Method and apparatus for detecting and blocking illegal devices on wired / wireless networks
The method and apparatus for detecting and blocking unauthorized devices in wired/wireless networks address the limitations of conventional technologies by preemptively identifying and blocking unauthorized devices using MAC address monitoring and control server commands, ensuring enhanced security in communication networks.
Patent Information
- Application Number
- JP2023577733
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-06-18
- Filing Date
- 2022-05-31
- Publication Date
- 2026-01-14
- Estimated Expiration
- 2042-05-31
AI Technical Summary
Conventional illegal device detection and blocking technologies fail to detect and block unauthorized devices in advance by monitoring transmission packets or frames, lacking the ability to preemptively identify and prevent illegal activities.
A method and apparatus for detecting and blocking unauthorized devices in wired/wireless networks by monitoring device information, utilizing a network connection unit to acquire MAC addresses, comparing them against a stored MAC list, and employing control units to block unauthorized devices through ARP spoofing or de-authentication packets based on control server commands.
The system effectively detects and blocks unauthorized devices before any illegal activity occurs, enhancing security in various communication networks by identifying and preventing unauthorized access.
Smart Images

Figure 0007798376000002 
Figure 0007798376000003 
Figure 0007798376000004
Abstract
Description
[Technical Field]
[0001] The present invention relates to a system for detecting unauthorized devices such as unauthorized cameras, and more particularly to a method and apparatus for detecting and blocking unauthorized devices in wired / wireless networks, which can monitor devices in wired and wireless networks and block unauthorized devices when detected. [Background technology]
[0002] Recently, security issues have become a hot topic, with malicious actors installing spy chips in computer peripherals to create wired and wireless backdoors and stealing confidential national documents, corporate technical and sales data, and personal information. The act of installing illegal cameras and secretly recording footage to violate personal privacy or illegally distributing the footage has also emerged as a social problem.
[0003] One prior art for preventing such illegal activities is the "AI Algorithm-Based Illegal Hidden Camera Real-Time Blocking and Alarm Device," published in the Korean Intellectual Property Office Patent Publication under Publication No. 10-2021-0009917. In this published patent, an HMM model application prediction unit performs prediction by applying an HMM model that uses a state transition probability matrix A, an emission probability B, and an initial state probability vector π, an illegal device blocking unit blocks illegal hidden cameras in real time by analyzing traffic and using device load based on current, and an illegal video determination unit identifies illegal videos through packet analysis.
[0004] In addition, the "Wireless LAN Intrusion Detection Method and System" disclosed in Publication No. 10-2014-0071776 involves an intrusion detection sensor detecting packets suspected of being attacks from either the outside or the inside, an intrusion detection AP managing AP-generated frames generated by all APs of the wireless LAN, and a threat management server extracting frames contained in packets suspected of being attacks, and then checking whether the extracted frames are frames present in AP-generated frames to determine whether the packets are attacks. Summary of the Invention [Problem to be solved by the invention]
[0005] Conventional illegal hidden camera blocking devices and wireless LAN intrusion detection technologies either detect illegal images by monitoring the transmission packets of captured images or inspect the frames included in the transmission packets, which means that they have the problem of not being able to detect and block illegal devices in advance.
[0006] The present invention has been proposed to solve the above problems, and an object of the present invention is to provide a method and apparatus for detecting and blocking illegal devices in wired / wireless networks, which can detect unauthorized illegal devices by monitoring device information in wired and wireless networks and block the illegal devices in advance before any illegal activity occurs. [Means for solving the problem]
[0007] An embodiment of the present invention discloses an apparatus for detecting and blocking rogue devices in a wired / wireless network.
[0008] The disclosed illegal device detection and blocking device includes a network connection unit for connecting to a monitored network to acquire a MAC address and blocking a device with the corresponding MAC address according to a control command, a storage means for storing the MAC addresses of illegal devices as a MAC list, and a control unit for receiving an input of a MAC address of a device connected to the monitored network through the network connection unit, comparing the MAC address with the MAC address in the MAC list to detect an illegal device, and controlling the network connection unit to block transmission of the illegal device through the network connection unit when an illegal device is detected.
[0009] The illegal device detection and blocking device may further include an input / output unit for communicating with a control server or an external host device, and the control unit may include a packet pattern information collection unit for collecting IP / MAC addresses of devices connected to the monitored network through the network connection unit, an illegal device detection unit for comparing the collected MAC addresses of the devices with MAC addresses registered in the MAC list of the storage means to detect illegal devices, an illegal device blocking unit for blocking the illegal device from the network when the illegal device is detected by the illegal device detection unit, and an input / output control unit for communicating with the control server through the input / output unit and updating the MAC list of the storage means.
[0010] The wired / wireless network illegal device detection and blocking device determines the MAC address of a device connected to the monitored network, and if it is determined to be a suspicious device, transmits the MAC address of the suspicious device to the control server. When the MAC address of the suspicious device is transmitted, the control server determines whether the suspicious device is an illegal device, and if it is determined to be an illegal device, transmits a blocking command to the illegal device detection and blocking device to block transmissions from the illegal device, and updates the MAC list as necessary.
[0011] If the network is a wired network, the network connection unit is a wired network connection unit that transmits an ARP request to the wired LAN to be monitored and then acquires a MAC address from the ARP table updated through an ARP response packet, and the control unit receives an input of a MAC address of a device connected to the wired network through the wired network connection unit and compares it with the MAC address in the MAC list, and if an illegal device is detected, notifies the control server, and if a blocking command is received from the control server as a text message, blocks the transmission of the corresponding illegal device by ARP spoofing through the wired network connection unit.
[0012] If the network is a wireless network, the network connection unit is a wireless network connection unit that acquires MAC addresses of devices present in the monitored wireless LAN in monitor mode and blocks illegal devices, and the control unit operates the wireless network connection unit in monitor mode, receives MAC addresses from the wireless network connection unit, compares them with MAC addresses in the MAC list, and if an illegal device is detected, notifies the control server, and if a blocking command is received from the control server by text message (SMS), transmits a de-authentication packet through the wireless network connection unit to block transmission of the illegal device.
[0013] Another embodiment of the present invention discloses a method for detecting and blocking rogue devices in a wired / wireless network.
[0014] The disclosed method for detecting and blocking an illegal device includes a step in which an illegal device detection and blocking terminal acquires a MAC address present in a monitored network, a step in which the illegal device detection and blocking terminal compares the acquired MAC address with a MAC address in a stored MAC list to detect an illegal device, and a step in which, when an illegal device is detected, the illegal device detection and blocking terminal notifies a control server, receives a blocking command from the control server by a text message, and blocks transmissions from the corresponding illegal device.
[0015] If the network is a wired network, the illegal device detection and blocking terminal obtains the MAC address of the monitored wired network through an ARP request, and when an illegal device is detected, it notifies the control server. When it receives a blocking command from the control server via a text message, it blocks the transmission of the illegal device through ARP spoofing.
[0016] If the network is a wireless network, the illegal device detection and blocking terminal operates in monitor mode to acquire MAC addresses present in the monitored wireless network, and when an illegal device is detected, it notifies the control server. When a blocking command is received from the control server via a text message, it transmits a de-authentication packet to the wireless network to block transmissions from the illegal device.
[0017] Another embodiment of the present invention discloses an apparatus for detecting and blocking rogue devices in a wired / wireless network.
[0018] The disclosed illegal device detection and blocking device includes a wired network connection unit for acquiring MAC addresses of devices present in a monitored wired LAN, a wireless network connection unit for acquiring MAC addresses of devices present in a monitored wireless LAN, a mobile communication network connection unit for communicating with a control server through a mobile communication network, a storage means for storing a MAC list and firmware, and a control unit that receives MAC addresses of devices connected to the wired network through the wired network connection unit and receives MAC addresses of devices connected to the wireless network through the wireless network connection unit to monitor devices connected to the wired / wireless networks, and transmits an illegal MAC address to the control server through the mobile communication network connection unit when an illegal MAC address is detected, and decodes and processes a text command when a text command is received through the mobile communication network connection unit.
[0019] The control unit includes an input / output control unit that communicates with the control server through the mobile communication network connection unit, interprets and executes a text command when the text command is received, a packet pattern information collection unit that transmits an ARP request to all IP addresses belonging to a subnet of a wired LAN to be monitored through the network connection unit, receives an ARP response packet from a device connected to the wired LAN, updates an ARP table, and operates in a monitor mode to collect MAC addresses of surrounding WiFi devices, an illegal device detection unit that detects wired illegal devices by comparing the MAC addresses of the wired LAN collected through the ARP response packet with the MAC addresses registered in the MAC list of the storage means, and detects wireless illegal devices by comparing the MAC addresses of the wireless LAN collected in the monitor mode with the MAC addresses registered in the MAC list of the storage means, and reports the wired illegal device or wireless illegal device to the control server through the input / output control unit when a blocking command is received from the control server through the input / output control unit, and blocks data transmission of the wired illegal device through an ARP spoofing function or sends a de-authentication packet to the wired illegal device when a blocking command is received from the control server through the input / output control unit. The illegal device blocking unit transmits a packet to block the operation of the illegal wireless device.
[0020] When the input / output control unit receives a text command, it interprets the text command and, if it is a wired / wireless blocking command, transmits it to the illegal device blocking unit; if it is a MAC list update command, it updates the MAC list of the storage means; and if it is a firmware update command, it updates the firmware of the storage means. [Effects of the Invention]
[0021] According to an embodiment of the present invention, an illegal device detection and blocking terminal can be connected to a wired / wireless internal network to detect unauthorized wired / wireless signals and block illegal devices before any illegal activity occurs, and can be applied to the security of various wired / wireless communication networks such as carrier mobile communication networks, military communication networks, and wireless communication networks.
[0022] Furthermore, according to an embodiment of the present invention, the location of the rogue device can be tracked using its signal strength. [Brief explanation of the drawings]
[0023] [Figure 1] 1 is a block diagram of an illicit device detection and blocking apparatus according to the present invention;
[0024] [Figure 2] 2 is a flowchart of a method for detecting and blocking rogue devices according to the present invention;
[0025] [Figure 3] 1 is a schematic diagram illustrating an illicit device detection and blocking system according to an embodiment of the present invention;
[0026] [Figure 4] 1 is a block diagram illustrating the configuration of an illegal device detection terminal according to an embodiment of the present invention;
[0027] [Figure 5] 1 is a diagram illustrating an example of the operation of an illegal camera in a network environment to which an embodiment of the present invention is applied;
[0028] [Figure 6] 1 is a diagram illustrating a method for detecting a wireless illegal camera according to an embodiment of the present invention;
[0029] [Figure 7] 1 is a diagram illustrating a method for blocking a wireless illegal camera according to an embodiment of the present invention;
[0030] [Figure 8] 1 is a diagram illustrating a method for detecting an illegal wired camera according to an embodiment of the present invention;
[0031] [Figure 9] 1 is a diagram illustrating a method for blocking an illegal wired camera according to an embodiment of the present invention;
[0032] [Figure 10] 2 is a flowchart illustrating the overall operation of an illegal device detection and blocking system according to an embodiment of the present invention.
[0033] [Figure 11] 1 is a schematic diagram illustrating an example of an illegal device detection and blocking system configured in an external network according to an embodiment of the present invention;
[0034] [Figure 12] 1 is a schematic diagram illustrating an example of a closed network configuration of an illegal device detection and blocking system according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0035] The present invention and the technical problems achieved by implementing the present invention will become more apparent from the preferred embodiments of the present invention described below. The following examples are merely illustrative for explaining the present invention and are not intended to limit the scope of the present invention.
[0036] FIG. 1 is a block diagram of an apparatus for detecting and blocking illegal devices according to the present invention.
[0037] As shown in FIG. 1, the illegal device detection and blocking apparatus 100 of the present invention comprises a network connection unit 110, a storage unit 120, and a control unit .
[0038] Referring to FIG. 1, the network connection unit 110 connects to a monitored network to acquire a MAC address and blocks devices with the corresponding MAC address according to a control command, and the storage unit 120 stores the MAC addresses of illegal devices as a MAC list.
[0039] The storage means may be configured to include volatile memory such as RAM (Random Access Memory), non-volatile memory such as ROM (Read Only Memory), EPROM (Erasable Programmable ROM), EEPROM (Electrically Erasable Programmable ROM), flash memory, etc., a hard disk, a removable disk, or any form of computer-readable recording medium widely known in the technical field to which the present invention belongs.
[0040] When devices are managed using blacklists and whitelists, a MAC list is a blocking list that stores the MAC addresses of illegal devices that correspond to a type of blacklist. It can be set when manufacturing or installing the illegal device detection and blocking device of the present invention, and can be continuously updated by the control server.
[0041] The control unit 130 receives MAC addresses of devices connected to the monitored network through the network connection unit 110, compares the MAC addresses with those in the MAC list of the storage unit 120, detects illegal devices, and if an illegal device is detected, notifies the control server through the mobile communication unit, receives a blocking command from the control server by a text message (MMS, SMS, etc.), and then blocks transmission from the illegal device through the network connection unit 110. The control unit 130 may be configured to include a CPU (Central Processing Unit), MPU (Micro Processor Unit), MCU (Micro Controller Unit), GPU (Graphic Processing Unit), or any other type of processor widely known in the technical field of the present invention.
[0042] FIG. 2 is a flowchart of the method for detecting and blocking rogue devices according to the present invention.
[0043] Referring to FIG. 2, in the MAC list recording step (S1), a MAC list of devices that are predicted to be illegal devices is obtained and recorded in the storage means 120.
[0044] In the packet information collection step (S2), the illegal device detection and blocking device collects packets present in the monitored network and extracts MAC addresses.
[0045] In the illegal device detection step (S3), the illegal device detection and blocking device compares the extracted MAC address with MAC addresses in a stored MAC list to detect illegal devices.
[0046] In the control server linkage step (S4), the illegal device detection and blocking device transmits the detected illegal device information (MAC address, detection distance, etc.) to the control server using the mobile communication network, and the control server transmits the illegal device blocking command to the illegal device detection and blocking device using a text message (MMS, SMS).
[0047] In the illegal device blocking step (S5), the illegal device detection and blocking device blocks transmission from the illegal device.
[0048] The apparatus and method of the present invention can be realized through the following specific embodiments.
[0049] FIG. 3 is a schematic diagram illustrating an illicit device detection and blocking system according to an embodiment of the present invention.
[0050] As shown in FIG. 3, the illegal device detection and blocking system according to an embodiment of the present invention may comprise an illegal device detection terminal 100 that is installed in a wireless LAN (LAN) 10 and a wired LAN (LAN) 20 environment and connected to a control server 200 via a mobile communication network 30 to detect illegal devices present in the wireless LAN (LAN) 10 and the wired LAN (LAN) 20 and block the connection, and a control server 200 that collectively manages the distributed illegal device detection and blocking terminals 100.
[0051] 3, a wired LAN 20 is a local area network (LAN) connected via a cable and operates according to the Ethernet or IEEE 802.3 protocol. Legitimate wired terminals are connected to the wired LAN, and wired illicit devices 60, which are the targets of monitoring in the present invention, may also be connected to the wired LAN.
[0052] The wireless LAN (LAN) 10 is a wireless LAN that operates according to the IEEE 802.11 protocol and is also called WiFi. The wireless LAN is connected to legitimate wireless terminals, and wireless illicit devices 50 that are the subject of monitoring in the present invention may also be connected to it.
[0053] The mobile communication network 30 is a 3G, 4G (LTE), or 5G communication network that can be accessed from a mobile terminal such as a mobile phone or a smartphone through a base station 31, and can identify a subscriber through a USIM chip, and a predetermined communication fee is charged by a communication carrier when used. In an embodiment of the present invention, a control server 200 can be connected to the illegal device detection and blocking terminal 100 through the mobile communication network 30.
[0054] The illegal device detection and blocking terminal 100 is installed in a wired LAN 20 and a wireless LAN 10 environment, and is connected to the control server 200 through a mobile communication network 30 to detect illegal devices present in the wired LAN 20 and the wireless LAN 10, report the detected illegal devices to the control server 200, and block the illegal devices according to a blocking command from the control server 200. In the embodiment of the present invention, the illegal devices are devices recorded in a MAC list, and the MAC address of the corresponding device is transmitted to the control server 200 for a determination, and if the device is determined to be an illegal device and a blocking command is received, the device is blocked.
[0055] The illegal device detection and blocking terminal 100 monitors illegal devices in monitor mode and blocks illegal devices according to the command of the control server 200. Here, the monitor mode is a wireless LAN operation mode in which a WiFi terminal can collect all wireless frames received through an antenna even if it is not connected to an AP.
[0056] In addition, the illegal device detection and blocking terminal 100 scans the network and then transmits the MAC address, detection distance, etc. to the control server 200 so that they can be registered in the DB 200a.
[0057] The control server 200 has a database 200a, which stores a version file that stores firmware (F / W) version and MAC list version information of the illegal device detection and blocking terminal 100, as well as MAC list and firmware (F / W) data.
[0058] The control server 200 accepts users who have installed the illegal device detection and blocking terminal 100 as members and registers the installation location and various information of the illegal device detection and blocking terminal 100 in the database 200a. Specifically, the control server 200 has functions for selecting devices, inputting installation locations and displaying maps, displaying a searched MAC list, checking the MAC list for suspicious devices and then registering and updating the MAC list when blocking, and uploading version files, firmware files, and MAC list files. It can also provide an administrator mode screen, a member information management screen, and a member device management screen. The searched MAC list records information such as sensitivity, data volume, and whether or not there is suspicion. Here, a suspicious device refers to a device that the illegal device detection and blocking terminal 100 identifies as a suspicious device through a predetermined procedure. If the control server 200 ultimately determines that a suspicious device reported by the illegal device detection and blocking terminal 100 is an illegal device, it can register the suspicious device in the MAC list and block it.
[0059] In addition, the control server 200 can transmit a text command to the corresponding illegal device detection and blocking terminal 100 through a text message (MMS) command as shown in Table 1 below.
[0060] [Table 1]
[0061] FIG. 4 is a block diagram illustrating the configuration of an illegal device detection and blocking terminal according to an embodiment of the present invention.
[0062] As shown in FIG. 4, the illegal device detection and blocking terminal 100 according to an embodiment of the present invention comprises a network connection unit 110 consisting of a wireless network connection unit 112 and a wired network connection unit 114, a control unit 130 consisting of a packet pattern information collection unit 131, an illegal device detection unit 132, an illegal device blocking unit 133, and an input / output control unit 134, a storage means 120 storing a MAC list 122, and an input / output unit 140 consisting of a control server input / output unit 141 and a device input / output unit 142.
[0063] Referring to FIG. 4, the wired network connection unit 114 is for connecting to the wired LAN 20 to be monitored and acquiring the MAC addresses of devices present on the wired network.
[0064] The wireless network connection unit 112 is for connecting to the monitored wireless LAN 10 and acquiring the MAC addresses of devices present in the wireless network.
[0065] The packet pattern information collection unit 131 transmits ARP requests to all IP addresses belonging to the subnet of the wired LAN 20 to be monitored through the wired network connection unit 114, receives ARP response packets from devices connected to the wired LAN, updates the ARP table, and operates in monitor mode through the wireless network connection unit 112 to collect MAC addresses of surrounding WiFi devices while not connected to an AP.
[0066] The illegal device detection unit 132 detects wired illegal devices 60 by comparing the MAC addresses of wired LANs collected through ARP response packets with the MAC addresses registered in the MAC list 122 of the storage means, and detects wireless illegal devices 50 by comparing the MAC addresses of wireless LANs collected in monitor mode with the MAC addresses registered in the MAC list 122 of the storage means.
[0067] When the rogue device detection unit 132 detects a wired rogue device 60, the rogue device blocking unit 133 blocks data transmission from the wired rogue device using the ARP spoofing function. Here, ARP spoofing refers to an attack method in which a PC's MAC address is spoofed to match the MAC address of another PC on the same network to intercept information between the PC and the server. Furthermore, when the rogue device detection unit 132 detects a wireless rogue device 50, it transmits a de-authentication packet to block the operation of the wireless rogue device. Here, de-authentication refers to blocking a device using a Disassociation frame (subtype: 1010) or a Deauthentication frame (subtype: 1100), which are types of 802.11 management frames.
[0068] The input / output control unit 134 communicates with the control server 200 through the control server input / output unit 141 to process operations such as updating the MAC list 122 of the storage unit 120 or updating firmware. That is, when the input / output control unit 134 detects an illegal device, it transmits illegal device information to the control server 200 through the control server input / output unit 141, and when a character is received through the control server input / output unit 141, it processes the corresponding character command. For example, when a MAC list update character is received, it retrieves the MAC list from the control server 200 and performs a blocking operation. Also, when a version file update character (firmware version or MAC list version) is received, it receives and updates the MAC list data or firmware data.
[0069] The control server input / output unit 141 is a communication means for communicating with the control server 200, and in the embodiment of the present invention, can communicate with the control server 200 through the mobile communication network 30.
[0070] In this embodiment of the present invention, in order to reduce communication costs, data communication is opened and used only when an illegal device is detected in transmission to the control server 200 using the mobile communication network 30, and data communication is closed after transmission. As data communication starts from the terminal 100, if there is information to be transmitted from the control server, as shown in Table 1 above, a corresponding command is transmitted in the form of a text message (SMS, MMS) through the mobile communication network 30, and when the illegal device detection and blocking terminal 100 receives the text command, it decodes it and performs the relevant operation.
[0071] FIG. 5 is a diagram illustrating an example of the operation of an illegal camera in a network environment to which an embodiment of the present invention is applied.
[0072] An example of a network environment to which an embodiment of the present invention is applied is shown in FIG. 5, in which wireless pirate cameras 50-1 and 50-2 are connected to an access point 11 via a wireless LAN 10, a wired pirate camera 60-1 is connected to a gateway 21 via a wired LAN 20, an pirate device detection and blocking terminal 100 is connected to wired / wireless networks 10 and 20 and a mobile communication network 30, and a control server 40 and an pirate device viewing device 70 are connected via the Internet 40.
[0073] 5, when the illegal cameras are operating in this state, the illegal images captured by the wireless illegal cameras 50-1 and 50-2 are transmitted to the AP 11 via the wireless LAN 10, and the illegal images transmitted to the AP 11 are transmitted to the illegal image viewing terminal 70 via the Internet 40. Also, the illegal images captured by the wired illegal camera 60-1 are transmitted to the gateway 21 via the wired LAN 20, and then transmitted to the illegal image viewing terminal 70 via the Internet 40. As a result, the illegal images can be viewed on the illegal image viewing device 70.
[0074] FIG. 6 is a diagram illustrating a method for detecting an illegal wireless camera according to an embodiment of the present invention, and FIG. 7 is a diagram illustrating a method for blocking an illegal wireless camera according to an embodiment of the present invention.
[0075] Referring to FIG. 6, the illegal device detection and blocking terminal 100 switches to a monitoring mode, receives wireless packets from devices connected to the wireless LAN 10, extracts the MAC addresses, and compares the MAC addresses with those in the MAC list to detect the illegal wireless cameras 50-1 and 50-2. When the illegal wireless cameras 50-1 and 50-2 are detected, as shown in FIG. 7, the illegal wireless cameras 50-1 and 50-2 are blocked from connecting to the access point 11 by transmitting a de-authentication packet to the wireless LAN 10.
[0076] FIG. 8 is a diagram illustrating a method for detecting illegal wired cameras according to an embodiment of the present invention, and FIG. 9 is a diagram illustrating a method for blocking illegal wired cameras according to an embodiment of the present invention.
[0077] Referring to FIG. 8, the illegal device detection and blocking terminal 100 requests an ARP request from the wired LAN 20, then receives an ARP Reply from a device connected to the wired LAN 20, extracts the MAC address, and compares it with the MAC address in the MAC list to detect the wired illegal camera 60-1. If the wired illegal camera 60-1 is detected, as shown in FIG. 9, the illegal device detection and blocking terminal 100 transmits an ARP Reply (spoofing) packet to the wired LAN 20 to block the wired illegal camera 60-1 from connecting to the gateway.
[0078] FIG. 10 is a flowchart illustrating the overall operation of the illegal device detection and blocking system according to an embodiment of the present invention.
[0079] Referring to FIG. 10, a user who has installed the illegal device detection and blocking terminal 100 according to an embodiment of the present invention registers as a member in the control server 200, registers the installation location of the illegal device detection and blocking terminal 100 and various information (such as the product serial number), and stores various lists such as a MAC list, an AP list, and a firmware list to perform initial configuration (S101).
[0080] Thereafter, when a reset command is received or the power is turned on (Power On Reset), the illegal device detection and blocking terminal 100 activates the wired network connection unit 114 and the wireless network connection unit 112 to activate the wired / wireless LAN (S102).
[0081] Next, the firmware version and MAC list version are checked in the version file of the control server 200 (S103).
[0082] If a new firmware version or a new MAC list version is detected, the illegal device detection and blocking terminal 100 can update the firmware or MAC list by downloading new firmware data or MAC list data from the control server 200 through the mobile communication network 30 (S104). If the firmware data is updated, the entire process starts anew through rebooting.
[0083] As described above, after checking for updates to the MAC list and firmware version at the initial stage of operation, the illegal device detection and blocking terminal 100 operates in a monitor (WiFi monitor) mode to receive wireless packets from devices connected to the wireless LAN 10, extracts the MAC address, and compares it with the MAC address in the MAC list to detect illegal wireless devices. If an illegal wireless device is detected, the control server 200 transmits the corresponding information to the control server 200 (S106-S109). If the control server 200 receives suspicious device information from the illegal device detection and blocking terminal 100, the control server 200 registers the suspicious device in the MAC list, generates an illegal device blocking command according to a predetermined procedure, and transmits it to the corresponding illegal device detection and blocking terminal 100 via a text message (MMS, SMS). After receiving the blocking command from the control server 200 via a text message (SMS), the illegal device detection and blocking terminal 100 transmits a de-Authentic packet to the wireless LAN 10 to block the illegal wireless device (S110-S112). To explain in more detail, the illegal device detection and blocking terminal 100 in the wireless LAN captures the MAC address in monitor mode, then checks whether there is an illegal device in address 2 and address 3 of the MAC header, and if an illegal device is detected, transmits the MAC address of the suspicious device to the control server 200 via the mobile communication network 30.
[0084] Next, for monitoring and blocking in the wired LAN 20, the illegal device detection and blocking terminal 100 refers to the subnet mask and sends an ARP request to all IPs in the local network (subnet), then receives an ARP response packet and updates the ARP table, checks whether there is a wired illegal device among the MAC addresses in the updated ARP table, and if an illegal device is detected, transmits the MAC address of the suspicious device to the control server 200 via the mobile communication network 30 (S113-S118).
[0085] When the control server 200 receives suspicious device information from the illegal device detection and blocking terminal 100, it registers it in the MAC list, generates an illegal device blocking command according to a predetermined procedure, and transmits it to the corresponding illegal device detection and blocking terminal 100 via a text message (MMS, SMS).In response, the illegal device detection and blocking terminal 100 blocks the corresponding wired illegal device using ARP spoofing (S119-S121).
[0086] Meanwhile, the control server 200 can generate a text (MMS or SMS) command as shown in Table 1 above as needed and transmit it to the corresponding illegal device detection and blocking terminal 100 via the mobile communication network 30, and when the illegal device detection and blocking terminal 100 receives the text (MMS, SMS) command, it can decode and process the corresponding text (MMS, SMS) command.
[0087] 11 is a schematic diagram illustrating an example of an illegal device detection and blocking device configured in an external network according to an embodiment of the present invention. In the embodiment of FIG. 11, a control server 200 is connected to the external Internet to which many users can connect, and illegal device detection and blocking terminals 100 installed in the internal network of each local network can be centrally integrated and managed.
[0088] Referring to FIG. 11, the internal network is formed by a wired LAN 20 including a switch 21 and a wireless LAN 10, and the external network is the ordinary Internet 40, and the internal network is connected to the external network through a gateway 21.
[0089] A normal device 60G, a wired illegal camera 60-1, and a wired illegal device 60-2 are installed in a wired LAN 20 of the internal network, and a wireless illegal camera 50-1 and a wireless illegal device 50-3 are installed in a wireless LAN 10 of the internal network, and the wireless LAN 10 is connected to a switch 21 via an AP 11.
[0090] The illegal device detection and blocking terminal 100 is installed in an internal network so that it can be connected to both a wired LAN 20 and a wireless LAN 10, and the control server 200 is connected to the external network, the Internet 40, so that multiple users can access it. In addition, the control server 200 stores information on MAC addresses of normal users and MAC addresses of illegal devices in a database 200a.
[0091] When the illegal device detection and blocking terminal 100 is powered on, it checks the MAC list version and firmware version and performs a series of MAC list update procedures and firmware update procedures.
[0092] After completing the version update procedure, the illegal device detection and blocking terminal 100 performs the illegal device detection and blocking procedure on the wired LAN 20 and the illegal device detection and blocking procedure on the wireless LAN 10 .
[0093] First, to examine the procedure for detecting and blocking illegal devices on a wired LAN, the illegal device detection and blocking terminal 100 refers to the subnet mask and sends an ARP request to all IPs in the subnet of the wired LAN 20, then receives an ARP response packet and updates the ARP table. It checks whether there is an illegal device among the MAC addresses in the updated ARP table, and if an illegal device is detected, it transmits the MAC address of the suspicious device to the control server 200.
[0094] When the control server 200 receives the MAC address of a suspicious device, it registers it in the MAC list and then transmits a MAC list update text command to the corresponding illegal device detection and blocking terminal 100 to block the illegal device. Accordingly, the corresponding illegal device detection and blocking terminal 100 blocks the illegal device using ARP spoofing.
[0095] The control server 200 can also transmit various management information and operation information for the illegal device to the user's mobile terminal 80 using the external network, the Internet 40 or the mobile communication network 30 .
[0096] Meanwhile, if we take a closer look at the illegal device detection and blocking procedure on a wireless LAN, the illegal device detection and blocking terminal 100 operates WiFi in monitor mode to capture the MAC address, and then checks whether there is an illegal device in address 2 and address 3 of the MAC header. If an illegal device is detected, it transmits the MAC address of the suspicious device to the control server 200.
[0097] When the control server 200 receives the MAC address of the suspicious device, it registers it in the MAC list and then transmits a MAC list update text command to the corresponding illegal device detection and blocking terminal 100 to block the illegal device. Accordingly, the corresponding illegal device detection and blocking terminal 100 transmits a de-Authenticate packet to block the operation of the illegal device.
[0098] According to this embodiment of the present invention, the control server 200 can be installed in an external network, and the illegal device detection and blocking terminals 100 of various users that are installed in the internal network of each local network can be centrally integrated and managed.
[0099] 12 is a schematic diagram illustrating an example in which an illegal device detection and blocking device according to an embodiment of the present invention is configured in a closed network. That is, FIG. 12 illustrates an example in which an internal network operator installs a control server 200 operated by himself in the internal network and manages his own illegal device detection and blocking terminal 100 installed in the internal network in a closed manner.
[0100] Referring to FIG. 12, the internal network is formed by a wired LAN 20 including a switch 21 and a wireless LAN 10, and the external network is the ordinary Internet 40, and the internal network is connected to the external network through a gateway 21.
[0101] A normal device 60G, a wired illegal camera 60-1, and a wired illegal device 60-2 are installed in a wired LAN 20 of the internal network, and a wireless illegal camera 50-1 and a wireless illegal device 50-3 are installed in a wireless LAN 10 of the internal network, and the wireless LAN 10 is connected to a switch 21 via an AP 11.
[0102] The illegal device detection and blocking terminal 100 is installed in an internal network so that it can be connected to both a wired LAN 20 and a wireless LAN 10, the control server 200 is connected to the internal network so that it can only be connected to the internal network, and a firmware update server 300 is connected to the external network, the Internet 40, for upgrading the firmware of the illegal device detection and blocking terminal 100. The firmware update server 300 can be operated by the manufacturer of the illegal device detection and blocking terminal, and the DB 200a of the control server 200 stores information on MAC addresses of normal users and MAC addresses of illegal devices.
[0103] In this structure, communication between the illegal device detection and blocking terminal 100 and the control server 200 can be performed through the mobile communication network 30.
[0104] In this embodiment of a closed network, the control server 200 is connected to the internal network and manages the illegal device detection and blocking terminal 100 of the internal network in a closed manner, and the MAC list version is upgraded through the control server 200 of the internal network, but the firmware version management is upgraded through the firmware update server 300 of the external network. Except for this, the operation between the illegal device detection and blocking terminal 100 and the control server 200 is the same as the example installed in the external network in Figure 11, so further explanation will be omitted.
[0105] Although the present invention has been described above with reference to one embodiment shown in the drawings, those skilled in the art will recognize that various modifications and equivalent alternative embodiments are possible.
Claims
1. An illegal device detection and blocking device that is additionally installed in an existing monitored network that has already been installed in order to detect and block illegal devices, a network connection unit for connecting to a monitored network, acquiring a MAC address, and blocking a device with the MAC address according to a control command; a storage means for storing MAC addresses of illegal devices as a MAC list; a control unit that receives a MAC address of a device connected to the monitored network through the network connection unit, compares the MAC address with the MAC address in the MAC list to detect an illegal device, and controls the network connection unit to block transmission of the illegal device through the network connection unit when an illegal device is detected; and Input / output section for communicating with the control server and external host devices Including, The control unit a packet pattern information collecting unit that collects IP / MAC addresses of devices connected to the monitored network through the network connection unit; an illegal device detection unit that compares the collected MAC addresses of the devices with MAC addresses registered in the MAC list of the storage means to detect illegal devices; an illegal device blocking unit that blocks an illegal device from a network when the illegal device is detected by the illegal device detection unit; an input / output control unit that communicates with a control server through the input / output unit to update the MAC list of the storage means; The illegal device detection and blocking device for the monitored network includes: The MAC address of a device connected to a monitored network is determined, and if the device is determined to be a suspicious device, the MAC address of the suspicious device is transmitted to a control server. When the MAC address of the suspicious device is transmitted, the control server determines whether the suspicious device is an illegal device, and if the suspicious device is determined to be an illegal device, transmits a blocking command to the illegal device detection and blocking device to block transmissions from the illegal device, and updates the MAC list as necessary. If the network is a wired network, The network connection unit is a wired network connection unit for transmitting an ARP request to a monitored wired LAN and then acquiring a MAC address from an ARP table updated through an ARP response packet; The control unit receives an input of a MAC address of a device connected to the wired network through the wired network connection unit, compares the MAC address with the MAC address in the MAC list, and notifies a control server when an illegal device is detected, and blocks transmission of the illegal device by ARP spoofing through the wired network connection unit when a blocking command is received from the control server as a text message, If the network is a wireless network, The network connection unit is a wireless network connection unit for obtaining MAC addresses of devices present in a monitored wireless LAN in a monitor mode and blocking illegal devices; The control unit operates the wireless network connection unit in a monitor mode, receives a MAC address from the wireless network connection unit, compares the MAC address with the MAC address in the MAC list, and notifies a control server when an illegal device is detected; and when a blocking command is received from the control server by a text message (SMS), transmits a de-authenticate packet through the wireless network connection unit to block transmission of the illegal device; communication between the illegal device detection and blocking device and the control server is performed via a mobile communication network, the illegal device detection and blocking device transmits data to the control server via data communication and closes the data communication after the transmission, the control server transmits an instruction using a text message via the mobile communication network, and the illegal device detection and blocking device receives the text message and decodes it to perform an operation; The rogue device detection and blocking device of a wired / wireless network, wherein the master list of the rogue device detection and blocking device is supplied by the control server and is upgradable, and the firmware of the rogue device detection and blocking device is supplied via a firmware update server of an external network and is upgradable.
2. A method for detecting and blocking rogue devices, which is additionally connected to an existing monitored network that has already been installed, in order to detect and block rogue devices, comprising: A step in which an illegal device detection and blocking terminal connects to a monitored network and acquires a MAC address present in the monitored network; The illegal device detection and blocking terminal compares the acquired MAC address with the MAC address in the stored MAC list to detect the illegal device; and When an illegal device is detected, the illegal device detection and blocking terminal notifies the control server, receives a blocking command from the control server by a text message, and blocks transmission of the corresponding illegal device; If the monitored network is a wired network, The illegal device detection and blocking terminal acquires a MAC address present in the monitored wired network through an ARP request, notifies a control server when an illegal device is detected, and blocks transmission of the illegal device through ARP spoofing when a blocking command is received from the control server as a text message. If the monitored network is a wireless network, The illegal device detection and blocking terminal operates in a monitor mode to acquire a MAC address present in the monitored wireless network, and when an illegal device is detected, it notifies the control server. When a blocking command is received from the control server as a text message, it transmits a de-authenticate packet to the wireless network to block transmission of the corresponding illegal device. communication between the illegal device detection and blocking terminal and the control server is performed via a mobile communication network, the illegal device detection and blocking terminal transmits data to the control server via data communication and closes the data communication after transmission, the control server transmits a command using a text message via the mobile communication network, and the illegal device detection and blocking terminal receives the text message and decodes it to perform an operation; The MAC list of the illegal device detection and blocking terminal is provided by the control server and is upgradable, and the firmware of the illegal device detection and blocking terminal is provided via a firmware update server in an external network and is upgradable.
3. An illegal device detection and blocking device that is additionally installed in an existing monitored network that has already been installed in order to detect and block illegal devices, a wired network connection unit for connecting to a wired LAN to be monitored and obtaining MAC addresses of devices present on the wired LAN to be monitored; a wireless network connection unit for connecting to a monitored wireless LAN and acquiring MAC addresses of devices present on the monitored wireless LAN; a mobile communication network connection unit for communicating with the control server through a mobile communication network; a storage means for storing a MAC list and firmware; and a control unit for receiving a MAC address of a device connected to a wired network through the wired network connection unit, receiving a MAC address of a device connected to a wireless network through the wireless network connection unit, and monitoring devices connected to the wired / wireless network; if an illegal MAC address is detected, transmitting the address to a control server through the mobile communication network connection unit; and if a text command is received through the mobile communication network connection unit, decoding the text command and processing the text command; The control unit an input / output control unit that communicates with a control server through the mobile communication network connection unit and, upon receiving a text command, interprets and executes the text command; a packet pattern information collecting unit that transmits an ARP request to all IP addresses belonging to a subnet of a wired LAN to be monitored through the wired network connection unit or the wireless network connection unit, receives an ARP response packet from a device connected to the wired LAN, updates an ARP table, and collects MAC addresses of surrounding Wi-Fi devices while operating in a monitor mode; an illegal device detection unit that detects wired illegal devices by comparing MAC addresses of wired LANs collected through ARP response packets with MAC addresses registered in the MAC list of the storage means, and detects wireless illegal devices by comparing MAC addresses of wireless LANs collected in monitor mode with MAC addresses registered in the MAC list of the storage means, and reports the detection of wired illegal devices or wireless illegal devices to the control server through the input / output control unit; and an illegal device blocking unit that blocks data transmission from a wired illegal device through an ARP spoofing function or blocks operation of a wireless illegal device by transmitting a de-authenticate packet when a blocking command is received from the control server through the input / output control unit, The input / output control unit When a text command is received, the corresponding text command is interpreted, and if it is a wired / wireless blocking command, the corresponding text command is transmitted to the illegal device blocking unit, if it is a MAC list update command, the MAC list of the storage means is updated, and if it is a firmware update command, the firmware of the storage means is updated; communication between the illegal device detection and blocking device and the control server is performed via a mobile communication network, the illegal device detection and blocking device transmits data to the control server via data communication and closes the data communication after the transmission, the control server transmits an instruction using a text message via the mobile communication network, and the illegal device detection and blocking device receives the text message and decodes it to perform an operation; The rogue device detection and blocking device of a wired / wireless network, wherein the master list of the rogue device detection and blocking device is supplied by the control server and is upgradable, and the firmware of the rogue device detection and blocking device is supplied via a firmware update server of an external network and is upgradable.
Citation Information
Patent Citations
Unauthorized use monitoring system, unauthorized use monitoring / alarming apparatus, and unauthorized use monitoring method
JP2005318037A
Network supervising system, network supervising server, and network supervising program
JP2011004135A
Router apparatus, and method of initializing router apparatus
JP2012049591A
Method for handing over between base stations
JP2014171128A
Firmware update system and update control method
JP2016018462A