Sensing device, wireless intrusion prevention system including the sensing device, and method of operation thereof

The sensing device employs a block template to generate targeted wireless communication messages for blocking unauthorized connections, addressing inefficiencies in existing systems by reducing analysis time and ensuring selective blocking across different frequency bands.

JP7742929B2Active Publication Date: 2025-09-22SECUI COM CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024508612
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-08-10
Filing Date
2022-04-13
Publication Date
2025-09-22
Estimated Expiration
2042-04-13

AI Technical Summary

Technical Problem

Existing wireless intrusion prevention systems face challenges in efficiently blocking harmful wireless network connections, particularly in complex network environments, due to the need for separate analysis and different blocking methods based on IEEE 802.11w compliance and frequency bands, leading to increased analysis time and potential disruption of normal connections.

Method used

A sensing device that uses a predefined block template to generate wireless communication messages for blocking connections, analyzing messages for inclusion in a blocking list, and transmitting targeted block messages with a channel change request command, regardless of IEEE 802.11w compliance and frequency band, thereby reducing analysis time and ensuring selective blocking.

Benefits of technology

This approach reduces unnecessary analysis time, minimizes the size of block messages, and allows for selective blocking of unauthorized connections without affecting normal terminals, improving overall blocking performance and efficiency across various frequency bands.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007742929000001
    Figure 0007742929000001
  • Figure 0007742929000002
    Figure 0007742929000002
  • Figure 0007742929000003
    Figure 0007742929000003
Patent Text Reader

Abstract

The present technology relates to an electronic device, and a sensing device for monitoring a connection between an access point and a terminal according to the present technology includes a template memory unit that stores a block template used to generate a wireless communication message for blocking the connection between the terminal and the access point, and a sensing control unit that acquires a message transmitted and received between the terminal and the access point, and when an analysis based on the message indicates that the terminal is included in a list of terminals to be blocked provided by a server, transmits a block message to the terminal, in which the address of the access point, the address of the terminal, and a channel change request command requesting a change of the channel on which the terminal and the access point communicate, are inserted into the block template, the address of the access point, the address of the terminal, and the channel change request command requesting a change of the channel on which the terminal and the access point communicate, the block template including an authentication method and an encryption method used for the connection between the terminal and the access point, and the block message includes information about the sensing device transmitting the block message and information about a reason for blocking.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to electronic devices, and more particularly to a sensing device, a wireless intrusion prevention system including the sensing device, and a method of operation thereof. [Background technology]

[0002] With the rapid development and spread of the Internet, the network environment has become increasingly large and complex due to the ease and convenience of network connections and the wide range of services it provides. However, due to various forms of network attacks, such as viruses, hacking, system intrusions, system administrator privilege acquisition, intrusion concealment, and denial of service attacks, the Internet is constantly at risk of hacking, and Internet infringements are increasing. The scale of damage to public institutions, social infrastructure facilities, and financial institutions is increasing and the impact is significant. To solve these Internet security issues, the need for network security technologies such as antivirus software, firewalls, integrated security management, and intrusion detection systems is becoming apparent.

[0003] A wireless network system for wireless Internet communication includes a wireless LAN access point (AP) and a wireless LAN terminal.

[0004] Recently, integrated network systems that use both wired and wireless networks have been widely developed and applied. While it is difficult to consistently block harmful traffic accessed via wired networks, it is even more difficult to consistently block harmful traffic accessed via wireless networks. To solve this problem, Wireless Intrusion Prevention Systems (WIPS) are being developed. WIPS is a system that detects and blocks wireless intrusions such as rogue APs / devices, unauthorized APs / devices, and DoS (Denial of Service) attacks by monitoring wireless sections. Summary of the Invention [Problem to be solved by the invention]

[0005] An embodiment of the present invention provides a sensing device that blocks a connection of a terminal, a wireless intrusion prevention system including the sensing device, and an operation method thereof. [Means for solving the problem]

[0006] A sensing device for monitoring a connection between an access point and a terminal according to an embodiment of the present invention includes: a template storage unit for storing a block template used to generate a wireless communication message for blocking the connection between the terminal and the access point; and a sensing control unit for acquiring a message transmitted and received between the terminal and the access point, and analyzing the message to transmit, to the terminal, a block message in which the address of the access point, the address of the terminal, and a channel change request command for requesting a change of a channel for communication between the terminal and the access point are inserted into the block template when the terminal is found to be included in a list of terminals to be blocked provided by a server. Including nothing.

[0007] According to an embodiment of the present invention, a method for operating a sensing device for monitoring a connection between an access point and a terminal includes the steps of: storing a block template used to generate a wireless communication message for blocking a connection between the terminal and the access point; acquiring a message to be transmitted by the terminal to the access point, and determining, based on the message, whether the terminal is included in a blocking target list provided by a server; and transmitting, to the terminal, a block message in which an address of the access point and a channel change request command for requesting a change of a channel for communication between the terminal and the access point are inserted into the block template. Including nothing.

[0008] A sensing device for monitoring connections between an access point and a plurality of terminals according to an embodiment of the present invention includes: a template storage unit for storing a block template used to generate a wireless communication message for blocking connections between the plurality of terminals and the access point; and a sensing control unit for acquiring messages transmitted and received between the plurality of terminals and the access point, and analyzing the messages to transmit to the plurality of terminals, if the access point is included in a blocking target list provided by a server, a block message in which the address of the access point, the addresses of each of the plurality of terminals, and a channel change request command for requesting a change of a channel for communication between the terminals and the access point are inserted into the block template. Including nothing. [Effects of the Invention]

[0009] The sensing device for blocking the connection of a terminal provided by the present technology, the wireless intrusion prevention system including the sensing device, and the operation method thereof, firstly, eliminate the need to analyze whether the network is IEEE 802.11w-compliant, separately manage a session list based on the analysis, or apply a separate blocking method according to the session list in order to generate a block message, thereby reducing unnecessary analysis time and shortening the time required to generate a block message.

[0010] Second, in the block message generation process, the present invention applies a block template in which only the minimum information required for generating a block message is predefined, thereby reducing the time required to duplicate unnecessary AP messages, reducing the size of the generated block message compared to a duplicated AP message, and since the inserted channel change request uses the same information regardless of the frequency band, the time required to determine the frequency band can be reduced, resulting in improved blocking performance.

[0011] Third, since the present invention transmits a block message only to the terminals to be blocked, it is possible to block only the terminals that send the block message without affecting normal terminals connected to the AP. Furthermore, if there are multiple terminals to be blocked, it is possible to obtain the effect of blocking all terminals that are attempting to connect to the AP by individually transmitting a block message to each terminal to be blocked.

[0013] No. four In addition, the present invention is based on wireless standards and can achieve the same blocking effect through blocking messages in the new 6GHz band in addition to the conventionally used frequency bands (2.4GHz, 5GHz). [Brief explanation of the drawings]

[0014] [Figure 1] 10 is a diagram illustrating a general operation of a WIPS for blocking a connection between an AP and a terminal. [Figure 2]1 is a flowchart illustrating a session determination and classification procedure of a conventional sensing device in a general wireless network and a wireless network to which a predetermined security technology is applied. [Figure 3] 1 is a flowchart illustrating a conventional procedure for shutting down a sensing device in a general wireless network and a wireless network to which a predetermined security technology is applied. [Figure 4] FIG. 1 is a diagram for explaining a WIPS according to an embodiment of the present invention. [Figure 5] FIG. 2 is a diagram illustrating the operation of a WIPS according to an embodiment of the present invention. [Figure 6] 10 is a diagram illustrating an operation of a sensing device cutting off a connection between a terminal and an AP according to an embodiment of the present invention. [Figure 7] 1 is a flowchart illustrating an improved shutdown procedure for a sensing device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0015] Specific structural and functional descriptions of embodiments in accordance with the inventive concepts disclosed in this specification or application are provided solely for purposes of illustrating embodiments in accordance with the inventive concepts, which may be embodied in various forms and should not be construed as being limited to the embodiments described in this specification or application.

[0016] The Wireless Intrusion Prevention System (WIPS) described below is a system that detects and blocks wireless intrusions such as rogue APs (Access Points) / terminals, unauthorized APs (Access Points) / terminals, or DoS (Denial of Service) attacks by monitoring wireless sections.

[0017] In this specification, a general wireless network may refer to a wireless network to which IEEE 802.11 technology is applied, and a wireless network to which a specific security technology is applied may refer to a wireless network to which IEEE 802.11w technology is applied. IEEE 802.11w is an IEEE 802.11 modified technology that improves the security of management frames. However, the present invention is not limited thereto, and embodiments of the present invention can be applied to general wireless networks to which various security technologies are applied and wireless networks to which a specific security technology is applied.

[0018] An access point (hereinafter, referred to as AP) is an entity that provides a connection to a distribution system via a wireless medium for terminals associated therewith. The term AP is used as a concept that includes a personal BSS coordination point (PCP) and, in a broad sense, may include concepts such as a centralized controller, a base station (BS), a Node-B, a base transceiver system (BTS), or a site controller. In the present invention, an AP may also be referred to as a base wireless communication terminal, and the base wireless communication terminal may be used as a term that, in a broad sense, includes an AP, a base station, an eNodeB (eNB), and a transmission point (TP). Furthermore, the base wireless communication terminal may include various types of wireless communication terminals that allocate communication medium resources and perform scheduling in communication with multiple wireless communication terminals.

[0019] A terminal (station) is any device that includes a medium access control (MAC) and a physical layer interface for a wireless medium according to the IEEE 802.11 standard. In a broad sense, the term may include not only non-AP stations but also access points (APs). In this specification, the term 'terminal' refers to a non-AP station, but may also refer to both non-AP stations and APs depending on the embodiment. A station for wireless communication includes a processor and a transmit / receive unit, and may further include a user interface and a display unit depending on the embodiment. The processor generates messages to be transmitted over the wireless network, processes messages received over the wireless network, and performs various other processes for controlling the station. The transceiver unit is functionally connected to the processor and transmits and receives messages over the wireless network for the station. The terminal can transmit and receive messages with the AP over the wireless network.

[0020] The sensing device, wireless intrusion prevention system including the sensing device, and its operating method according to an embodiment of the present invention can provide a technology for blocking connection between an AP and a terminal, regardless of which frequency band (2.4 GHz / 5 GHz / 6 GHz) is used in the connection process between the AP and the terminal, whether the wireless network applies IEEE 802.11w (PMF, Protected Management Frame), which authentication method and encryption method are applied, or whether it is before or after network connection.

[0021] FIG. 1 is a diagram illustrating a general operation of a WIPS to block a connection between an AP and a terminal.

[0022] Referring to FIG. 1, the WIPS 10 may include a sensing device 100 and a server 200 .

[0023] The sensing device 100 may monitor a connection between the AP 20 and the terminal 30. In an embodiment, the sensing device 100 may receive a wireless frame. For example, the sensing device 100 may acquire a message transmitted and received by the terminal 30 and the AP 20 in an attempt to establish a connection. Based on the message acquired from the terminal 30 and the AP 20, the sensing device 100 may determine whether the terminal 30 or the AP 20 is included in the blocking target list provided by the server 200. Then, the sensing device 100 may transmit a blocking message onto the wireless network to block the connection between the terminal 30 and the AP 20.

[0024] FIG. 2 is a flowchart illustrating a session determination and classification procedure of a conventional sensing device in a general wireless network and a wireless network to which a predetermined security technology is applied.

[0025] 2, in step S201, the conventional sensing device can receive a wireless frame, for example, a message transmitted between a terminal and an AP.

[0026] In step S203, the conventional sensing device can acquire a message transmitted and received between the terminal and the AP and determine whether the terminal is a new terminal. If the conventional sensing device determines that the terminal is a new terminal as a result of analyzing the message transmitted and received between the terminal and the AP, it can execute step S205. Alternatively, if the conventional sensing device determines that the terminal is not a new terminal as a result of analyzing the message transmitted and received between the terminal and the AP, it can execute step S201 again.

[0027] In step S205, the conventional sensing device can analyze messages transmitted and received between the new terminal and the AP to determine whether the connection is based on 802.11w technology.

[0028] In step S207, if the message transmitted and received between the new terminal and the AP is a connection to which 802.11w technology is applied, the conventional sensing device classifies the connection as a wireless network to which a predetermined security technology is applied and adds it to the session list in step S209. Alternatively, if the message transmitted and received between the new terminal and the AP is not a connection to which 802.11w technology is applied, the conventional sensing device analyzes the message transmitted and received between the new terminal and the AP and classifies the connection as a general wireless network connection and adds it to the session list separately in step S209.

[0029] In step S209, the conventional sensing device analyzes messages transmitted and received between the terminal and the AP, classifies the session information according to whether it is an 802.11w connection, and adds the information to a session list.

[0030] As described above with reference to FIG. 2, the conventional sensing device performs a procedure of separately classifying a session list depending on whether a message transmitted and received between a terminal and an AP is an IEEE 802.11w connection.

[0031] FIG. 3 is a flowchart illustrating a conventional procedure for shutting down a sensing device in a general wireless network and a wireless network to which a predetermined security technology is applied.

[0032] 3, in steps S301 and S303, a conventional sensing device can analyze messages exchanged between a terminal and an AP to determine whether the terminal or the AP is a blocking target. If the conventional sensing device determines that the terminal or the AP is a blocking target as a result of analyzing the messages exchanged between the terminal and the AP, it can proceed to step S305. Alternatively, if the terminal or the AP is not a blocking target, it can perform step S301 again.

[0033] In step S305, the conventional sensing device can analyze messages exchanged between the terminal and the AP to determine whether the connection is an 802.11w connection. If the messages exchanged between the terminal and the AP are an 802.11w connection, the conventional sensing device can determine that the connection is a wireless network to which a predetermined security technology is applied, and proceed to step S307. On the other hand, if the messages exchanged between the terminal and the AP are not an 802.11w connection, the conventional sensing device can determine that the connection is a general wireless network, and proceed to step S315.

[0034] In step S307, if the message transmitted and received between the terminal and the AP is an 802.11w connection, the conventional sensing device can replicate the wireless communication message transmitted by the AP.

[0035] In step S315, the conventional sensing device may send a fake unauthenticated message if the message exchanged between the terminal and the AP is not an 802.11w connection.

[0036] In step S309, the conventional sensing device may determine whether the frequency band of the message transmitted and received between the terminal and the AP is 2.4 GHz. If the frequency band of the message transmitted and received between the terminal and the AP is 2.4 GHz, step S311 may be performed. Alternatively, if the frequency band of the message transmitted and received between the terminal and the AP is 5 GHz instead of 2.4 GHz, step S317 may be performed.

[0037] In step S311, if the frequency band of the wireless communication message of the duplicated AP is 2.4 GHz, the conventional sensing device can generate a fake message by inserting a channel change request command CSA into the wireless communication message of the duplicated AP.

[0038] The channel change request command may be a command requesting a change of the channel on which the terminal and the AP connect or communicate.

[0039] In step S317, if the frequency band of the duplicated AP wireless communication message is 5 GHz instead of 2.4 GHz, the conventional sensing device can generate a fake message by additionally inserting an extended channel change request command (extended CSA) into the duplicated AP wireless communication message.

[0040] In step S313, the conventional sensing device can transmit the generated fake message.

[0041] As described above with reference to Fig. 3, in order to block a connection between a terminal and an AP, the conventional sensing device generates a fake unauthorized message or a fake message in which a channel change request command CSA is inserted into a duplicated wireless communication message of the AP depending on whether the message transmitted between the terminal and the AP is an 802.11w connection, and transmits the fake message over a wireless network. In addition, the conventional sensing device inserts a different channel change request command for each band into the fake message depending on whether the frequency band of the wireless communication message of the duplicated AP is 2.4 GHz or 5 GHz.

[0042] In other words, conventional sensing devices required separate procedures for determining whether the message sent by the terminal is an 802.11w connection, determining whether the frequency band of the duplicated AP's wireless communication message is 2.4 GHz, and generating different channel change request commands for each frequency band.

[0043] FIG. 4 is a diagram illustrating a WIPS according to an embodiment of the present invention.

[0044] 4, the WIPS 10 may include a sensing device 100 and a server 200. In an embodiment, the sensing device 100 monitors messages transmitted and received between a terminal and an AP, and processes information such as the MAC address of the terminal or AP that transmitted the monitored message, security settings, frame appearance frequency, transmission rate, data volume, SSID, IEEE 802.11 a / b / g / n / ac / ax, channel, and RSSI based on the monitored message. The sensing device 100 may then transmit the processed information to the server 200.

[0045] The server 200 can compare the processed information with signature information stored in a database to determine whether the terminal or AP is unauthorized or is operating abnormally. In this case, the signature information can include information such as message header information or message occurrence frequency.

[0046] The server 200 can determine whether the detected AP is unauthorized. If the AP is not pre-classified as an authorized AP based on other information stored in the DB, such as the BSSID and MAC address, the server 200 can determine that the AP is an unauthorized AP. Unauthorized terminals can also be determined in a similar manner.

[0047] If the server 200 determines that the AP is an unauthorized AP, the server 200 may automatically block the AP according to a blocking policy or may generate an alarm and allow an administrator to manually block the AP. Depending on the blocking decision, the server 200 may transmit a list of APs to be blocked or blocking policy information to the sensor device 100.

[0048] The sensor device 100 selects APs and terminals to be blocked based on the blocking target list and the blocking policy, and can implement blocking.

[0049] In an embodiment, the blocking of the sensing device 100 based on the blocking target list and the blocking policy may include blocking a connection between a specific AP and a specific terminal. The sensing device 100 may block a connection when an authorized terminal connects to an unauthorized AP or when an unauthorized terminal connects to an authorized AP. For example, when the BSSID of the unauthorized AP is detected, the sensing device 100 may block the authorized terminal from connecting to the unauthorized AP. As another example, when the MAC address of the unauthorized terminal is detected, the sensing device 100 may block the unauthorized terminal from connecting to the authorized AP.

[0050] In an embodiment, the sensing device 100 may include a template storage unit 110 and a sensing control unit 120 .

[0051] The template storage unit 110 can store block templates used to generate wireless communication messages for disconnecting a connection between a terminal and an access point.

[0052] For example, the block template may be a template used to generate a wireless communication message for blocking a connection between a terminal and an AP, even if the authentication method, encryption method, frequency band, etc. included in the communication method between the terminal and the AP differ from terminal to terminal or from AP to AP. The block template may include an authentication method and an encryption method to be used for connection between the terminal and the access point, and the block message may include information about the sensing device sending the block message and information about the reason for blocking. As another example, the block template may be a template used to generate a wireless communication message to block a connection between a terminal and an AP, regardless of whether it is a general wireless network or a wireless network to which a specific security technology is applied.

[0053] For example, the block template may include Support rate, DSP, TIM, RSN, and the like.

[0054] In a wireless network where a certain security technology is applied, a conventional sensing device copies wireless communication messages sent by APs to be blocked and sends a channel change request command (CSA) or an extended channel change request command ( Expansion However, in an embodiment of the present invention, only the items necessary for generating a wireless communication message for blocking are stored in advance in the template storage unit 110 so that the terminal can determine that the wireless communication message is sent by the AP. This reduces the time required to generate the wireless communication message and the size of the wireless communication message compared to a method of duplicating the wireless communication message.

[0055] The sensing control unit 120 monitors the connection between the AP and the terminal, and generates a block message based on the message that the terminal transmits and receives to the AP. (fake beacon) can be generated and sent to the terminal.

[0056] In an embodiment, the sensing control unit 120 may include a block message generating unit 121 and a communication module 122 .

[0057] The block message generation unit 121 can analyze messages transmitted and received between a terminal and an AP, which are acquired by the communication module 122. The block message generation unit 121 can add / update information about the terminal that sends the message. The block message generation unit 121 can determine whether the terminal that sends the message corresponds to a blocked terminal list provided by the server 200. If the terminal that sends the message corresponds to the blocked terminal list, the block message generation unit 121 can generate a block message.

[0058] The block message generation unit 121 receives a block template from the template storage unit 110 and generates a block message. (fake beacon)In an embodiment, if the AP to which the terminal is to connect is an unauthorized AP, the block message generator 121 may generate a block message using a block template. For example, the block message generator 121 may generate a block message by setting the sending address in the block template to the BSSID of the unauthorized AP and the receiving address to the MAC of the terminal to connect to the unauthorized AP, and inserting a channel change request command and other necessary information. The channel change request command may be a command requesting a change of the channel on which the terminal and the AP are connected or communicate. In an embodiment, the channel change request command may include a channel value to be changed by the terminal. 。

[0059] In another embodiment, when the AP that multiple terminals are attempting to connect to is an unauthorized AP, the block message generator 121 may generate a block message by setting the address to be sent to the block template to the BSSID of the unauthorized AP and the address to be received to each of the MAC addresses of the multiple terminals attempting to connect to the unauthorized AP, and inserting a channel change request command and other necessary information. Thereafter, the block message generator 121 may individually transmit the generated block message to the multiple terminals attempting to connect to the unauthorized AP via the communication module 122.

[0060] In an embodiment, the block message generator 121 may block connection between the authorized terminal and the unauthorized AP by transmitting the generated block message to the authorized terminal via the communication module 122. Specifically, the authorized terminal may attempt to connect to the unauthorized AP through a channel to be changed according to the channel change request command inserted in the block message. In an embodiment, the channel value to be changed included in the channel change request command is a channel value different from the channel value actually used by the unauthorized AP to which the terminal is attempting to connect. For example, the channel value to be changed may be a randomly generated channel value. In other words, since the channel value to be changed inserted in the block message is not the channel value used in a message transmitted by the unauthorized AP to which the authorized terminal is attempting to connect, the authorized terminal may be blocked from connecting to the unauthorized AP.

[0061] In an embodiment, the same channel change request command may be generated and inserted into the block message regardless of the frequency bands used by the terminal and the AP for transmission and reception. Specifically, the channel value to be changed included in the channel change request command may be determined randomly, so the same channel change request command may be generated for the 2.4 GHz, 5 GHz, and 6 GHz frequency bands. This eliminates the need for time to determine the frequency band of the wireless communication message to be transmitted by the AP, and reduces the time required to generate the channel change request command, thereby reducing the time required to disconnect the connection between the terminal and the AP.

[0062] In another embodiment, even when an unauthorized terminal attempts to connect to an authorized AP, the block message generation unit 121 can block the connection between the unauthorized terminal and the authorized AP by generating a block message based on a block template in the same manner as described above and sending it to the unauthorized terminal.

[0063] In the embodiment, the block message generator 121 may transmit a block message to the terminal via the communication module 122 to block the connection between the terminal and the AP and generate a block event. The block message generator 121 may deliver the generated block event to the server 200.

[0064] The communication module 122 can acquire messages transmitted and received between the AP and the terminal. In an embodiment, the communication module 122 can provide the block message generator 121 with messages acquired during communication between the AP and the terminal.

[0065] The communication module 122 analyzes the message acquired during the communication process between the AP and the terminal, and if it corresponds to the blocked target list provided by the server 200, it can receive the block message generated by the block message generation unit 121 and send it to the terminal.

[0066] The present invention can individually block terminals to be blocked by setting the address receiving the block message to the terminal's MAC. Specifically, in both cases where an authorized terminal attempts to connect to an unauthorized AP or an unauthorized terminal attempts to connect to an authorized AP, blocking can be performed individually by sending a block message only to the terminal to be blocked. This can have no effect on the connection of normal terminals attempting to connect to the unauthorized AP or authorized AP.

[0067] Conventional sensing devices distinguish between a general wireless network environment in which an AP and a terminal are connected and a wireless network that applies a specific security technology. In a general wireless network environment, the conventional sensing device blocks the connection between the AP and the terminal using a fake unauthorized message. In a wireless network environment that applies a specific security technology, the conventional sensing device creates a fake message by duplicating the AP's wireless message to be blocked and then uses the created fake page to block the connection between the AP and the terminal. In particular, the fake message used in a wireless network environment that applies a specific security technology duplicates the AP's wireless communication message (commonly referred to as a beacon) and modifies only the channel change request. Because the basic destination address in the duplicated AP's wireless communication message is a broadcast value, the fake message is transmitted to all terminals attempting to connect to the duplicated AP, blocking the connections of all terminals (commonly referred to as 'AP blocking').

[0068] For example, when the BSSID of an unauthorized AP is detected, AP blocking, which blocks all terminals connected to the AP, may also block the connection of normal terminals connected to the unauthorized AP. That is, if the unauthorized AP is an AP used for public services, AP blocking of authorized terminals to the unauthorized AP may also prevent the connection of terminals normally connected to the unauthorized AP. Furthermore, if AP blocking is performed when an unauthorized terminal attempts to connect to an authorized AP, a problem may arise in which all authorized terminals normally connected to the authorized AP are also blocked.

[0069] Therefore, the present invention can improve the problems caused by AP blocking by sending a block message only to the terminal that is to be blocked, and can achieve the same effect as AP blocking by individually transmitting a block message to multiple terminals that are attempting to connect to an unauthorized AP.

[0070] FIG. 5 is a diagram illustrating the operation of the WIPS according to an embodiment of the present invention.

[0071] Referring to FIG. 5, the WIPS 10 may include a sensing device 100 and a server 200 .

[0072] In an embodiment, the sensing device 100 may include a template storage unit 110 , a block message generator 121 and a communication module 122 .

[0073] In step S501, the communication module 122 may receive a wireless frame, for example, the communication module 122 may obtain a message transmitted and received between the terminal and the AP.

[0074] In step S503, the communication module 122 can call the block message generator 121 to analyze messages acquired during the communication process between the AP and the terminal.

[0075] In step S505, the template storage unit 110 may provide a block template to the block message generation unit 121. In an embodiment, the template storage unit 110 may provide the block template to the block message generation unit 121, the block template being used to generate a wireless communication message for disconnecting a connection between a terminal and an AP.

[0076] In step S507, the server 200 may provide the blocking target list to the block message generating unit 121. In an embodiment, the blocking target list may include lists for unauthorized APs, unauthorized terminals, authorized APs, and authorized terminals.

[0077] In step S509, the block message generating unit 121 analyzes the message acquired by the communication module 122 during the communication between the AP and the terminal, and can add or update information about the terminal that transmits the message.

[0078] In step S511, the block message generation unit 121 analyzes the information contained in the message acquired during the communication process between the AP and the terminal, and can determine whether the AP or terminal is a blocked AP or terminal by comparing it with the blocked AP or terminal list provided by the server 200.

[0079] In step S513, the block message generating unit 121 determines whether the message of the terminal is blocked. Target List If the terminal is included in the list, a block message can be generated by inserting the BSSID of the AP to which the terminal is trying to connect, the terminal's MAC, and a channel change request command into the block template. 。

[0080] In step S515, the block message generator 121 can provide the generated block message to the communication module 122.

[0081] In step S517, the communication module 122 can send a block message to the terminal.

[0082] In step S519, the block message generator 121 may block the connection between the terminal and the AP and transmit the block event information to the server 200.

[0083] FIG. 6 is a diagram illustrating an operation of a sensing device cutting off a connection between a terminal and an AP according to an embodiment of the present invention.

[0084] 6, step S601 may be a process of connecting the terminal 30 and the AP 20. In one embodiment, the AP 20 may be an unauthorized AP, and the terminal 30 may be an authorized terminal. In another embodiment, the AP 20 may be an authorized AP, and the terminal 30 may be an unauthorized terminal.

[0085] In step S603, the sensing device 100 may receive a wireless frame. For example, the sensing device 100 may acquire a message transmitted and received between the terminal 30 and the AP 20 during a connection process between the terminal 30 and the AP 20. The sensing device 100 may analyze information included in the message acquired during communication between the terminal 30 and the AP 20 and determine whether the message corresponds to a blocked target list provided by the server 200.

[0086] In step S605, the sensing device 100 analyzes the information contained in the message acquired during the communication process between the terminal 30 and the AP 20, and if the AP or the terminal corresponds to the blocking target list provided by the server 200, the sensing device 100 can generate a block message in which the BSSID of the AP 20, the MAC of the terminal 30, a channel change request command and other necessary information are inserted into a block template and transmit the block message to the terminal 30.

[0087] In step S607, the terminal 30 receives the block message and attempts to connect to the AP 20 through the changed channel value, and the connection to the AP 20 can be blocked.

[0088] FIG. 7 is a flowchart illustrating an improved sensing device shutdown procedure according to one embodiment of the present invention.

[0089] 7, in step S701, the sensing device 100 may receive a wireless frame. For example, the sensing device 100 may obtain a message transmitted and received during communication between a terminal and an AP.

[0090] In step S703, the sensing device 100 may analyze a message acquired during communication between the terminal and the AP to determine whether the message is a blocking target. In the embodiment, the sensing device 100 may determine whether the message acquired during communication between the terminal and the AP corresponds to a blocking target list provided by the server 200. If the sensing device 100 analyzes information included in the message acquired during communication between the terminal and the AP and determines that the AP or the terminal corresponds to the blocking target list, the sensing device 100 may proceed to step S705. Alternatively, if the sensing device 100 analyzes information included in the message acquired during communication between the terminal and the AP and determines that the AP or the terminal does not correspond to the blocking target list, the sensing device 100 may terminate the step.

[0091] In step S705, the AP or the terminal is included in the blocked list as a result of analyzing the information included in the message acquired during the communication between the terminal and the AP. corresponds to In this case, the sensing device 100 can generate a block message by inserting the BSSID of the AP to which the terminal is to connect, the terminal's MAC, a channel change request command CSA, and other necessary information into the block template.

[0092] In step S707, the sensing device 100 may transmit the generated block message to the terminal.

[0093] Compared to the conventional sensing device shutdown procedure shown in FIG. 3, the sensing device 100 shown in FIG. 7 generates the same block message regardless of whether the connection between the terminal and the AP is 802.11w, thereby reducing the time consumed in determining whether the connection is 802.11w. Furthermore, instead of duplicating the entire wireless communication message of the AP, the sensing device 100 stores a block template consisting of only items used to block the connection between the terminal and the AP, thereby reducing the time required to duplicate the wireless communication message of the AP. Furthermore, the sensing device 100 generates a random channel value by excluding the channel value included in the wireless communication message transmitted by the AP as the channel value to be changed included in the channel change request command. This reduces the time required to determine the frequency band of the wireless communication message transmitted by the AP and the time required to separately generate channel change request commands for each frequency band, compared to the conventional sensing device.

Claims

1. A sensing device for monitoring connections between an access point and a plurality of terminals, a template storage unit configured to store a block template used to generate a wireless communication message for disconnecting a connection between a target terminal among the plurality of terminals and the access point; a sensing control unit configured to acquire a message transmitted and received between the target terminal and the access point, and, if the target terminal is found to be included in a blocking target list provided by a server as a result of analyzing the message, transmit to the target terminal a block message (fake beacon) in which an address of the access point, an address of the target terminal, and a channel change request command requesting a change of a channel for communication between the target terminal and the access point are inserted into the block template; The block template includes an authentication method and an encryption method to be used for connection between the target terminal and the access point, and the block message includes information about the sensing device sending the block message and information about the reason for blocking.

2. The channel change request command The sensing device of claim 1 , further comprising a channel value to be changed, the channel value to be changed being a channel value different from the channel value used by the access point.

3. The channel value to be changed is The sensing device of claim 2 , wherein the channel values ​​are randomly generated.

4. 1. A method for operating a sensing device that monitors connections between an access point and a plurality of terminals, storing a block template used to generate a wireless communication message for disconnecting a connection between a target terminal of the plurality of terminals and the access point; receiving a message sent by the target terminal to the access point, and determining based on the message whether the target terminal is included in a blocked terminal list provided by a server; transmitting a block message (fake beacon) to the target terminal, the block message including an address of the access point and a channel change request command for requesting a change of a channel for communication between the target terminal and the access point inserted into the block template; A method for operating a sensing device, wherein the block template includes an authentication method and an encryption method to be used for connection between the target terminal and the access point, and the block message includes information about the sensing device sending the block message and information about the reason for blocking.

5. The channel change request command The method of claim 4 , further comprising changing a channel value, the changed channel value being a channel value different from the channel value used by the access point.

6. The channel value to be changed is 6. The method of claim 5, wherein the channel values ​​are randomly generated.

7. A sensing device for monitoring connections between an access point and a plurality of terminals, a template storage unit configured to store a block template used to generate a wireless communication message for disconnecting a connection between the plurality of terminals and the access point; a sensing control unit that acquires messages transmitted and received between the plurality of terminals and the access point, and, if the access point is found to be included in a blocking target list provided by a server as a result of analyzing the messages, transmits a block message (fake beacon) to the plurality of terminals, the block message including an address of the access point, addresses of the plurality of terminals, and a channel change request command for requesting a change of a channel for communication between the plurality of terminals and the access point inserted into the block template; The block template includes an authentication method and an encryption method to be used for connection between the terminal and the access point, and the block message includes information about the sensing device sending the block message and information about the reason for blocking.

8. The channel change request command The sensing device of claim 7 , further comprising a channel value to be changed, the channel value to be changed being a channel value different from the channel value used by the access point.

9. The channel value to be changed is The sensing device of claim 8 , wherein the channel values ​​are randomly generated.

Citation Information

Patent Citations

  • JPP7079994B

  • Method for blocking connection in wireless intrusion prevention system and device therefor

    US20180324200A1