and the AP has not been released, and if the control unit confirms that the terminal to be blocked does not transmit a QoS null packet to the AP after transmitting the third fake frame, it may confirm that the connection between the terminal to be blocked and the AP has been released.

[0028] In one embodiment, the third fake frame may include an extended channel switch notification element for changing the channel of the terminal to be blocked. [Effects of the Invention]

[0029] According to the embodiment, there is an advantage that the wireless network connection of a wireless terminal that has violated a security policy and is subject to blocking can be efficiently blocked. [Brief explanation of the drawings]

[0030] [Figure 1] 1 is a diagram showing a network configuration including a wireless network management device, a wireless terminal, and an AP according to an embodiment. [Figure 2] 4 is a flowchart illustrating a connection establishment process between a wireless terminal and an AP according to an embodiment. [Figure 3] 10 is a flowchart illustrating a process in which a wireless network management device releases a connection between an AP and a wireless terminal when the wireless terminal that has established a connection with the AP is a terminal to be blocked. [Figure 4] 1 is a flow diagram illustrating a method for managing a wireless network according to one embodiment. [Figure 5] FIG. 10 illustrates an exemplary fake frame transmitted to a terminal to be blocked in one embodiment. [Figure 6] 10 is a diagram illustrating exemplary data packets collected to determine whether a connection between a blocked terminal and an AP has been released in one embodiment. FIG. DETAILED DESCRIPTION OF THE INVENTION

[0031] The above-mentioned objects, features, and advantages will be described in detail below with reference to the accompanying drawings, so that those skilled in the art can easily implement the embodiments of the present specification. In describing the present specification, if a detailed description of known technologies related to the present specification is deemed to obscure the gist of the present specification, the detailed description will be omitted. Hereinafter, preferred embodiments of the present specification will be described in detail with reference to the accompanying drawings. The same reference numerals in the drawings indicate the same or similar components.

[0032] FIG. 1 shows a network configuration including a wireless network management device, a wireless terminal, and an AP according to an embodiment.

[0033] 1, a wireless network according to one embodiment may include a wireless network management device 1, a WIPS server 2, an AP (Access Point) 3, and a wireless terminal 4. For convenience of explanation, only one wireless terminal 4 is shown in FIG. 1, but a wireless network in other embodiments may include multiple wireless terminals.

[0034] The AP 3 is a device that provides a connection to a distribution system via a wireless medium for associated terminals. The term AP is used to refer to a concept including a Personal BSS Coordination Point (PCP), and may broadly include concepts such as a centralized controller, a base station (BS), a Node-B, a base transceiver system (BTS), or a site controller. In this specification, the AP may also be referred to as a base wireless communication terminal, and the base wireless communication terminal is used to broadly include an AP, a base station, an eNodeB (eNB), and a transmission point (TP). In addition, the base wireless communication terminal may include various types of wireless communication terminals that allocate resources of a communication medium and perform scheduling for communication with multiple wireless communication terminals.

[0035] The wireless terminal (station) 4 is a device that can wirelessly connect to the AP 3 via wireless communication. Examples of the wireless terminal 4 include a desktop computer or laptop computer equipped with a wireless LAN device, a smartphone, a tablet, etc., but the type of the wireless terminal 4 is not limited to these. The wireless terminal 4 is any device that includes a medium access control (MAC) according to the IEEE 802.11 standard and a physical layer interface to the wireless medium, and in a broad sense, may include both a non-access point (non-AP) station and an access point (AP). In this specification, the term "terminal" refers to a non-AP station, but may be used to refer to both a non-AP station and an AP depending on the embodiment.

[0036] The wireless terminal 4 includes a processor and a transmit / receive unit, and may further include a user interface unit and a display unit, depending on the embodiment. The processor generates frames to be transmitted over the wireless network, processes frames received over the wireless network, and performs various other processes to control the station. The transceiver is functionally connected to the processor and transmits and receives frames over the wireless network for the station. The wireless terminal 4 can exchange frames with the AP 3 over the wireless network.

[0037] According to one embodiment, the wireless network management device 1 can detect or collect data packets transmitted between the AP 3 and the wireless terminal 4. A data packet may refer to a unit of information transmitted in blocks from one device to another over a communication network. In one embodiment, the data packet may include various element fields such as a service set identifier (ID), supported speeds, a timestamp, a cover interval, and channel information. In one embodiment, the wireless network management device 1 may also be referred to as a WIPS sensor.

[0038] The wireless network management device 1 can determine whether the wireless terminal 4 is a terminal to be blocked based on the collected data packets. In this specification, a "terminal to be blocked" can be defined as a terminal included in a predetermined list of terminals to be blocked or a terminal that violates a predetermined blocking policy. If the wireless terminal 4 is determined to be a terminal to be blocked, the wireless network management device 1 can release the connection between the wireless terminal 4 and the AP 3.

[0039] The WIPS server 2 can transmit a blocking target list or a blocking policy to the wireless network management device 1. According to an embodiment, the WIPS server 2 can receive data packets collected by the wireless network management device 1 and determine whether the wireless terminal 4 is a blocking target terminal based on the received data packets. The WIPS server 2 can provide the wireless network management device 1 with the determination result on whether the wireless terminal 4 is a blocking target terminal.

[0040] In another embodiment, the wireless network management device 1 can also determine by itself whether the wireless terminal 4 is a blocked terminal based on the blocked terminal list or blocking policy provided by the WIPS server 2.

[0041] The wireless network management device 1 according to one embodiment may include a communication unit 10, a frame generation unit 11, and a control unit 12.

[0042] The communication unit 10 can transmit data packets to other devices or receive data packets transmitted by other devices.

[0043] The frame generator 11 can generate data frames to be transmitted to other devices according to instructions from the controller 12. In one embodiment, the frame generator 11 can generate fake frames.

[0044] The control unit 12 can determine whether the wireless terminal 4 connected to the AP 3 is a blocked terminal based on a data packet received via the communication unit 10. In one embodiment, the control unit 12 can determine whether the wireless terminal 4 is a blocked terminal by transmitting the data packet received via the communication unit 10 to the WIPS server 2 and receiving a determination result on whether the wireless terminal 4 is a blocked terminal from the WIPS server 2. In another embodiment, the control unit 12 can determine whether the wireless terminal 4 is a blocked terminal based on a blocked terminal list or a blocking policy provided by the WIPS server 2.

[0045] In one embodiment, the controller 12 may analyze each data packet collected via the communication unit 10 to acquire information about the AP 3 and the wireless terminal 4. For example, the information about the AP 3 acquired by the controller 12 may include the BSSID (basic service set ID), SSID (service set ID), channel information, whether PMF is used, encryption information, MAC (medium access control) address, etc. of the AP 3 included in the beacon frame continuously broadcast by the AP 3. Furthermore, the information about the wireless terminal 4 acquired by the controller 12 may include the BSSID, MAC (medium access control) address, SSID of the connected AP 3, BSSID of the connected AP 3, channel information communicating with the connected AP 3, etc.

[0046] The control unit 12 can transmit to the WIPS server 2 the acquired data packet or information about the AP 3 or the wireless terminal 4 acquired through the data packet.

[0047] In one embodiment, when it is determined that the wireless terminal 4 connected to the AP 3 is a terminal to be blocked, the control unit 12 can request the frame generation unit 11 to generate a fake frame.

[0048] The frame generator 11 can generate fake frames according to a request from the controller 12. In one embodiment, the frame generator 11 can generate a first fake frame, a second fake frame, and a third fake frame.

[0049] In one embodiment, the fake frame may include a Channel Switch Announcement element to induce the wireless terminal 4 to switch channels or change channels.

[0050] When the frame generation unit 11 generates a fake frame, the control unit 12 can request the communication unit 12 to transmit the generated fake frame to the wireless terminal 4, which is a terminal to be blocked. This allows the communication unit 12 to transmit the fake frame to the wireless terminal 4.

[0051] In one embodiment, the fake frame generated by the frame generator 11 may be an unencrypted frame or an encrypted frame based on a Protected Managed Frame (PMF) function.

[0052] In one embodiment, the fake frame generated by the frame generator 11 may be a public action frame defined in the IEEE 802.11 standard.

[0053] In one embodiment, the fake frame generated by the frame generator 11 may include a Channel Switch Announcement element and a Capabilities Information field to change the channel of the terminal to be blocked. The Capabilities Information field may include a Spectrum Management field. The field value of the Spectrum Management field may be set to an active state or a deactivated state.

[0054] In one embodiment, the channel switch announcement information included in the fake frame generated by the frame generator 11 can be defined by an Extended Channel Switch Announcement element included in the public action frame.

[0055] In one embodiment, the frame generator 11 can generate a fake frame by changing at least one of the field values ​​of the New Operating Class field and the New Channel Number field included in the extended channel switch notification element.

[0056] In one embodiment, the destination address of the fake frame generated by the frame generation unit 11 can be set to the address of the AP 3. In one embodiment, the destination address of the fake frame generated by the frame generation unit 11 can be set to the address of the wireless terminal 4.

[0057] In the following, an exemplary embodiment will be described in which the wireless network management device 1 according to an embodiment releases the communication connection between the wireless terminal 4 and the AP 3 when the wireless terminal 4 is a terminal to be blocked.

[0058] FIG. 2 is a flow chart illustrating a connection establishment process between a wireless terminal and an AP according to an embodiment.

[0059] Referring to FIG. 2, AP 3 transmits a beacon frame (101). In step 101, AP 3 can set a receiver address or a destination address so that the receiver or destination of the beacon frame is not identified (e.g., set to "ff:ff:ff:ff:ff:ff"). That is, in step 101, AP 3 can transmit the beacon frame in a broadcasting manner. The beacon frame may include the AP 3's basic service set ID (BSSID), service set ID (SSID), channel information, whether PMF is used, encryption information, medium access control (MAC) address, etc.

[0060] The wireless terminal 4 receives the beacon frame transmitted by the AP 3 and transmits a probe request frame to the AP 3 (102).

[0061] The AP 3 that has received the probe request frame transmits a probe response frame to the wireless terminal 4 (103). At this time, the recipient address or destination address of the probe response frame may be specified as the address of the wireless terminal 4. That is, the probe response frame may be transmitted to the wireless terminal 4 by a unicasting method.

[0062] The wireless terminal 4 that receives the probe response frame transmits an authentication request frame to the AP 3 (104).

[0063] Upon receiving the authentication request frame, the AP 3 transmits an authentication response frame to the wireless terminal 4 (105). When the wireless terminal 4 receives the authentication response frame, an authentication procedure between the AP 3 and the wireless terminal 4 is performed.

[0064] Upon receiving the authentication response frame and completing the authentication procedure, the wireless terminal 4 transmits an association request frame to the AP 3 (106).

[0065] The AP 3, which has received the authentication request frame, transmits an association response frame to the wireless terminal 4 (107). When the wireless terminal 4 receives the association response frame, it can perform an association process between the AP 3 and the wireless terminal 4 based on information included in the beacon frame or the probe response frame.

[0066] When the wireless terminal 4 receives the connection response frame and completes connection with the AP 3, an encryption key is exchanged between the AP 3 and the wireless terminal 4 (108). An example of a method for exchanging the encryption key is a 4-way handshake, but the encryption key exchange method is not limited to this.

[0067] Once the encryption key exchange step (108) is completed, a connection between the AP 3 and the wireless terminal 4 is established, and communication between the AP 3 and the wireless terminal 4 using encryption (e.g., PMF) becomes possible.

[0068] FIG. 3 is a flowchart illustrating a process in which a wireless network management device releases a connection between an AP and a wireless terminal when the wireless terminal connected to the AP is a terminal to be blocked.

[0069] Referring to Fig. 3, a connection can be established between an AP 3 and a wireless terminal 4 (step 201). The connection establishment step (step 201) may include steps 101 to 108 shown in Fig. 2. However, depending on the embodiment, the connection can be established between the AP 3 and the wireless terminal 4 through other processes.

[0070] While the connection between the AP 3 and the wireless terminal 4 is being established, the control unit 12 of the wireless network management device 1 can collect data packets exchanged between the AP 3 and the wireless terminal 4 via the communication unit 10 (202). The control unit 12 can also collect data packets exchanged between the AP 3 and the wireless terminal 4 after the connection between the AP 3 and the wireless terminal 4 has been established.

[0071] The control unit 12 of the wireless network management device 1 can determine whether the wireless terminal 4 is a terminal to be blocked by using information included in the collected data packets (203). In one embodiment, the control unit 12 can transmit the collected data packets and / or information included in the collected data packets to the WIPS server 2, request the WIPS server 2 to determine whether the wireless terminal 4 is a terminal to be blocked, and receive the result of the determination from the WIPS server 2. In another embodiment, the control unit 12 can determine whether the wireless terminal 4 is a terminal to be blocked by itself based on the collected data packets and / or information included in the collected data packets.

[0072] If it is determined in step (203) that the wireless terminal 4 is a terminal to be blocked, the control unit 12 can request the frame generation unit 11 to generate a fake frame.

[0073] The frame generator 11 can generate a fake frame by referring to the data packets collected by the controller 12 and / or information included in the collected data packets (204).

[0074] The fake frame generated by the frame generation unit 11 in step (204) may include a channel change notification element as channel change notification information, in which at least one of the new operation class field and the new channel number field is changed, as described above, in order to change to a channel different from the current channel used by the wireless terminal 4 for communication with the AP 3.

[0075] In addition, the sending address of the fake frame generated by the frame generating unit 11 can be set to the address of the AP 3, and the receiving address can be set to the address of the wireless terminal 4. This allows the communication connection release procedure described later to be applied only to the wireless terminal 4, which is the terminal to be blocked, excluding normal wireless terminals.

[0076] The control unit 12 can request the communication unit 10 to transmit the fake frame. This allows the communication unit 10 to transmit the fake frame to the wireless terminal 4 (205).

[0077] The fake frame transmitted by the wireless network management device 1 may be a public action frame that is not protected by the PMF function. Therefore, the wireless terminal 4 that receives the fake frame refers to the channel change notification information (e.g., the channel change notification field) included in the fake frame and switches to the new channel specified by the fake frame (206).

[0078] When the wireless terminal 4 switches channels, it becomes impossible to transmit or receive data to or from the AP 3. This allows the AP 3 to send a query message to the wireless terminal 4 (207). An example of the query message is an SA Query, but the type of query message is not limited to this.

[0079] Even if AP3 transmits a query message, wireless terminal 4 does not transmit a response message to AP3's query message because it has already completed channel switching. If AP3 does not receive a response message to the query message from wireless terminal 4, AP3 disconnects the communication connection with wireless terminal 4 (208). This may disconnect the communication connection between AP3 and wireless terminal 4, which is a terminal to be blocked.

[0080] The control unit 12 can collect data packets transmitted to the AP 3 by the wireless terminal 4, which is a terminal to be blocked (209).

[0081] The control unit 12 can check whether the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has been released based on the collected data packets (210).

[0082] In one embodiment, the controller 12 may determine whether the wireless terminal 4 has transmitted a data packet including a QoS Null element to the AP 3. If it is determined that the wireless terminal 4 has not transmitted a data packet including a QoS Null element to the AP 3, the controller 12 may determine that the communication connection between the wireless terminal 4, which is a terminal to be blocked, and the AP 3 has been terminated. If it is determined that the wireless terminal 4 has transmitted a data packet including a QoS Null element to the AP 3, the controller 12 may determine that the communication connection between the wireless terminal 4, which is a terminal to be blocked, and the AP 3 has not been terminated.

[0083] If it is determined that the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has been disconnected, the control unit 12 may terminate the operation of disconnecting the communication connection between the wireless terminal 4 and the AP 3.

[0084] If it is determined that the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has not been released, the control unit 12 may further perform steps 204 to 210. When steps 204 to 210 are further performed, the type of fake frame transmitted to the wireless terminal 4 may change.

[0085] Fig. 4 is a flow chart illustrating a method for managing a wireless network according to an embodiment. Fig. 5 illustrates an exemplary fake frame transmitted to a terminal to be blocked according to an embodiment. Fig. 6 illustrates an exemplary data packet collected to determine whether a connection between a terminal to be blocked and an AP has been released according to an embodiment.

[0086] Referring to Figure 4, when a connection between AP3 and wireless terminal 4 is established, the control unit 12 of the wireless network management device 1 can collect data packets transmitted between AP3 and wireless terminal 4.

[0087] The control unit 12 can determine whether the wireless terminal 4 is a terminal to be blocked by using information included in the collected data packets (301). In one embodiment, the control unit 12 can transmit the collected data packets and / or information included in the collected data packets to the WIPS server 2, request the WIPS server 2 to determine whether the wireless terminal 4 is a terminal to be blocked, and receive the result of the determination from the WIPS server 2. In another embodiment, the control unit 12 can determine whether the wireless terminal 4 is a terminal to be blocked by itself based on the collected data packets and / or information included in the collected data packets.

[0088] When it is confirmed that the wireless terminal 4 is a terminal to be blocked, the control unit 12 can request the frame generation unit 11 to generate a first fake frame.

[0089] In one embodiment, the first fake frame may include a Channel Switch Announcement element and a Capabilities Information field to change the channel of the wireless terminal 4, which is the terminal to be blocked.

[0090] In one embodiment, the channel switch notification element included in the first fake frame may include identification information of a channel other than the channel to which the wireless terminal 4 is currently connected, thereby allowing the wireless terminal 4 to change the communication channel from the currently connected channel to another channel.

[0091] In one embodiment, the sending address of the first fake frame can be set to the address of the AP 3. In one embodiment, the receiving address of the first fake frame can be set to the address of the wireless terminal 4.

[0092] In one embodiment, the capability information field included in the first fake frame may include a Spectrum Management field, and a field value of the Spectrum Management field included in the first fake frame may be set to an activated state.

[0093] For example, as shown in Fig. 5, the first fake frame may include a Capabilities Information field. The Capabilities Information field may also include a Spectrum Management field 401. As shown in Fig. 5, the field value of the Spectrum Management field included in the first fake frame may be set to an activation state of 1.

[0094] When the first fake frame is generated, the control unit 12 can transmit the first fake frame to the wireless terminal 4, which is the terminal to be blocked, via the communication unit 10 (302).

[0095] In one embodiment, the control unit 12 may repeatedly transmit the first fake frame to the wireless terminal 4 for a predetermined first transmission time. The first transmission time may be set differently depending on the embodiment.

[0096] When a first fake frame including a Channel Switch Announcement element and a Capabilities Information field in which the field value of the Spectrum Management field is activated is transmitted to the wireless terminal 4, the wireless terminal 4 can change the communication channel by referring to information about the new channel included in the Channel Switch Announcement element, thereby disconnecting the communication connection between the wireless terminal 4 and the AP 3.

[0097] However, when a first fake frame including a Capabilities Information field in which the field value of the spectrum management field is in an activated state is transmitted to the wireless terminal 4, other wireless terminals other than the wireless terminal 4, which is a terminal to be blocked, may also refer to the first fake frame and change channels. Therefore, the control unit 12 may repeatedly transmit the first fake frame to the wireless terminal 4 only during a predetermined first transmission time. This may minimize the phenomenon of communication connection being disconnected between a wireless terminal other than a terminal to be blocked and the AP 3.

[0098] After the first fake frame is transmitted, the control unit 12 may collect data packets transmitted by the wireless terminal 4, which is the terminal to be blocked, to the AP 3. Based on the collected data packets, the control unit 12 may check whether the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has been released (303).

[0099] In one embodiment, the controller 12 may determine whether the wireless terminal 4 has transmitted a data packet including a QoS Null element to the AP 3. If the communication connection between the wireless terminal 4 and the AP 3 is maintained, or if the wireless terminal 4 reconnects to the AP 3 after the communication connection between the wireless terminal 4 and the AP 3 is temporarily disconnected by the first fake frame, the wireless terminal 4 may transmit the data packet including the QoS Null element multiple times (e.g., 10 times) as shown in Fig. 6. Therefore, the controller 12 may determine whether the communication connection between the wireless terminal 4 and the AP 3 is maintained by determining whether the wireless terminal 4 has transmitted a data packet including a QoS Null element to the AP 3.

[0100] When it is confirmed in step (303) that the wireless terminal 4 has not transmitted a data packet including a QoS Null element to the AP 3, the control unit 12 can determine that the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has been terminated.

[0101] If it is determined in step 303 that the communication connection between the wireless terminal 4 and the AP 3 has been released, the control unit 12 can request the frame generation unit 11 to generate a second fake frame.

[0102] In one embodiment, the second fake frame may include a Channel Switch Announcement element and a Capabilities Information field to change the channel of the wireless terminal 4, which is the terminal to be blocked.

[0103] In one embodiment, the channel switch notification element included in the second fake frame may include identification information of a channel other than the channel to which the wireless terminal 4 is currently connected, thereby allowing the wireless terminal 4 to change the communication channel from the currently connected channel to another channel.

[0104] In one embodiment, the sending address of the second fake frame can be set to the address of the AP 3. In one embodiment, the receiving address of the second fake frame can be set to the address of the wireless terminal 4.

[0105] In one embodiment, the capability information field included in the second fake frame may include a Spectrum Management field, and a field value of the Spectrum Management field included in the second fake frame may be set to a deactivated state.

[0106] For example, as shown in Fig. 5, the second fake frame may include a Capabilities Information field. The Capabilities Information field may also include a Spectrum Management field 401. However, unlike the example of Fig. 5, the field value of the Spectrum Management field included in the second fake frame may be set to a deactivated state (0).

[0107] When a second fake frame including a Channel Switch Announcement element and a Capabilities Information field in which the field value of the Spectrum Management field is in an inactive state is transmitted to the wireless terminal 4, the wireless terminal 4 can change the communication channel by referring to information about the new channel included in the Channel Switch Announcement element, thereby disconnecting the communication connection between the wireless terminal 4 and the AP 3.

[0108] When the second fake frame is generated, the control unit 12 can transmit the second fake frame to the wireless terminal 4, which is the terminal to be blocked, via the communication unit 10 (302).

[0109] In one embodiment, the control unit 12 may repeatedly transmit the second fake frame to the wireless terminal 4 for a predetermined second transmission time. The second transmission time may be set differently depending on the embodiment.

[0110] When a second fake frame including a Capabilities Information field in which the field value of the spectrum management field is in an inactive state is transmitted to wireless terminal 4, it is possible to block wireless terminal 4, which is a terminal to be blocked, from reconnecting to AP3 without affecting other wireless terminals other than wireless terminal 4, which is a terminal to be blocked.

[0111] After the second fake frame is transmitted, the control unit 12 may collect data packets transmitted by the wireless terminal 4, which is the terminal to be blocked, to the AP 3. The control unit 12 may determine whether the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has been released based on the collected data packets (305). In one embodiment, the control unit 12 may determine whether the wireless terminal 4 has transmitted a data packet including a QoS Null element to the AP 3.

[0112] When it is confirmed in step (305) that the wireless terminal 4 has transmitted a data packet including a QoS Null element to the AP 3, the control unit 12 can determine that the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has not been released.

[0113] If it is determined in step 305 that the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has not been released, the control unit 12 can further perform step 302.

[0114] When it is confirmed in step (305) that the wireless terminal 4 has not transmitted a data packet including a QoS Null element to the AP 3, the control unit 12 can determine that the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has been terminated.

[0115] If it is determined in step (305) that the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has been disconnected, the control unit 12 may terminate the operation of disconnecting the communication connection between the wireless terminal 4 and the AP 3.

[0116] On the other hand, if it is confirmed in step (303) that wireless terminal 4 has transmitted a data packet including a QoS Null element to AP3, the control unit 12 can determine that the communication connection between wireless terminal 4, which is a terminal to be blocked, and AP3 has not been released.

[0117] If it is determined in step (303) that the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has not been released, the control unit 12 can request the frame generation unit 11 to generate a third fake frame.

[0118] In one embodiment, the third fake frame may include an Extended Channel Switch Announcement element to change the channel of the wireless terminal 4, which is the terminal to be blocked.

[0119] In one embodiment, the third fake frame may further include a disassociation packet.

[0120] As a result of experiments, it was confirmed that wireless terminals 4 to which communication standards such as 802.11a, 802.11b, 802.11g, and 802.11n are applied change channels upon receiving a Channel Switch Announcement element. However, it was confirmed that wireless terminals 4 to which communication standards such as 802.11ac and 802.11ax are applied change channels only upon receiving an Extended Channel Switch Announcement element, not a Channel Switch Announcement element. Therefore, if the communication connection between the wireless terminal 4, which is a terminal to be blocked, and the AP 3 is not released by the first fake frame, an attempt can be made to release the communication connection between the wireless terminal 4 and the AP 3 by transmitting a third fake frame including an Extended Channel Switch Announcement element to the wireless terminal 4.

[0121] In one embodiment, the extended channel switch notification element included in the third fake frame may include identification information of a channel other than the channel to which the wireless terminal 4 is currently connected, thereby allowing the wireless terminal 4 to change the communication channel from the currently connected channel to another channel.

[0122] In one embodiment, the sending address of the third fake frame may be set to the address of AP 3. In one embodiment, the receiving address of the third fake frame may be set to the address of wireless terminal 4.

[0123] When the third fake frame is generated, the control unit 12 can transmit the third fake frame to the wireless terminal 4, which is the terminal to be blocked, via the communication unit 10 (306).

[0124] In one embodiment, the control unit 12 may repeatedly transmit the third fake frame to the wireless terminal 4 for a predetermined third transmission time. The third transmission time may be set differently depending on the embodiment.

[0125] After the third fake frame is transmitted, the control unit 12 may collect data packets transmitted by the wireless terminal 4, which is the terminal to be blocked, to the AP 3. The control unit 12 may determine whether the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has been released based on the collected data packets (307). In one embodiment, the control unit 12 may determine whether the wireless terminal 4 has transmitted a data packet including a QoS Null element to the AP 3.

[0126] When it is confirmed in step (307) that wireless terminal 4 has transmitted a data packet including a QoS Null element to AP3, control unit 12 can determine that the communication connection between wireless terminal 4, which is a terminal to be blocked, and AP3 has not been released.

[0127] If it is determined in step 307 that the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has not been released, the control unit 12 may classify the wireless terminal 4, which is the terminal to be blocked, as an unblocked terminal (308). The control unit 12 may store log information including at least one of information about the wireless terminal 4 and information about the blocking process of the wireless terminal 4 in a storage unit (not shown). The stored log information may be checked by an administrator, who may refer to the log information and take additional measures to release the communication connection between the unblocked terminal and the AP 3.

[0128] If it is confirmed in step (307) that the wireless terminal 4 has not transmitted a data packet including a QoS Null element to the AP 3, the control unit 12 can determine that the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has been terminated.

[0129] If it is determined in step (307) that the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has been terminated, the control unit 12 may terminate the operation of disconnecting the communication connection between the wireless terminal 4 and the AP 3.

[0130] In another embodiment, if it is determined in step (307) that the communication connection between the wireless terminal 4, which is the terminal to be blocked, and the AP 3 has been released, the control unit 12 may transmit the third fake frame to the terminal to be blocked for a predetermined fourth transmission time. In one embodiment, the control unit 12 may repeatedly transmit the third fake frame to the wireless terminal 4 for a predetermined fourth transmission time. The fourth transmission time may be set differently depending on the embodiment. This may prevent the wireless terminal 4 from reconnecting to the AP 3 after the communication connection between the wireless terminal 4 and the AP 3 has been released.

[0131] As described above, the present specification has been described with reference to exemplary drawings, but the present specification is not limited to the embodiments and drawings disclosed in the present specification, and various modifications may be made by those skilled in the art. Note that even if the effects of the configurations of the present specification are not explicitly described in the above-described embodiments of the present specification, the effects that can be predicted by the configurations should also be recognized.

Claims

1. Recognizing a terminal to be blocked that is connected to an access point (AP); transmitting a first fake frame to the terminal to be blocked for a predetermined first transmission time; After transmitting the first fake frame, checking whether there is a connection between the terminal to be blocked and the AP; and transmitting a second fake frame to the blocking target terminal for a second predetermined transmission time when it is confirmed that the connection between the blocking target terminal and the AP has been released after transmitting the first fake frame; Including, How to manage your wireless network.

2. The first fake frame includes: The channel switch announcement element and capabilities information field are included to change the channel of the terminal to be blocked, The capability information field includes a spectrum management field; the field value of the spectrum management field is set to an activated state; The method of claim 1 .

3. The second fake frame includes: A channel switch notification element and a capability information field are included to change the channel of the blocked terminal, the capability information field includes a spectrum management field; the field value of the spectrum management field is set to a deactivated state; The method of claim 1 .

4. The step of checking whether or not there is a connection between the target terminal and the AP after transmitting the first fake frame includes: If it is determined that the terminal to be blocked transmits a QoS null packet to the AP after transmitting the first fake frame, determining that the connection between the terminal to be blocked and the AP is not released; and confirming that the connection between the barrier target terminal and the AP is released when it is confirmed that the barrier target terminal does not transmit a QoS null packet to the AP after transmitting the first fake frame; Including, The method of claim 1 .

5. If it is determined that the connection between the blocking target terminal and the AP has not been released after transmitting the first fake frame, transmitting a third fake frame to the blocking target terminal for a predetermined third transmission time. The method of claim 1 .

6. If it is determined that the connection between the blocking target terminal and the AP has been released after transmitting the third fake frame, the method further includes transmitting the third fake frame to the blocking target terminal for a predetermined fourth transmission time. The method for managing a wireless network according to claim 5.

7. If it is confirmed that the connection between the blocked terminal and the AP is not released after the third fake frame is transmitted, the blocked terminal is classified as an unblocked terminal and log data is stored. The method for managing a wireless network according to claim 5.

8. If it is determined that the terminal to be blocked transmits a QoS null packet to the AP after transmitting the third fake frame, determining that the connection between the terminal to be blocked and the AP is not released; and confirming that the connection between the terminal to be blocked and the AP has been released when it is determined that the terminal to be blocked does not transmit a QoS null packet to the AP after transmitting the third fake frame; Including, The method for managing a wireless network according to claim 5.

9. The third fake frame is An extended channel switch announcement element is included to change the channel of the terminal to be blocked. The method for managing a wireless network according to claim 5.

10. a control unit that recognizes a terminal to be blocked that is connected to the AP; a frame generator that generates a first fake frame and a second fake frame; and a communication unit for transmitting or receiving data; The control unit The communication unit controls the communication to transmit a first fake frame to the blocking target terminal for a predetermined first transmission time, and after transmitting the first fake frame, checks whether a connection exists between the blocking target terminal and the AP, and if it is confirmed that the connection between the blocking target terminal and the AP has been released after transmitting the first fake frame, controls the communication unit to transmit a second fake frame to the blocking target terminal for a predetermined second transmission time; A wireless network management device.

11. The first fake frame includes: A channel switch notification element and a capability information field are included to change the channel of the blocked terminal, the capability information field includes a spectrum management field; the field value of the spectrum management field is set to an activated state; The wireless network management device according to claim 10.

12. The second fake frame includes: A channel switch notification element and a capability information field are included to change the channel of the blocked terminal, the capability information field includes a spectrum management field; the field value of the spectrum management field is set to a deactivated state; The wireless network management device according to claim 10.

13. The control unit If it is determined that the terminal to be blocked transmits a QoS null packet to the AP after transmitting the first fake frame, it is determined that the connection between the terminal to be blocked and the AP is not released; If it is determined that the terminal to be blocked does not transmit a QoS null packet to the AP after transmitting the first fake frame, it is determined that the connection between the terminal to be blocked and the AP has been released. The wireless network management device according to claim 10.

14. the frame generation unit generates a third fake frame; The control unit If it is confirmed that the connection between the blocking target terminal and the AP has not been released after transmitting the first fake frame, the communication unit controls the communication unit to transmit the third fake frame to the blocking target terminal for a predetermined third transmission time. The wireless network management device according to claim 10.

15. The control unit If it is confirmed that the connection between the blocking target terminal and the AP has been released after transmitting the third fake frame, the communication unit controls the third fake frame to be transmitted to the blocking target terminal for a predetermined fourth transmission time.

15. The wireless network management device according to claim 14.

16. The control unit If it is confirmed that the connection between the blocked terminal and the AP is not released after the third fake frame is transmitted, the blocked terminal is classified as an unblocked terminal and log data is stored.

15. The wireless network management device according to claim 14.

17. The control unit If it is determined that the terminal to be blocked transmits a QoS null packet to the AP after transmitting the third fake frame, it is determined that the connection between the terminal to be blocked and the AP is not released; If it is determined that the terminal to be blocked does not transmit a QoS null packet to the AP after transmitting the third fake frame, it is determined that the connection between the terminal to be blocked and the AP has been released.

15. The wireless network management device according to claim 14.

18. The third fake frame is An extended channel switch notification element is included to change the channel of the terminal to be blocked.

15. The wireless network management device according to claim 14.

Citation Information

Patent Citations

  • WIPS sensor and method for blocking intrusion of unauthorized wireless terminal using WIPS sensor

    JP2023000990A

  • Wireless network security system

    US20140157364A1

  • Method for terminating a wireless communication of a mobile communication unit

    US5826186A